Poland Poland

Sole trader

2,415 €

GDPR enforcement action by Polish National Personal Data Protection Office (UODO) on 2026-04-13.

Rank · Sector
#427
of 619 in Industry and Commerce
Rank · Poland
#100
of 118
Rank · All fines
#2,274
of 3,152

Case details

Authority
Polish National Personal Data Protection Office (UODO)
Date
2026-04-13
Controller / Processor
Sole trader
Sector
Industry and Commerce
Quoted Articles
Art. 32 (1), (2) GDPR, Art. 28 (4) GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Polish DPA has imposed a fine of EUR 2,415 on a sole trader. The sole trader was a sub-agent of an energy company, selling partly through door-to-door sales. For this purpose, the controller passed on the processing of customer data to two agents, who then passed it on to the sub-agent fined in this case. The sole trader sent its staff to visit potential customers. They used an unauthorised messaging app to organise this, sending each other screenshots and images of potential customers' personal data, such as their names, addresses, ID numbers, email addresses, phone numbers, customer numbers and electricity connection point numbers. This data was then used by other employees to prepare contracts. Although the messages themselves were encrypted, the chats and media attachments stayed stored on the phones. The sub-processor did not implement measures to ensure deletion when staff left.

Open original source Links to the regulator's original publication or another source.

Related fines