Back to all lessons
Awareness Lessons
6 months ago

Polish Company Fined €1.4M for Excessive Data Collection Without Legal Basis

A Polish company was fined €1.4 million for collecting excessive personal data including ID cards, passports, and payment card photos from users suspected of fraud without establishing a valid legal basis under GDPR. The company violated fundamental data protection principles including lawfulness, data minimization, and accountability by requesting more personal information than necessary for their stated purpose. This case demonstrates that organizations cannot simply collect any personal data they want from users, even for legitimate business purposes like fraud prevention, without ensuring they have proper legal grounds and are following data minimization principles. The substantial fine and order to delete all collected data highlights the serious consequences of failing to implement proper data governance frameworks.

Tactical Insight

Immediate actions

  • Conduct a comprehensive audit of all personal data collection practices and legal bases
  • Implement data minimization reviews before requesting any personal information from users
  • Establish clear procedures for determining valid legal basis before processing personal data

Long-term improvements

  • Develop and document data protection impact assessments for all data processing activities
  • Train staff on GDPR principles including lawfulness, data minimization, and purpose limitation
  • Implement privacy-by-design principles in all systems that handle personal data

Governance measures

  • Establish regular legal basis reviews with privacy counsel for ongoing data processing
  • Create automated controls to prevent collection of unnecessary personal data
  • Implement data retention policies with automatic deletion of excessive or unlawfully collected data