Back to all lessons
Awareness Lessons
2 weeks ago

Polish DPA Fines Company for Obstructing GDPR Investigation and Hiding Identity

A Polish company was fined for a dual failure: it collected personal data without disclosing its identity or contact details on its websites, and then refused to cooperate with UODO's investigation by denying the authority access to required information. These violations of GDPR Articles 58(1)(a) and 58(1)(e) undermine the fundamental accountability principle that data controllers must be identifiable and transparent. Regulatory cooperation is not optional — obstructing a DPA investigation compounds the original violation and significantly increases enforcement risk. This case highlights that transparency and responsiveness to supervisory authorities are non-negotiable obligations under GDPR.

Tactical Insight

Immediate actions

  • Publish clear controller identity, contact details, and privacy policy information on all websites and digital touchpoints that collect personal data.
  • Establish a dedicated point of contact (e.g., a DPO or legal counsel) responsible for responding promptly to regulatory inquiries.

Compliance & governance improvements

  • Conduct a GDPR compliance audit to verify that all data collection channels meet transparency and lawfulness requirements under Articles 13 and 14.
  • Implement a formal regulatory response procedure that mandates acknowledgment and cooperation with DPA requests within defined SLA timelines.
  • Maintain a data processing register (Article 30 record) to ensure the organization can quickly provide regulators with required documentation.

Awareness & training measures

  • Train legal, compliance, and marketing teams on controller obligations under GDPR, including the duty to cooperate with supervisory authorities.
  • Embed privacy-by-design checks into website and product launches to catch missing identity disclosures before go-live.