Poland Poland

Company

3,400 €

GDPR enforcement action by Polish National Personal Data Protection Office (UODO) on 2023-07-18.

Rank · Sector
#112
of 218 in Not assigned
Rank · Poland
#86
of 110
Rank · All fines
#1,972
of 3,042

Case details

Authority
Polish National Personal Data Protection Office (UODO)
Date
2023-07-18
Controller / Processor
Company
Sector
Not assigned
Quoted Articles
Art. 5 (1) f) GDPR, Art. 5 (2) GDPR, Art. 24 (1) GDPR, Art. 25 (1) GDPR, Art. 32 (1), (2) GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Polish DPA has imposed a fine of EUR 3,400 on a company. The controller had reported a data breach to the DPA. The company car of a senior employee had been broken into, resulting in the theft of a company laptop on which personal data of three persons were processed. During its investigation, the DPA determined that the controller had failed to implement appropriate technical and organizational measures to protect personal data. Among other things, the laptop had not been properly encrypted.

Open original source Links to the regulator's original publication or another source.

Related fines