Court bailiff at a district court
GDPR enforcement action by Polish National Personal Data Protection Office (UODO) on 2026-07-29.
Case details
- Authority
- Polish National Personal Data Protection Office (UODO)
- Date
- 2026-07-29
- Controller / Processor
- Court bailiff at a district court
- Sector
- Public Sector and Education
- Quoted Articles
- Art. 37 (7) GDPR, Art. 38 (6) GDPR, Art. 83 (4) a) GDPR
- Type of violation
- Lack of appointment of data protection officer
Summary
The Polish DPA has imposed a fine of EUR 3,580 on a court bailiff. The court bailif had reported a breach of data security in 2023, the data breach had occurd, because a debtor letter about a abnk account seizure had been sent to the fals debtor. The report named the court bailiff themselfes as DPO, in the following investigation, the authority did not find a DPO in its register, the bailiff then stated, that no DPO had formally been appointed, becouse none would be required. From the bginning of their swearing in as court bailiff on 30 January 2020 onwards, the bailiff had presented themsefes as the DPO to data subjects. The UODO found that as a part of the public-finance sector, a DPO is required, that the court baiuliff had therfore failed to appoint a DPO and had acted in a conflict of interst in acting as DPO for themselfes. UODO fined the court bailiff for the afformentioned reasons, not the data breach reported in 2023.