Skip to content

🇪🇺 POLAND

121 decisions · €29.8M total fines · Polish National Personal Data Protection Office (UODO)

Date ↓ Company / party Authority Articles Fine
2026-01-09 Komendanta Miejskiego Policji w Krakowie
Non-compliance with general data processing principles
🇪🇺 Polish National Personal Data Protection Office (UODO) €18,500
2026-01-09 Komendanta Miejskiego Policji w Krakowie
Non-compliance with general data processing principles
🇪🇺 Polish National Personal Data Protection Office (UODO) €18,500
2026-01-02 Polish Postal Service
Lack of appointment of data protection officer
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 38 €232,379
2025-12-30 POLAND DPA: Insufficient cooperation with supervisory authority
Insufficient cooperation with supervisory authority
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 58 €960
2025-12-30 POLEN, Autoriteit voor Persoonsgegevens: Onvoldoende samenwerking met de toezichthoudende instantie.
Insufficient cooperation with supervisory authority
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 58 €960
2025-11-15 Powiatowego Inspektora Sanitarnego w Policach
Insufficient technical and organisational measures to ensure information security
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 5Art. 24Art. 25Art. 32 €4,750
2025-11-15 Powiatowego Inspektora Sanitarnego w Policach
Insufficient technical and organisational measures to ensure information security
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 5Art. 24Art. 25Art. 32 €4,750
2025-10-27 Gynecological Center
Insufficient fulfilment of data breach notification obligations
🇪🇺 Polish National Personal Data Protection Office (UODO) €9,450
2025-10-27 Gynecological Center
Insufficient fulfilment of data breach notification obligations
🇪🇺 Polish National Personal Data Protection Office (UODO) €9,450
2025-10-23 Court Bailiff
Insufficient fulfilment of data breach notification obligations
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 33Art. 34 €5,000
2025-10-23 Court Bailiff
Insufficient fulfilment of data breach notification obligations
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 33Art. 34 €5,000
2025-09-12 POLAND DPA: Lack of appointment of data protection officer
Lack of appointment of data protection officer
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 38 €2,670
2025-09-12 POLEN, Autoriteit voor gegevensbescherming: Gebrek aan benoeming van een functionaris voor gegevensbescherming.
Lack of appointment of data protection officer
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 38 €2,670
2025-08-26 ING Bank Śląski
Insufficient legal basis for data processing
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 5Art. 6 €4,323,250
2025-08-26 ING Bank Śląski
Insufficient legal basis for data processing
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 5Art. 6 €4,323,250
2025-08-04 Non-Public Health Care Institution
Insufficient technical and organisational measures to ensure information security
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 5Art. 25Art. 32 €7,700
2025-08-04 Non-Public Health Care Institution
Insufficient technical and organisational measures to ensure information security
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 5Art. 25Art. 32 €7,700
2025-07-28 Entrepreneur
Insufficient cooperation with supervisory authority
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 58 €4,400
2025-07-28 Entrepreneur
Insufficient cooperation with supervisory authority
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 58 €4,400
2025-07-21 McDonald’s Polska Sp. z o.o.
Non-compliance with general data processing principles
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 5Art. 25Art. 28Art. 38 €3,955,000
2025-07-21 McDonald’s Polska Sp. z o.o.
Non-compliance with general data processing principles
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 5Art. 25Art. 28Art. 38 €3,955,000
2025-07-21 24/7 Communication Sp. z o.o.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 5Art. 25Art. 38 €43,000
2025-07-21 24/7 Communication Sp. z o.o.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 5Art. 25Art. 38 €43,000
2025-06-30 L. Zamenhof University Children's Clinical Hospital in Białystok
Insufficient technical and organisational measures to ensure information security
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 5Art. 32 €15,600
2025-06-30 L. Zamenhof University Children's Clinical Hospital in Białystok
Insufficient technical and organisational measures to ensure information security
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 5Art. 32 €15,600