DKN.5131.5.2025
A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’) personal data to a specialised entity established for this purpose (the processor). In January 2023, a work laptop belonging to an employee of the processor was stolen from the trunk of a car parked in a parking garage. This resulted in a breach of confidentiality of the data subjects’ personal data, including names, addresses, ID numbers, and land registry numbers. The controller notified this data breach to the DPA later in January 2023. The DPA conducted an investigation and initiated administrative proceedings regarding the GDPR compliance of the processing operations carried out by the controller and the processor in March 2025. Holding — The DPA issued the controller a fine of PLN 21,000 (€4,900) and the processor a fine of PLN 12,500 (€2,900). First, the DPA held that the controller had violated Articles 24(1), 25(1), 32(1), and 32(2) GDPR by failing to implement appropriate technical and organisational measures to ensure the security of personal data processing – the controller had failed to demonstrate that it had conducted a thorough risk assessment in a manner that would have allowed for the selection of adequate security measures. These infringements resulted in the violations of the principles of integrity, confidentiality and accountability laid down in Articles 5(1)(f) and 5(2) GDPR. Second, the DPA found that the controller had also violated Article 28(1) GDPR: it had failed to verify the adequacy of the technical and organisational measures implemented by the processor. Finally, the DPA came to the conclusion that the processor had infringed Articles 32(1) and 32(2) GDPR in conjunction with Articles 28(3)(c) and 28(3)(f) GDPR. The DPA held that the processor had failed to assist the controller in fulfilling its obligations and contributed to the controller’s GDPR violations. Unlike the controller, the processor had conducted a risk assessment covering the processing operations at issue; however, the processor had not implemented security measures to protect data stored on laptops used outside of its office premises, such as encryption.
How it connects
Related across sources
Full text 172 findings
The County Administrator (…) (ul. (…), (…)-(…) Z.) (hereinafter also referred to as the “County Administrator” or “Controller”) on January 26, 2023, filed a report with the President of the Personal Data Protection Office (hereinafter also referred to as the “President of the PDPO” or “supervisory authority”) a data breach that occurred on January 22, 2023 (registered under ref. no.: (…)). The data breach resulted from the theft of a work laptop belonging to employee M. (…) in A. (currently: R. (…) in A.).
This report of a personal data breach prompted the supervisory authority to assess the Controller’s compliance with its obligations under Regulation 2016/679 regarding proper data security and the organization of the personal data protection system. In light of the above, the President of the Personal Data Protection Office (UODO) conducted an investigation into the matter and, on March 5, 2025, initiated ex officio administrative proceedings against the Controller regarding a possible breach by the County Administrator of the obligations arising from the provisions of Article 5(1)(f), Article 5(2), Article 24(1), Article 25(1), Article 32(1) and (2), Article 28(1), and Article 28(3) of Regulation 2016/679. On March 5, 2025, the President of the Personal Data Protection Office (UODO) also initiated administrative proceedings against R. (…) in A. ((…)-(…) A., (… Street)) (hereinafter also referred to as “R. (…)” or “Processor”) regarding a possible breach by the Processor of its obligations under Article 32(1) and (2) in conjunction with Article 28(3)(c) and (f) of Regulation 2016/679. The President of the Personal Data Protection Office (UODO), following an investigation and administrative proceedings, established the following facts.
The subject matter of the administrative proceedings is a violation of the provisions of Article 5(1)(f), Article 5(2), Article 24(1), Article 25(1), Article 28(1) and (3), and Article 32(1) and (2) of Regulation 2016/679, rather than identifying the causes of the data breach that occurred on January 22, 2023. Consequently, the factual findings focused primarily on examining whether the Controller and the Processor had in fact implemented adequate security measures to ensure the security of the personal data processing process, in particular, whether the implementation of these measures was preceded by risk assessments. In establishing the facts, the supervisory authority also examined whether the implemented measures were subject to regular testing, measurement, and evaluation of the effectiveness of the technical and organizational measures intended to ensure the security of processing. It was also important to examine the relationship between the Controller and the processor in the context of fulfilling the obligations under Regulation 2016/679. In turn, the findings regarding the data breach of January 22, 2023, highlight the consequences of the violation of the provisions identified in the operative part of this decision. Nor was the subject of these administrative proceedings an examination of the effectiveness of a specific technical measure, namely the use of the Y.. software for the processing of personal data. I. Details regarding the personal data breach of January 22, 2023
The data breach occurred as a result of the theft of employee M.’s work laptop (…) in A.. The controller described the nature of the breach, stating that “(…) on (…).2023, (…) between 2:30 a.m. and 12:00 p.m., in a locked underground parking garage in C., the work laptop belonging to employee M. (…) in A. (…) was stolen from the trunk of a car.” In the submitted report, the Controller indicated that, as a result of the aforementioned data breach, the confidentiality of personal data was compromised. The Controller stated that the approximate number of data subjects affected by the data breach is (…), and the categories of personal data that were compromised include: first and last names, parents’ names, date of birth, residential or temporary address, PESEL identification number, ID card series and number, and other data (land registry numbers). The Controller specified the categories of data subjects whose data were compromised, noting that the data pertained to clients of public entities. II. Findings Regarding the Risk Analysis Conducted by the Controller and the Processor.
