Skip to content
News · GDPRhub EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

UODO (Poland) - DKN.5131.12.2022

How it connects

Full text

The DPA reprimanded a hospital and its email service provider for a failure to implement technical and organisational measures following a data breach that involved health data of patients. English Summary. Facts. The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses, phone numbers, vaccination appointments, and national identification numbers of approximately 200 patients (the data subjects). The email account was hosted on the servers of an external service provider (the processor). The controller notified the supervisory authority of this data breach at the end of December 2021. The DPA started an investigation regarding potential GDPR infringements by the controller and the processor in March 2022 Holding. The DPA issued the controller a reprimand for multiple GDPR violations. First, it held that the controller had violated Article 28(1) GDPR: while the control

Similar Content