UODO (Poland) - DKN.5131.5.2025
Poland's UODO fines controller and processor for data breach due to inadequate security measures and oversight.
Summary
Poland's data protection authority (UODO) issued fines totaling €7,800 (PLN 33,500) following a January 2023 data breach where a work laptop was stolen from a parked car, exposing landowners' personal data including names, addresses, and ID numbers. The controller was fined €4,900 for failing to implement appropriate technical and organisational security measures and conduct adequate risk assessments, while the processor was fined €2,900 for insufficient security controls on external devices and failure to assist the controller with GDPR compliance. The DPA found violations of Articles 24, 25, 28, and 32 GDPR, determining that inadequate encryption and device protection measures directly enabled the breach.
Full text
Help UODO (Poland) - DKN.5131.5.2025: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 13:26, 30 July 2026 view source Av (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators107 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 13:26, 30 July 2026 UODO - DKN.5131.5.2025 Authority: UODO (Poland) Jurisdiction: Poland Relevant Law: Article 24(1) GDPR Article 25(1) GDPR Article 28(1) GDPR Article 28(3) GDPR Article 32(1) GDPR Article 32(2) GDPR Type: Investigation Outcome: Violation Found Started: 05.03.2025 Decided: 25.05.2026 Published: 29.07.2026 Fine: 21000.0 PLN Parties: n/a National Case Number/Name: DKN.5131.5.2025 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Polish Original Source: UODO (in PL) Initial Contributor: av The DPA fined the controller PLN 21,000 (€4,900) and the processor PLN 12,500 (€2,900) following a data breach due to a failure to implement appropriate technical and organisational measures and insufficient processor oversight. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’) personal data to a specialised entity established for this purpose (the processor). In January 2023, a work laptop belonging to an employee of the processor was stolen from the trunk of a car parked in a parking garage. This resulted in a breach of confidentiality of the data subjects’ personal data, including names, addresses, ID numbers, and land registry numbers. The controller notified this data breach to the DPA later in January 2023. The DPA conducted an investigation and initiated administrative proceedings regarding the GDPR compliance of the processing operations carried out by the controller and the processor in March 2025. Holding The DPA issued the controller a fine of PLN 21,000 (€4,900) and the processor a fine of PLN 12,500 (€2,900). First, the DPA held that the controller had violated Articles 24(1), 25(1), 32(1), and 32(2) GDPR by failing to implement appropriate technical and organisational measures to ensure the security of personal data processing – the controller had failed to demonstrate that it had conducted a thorough risk assessment in a manner that would have allowed for the selection of adequate security measures. These infringements resulted in the violations of the principles of integrity, confidentiality and accountability laid down in Articles 5(1)(f) and 5(2) GDPR. Second, the DPA found that the controller had also violated Article 28(1) GDPR: it had failed to verify the adequacy of the technical and organisational measures implemented by the processor. Finally, the DPA came to the conclusion that the processor had infringed Articles 32(1) and 32(2) GDPR in conjunction with Articles 28(3)(c) and 28(3)(f) GDPR. The DPA held that the processor had failed to assist the controller in fulfilling its obligations and contributed to the controller’s GDPR violations. Unlike the controller, the processor had conducted a risk assessment covering the processing operations at issue; however, the processor had not implemented security measures to protect data stored on laptops used outside of its organisation, such as encryption. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Polish original. Please refer to the Polish original for more details. Warsaw, May 25, 2026 Not yet final Decision DKN.5131.5.2025 Pursuant to Article 104 § 1 of the Act of June 14, 1960, Code of Administrative Procedure (Journal of Laws of 2025, item 1691), Article 7(1) and (2), Article 60, Article 102(1)(1) and (3) of the Act of May 10, 2018, on data protection (Journal of Laws of 2019, Item 1781, as amended) and Article 57(1)(a) and (h), Article 58(2)(i), Article 83(1)–(3), and Article 83(4)(a) in conjunction with Article 24(1), Article 25(1), Article 28(1) and (3), and Article 32(1) and (2), as well as Article 83(5)(a) in conjunction with Article 5(1)(f) and Article 5( 2 of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ EU L 119 of May 4, 2016, p. 1, OJ EU L 127 of May 23, 2018, p. 2, and Official Journal of the EU L 74 of March 4, 2021, p. 35) (hereinafter also referred to as “Regulation 2016/679”), following an ex officio administrative proceeding concerning a data breach by the County Administrator (…) (ul. (…), (…)-(…) Z.) and by R. (…) in A. ((…)-(…) A., ul. (…), previously operating under the name M. (…) in A. ((…)-(…) A., ul. (…),) the President of the Personal Data Protection Office 1) having found a violation by the County Administrator of (…) (ul. (…), (…)-(…) Z.) of Article 24(1), Article 25(1), Article 28(1), and Article 32(1) and (2) of Regulation 2016/679, consisting of: a) failure to implement appropriate technical and organizational measures based on a risk assessment that takes into account the state of the art, the cost of implementation, the nature, scope, context, the processing purposes, and the risk to the rights or freedoms of natural persons, to ensure the security of data processing in connection with the use of laptops and the protection of data subject rights, b) failure to implement appropriate technical and organizational measures to ensure the regular testing, measurement, and evaluation of the effectiveness of technical and organizational measures designed to ensure the security of personal data processed using portable computers, in particular with regard to vulnerabilities, errors, updates, and their potential consequences, as well as the measures taken to minimize the risk of their occurrence, c) failure to verify whether the processor provides sufficient guarantees that appropriate technical and organizational measures have been implemented so that the processing complies with the requirements of Regulation 2016/679 and protects data subject rights, resulting in a breach of the principle of confidentiality (Article 5(1)(f) of Regulation 2016/679) and the principle of accountability (Article 5(2) of Regulation 2016/679), imposes on the County Administrator (…) (ul. (…), (…)-(…) Z.), for violating Article 5(1)(f), Article 5(2), Article 25(1), Article 28(1), and Article 32(1) and (2) of Regulation 2016/679, an administrative fine in the amount of 21,000 PLN (in words: twenty-one thousand zlotys); 2) finding that R. (…) in A. ((…)-(…) A., (… Street)) of Art 32(1) and (2) in conjunction with Art 28(3)(c) and (f) of Regulation 2016/679, consisting of: a) failure to implement appropriate technical and organizational measures ensuring a level of security appropriate to the risk associated with data processing in connection with the use of laptops, in order to protect the personal data stored therein, including protection against accidental loss, destruction, or damage, as well as disclosure to unauthorized persons, b) failure to implement appropriate technical and organizational measures to achieve the purpose of regular testing, measurement, and evaluation of the effectiveness of technical and organizational measures designed to ensure the security of personal data processed using portable computers, imposes on R. (…) in A. ((…)-(…) A., ul. (…)), for violating Article 32(1) and (2) in conjunction with Article 28(3)(c) and (f) of Regulation 2016/679, an administrative fine in the amount of 12,500 PLN (in words: twelve thousand five hundred zlotys). Statem