In a letter dated February 9, 2023, the Controller stated that it had not conducted a risk analysis that would take into account the threat posed by the theft of computer equipment located outside its processing area. It justified its decision not to conduct such a risk analysis by stating that “(…) employees of the County Office in Z. do not work remotely, and work computers and laptops do not leave the area where personal data is processed, i.e., the headquarters of the County Office in Z. (…)”. At the same time, in the aforementioned letter, the Controller stated that he had received information from the processor that “(…) in M. (…) in A., a risk analysis was conducted (…) in 2021 and (…) in 2022. It did not take into account the risk of theft of computer equipment located outside the processing area, because the Controller [i.e., R. (…) —note by the President of the Personal Data Protection Office (UODO)—did not authorize such action and did not issue written consent for the use of data storage media containing personal data outside the processing area, as stated in Chapter (…) of the Policy (…) of M. (…) in A. (…)”.
Along with the letter dated February 5, 2024, The processor submitted documents confirming that it had conducted a risk assessment prior to the data breach. These documents confirm that risk assessments were conducted on (…) 2021 and (…) 2022. In the section concerning the identification of risks related to the data breach in question, the documents in question are consistent with one another. In the risk assessments, the processor identified threats and vulnerabilities in very general terms. The processor identified threats such as, among others: “accidental event—loss of paper documents or data storage devices (USB drive, hard drive),” “intentional action—theft of personal data at the personal data processing site,” “intentional action—theft of personal data outside the personal data processing site.” As mitigation measures, the processor indicated that (…). Furthermore, in a letter dated February 5, 2024, the processor, in describing the risk analysis conducted, stated that “(…) in the table containing basic information about the measures taken and control mechanisms, the last two columns specify the type of personal data obtained from third parties and transferred to them for processing during the performance of work (…). Given that this data is processed by a large number of employees, it was determined that there is a general risk of a data breach in this regard. However, as a general description of security measures, it was indicated that (…). Further on in the risk analysis, in the table regarding the identification of threats and the likelihood of their occurrence, row 15 identifies a threat in the form of an intentional act involving the theft of personal data outside the personal data processing site, with the response “yes” entered for data obtained from external Controllers, obtained for the processing purpose to carry out work (…). I would like to emphasize that the risk analysis conducted relates to the loss of personal data that may be stored and processed on various types of media, including laptops, outside the processing area (…)”.
The submitted documents therefore indicate that the processor was aware of the risk of a data breach in connection with the use of portable computers outside its organization’s premises. III. Findings regarding the organizational and technical measures implemented by the Controller to ensure an adequate level of security in the processing of personal data.
The Controller provided explanations regarding the rules for using portable computers that are in effect within its organization. In a letter dated February 9, 2023, the Controller stated that the County Office in Z. has in place “(…)”, a portion of which (…) governs the rules for removing data storage devices from the premises of the County Office in Z.. Furthermore, the Controller stated that his organization has in place “Instructions (…)”, which in section (…) - “Procedure (…)” governs the use of laptops. Attached to it are the Rules for the Use of Laptops, which an employee must read and sign before using the device outside the County Office’s premises. At the same time, the Administrator indicated that “(…) laptops used by employees of the District Office in Z. are not used outside the District Office’s premises (…)”.
