Poland Poland

DPD Polska sp. z o.o.

2,682,000 €

GDPR enforcement action by Polish National Personal Data Protection Office (UODO) on 2026-02-05.

Rank · Sector
#21
of 167 in Transportation and Energy
Rank · Poland
#3
of 111
Rank · All fines
#112
of 3,050

Case details

Authority
Polish National Personal Data Protection Office (UODO)
Date
2026-02-05
Controller / Processor
DPD Polska sp. z o.o.
Sector
Transportation and Energy
Quoted Articles
Art. 5 (1) a), f), (2) GDPR, Art. 24 (1), (2) GDPR, Art. 29 GDPR, Art. 32 (1), (4) GDPR
Type of violation
Insufficient data processing agreement

Summary

The Polish DPA has imposed a fine of EUR 2,682,000 on DPD Polska sp. z.o.o. The controller offers postal services and uses subcontractors for certain transport services. As they are processing data to fulfil their obligations, the subcontractors are therefore processors. However, the controller failed to enter into a data processing agreement with the subcontractors. The controller also failed to ensure that the processors only processed the data according to their instructions.

Open original source Links to the regulator's original publication or another source.

Related fines