Polish Municipality Fined for Failing to Report GDPR Data Breach
A Polish municipality inadvertently published personal data — including names and addresses — of petition signatories, constituting a clear personal data breach under GDPR. Rather than reporting the incident to the supervisory authority within the mandatory 72-hour window, the municipality chose not to notify UODO, incorrectly self-assessing the risk as low. GDPR Article 33 requires breach notification regardless of the organization's own risk perception, and this case demonstrates that subjective risk assessments do not override legal obligations. The relatively modest fine underscores that even smaller public bodies face regulatory consequences for procedural non-compliance. This case serves as a reminder that breach reporting obligations are non-negotiable and that internal risk minimization reasoning is not a valid substitute for regulatory notification.
Tactical Insight
Immediate actions
- Establish and document a GDPR breach response procedure that mandates supervisory authority notification within 72 hours of discovering any potential breach.
- Assign a Data Protection Officer (DPO) or designated responsible person to make breach notification decisions, removing reliance on ad-hoc subjective risk judgments.
Long-term improvements
- Conduct regular GDPR training for all staff involved in handling or publishing personal data, emphasizing mandatory reporting thresholds.
- Implement a formal Data Breach Register to log all incidents — including near-misses — ensuring a consistent, auditable record for regulators.
- Introduce a pre-publication review checklist requiring privacy impact checks before any document containing personal data is made publicly available.
Detection measures
- Deploy automated scanning or content review tools on public-facing web portals to detect accidental exposure of personal data (e.g., names, addresses, national IDs).
- Establish an internal incident triage process that triggers escalation to the DPO within 24 hours of any suspected data exposure event.