Skip to content
Enforcement · UODO (Poland) ·DKN.5131.12.2022 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021

The compromised email account contained e.g.

Summary

names, addresses, phone numbers, vaccination appointments, and national identification numbers of approximately 200 patients (the data subjects). The email account was hosted on the servers of an external service provider (the processor). The controller notified the supervisory authority of this data breach at the end of December 2021. The DPA started an investigation regarding potential GDPR infringements by the controller and the processor in March 2022. Holding — The DPA issued the controller a reprimand for multiple GDPR violations. First, it held that the controller had violated Article 28(1) GDPR: while the controller had concluded a data processing agreement with the processor, it had failed to verify whether the processor provided sufficient guarantees to implement appropriate technical and organisational measures. Second, the DPA found that the controller had infringed Articles 24(1), 25(1), and 32(1) and 32(2) GDPR by failing to implement appropriate technical and organisational measures to ensure the security of processing via the email system. The DPA took into account that the controller had not taken any measures to minimise the risks identified. In addition, the DPA pointed out that the breach involved sensitive health data, and the passwords used by the controller did not meet the usual security requirements. As a consequence of the previous violations, the controller had infringed the principles of integrity, confidentiality and accountability laid down in Articles 5(1)(f) and 5(2) GDPR as well. Finally, the DPA found a violation of Article 35(1) GDPR in conjunction with Article 35(3) GDPR due to the controller’s failure to conduct a data protection impact assessment. The DPA also reprimanded the processor for the failure to implement appropriate technical and organisational measures to ensure the security of processing – the processor had failed to conduct a risk analysis and to implement adequate security measures, such as blocking a user’s account after a certain amount of login attempts. The DPA held that the processor had violated Articles 32(1) and 32(2) GDPR in conjunction with Article 28(3)(c) GDPR.

How it connects

3 of 3 paragraphs apply legislation or carry a topic — see them in the full text ↓

Full text 3 findings

Paragraphs carrying a topic or an applied provision show those connections inline Original at the source →
§

Similarly, the President of the Personal Data Protection Office (UODO) found that, under the established circumstances of this case, issuing a warning to the Controller is a sufficient remedy for the infringement of Article 5 paragraph 1 letter f) and paragraph 2, Article 24 paragraph 1, Article 25 paragraph 1, and Article 32 paragraphs 1 and 2 of Regulation 2016/679. The President of the Personal Data Protection Office (UODO) found that the Controller had taken a number of remedial actions to minimize the risk of recurrence of the infringement (new server room, replacement of hardware and software – enabling the implementation of supported and secure email systems, introduction of additional procedures). It should be noted that during the period of the infringement of the aforementioned provisions, the Controller was in the process of building a new server room, where the investment value was estimated at PLN 7 million, which involved a thorough replacement of the IT infrastructure and software.

§

The Controller reported the personal data breach to the President of the UODO, and the personal data breach itself did not affect a large number of individuals. Furthermore, in the opinion of the President of the Personal Data Protection Office (UODO), the Controller fulfilled the obligation to regularly test, measure, and evaluate the technical and organizational measures used, referred to in Article 32 paragraph 1 letter d) of Regulation 2016/679. This was reflected in audits and inspections, during which threats were identified. The Controller responded to some threats by, among other things, amending procedures, conducting training, issuing newsletters, announcements, and sending emails to employees. It should be noted that, based on the audit of February 8, 2021, the Controller identified functional limitations of the email server in use. The recommendations, among other things, required a market analysis to verify the feasibility of modernizing the previously used email server, a comparison with other systems available on the market, a cost analysis, and a risk assessment.

§

Consequently, the Controller, on its own initiative, although significantly delayed, nevertheless took steps to increase the security of the entrusted personal data in the application of technical security measures, requesting the Processor to implement specific functionalities. The above circumstances were not omitted by the President of the Personal Data Protection Office and were assessed as mitigating circumstances for the Controller.