The Administrator provided explanations regarding the rules for the use of computer equipment by employees of the processor. In a letter dated February 9, 2023, the Administrator stated that “(…) in M. (…) in A., a set of regulations regarding personal data security was developed and implemented by Order No. (…) dated (…) June 2018. The Personal Data Protection Policy of M. (…) in A. and Annexes No. (…) to the aforementioned Policy, “Instruction (…)”, Annex No. (…) to the aforementioned Policy ‘Definition (…)’ and Appendix No. (…) to the aforementioned Policy ‘Instruction (…)’ (…)” [original spelling—note by the President of the Personal Data Protection Office (UODO)]. The controller also indicated that “(…) the above documents describe procedures regarding the use, transport, and security of laptops containing personal data, as well as the course of action in the event of a personal data breach. Furthermore, every employee of M. (…) in A. signs the “Clauses (…)” and is granted authorization to process personal data (…)”.
The controller submitted a document titled “Policy (…)” dated August 26, 2018. In the chapter (…) “Computers (…),” the following is stated: “ (…) 1 (…). 2 (…). 3 (…). 4 (…). 5 (…).”
In a letter dated February 9, 2023, the Controller further stated that “(…) the employee whose laptop was stolen violated the Security Policy because he did not have the Controller’s consent [i.e., M. (…) at A. — note by the President of the Personal Data Protection Office] to remove the equipment outside the data processing area and left the equipment unattended in a car, thereby violating the security rules set forth in Chapter (…)”.
The Controller provided the supervisory authority with detailed explanations regarding the encryption of the hard drive of the lost laptop. In a letter dated February 9, 2023, the County Administrator noted that “(…) according to the response from M. (…) in A., the hard drive in the stolen laptop was not encrypted. However, all computers at M. (…) in A. are secured in accordance with the adopted security policy (…). Specifically, the Accounting and Human Resources departments perform personal data processing using the H. software purchased from H. Sp. z o.o. Meanwhile, (…) performs the entrusted data processing using the Y. software from (…) Sp. z o.o. or in the (…) software from (…) Sp. z o.o. On the stolen laptop, the data was saved in a file in the (…) format using the Y. software and was secured (…)”.
In a letter dated November 5, 2024, the processor stated that “(…) the files (…) are protected against the possibility of reading personal data using the demo version of program Y.. Access to the fdp database created by employee R. (…) at A. is held by (…)”. IV. Findings regarding the relationship between the Controller and the Processor.
The Controller provided explanations regarding its relationship with the processor. In a letter dated February 9, 2023, it indicated that “(…) M. (…) in A. is a processor for (…). On June 23, 2022, Agreement No. (…) was concluded between (…) and the Province of (…) - M. (…) in A., pursuant to which the aforementioned entity was commissioned to develop a project (…). Prior to the conclusion of the aforementioned agreement, a personal data processing agreement was concluded on January 21, 2022, between (…) and M. (…) in A. (…)”.
Along with the letter dated April 7, 2023, the Controller submitted to the supervisory authority the “Personal Data Processing Agreement,” which was concluded on January 21, 2022, in Z. between (…) (referred to in this agreement as the “Data Provider”) and M. (…) in A. (referred to in this agreement as the “Contractor”).
In the Personal Data Processing Agreement, the parties agreed, among other things, that: a. The Data Provider entrusts the Contractor, pursuant to Art. 28 of Regulation 2016/679, with the processing of personal data, solely for the purpose of performing the tasks arising from the decision of the Starost of Z., ref. no.: (…) dated January 5, 2022, in accordance with the terms and to the extent specified in this agreement (§ 1(1) of the personal data processing agreement); b. The Contractor undertakes to process the personal data entrusted to it in accordance with this agreement, Regulation 2016/679, and other generally applicable legal provisions that protect data subject rights (§ 1(2) of the Personal Data Processing Agreement); c. The Contractor shall process the ordinary personal data of landowners or those in possession of land—including first names, last names, and addresses—entrusted to it under this agreement (§ 2(1) of the Personal Data Processing Agreement); d. The personal data specified in paragraph 1 will be processed in both electronic and paper form. Processing will include, in particular, operations such as: collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, viewing, using, disclosing by transmission, dissemination, or other forms of disclosure, matching or combining, restricting, erasing, or destroying (§ 2(2) of the Personal Data Processing Agreement); e. The Contractor shall assist the Data Controller in fulfilling the obligations set forth in Articles 32–36 of Regulation 2016/679 (Section 3(1)(e) of the Personal Data Processing Agreement); f. “(…) provides the Data Controller with all information necessary to demonstrate compliance with the obligations set forth in Art. 28 of the GDPR (…)” [original spelling—note by the President of the Personal Data Protection Office] (Section 3(1)(g) of the personal data processing agreement); g. The Contractor is liable for disclosing or using personal data in a manner inconsistent with the terms of the agreement or applicable law, and in particular for disclosing personal data entrusted for processing to unauthorized entities. In the event that personal data is disclosed or used in a manner inconsistent with the terms of the agreement or applicable law, the Contractor shall be liable for damages incurred by the Data Provider or third parties as a result of processing the entrusted personal data in violation of the contract or Regulation 2016/679, in accordance with general principles. The Contractor shall be liable for all acts and omissions of persons employed in the processing of the entrusted personal data, as if they were its own acts and omissions (§ 4, paras. 