[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5MzdbRk27WgksbxUs-g7phOUXFq74fXvOpet3J_4554":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"63337c99-1101-497f-a52e-7b6ba745d4a4","polish-dpa-fines-company-for-ignoring-gdpr-information-obligations-and-regulator-communications","c612ef91-cc50-4047-8d9d-9578b132ad07","Polish DPA Fines Company for Ignoring GDPR Information Obligations and Regulator Communications","A Polish company was fined for failing to fulfill its Article 14 GDPR obligations — which require organizations to inform individuals about how their personal data is processed when collected indirectly — even after the data protection authority issued a formal order. Compounding the violation, the company failed to respond to multiple communications from the regulator, demonstrating a systemic breakdown in compliance governance. This left the affected data subject unable to understand or exercise their privacy rights, which is precisely the harm GDPR transparency requirements are designed to prevent. Ignoring a DPA decision is treated as a serious aggravating factor and exposes organizations to escalating fines and enforcement actions. This case underscores that non-response to regulators is never a viable strategy and carries significant legal and reputational risk.","**Immediate actions:**\n- Designate a named Data Protection Officer or compliance contact responsible for receiving and responding to all DPA and data subject communications within defined SLAs.\n- Conduct an urgent audit to identify any outstanding regulatory obligations, DPA decisions, or unanswered data subject requests.\n\n**Compliance & process improvements:**\n- Implement a documented Article 13\u002F14 GDPR notice procedure covering all scenarios where personal data is collected indirectly, ensuring notices are issued within the required one-month window.\n- Establish a regulatory correspondence log to track, escalate, and respond to all DPA communications with mandatory internal deadlines.\n- Train legal, compliance, and management teams on the consequences of non-compliance with DPA decisions, including escalating fines and reputational damage.\n\n**Governance & monitoring:**\n- Schedule periodic GDPR compliance reviews to verify that transparency obligations, data subject rights workflows, and regulator response processes remain active and effective.\n- Define an escalation path so that unanswered regulatory correspondence automatically triggers senior management attention within 48 hours.",[12,13,14,15,16,17,18,19],"GDPR Article 14 (Information to be provided where personal data have not been obtained from the data subject)","GDPR Article 58 (Powers of supervisory authorities)","GDPR Article 83 (General conditions for imposing administrative fines)","NIST SP 800-53 PT-2 (Authority to Process Personally Identifiable Information)","NIST SP 800-53 IR-6 (Incident Reporting)","CIS Control 17 (Incident Response Management)","ISO\u002FIEC 27701:2019 Section 7.3.2 (Obligations to PII Principals)","ITIL Service Management — Compliance and Regulatory Management practice","published","2026-10-07T08:21:09.177469+00:00","2026-10-07T08:21:08.909+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=UODO_(Poland)_-_DKE.561.3.2026&diff=53322&oldid=53302","uodo-poland-dke-561-3-2026-3c9c82","UODO (Poland) - DKE.561.3.2026",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":35,"name":36,"slug":37,"description":38,"color":39},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]