Back to all lessons
Awareness Lessons
4 months ago

Employee Email Mistake Costs Electricity Company €212 in GDPR Damages

An employee at a Polish electricity company accidentally sent a file containing multiple clients' personal data — including names, addresses, and invoice numbers — to the wrong recipient, constituting a personal data breach under GDPR Article 4(12). The root cause was a human error driven by insufficient security awareness training and a lack of technical controls to prevent misdirected emails containing sensitive data. The Warsaw-Praga District Court confirmed that even a single accidental disclosure of personal data to an unintended party qualifies as a compensable GDPR breach under Article 82, regardless of intent. This case underscores that non-material damages (stress, loss of privacy control) are recognized by courts, making even 'minor' data handling mistakes legally and financially consequential.

Tactical Insight

Immediate actions

  • Implement Data Loss Prevention (DLP) tools that flag or block outbound emails containing personal data such as names, addresses, or account numbers.
  • Require employees to use a mandatory confirmation prompt when sending emails to external recipients with attachments containing personal data.
  • Conduct targeted security awareness training focused on safe handling and transmission of customer personal data.

Long-term improvements

  • Establish a formal data classification policy so employees can identify and handle sensitive files appropriately before sharing.
  • Replace bulk personal data file attachments with secure, access-controlled customer portals to eliminate the risk of misdirected emails.
  • Integrate regular phishing and data-handling simulation exercises into the employee training programme.

Detection & Response measures

  • Deploy email audit logging to detect and alert on unusual outbound data transfers to unintended recipients.
  • Define and rehearse an incident response playbook specifically for personal data breaches, including GDPR 72-hour supervisory authority notification requirements.
  • Assign a designated Data Protection Officer (DPO) point of contact to triage and assess potential breaches swiftly upon discovery.