Social welfare centre
GDPR enforcement action by Polish National Personal Data Protection Office (UODO) on 2026-05-19.
Case details
- Authority
- Polish National Personal Data Protection Office (UODO)
- Date
- 2026-05-19
- Controller / Processor
- Social welfare centre
- Sector
- Public Sector and Education
- Quoted Articles
- Art. 5 (1) f) GDPR, Art. 5 (2) GDPR, Art. 25 (1) GDPR, Art. 32 (1), (2) GDPR, Art. 33 (1) GDPR, Art. 34 (1) GDPR, Art. 83 (4) a) GDPR, Art. 83 (5) a) GDPR
- Type of violation
- Insufficient technical and organisational measures to ensure information security
Summary
The Polish DPA has imposed a fine of EUR 7,950 on a social welfare centre. In 2020, the district sanitary station sent a document regarding quarantine measures for people with suspected or confirmed cases of the novel Coronavirus (SARS-CoV-2) to the social welfare centre. The centre was tasked with assessing the needs of different residents and coordinating the help of volunteer firefighters. In November 2020, the facility's coordinator uploaded a document containing the names, phone numbers, addresses and quarantine statuses of residents to his private web server. This document was publicly available, and its full content was indexed by a search engine. The authority only became aware of the breach following a tip-off in 2021. The coordinator deleted the document a few days later. The centre stated that it was not the controller of the document; however, the UODO determined that it was, as the centre had received the list, set the purpose of processing, and authorised the coordinator. Therefore, the centre would also have had to inform the authority and data subjects about the breach.