Sole trader
GDPR enforcement action by Polish National Personal Data Protection Office (UODO) on 2026-04-13.
Case details
- Authority
- Polish National Personal Data Protection Office (UODO)
- Date
- 2026-04-13
- Controller / Processor
- Sole trader
- Sector
- Industry and Commerce
- Quoted Articles
- Art. 32 (1), (2) GDPR, Art. 28 (4) GDPR
- Type of violation
- Insufficient technical and organisational measures to ensure information security
Summary
The Polish DPA has imposed a fine of EUR 2,415 on a sole trader. The sole trader was a sub-agent of an energy company, selling partly through door-to-door sales. For this purpose, the controller passed on the processing of customer data to two agents, who then passed it on to the sub-agent fined in this case. The sole trader sent its staff to visit potential customers. They used an unauthorised messaging app to organise this, sending each other screenshots and images of potential customers' personal data, such as their names, addresses, ID numbers, email addresses, phone numbers, customer numbers and electricity connection point numbers. This data was then used by other employees to prepare contracts. Although the messages themselves were encrypted, the chats and media attachments stayed stored on the phones. The sub-processor did not implement measures to ensure deletion when staff left.