# UODO (Poland) - DKN.5131.12.2022

- Type: News
- Source: GDPRhub
- Date: 2026-07-21
- Original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKN.5131.12.2022
- Canonical: https://overview.legal/posts/144031
- Topics: Health Data, Types of Special Categories of Personal Data, Identification, Competent Authorities Designation and Powers under DSA, Processors, Data Breaches, Special Categories of Data, Supervisory Authorities, Healthcare, Healthcare

## Summary

The DPA reprimanded a hospital and its email service provider for a failure to implement technical and organisational measures following a data breach that involved health data of patients. English Summary. Facts. The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses, phone numbers, vaccination appointments, and national identification numbers of approximately 200 patients (

## Full text

The DPA reprimanded a hospital and its email service provider for a failure to implement technical and organisational measures following a data breach that involved health data of patients. English Summary. Facts. The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses, phone numbers, vaccination appointments, and national identification numbers of approximately 200 patients (the data subjects). The email account was hosted on the servers of an external service provider (the processor). The controller notified the supervisory authority of this data breach at the end of December 2021. The DPA started an investigation regarding potential GDPR infringements by the controller and the processor in March 2022 Holding. The DPA issued the controller a reprimand for multiple GDPR violations. First, it held that the controller had violated Article 28(1) GDPR: while the control

## Cited law provisions (1)

### GDPR — gdpr-art-28-par-1-en

Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject.

---
Generated by overview.legal · https://overview.legal/posts/144031 · 2026-07-21
