[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fRIP9VONv4KkT7Km8pNgaTLtNqxKVpsygXrYuvJAgVMA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"d99292c6-be79-4797-8c03-f52a0234ff3c","polish-accounting-firm-fined-after-email-breach-exposes-client-data","2c91df7e-c7f7-4696-9878-d7ed27c07850","Polish Accounting Firm Fined After Email Breach Exposes Client Data","An accounting and tax consulting firm in Poland was fined €2,760 by UODO after an unauthorized party gained access to an employee's email account, exposing sensitive personal data belonging to clients and their families. The core failure was the absence of adequate technical and organizational security measures — such as multi-factor authentication and proper access controls — prior to the breach occurring. Critically, the DPA ruled that the mere act of unauthorized access constitutes a reportable data breach, regardless of whether data was exfiltrated or misused. The company's reactive approach — only tightening security after the breach was reported — demonstrated a lack of proactive GDPR compliance. This case underscores that organizations handling sensitive financial and personal data have a legal obligation to implement proportionate safeguards before incidents occur, not in response to them.","**Immediate actions:**\n- Enable multi-factor authentication (MFA) on all employee email accounts and critical business systems immediately.\n- Conduct an emergency audit of all user accounts with access to sensitive client data and revoke unnecessary permissions.\n\n**Long-term improvements:**\n- Implement a formal Access Control Policy that enforces the principle of least privilege across all systems holding personal data.\n- Establish a regular GDPR compliance review cycle to assess whether technical and organizational measures remain adequate as threats evolve.\n- Develop and test an Incident Response Plan that specifically addresses personal data breaches and UODO\u002FDPA notification obligations.\n\n**Detection measures:**\n- Deploy email security monitoring tools to detect anomalous login behavior, such as logins from unusual locations or at unusual times.\n- Implement centralized logging and alerting for all authentication events on systems processing personal data to enable early breach detection.",[12,13,14,15,16,17,18,19,20,21,22],"GDPR Article 5(1)(f) — Integrity and confidentiality principle","GDPR Article 25 — Data protection by design and by default","GDPR Article 32 — Security of processing","GDPR Article 33 — Notification of a personal data breach to the supervisory authority","NIST SP 800-53 AC-2 — Account Management","NIST SP 800-53 IA-5 — Authenticator Management (MFA)","CIS Control 5 — Account Management","CIS Control 6 — Access Control Management","CIS Control 13 — Network Monitoring and Defense","ISO\u002FIEC 27001:2022 — A.5.15 Access Control","ISO\u002FIEC 27001:2022 — A.8.5 Secure Authentication","published","2026-06-29T14:21:08.5558+00:00","2026-06-29T14:21:08.431+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=UODO_(Poland)_-_DKN.5131.34.2023&diff=52008&oldid=0","uodo-poland-dkn-5131-34-2023-56603d","UODO (Poland) - DKN.5131.34.2023",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":44,"name":45,"slug":46,"description":47,"color":48},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]