Polish Financial Ombudsman Fined After IT Failure Exposes Data to 28,000+ Unauthorised Entities
An IT system failure on a government platform caused Poland's Financial Ombudsman to inadvertently disclose one customer's personal data to 28,366 unauthorised recipients, resulting in a court-ordered PLN 40,000 GDPR damages award. The root cause was a failure to implement adequate technical and organisational security measures as required by GDPR Article 25 (data protection by design) and Article 32 (security of processing). This case illustrates that even unintentional data disclosures caused by technical misconfiguration carry significant legal and reputational consequences. It also highlights that non-material harm — such as stress and loss of control over personal data — is recognised as compensable damage under EU law, raising the stakes for any organisation handling personal data.
Tactical Insight
Immediate actions
- Conduct an emergency audit of all data-sharing integrations with government or third-party platforms to verify access controls are correctly scoped.
- Implement input/output validation and recipient-list verification checks on any automated data-distribution workflows.
Long-term improvements
- Apply the principle of data minimisation and need-to-know access so that system failures cannot propagate data beyond the intended single recipient.
- Establish a formal Data Protection Impact Assessment (DPIA) process for any system that transmits personal data to external platforms before go-live.
- Integrate regular penetration testing and configuration reviews of government-connected IT systems into the annual security programme.
Detection & Response measures
- Deploy real-time anomaly detection on data egress to alert when the volume or number of recipients of a data transfer exceeds expected thresholds.
- Define and rehearse a GDPR breach-response playbook, including the 72-hour supervisory authority notification requirement and individual notification procedures.