1–3 of the personal data processing agreement); h. The Granting Party or a person authorized by it shall have the right, throughout the term of the Agreement, to conduct audits or inspections during the Contractor’s business hours to verify the proper security and processing of the data entrusted to the Contractor. The dates of individual audits or inspections shall be agreed upon in advance with the Contractor, but no later than 3 days prior to the inspection. The Contractor is obligated to present the relevant documents for inspection and to provide written explanations upon each request by the Data Provider (§ 5(1) of the Personal Data Processing Agreement); i. The Contractor undertakes to keep confidential all personal data, information, and materials provided or made available to it, or of which it has become aware in connection with the performance of the agreement, as well as any information and materials arising from its performance, whether in written, graphic, or any other form. Confidential information and materials may not be disclosed to any third party or otherwise made public without the prior written consent of the Provider, unless they were already in the public domain on the date of disclosure or must be disclosed in accordance with generally applicable laws, a Court ruling, or a decision by a government authority (§ 7(1) of the personal data processing agreement).
The Controller provided the supervisory authority with explanations regarding the verification of the processor. In a letter dated April 7, 2023, the Controller stated that “(…) Starosta Z. did not verify whether M. (…) as a processor provides sufficient guarantees to implement appropriate technical and organizational measures so that the processing complies with the requirements of Regulation 2016/679 and protects data subject rights [Article 28(1) of Regulation 2016/679]. This failure stems, among other things, from the fact that, pursuant to Article 3(4) of the Act of March 26, 1982, on Land Consolidation and Exchange, consolidation and exchange work is coordinated and carried out by the provincial government with the assistance of organizational units transferred to it pursuant to Art. 25(1)(3) of the Act of October 13, 1998, - Provisions implementing the Acts reforming public administration (Journal of Laws, item 872, as amended) or by units established by that local government to carry out these tasks. County Administrator Z. determined that M. (…), as a highly specialized entity established to perform such tasks, has all the necessary procedures in place to ensure data protection, and that a personal data processing agreement had been concluded with the aforementioned entity, in which the contractor clearly and unambiguously guaranteed compliance with the rules for personal data processing (…)”. In a letter dated June 26, 2024, the controller stated that “(…) during the many years of cooperation with M. (…) to date, the Z. County Office in A. had no suspicions or doubts regarding the processing of personal data by that entity, therefore, we did not exercise the right to audit referred to in Art. 28(3)(h) of Regulation 2016/679 with respect to R. (…) in A. in connection with the conclusion of the personal data processing entrustment agreement dated January 21, 2022 (…)”.
The Controller conducted oversight activities related to the outsourcing of personal data processing only after a data breach had occurred. A letter dated April 7, 2023, indicates that “(…) on March 24, 2023, County Administrator Z. instructed M. (…) to complete the checklist for the organization acting as a processor with the purpose of conducting an audit in accordance with Art 28(3)(h) of the GDPR in relation to Article 32 of the GDPR, and also requested information on what measures the processor had taken to strengthen the security of personal data following the incident (…)”.
Subsequently, in a letter dated July 5, 2023, the Controller provided the supervisory authority with a copy of the correspondence it had received from the processor, including the checklist referred to above, as completed by the processor. In the aforementioned checklist, the processor identified a number of provisions regarding the personal data it processes, which concerned, among other things, the Policy (…), instructions for managing the IT system with respect to personal data, risk analysis, and the selection of appropriate safeguards for data protection. As indicated in this correspondence, the processor notified the controller that “(…) 1 An ad hoc internal review was conducted to verify whether (…); 2 A risk analysis was conducted; 3 A review of the security policy was conducted with the purpose of preventing similar incidents in the future; 4 In the second quarter of 2023, in accordance with the internal audit plan, an audit will be conducted in three organizational units regarding the security of personal data. Audits in the remaining organizational units will take place in the third and fourth quarters of 2023. During the audit, additional security measures will be implemented (…); 5 In April 2023, employee training and DPO training were scheduled; 6 The purpose of implementing additional security measures (…) in A. (…) is currently underway. V. Findings regarding the principles of regularly testing, measuring, and evaluating the effectiveness of technical and organizational measures intended to ensure the security of personal data processing. The Controller did not regularly test, measure, or evaluate the effectiveness of the technical and organizational measures ensuring the security of personal data processing at the processor, arguing that it had no suspicions or doubts regarding the processing of personal data by that entity (see the Controller’s letter dated June 26, 2024).
