Employee Email Mistake Costs Electricity Company €212 in GDPR Damages
An employee at a Polish electricity company accidentally sent a file containing multiple clients' personal data — including names, addresses, and invoice numbers — to the wrong recipient, constituting a personal data breach under GDPR Article 4(12). The root cause was a human error driven by insufficient security awareness training and a lack of technical controls to prevent misdirected emails containing sensitive data. The Warsaw-Praga District Court confirmed that even a single accidental disclosure of personal data to an unintended party qualifies as a compensable GDPR breach under Article 82, regardless of intent. This case underscores that non-material damages (stress, loss of privacy control) are recognized by courts, making even 'minor' data handling mistakes legally and financially consequential.
Tactical Insight
Immediate actions
- Implement Data Loss Prevention (DLP) tools that flag or block outbound emails containing personal data such as names, addresses, or account numbers.
- Require employees to use a mandatory confirmation prompt when sending emails to external recipients with attachments containing personal data.
- Conduct targeted security awareness training focused on safe handling and transmission of customer personal data.
Long-term improvements
- Establish a formal data classification policy so employees can identify and handle sensitive files appropriately before sharing.
- Replace bulk personal data file attachments with secure, access-controlled customer portals to eliminate the risk of misdirected emails.
- Integrate regular phishing and data-handling simulation exercises into the employee training programme.
Detection & Response measures
- Deploy email audit logging to detect and alert on unusual outbound data transfers to unintended recipients.
- Define and rehearse an incident response playbook specifically for personal data breaches, including GDPR 72-hour supervisory authority notification requirements.
- Assign a designated Data Protection Officer (DPO) point of contact to triage and assess potential breaches swiftly upon discovery.