Back to all lessons
Awareness Lessons
6 months ago

Polish Company Fined €1.4M for Excessive ID Document Collection

A Polish company was fined €1.4 million for unlawfully collecting users' ID cards and passports through their application under the guise of fraud prevention. The data protection authority found that the company violated fundamental GDPR principles by processing personal data without a valid legal basis, collecting more data than necessary, and failing to demonstrate accountability. This case highlights that companies cannot simply claim 'fraud prevention' as justification for collecting sensitive identity documents without proper legal grounds and proportionate need. The violation demonstrates how poor data governance and lack of privacy impact assessments can lead to significant financial penalties and reputational damage.

Tactical Insight

Immediate actions

  • Conduct a comprehensive data audit to identify all personal data being collected and processed
  • Review and document the legal basis for each type of personal data processing activity
  • Implement data minimization controls to collect only necessary personal data for specific purposes

Long-term improvements

  • Establish a privacy-by-design framework for all new products and services
  • Develop clear data retention policies with automatic deletion schedules for sensitive documents
  • Create regular privacy impact assessments for any data processing activities involving personal documents

Governance measures

  • Train staff on GDPR requirements and data protection principles
  • Implement privacy management software to track consent and legal bases for processing
  • Establish regular compliance audits with external privacy experts