The processor informed the supervisory authority that, prior to the data breach, it had regularly tested, measured, and evaluated the effectiveness of the technical and organizational measures intended to ensure the security of personal data processing. It attached reports confirming periodic reviews in this regard (see letter dated July 9, 2024).
The “Report (…)” dated October 7, 2020, indicated that “ (…) the following computer equipment was inspected: Desktop computers, Laptops, Uninterruptible power supplies, Printers, Plotters, Scanners, Network switches, Routers, Telephones, Projectors. The following actions were performed as part of the inspection: 1 (…). 2 (…). 3 (…). 4 (…). 5 (…). 6 (…). 7 (…). 8 (…). 9 (…). 10 (…)”.
The “Report (…)” dated August 25, 2022, indicated that “ (… ) the following computer equipment was inspected: Desktop computers, Laptops, Uninterruptible power supplies, Printers, Plotters, Scanners, Network switches, Routers, Telephones, Projectors. The following actions were performed as part of the inspection: 1 (…). 2 (…). 3 (…). 4 (…). 5 (…). 6 (…). 7 (…). 8 (…). 9 (…). 10 (…)”.
The Controller and the Processor took action in this area following the data breach that occurred on January 22, 2023. These actions are discussed in sections IV and VI of the description of the facts. VI. Findings Regarding Security Measures Implemented Following the Data Breach.
The Controller provided explanations regarding the measures taken with the purpose of mitigating the risk of a similar incident recurring in the future. In a letter dated February 9, 2023, the Controller stated that “(…)” [original spelling—note by the President of the Personal Data Protection Office]. Furthermore, the Controller stated that “(…) the County Office in Z. plans to conduct cybersecurity training for employees who process personal data, and, due to changes in the Labor Code regarding the rules for remote work, the Personal Data Protection Policy will be updated to bring it into line with the new legal provisions (…)”.
Along with the letter dated July 12, 2023, the Controller provided the supervisory authority with correspondence dated July 7, 2023, which it had received from the processor.
This correspondence indicates that the processor informed the Controller of the measures it had taken following the data breach. The purpose of these measures was “to improve the security of personal data protection following the incident.” In this letter, the processor indicated, among other things, that “(…)”.
The processor also stated that it had commissioned an external entity to conduct training for all employees in administrative positions on “(…) the basic principles of personal data security, including elements of cybersecurity.” In addition to the aforementioned training, the data protection officer and the Manager (…) participated in GDPR workshops on risk analysis, DPIA, and the record of processing activities (…) on April 20–21, 2023.”
The processor informed the controller of the audits conducted and indicated that “(…) the audit had the purpose of determining the actual status of implementation by individual organizational units of tasks arising from generally applicable laws and internal regulations in force at R. (…) in A., and of comparing this status with the required status (…)”.
The letter in question outlined a number of security measures implemented by the processor in the IT area. One of the measures implemented was (…).
The processor also provided explanations in this regard, stating in a letter dated February 5, 2024, that “(…) since the incident occurred, the following actions have been taken: (…)”.
The supervisory authority assessed the evidence to determine its reliability and probative value. The evidence gathered is consistent and mutually corroborative, meaning that it forms a logical account of the actions taken by the Controller and the processor. The explanations and other evidence complement one another, pointing to a specific course of action taken by the Controller and the processor. There are no grounds to question their credibility, as the evidence shows no signs of forgery, is authentic, and is formally correct. The probative value of the gathered evidence is sufficient to issue a decision in this administrative proceeding.
