Poland Poland

Fundację Lumus

5,220 €

GDPR enforcement action by Polish National Personal Data Protection Office (UODO) on 2026-02-10.

Rank · Sector
#63
of 351 in Individuals and Private Associations
Rank · Poland
#69
of 111
Rank · All fines
#1,681
of 3,050

Case details

Authority
Polish National Personal Data Protection Office (UODO)
Date
2026-02-10
Controller / Processor
Fundację Lumus
Sector
Individuals and Private Associations
Quoted Articles
Art. 33 (1) GDPR, Art. 34 (1) GDPR, Art. 37 (7) GDPR, Art. 38 (6) GDPR,
Type of violation
Non-compliance with general data processing principles

Summary

The Polish DPA has imposed a fine of EUR on Fundację Lumus. The controller suffered a personal data breach as a result of forwarding a document without prior redaction and failed to adequately notify the DPA. In addition, the controller appointed a member of its board as DPO, who later became its president, thereby giving rise to a conflict of interest. The controller also failed to notify the DPA of the designation of the DPO.

Open original source Links to the regulator's original publication or another source.

Related fines