Back to Feed
PolicyAug 5, 2026

UODO (Poland) - DKN.5131.5.2025

Poland's DPA fines controller PLN 21,000 and processor PLN 12,500 for data breach.

Summary

Poland's DPA has fined a provincial government unit (controller) PLN 21,000 (€4,900) and a specialized entity (processor) PLN 12,500 (€2,900) following a data breach. The breach occurred when a work laptop containing personal data was stolen from the processor's employee, violating confidentiality. The DPA found the controller failed to implement adequate technical and organizational measures and did not sufficiently oversee the processor, while the processor failed to assist the controller and contributed to the violations.

Full text

Help UODO (Poland) - DKN.5131.5.2025: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 13:29, 30 July 2026 view sourceAv (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators113 edits Tag: Visual edit← Older edit Latest revision as of 07:22, 5 August 2026 view source Fm (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators113 editsmTag: Visual edit Line 100: Line 100: }}}} The DPA fined the controller PLN 21,000 (€4,900) and the processor PLN 12,500 (€2,900) following a data breach due to a failure to implement appropriate technical and organisational measures and insufficient processor oversight.The DPA fined a controller PLN 21,000 (€4,900) and a processor PLN 12,500 (€2,900) following a data breach due to a failure to implement appropriate technical and organisational measures and insufficient processor oversight. == English Summary ==== English Summary == Latest revision as of 07:22, 5 August 2026 UODO - DKN.5131.5.2025 Authority: UODO (Poland) Jurisdiction: Poland Relevant Law: Article 24(1) GDPR Article 25(1) GDPR Article 28(1) GDPR Article 28(3) GDPR Article 32(1) GDPR Article 32(2) GDPR Type: Investigation Outcome: Violation Found Started: 05.03.2025 Decided: 25.05.2026 Published: 29.07.2026 Fine: 21000.0 PLN Parties: n/a National Case Number/Name: DKN.5131.5.2025 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Polish Original Source: UODO (in PL) Initial Contributor: av The DPA fined a controller PLN 21,000 (€4,900) and a processor PLN 12,500 (€2,900) following a data breach due to a failure to implement appropriate technical and organisational measures and insufficient processor oversight. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’) personal data to a specialised entity established for this purpose (the processor). In January 2023, a work laptop belonging to an employee of the processor was stolen from the trunk of a car parked in a parking garage. This resulted in a breach of confidentiality of the data subjects’ personal data, including names, addresses, ID numbers, and land registry numbers. The controller notified this data breach to the DPA later in January 2023. The DPA conducted an investigation and initiated administrative proceedings regarding the GDPR compliance of the processing operations carried out by the controller and the processor in March 2025. Holding The DPA issued the controller a fine of PLN 21,000 (€4,900) and the processor a fine of PLN 12,500 (€2,900). First, the DPA held that the controller had violated Articles 24(1), 25(1), 32(1), and 32(2) GDPR by failing to implement appropriate technical and organisational measures to ensure the security of personal data processing – the controller had failed to demonstrate that it had conducted a thorough risk assessment in a manner that would have allowed for the selection of adequate security measures. These infringements resulted in the violations of the principles of integrity, confidentiality and accountability laid down in Articles 5(1)(f) and 5(2) GDPR. Second, the DPA found that the controller had also violated Article 28(1) GDPR: it had failed to verify the adequacy of the technical and organisational measures implemented by the processor. Finally, the DPA came to the conclusion that the processor had infringed Articles 32(1) and 32(2) GDPR in conjunction with Articles 28(3)(c) and 28(3)(f) GDPR. The DPA held that the processor had failed to assist the controller in fulfilling its obligations and contributed to the controller’s GDPR violations. Unlike the controller, the processor had conducted a risk assessment covering the processing operations at issue; however, the processor had not implemented security measures to protect data stored on laptops used outside of its organisation, such as encryption. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Polish original. Please refer to the Polish original for more details. Warsaw, May 25, 2026 Not yet final Decision DKN.5131.5.2025 Pursuant to Article 104 § 1 of the Act of June 14, 1960, Code of Administrative Procedure (Journal of Laws of 2025, item 1691), Article 7(1) and (2), Article 60, Article 102(1)(1) and (3) of the Act of May 10, 2018, on data protection (Journal of Laws of 2019, Item 1781, as amended) and Article 57(1)(a) and (h), Article 58(2)(i), Article 83(1)–(3), and Article 83(4)(a) in conjunction with Article 24(1), Article 25(1), Article 28(1) and (3), and Article 32(1) and (2), as well as Article 83(5)(a) in conjunction with Article 5(1)(f) and Article 5( 2 of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ EU L 119 of May 4, 2016, p. 1, OJ EU L 127 of May 23, 2018, p. 2, and Official Journal of the EU L 74 of March 4, 2021, p. 35) (hereinafter also referred to as “Regulation 2016/679”), following an ex officio administrative proceeding concerning a data breach by the County Administrator (…) (ul. (…), (…)-(…) Z.) and by R. (…) in A. ((…)-(…) A., ul. (…), previously operating under the name M. (…) in A. ((…)-(…) A., ul. (…),) the President of the Personal Data Protection Office 1) having found a violation by the County Administrator of (…) (ul. (…), (…)-(…) Z.) of Article 24(1), Article 25(1), Article 28(1), and Article 32(1) and (2) of Regulation 2016/679, consisting of: a) failure to implement appropriate technical and organizational measures based on a risk assessment that takes into account the state of the art, the cost of implementation, the nature, scope, context, the processing purposes, and the risk to the rights or freedoms of natural persons, to ensure the security of data processing in connection with the use of laptops and the protection of data subject rights, b) failure to implement appropriate technical and organizational measures to ensure the regular testing, measurement, and evaluation of the effectiveness of technical and organizational measures designed to ensure the security of personal data processed using portable computers, in particular with regard to vulnerabilities, errors, updates, and their potential consequences, as well as the measures taken to minimize the risk of their occurrence, c) failure to verify whether the processor provides sufficient guarantees that appropriate technical and organizational measures have been implemented so that the processing complies with the requirements of Regulation 2016/679 and protects data subject rights, resulting in a breach of the principle of confidentiality (Article 5(1)(f) of Regulation 2016/679) and the principle of accountability (Article 5(2) of Regulation 2016/679), imposes on the County Administrator (…) (ul. (…), (…)-(…) Z.), for violating Article 5(1)(f), Article 5(2), Article 25(1), Article 28(1), and Article 32(1) and (2) of Regulation 2016/679, an administrative fine in the amount of 21,000 PLN (in words: twenty-one thousand zlotys); 2) finding that R. (…) in A. ((…)-(…) A., (… Street)) of Art 32(1) and (2) in conjunction with Art 28(3)(c) and (f) of Regulation 2016/679, consisting of: a) failure to implement appropriate technical and organizational measures ensuring a level of security appropriate to the risk associated with data processing in connection with the use of laptops, in order to protect the personal data st

Entities

UODO (vendor)