Prior to the issuance of the decision in question, the parties to these administrative proceedings were informed of their rights under Article 10, § 1, and Article 73, § 1, of the Code of Administrative Procedure[1], including the possibility to review the evidence, comment on the evidence gathered, the materials, and the requests submitted, as well as the right to inspect the case file and take notes, make copies, or prepare transcripts thereof. Under these circumstances, after reviewing all the evidence gathered in the case, the President of the Personal Data Protection Office concluded as follows:
Pursuant to Article 34 of the Personal Data Protection Act [2], the President of the Personal Data Protection Office (UODO) is the competent authority for data protection and the supervisory authority within the meaning of Regulation 2016/679. Pursuant to Article 57(1)(a) and (h) of Regulation 2016/679, without prejudice to other tasks specified under that Regulation, each supervisory authority shall, within its territory, monitor and enforce compliance with this Regulation and conduct proceedings regarding infringements of this Regulation, including on the basis of information received from another supervisory authority or another public authority. I. Principles of security in the processing of personal data.
Article 5 of Regulation 2016/679 sets forth the principles governing the processing of personal data, which must be respected by all controllers, i.e., entities that, alone or jointly with others, determine the purposes and means of personal data processing. Pursuant to Article 5(1)(f) of Regulation 2016/679, personal data must be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures (“confidentiality and integrity”). Pursuant to Article 5(2) of Regulation 2016/679, the controller is responsible for compliance with the provisions of paragraph 1 and must be able to demonstrate such compliance (“accountability”). The principle of confidentiality referred to in Article 5(1)(f) of Regulation 2016/679 is further specified in the subsequent provisions of that legal act. Pursuant to Article 24(1) of Regulation 2016/679, taking into account the nature, scope, context, and processing purposes, as well as the risks of varying likelihood and severity to the rights and freedoms of natural persons, the controller shall implement appropriate technical and organizational measures to ensure that processing is carried out in accordance with this Regulation and to be able to demonstrate compliance. These measures shall be reviewed and updated as necessary.
Pursuant to Article 25(1) of Regulation 2016/679, taking into account the state of the art, the cost of implementation, and the nature, scope, context, and processing purposes, as well as the risk of varying likelihood and severity of a breach of the rights or freedoms of natural persons resulting from the processing, the controller—both when determining the means of processing and during the processing itself—shall implement appropriate technical and organizational measures, such as pseudonymisation, designed with the purpose of effectively implementing data protection principles, such as data minimisation, and to provide the processing with the necessary safeguards to meet the requirements of this Regulation and protect data subject rights.
It follows from Article 32(1) of Regulation 2016/679, it follows that the controller and the processor are required to implement technical and organizational measures commensurate with the risk to the rights and freedoms of natural persons, taking into account the varying likelihood and severity of the threat. The provision specifies that when determining the technical and organizational measures, the state of the art, the cost of implementation, the nature, scope, context, and processing purposes, as well as the risk to the rights or freedoms of natural persons—which may vary in likelihood and severity—must be taken into account. Pursuant to Article 32(2) of Regulation 2016/679, when assessing whether the level of security is appropriate, the controller shall take into account, in particular, the risks associated with the processing, especially those resulting from accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access to personal data that is transmitted, stored, or otherwise processed.
As indicated in Article 24(1) of Regulation 2016/679, the nature, scope, context, and processing purposes, as well as the risk of varying likelihood and severity of infringement of the rights or freedoms of natural persons, are factors which the controller is required to take into account when establishing a data protection system, particularly in light of the other obligations set forth in Art. 25(1), Art. 32(1), and Art. 32(2) of Regulation 2016/679. These provisions elaborate on the principle of confidentiality set forth in Art. 5(1)(f) of Regulation 2016/679, and compliance with this principle is necessary for the proper implementation of the principle of accountability under Article 5(2) of Regulation 2016/679. II. Risk Management in the Processing of Personal Data. Failure by the Controller and the Processor to implement adequate technical and organizational measures to ensure security in the processing of personal data. Violation of Article 24(1), Article 25(1), and Article 32( 1 and 2 of Regulation 2016/679, which also resulted in a violation of Article 5(1)(f) and, consequently, Article 5(2) of Regulation 2016/679. One of the legal bases for the protection of personal data introduced by Regulation 2016/679 is the obligation to ensure the security of the data being processed, as set forth, among other places, in Art. 32(1) of Regulation 2016/679 cited above. It should be emphasized that Regulation 2016/679 introduced an approach in which risk management is the foundation of activities related to data protection and is a continuous process. In addition to the risk of infringing the rights or freedoms of natural persons, one must also take into account the state of the art, the cost of implementation, and the nature, scope, context, and processing purposes.
