[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f45Mb5CaA431BQLAml1sTafbkVm20QiU_KKYpz2pXIsE":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":26,"created_at":27,"published_at":28,"article":29,"tags":33,"podcasts":52},"56386737-a303-4fd6-b106-9b128df20f8d","polish-accounting-firm-fined-for-email-breach-due-to-absent-risk-assessments-and-weak-access-control","bbf5dcc0-b2e6-497a-8c30-d91f6bf54441","Polish Accounting Firm Fined for Email Breach Due to Absent Risk Assessments and Weak Access Controls","An accounting and tax consulting firm in Poland suffered a data breach when an employee's email account was accessed without authorization, exposing sensitive personal data of clients, their employees, and minors. The root failure was twofold: the company lacked adequate access controls to prevent unauthorized account access, and it had never conducted formal risk assessments or tested its security measures before the incident occurred. Poland's UODO ruled that the mere unauthorized access constituted a reportable data breach, reinforcing that organizations cannot wait for confirmed data exfiltration to act. This case highlights that professional services firms handling highly sensitive financial and personal data carry an elevated duty of care under GDPR, and that untested, undocumented security postures leave organizations legally and operationally exposed.","**Immediate actions:**\n- Enable multi-factor authentication (MFA) on all employee email accounts, especially those handling sensitive client data.\n- Audit all email accounts for suspicious login activity and revoke any unrecognized active sessions immediately.\n- Notify affected data subjects and relevant supervisory authorities within GDPR-mandated timeframes.\n\n**Long-term improvements:**\n- Conduct and document formal GDPR Article 32 risk assessments for all data processing activities on a regular, scheduled basis.\n- Implement a least-privilege access policy ensuring employees can only access data necessary for their specific role.\n- Establish a written information security policy that includes documented technical and organizational measures for protecting personal data.\n\n**Detection & testing measures:**\n- Deploy email security monitoring with alerts for anomalous login locations, times, or failed authentication attempts.\n- Schedule periodic penetration testing and security control validation to verify that protective measures function as intended.\n- Maintain audit logs of all access to systems storing personal data and review them on a regular basis.",[12,13,14,15,16,17,18,19,20,21,22,23,24,25],"GDPR Article 5(1)(f) – Integrity and confidentiality principle","GDPR Article 32 – Security of processing (risk assessments and technical\u002Forganizational measures)","GDPR Article 33 – Notification of a personal data breach to the supervisory authority","GDPR Article 34 – Communication of a personal data breach to the data subject","CIS Control 6 – Access Control Management","CIS Control 8 – Audit Log Management","CIS Control 16 – Application Software Security","NIST SP 800-53 AC-2 – Account Management","NIST SP 800-53 IA-2 – Identification and Authentication (Multi-Factor)","NIST SP 800-53 RA-3 – Risk Assessment","NIST CSF ID.RA – Risk Assessment","NIST CSF PR.AC – Identity Management and Access Control","ISO\u002FIEC 27001:2022 A.8.3 – Information access restriction","ISO\u002FIEC 27001:2022 A.8.5 – Secure authentication","published","2026-06-30T18:20:57.552373+00:00","2026-06-30T18:20:57.408+00:00",{"id":7,"url":30,"slug":31,"title":32},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=UODO_(Poland)_-_DKN.5131.34.2023&diff=52032&oldid=52010","uodo-poland-dkn-5131-34-2023-48f7cb","UODO (Poland) - DKN.5131.34.2023",[34,40,46],{"id":35,"name":36,"slug":37,"description":38,"color":39},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":41,"name":42,"slug":43,"description":44,"color":45},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":47,"name":48,"slug":49,"description":50,"color":51},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]