[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fH94s38ef0LdEgSG_JWxL-J_sfX2p8BSWLMfm3mRT_s8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"e0623729-4872-49e1-9c12-7fe0130e3b10","polish-financial-ombudsman-fined-after-it-failure-exposes-data-to-28000-unauthorised-entities","3149105f-48f2-454d-97be-aa260607acbc","Polish Financial Ombudsman Fined After IT Failure Exposes Data to 28,000+ Unauthorised Entities","An IT system failure on a government platform caused Poland's Financial Ombudsman to inadvertently disclose one customer's personal data to 28,366 unauthorised recipients, resulting in a court-ordered PLN 40,000 GDPR damages award. The root cause was a failure to implement adequate technical and organisational security measures as required by GDPR Article 25 (data protection by design) and Article 32 (security of processing). This case illustrates that even unintentional data disclosures caused by technical misconfiguration carry significant legal and reputational consequences. It also highlights that non-material harm — such as stress and loss of control over personal data — is recognised as compensable damage under EU law, raising the stakes for any organisation handling personal data.","**Immediate actions:**\n- Conduct an emergency audit of all data-sharing integrations with government or third-party platforms to verify access controls are correctly scoped.\n- Implement input\u002Foutput validation and recipient-list verification checks on any automated data-distribution workflows.\n\n**Long-term improvements:**\n- Apply the principle of data minimisation and need-to-know access so that system failures cannot propagate data beyond the intended single recipient.\n- Establish a formal Data Protection Impact Assessment (DPIA) process for any system that transmits personal data to external platforms before go-live.\n- Integrate regular penetration testing and configuration reviews of government-connected IT systems into the annual security programme.\n\n**Detection & Response measures:**\n- Deploy real-time anomaly detection on data egress to alert when the volume or number of recipients of a data transfer exceeds expected thresholds.\n- Define and rehearse a GDPR breach-response playbook, including the 72-hour supervisory authority notification requirement and individual notification procedures.",[12,13,14,15,16,17,18,19,20,21,22,23],"GDPR Article 25 – Data Protection by Design and by Default","GDPR Article 32 – Security of Processing","GDPR Article 82 – Right to Compensation and Liability","NIST SP 800-53 AC-3 – Access Enforcement","NIST SP 800-53 SI-10 – Information Input Validation","NIST SP 800-53 AU-12 – Audit Record Generation","CIS Control 3 – Data Protection","CIS Control 6 – Access Control Management","CIS Control 13 – Network Monitoring and Defence","ISO\u002FIEC 27001:2022 Annex A 8.11 – Data Masking","ISO\u002FIEC 27001:2022 Annex A 5.34 – Privacy and Protection of Personal Data","ITIL 4 – Service Configuration Management Practice","published","2026-06-30T10:22:19.076756+00:00","2026-06-30T10:22:18.722+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=SO_Warszawa_-_III_C_904\u002F23&diff=52013&oldid=0","so-warszawa-iii-c-904-23-f41578","SO Warszawa - III C 904\u002F23",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":39,"name":40,"slug":41,"description":42,"color":43},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":45,"name":46,"slug":47,"description":48,"color":49},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]