Establishing appropriate technical and organizational measures is a two-step process. First, it is essential to determine the level of risk associated with the processing of personal data, taking into account the criteria set forth in Article 32(1) of Regulation 2016/679, and then to select technical and organizational measures that will ensure an appropriate level of security in light of that risk. Where appropriate, measures such as pseudonymisation and encryption of personal data, the ability to continuously ensure the confidentiality, integrity, availability, and resilience of processing systems and services; the ability to quickly restore the availability of and access to personal data in the event of a physical or technical incident; and the regular testing, measurement, and evaluation of the effectiveness of technical and organizational measures designed to ensure the security of processing. The necessity of implementing appropriate security measures is also highlighted in Art. 24(1) and Art. 25(1) of Regulation 2016/679.
An entity that engages in personal data processing is obligated not only to ensure compliance with the guidelines of the aforementioned Regulation through a one-time implementation of organizational and technical security measures, but also to ensure continuous monitoring of the level of risk and to ensure accountability regarding the level and adequacy of the security measures implemented. This means that it is essential to be able to demonstrate to the supervisory authority that the measures implemented to ensure the security of personal data are appropriate to the level of risk and take into account the nature of the organization and the mechanisms used for personal data processing. The controller is responsible for conducting a detailed analysis of its data processing operations and performing a risk assessment, and then implementing measures and procedures that are appropriate to the assessed risk. The consequence of this approach is the move away from lists of security requirements imposed by the legislature in favor of the independent selection of security measures based on a threat analysis. No specific security measures or procedures are prescribed for data controllers.
In light of the foregoing, it should be noted that the risk analysis conducted should be documented and justified primarily on the basis of the factual circumstances existing at the time it was conducted. In particular, the characteristics of the processes taking place, the assets, vulnerabilities, threats, and existing safeguards within the context of the personal data processing activities must be taken into account. Furthermore, the scope and nature of the personal data processed during these activities must not be overlooked, as the potential negative consequences for an individual in the event of a data breach will depend precisely on the scope and nature of the disclosed data.
For the risk analysis to be conducted properly, the threats that may arise in data processing operations must be defined for each asset.
The term “asset” is used to refer to anything that holds value for the controller. Some assets will be of greater value than others, and they should be assessed and protected from this perspective as well. The interrelationships among existing assets are also very important; for example, the confidentiality of assets (personal data) will depend on the type and method of processing such data. Determining the value of assets is necessary to assess the impact of a potential (a data breach involving personal data). It is evident that a broad scope of personal data or the processing of personal data referred to in Article 9(1) or Article 10 of Regulation 2016/679 may result (in the event of a data breach) in far-reaching negative consequences for data subjects; therefore, such data should be assessed as high-value assets, and consequently, the level of data protection afforded to them should be correspondingly high.
Identifying existing or implemented security measures is necessary, among other purposes, to avoid duplicating them. It is also essential to verify the effectiveness of these security measures, because the existence of an untested security measure, first, may negate its value, and second, it may create a false sense of security and result in the failure to detect a critical vulnerability, which, if exploited, would have very negative consequences, including, in particular, a data breach.
According to the ISO/IEC 27000 standard, a vulnerability is defined as a weakness or gap in security that, if exploited by a given threat, may disrupt operations and may also lead to incidents or data breaches. Threat identification involves determining what threats may arise and from what source (cause)[3].
One method of conducting a risk analysis is, for example, to define the risk level as the product of the probability and the impact of a given incident occurring. A risk matrix is typically used to visually illustrate risk levels, showing the risk levels for which the organization defines appropriate actions.
Risk analysis and risk management are processes that require the cooperation of all stakeholders and, as such, primarily require planning, organizing, directing, and controlling the resources used for processing, carrying out the processing activities themselves, and investigating and detecting potential vulnerabilities and gaps in the security system.
The necessity of conducting a risk analysis is also emphasized in court judgements. The Provincial Administrative Court in Warsaw addressed this issue, among other things, in its judgement of May 13, 2021, case no. II SA/Wa 2129/20, where it stated that “The controller should therefore conduct a risk analysis and assess the threats it faces.” The Provincial Administrative Court in Warsaw, in the reasoning for its judgment of August 26, 2020, Case No. II SA/Wa 2826/19 (upheld by the judgment of the Supreme Administrative Court of February 28, 2024, Case No. II OSK 3839/21), indicated that “(…) This provision [Article 32 of Regulation 2016/679] does not require the controller to implement any technical or organizational measures intended to serve as measures for personal data protection, but rather requires the implementation of appropriate measures. Such adequacy must be assessed in light of the manner and purpose for which personal data are processed, but the risks associated with the processing of such personal data—which may vary in severity—must also be taken into account. The measures adopted must be effective; in specific cases, some measures will need to mitigate low risk, while others must mitigate high risk; however, it is important that all measures (as well as each one individually) be adequate and proportionate to the level of risk (…) technical and organizational measures fall within the responsibility of the controller of personal data, but they cannot be selected in a completely arbitrary and voluntary manner, without taking into account the level of risk and the nature of the personal data being protected (…)”.
