Poland Poland

Social welfare centre

7,950 €

GDPR enforcement action by Polish National Personal Data Protection Office (UODO) on 2026-05-19.

Rank · Sector
#212
of 385 in Public Sector and Education
Rank · Poland
#56
of 122
Rank · All fines
#1,600
of 3,170

Case details

Authority
Polish National Personal Data Protection Office (UODO)
Date
2026-05-19
Controller / Processor
Social welfare centre
Sector
Public Sector and Education
Quoted Articles
Art. 5 (1) f) GDPR, Art. 5 (2) GDPR, Art. 25 (1) GDPR, Art. 32 (1), (2) GDPR, Art. 33 (1) GDPR, Art. 34 (1) GDPR, Art. 83 (4) a) GDPR, Art. 83 (5) a) GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Polish DPA has imposed a fine of EUR 7,950 on a social welfare centre. In 2020, the district sanitary station sent a document regarding quarantine measures for people with suspected or confirmed cases of the novel Coronavirus (SARS-CoV-2) to the social welfare centre. The centre was tasked with assessing the needs of different residents and coordinating the help of volunteer firefighters. In November 2020, the facility's coordinator uploaded a document containing the names, phone numbers, addresses and quarantine statuses of residents to his private web server. This document was publicly available, and its full content was indexed by a search engine. The authority only became aware of the breach following a tip-off in 2021. The coordinator deleted the document a few days later. The centre stated that it was not the controller of the document; however, the UODO determined that it was, as the centre had received the list, set the purpose of processing, and authorised the coordinator. Therefore, the centre would also have had to inform the authority and data subjects about the breach.

Open original source Links to the regulator's original publication or another source.

Related fines