The obligation to implement appropriate technical and organizational measures to provide the necessary safeguards for processing, given the adopted method of processing personal data, also stems directly from Article 25(1) of Regulation 2016/679. This provision requires the controller to take data protection into account, in particular during the design phase. It follows that the Data Controller—without precluding the possibility of using laptops outside the organization’s premises to process personal data by persons acting on behalf of the processor—should already at this stage define (and implement) appropriate security measures. The conclusion of a data processing agreement does not relieve the Data Controller of this obligation. As the Supreme Administrative Court noted in its judgment of July 5, 2024, case no. III OSK 2654/22, “(…) the controller was obligated to ‘implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.’ The implementation of such measures should be understood as the introduction of safeguards that are commensurate with the assessed risk, and thus prevent a breach of the rules governing the processing of personal data under normal circumstances. In the circumstances of this case, therefore, the issue was not to prevent the loss of data storage media containing personal data, but to prevent their disclosure in the event of such a loss.”
Applying the above considerations to the facts of this case, it should be noted that since the Controller and the Processor allowed for the processing of personal data in connection with the performance of a specific task, then, in order to properly fulfill the obligations arising from the aforementioned provisions of Regulation 2016/679, they should first conduct a risk assessment and, based on it, identify and implement appropriate measures to ensure security in the processing of personal data. This analysis should identify the risks associated with the aforementioned personal data processing activities and should provide for appropriate security measures to ensure an adequate level of data protection. In the case at hand, conducting such an analysis was particularly important given the specific nature of the tasks performed by the processor on behalf of the Controller. When commissioning the preparation of the project (…), the Controller entered into a personal data processing agreement with R. (…). The Controller and the Processor were therefore aware that the land consolidation project involved the processing of personal data.
Given the nature of the commissioned task and the tool used to perform it (in this case, a laptop), the Controller and the Processor should have identified the risk of a breach of confidentiality of the personal data stored on the computer due to its processing outside the Processor’s premises, especially since no encryption mechanism was used to secure the data processed during its processing, as referred to in Art. 32(1)(a) of Regulation 2016/679.
The evidence gathered indicates that, prior to the data breach, the Controller did not conduct a risk assessment for the process in question, as it relied on the processor’s assurances that the latter had conducted such an assessment. The Controller justified its decision not to conduct such a risk assessment by stating that its employees do not work remotely and that company computers and laptops do not leave the area where personal data is processed, i.e., the organization’s headquarters. The Controller also stated that the reason for not considering the risk of theft of computer equipment located outside the processing area was that neither the Controller’s employees nor the Processor’s employees engaged in personal data processing outside the organizations’ premises or had consent to do so.
The controller also did not take any independent actions to conduct a risk analysis that would account for risks related to the improper performance of the data processing agreement (and related, for example, to the use of portable work computers by the Processor’s employees outside its premises in a manner inconsistent with the rules adopted by that entity). The Controller also did not verify whether the Processor had conducted such an analysis.
The Controller is also required to comply with the principle of accountability referred to in Art. 5(2) of Regulation 2016/679. Case law indicates that “(…) Regulation 2016/679 does not, however, prescribe exactly how a controller should fulfill the obligations arising from the principle of accountability set forth in Art. 5(2) of the aforementioned Regulation; nevertheless, it emphasizes the need to account for compliance with the provisions, report on their implementation, and provide evidence demonstrating the proper performance of those obligations. The principle of accountability requires controllers to demonstrate that they have taken all measures necessary to ensure compliance with the obligation to protect personal data. In light of the aforementioned principle, it is the controller—and not the supervisory authority responsible for personal data protection—who is responsible for developing, updating, and maintaining all procedures and documents related to personal data protection, as well as for establishing evidence demonstrating that processing complies with the regulations (…)” (Judgment of the Provincial Administrative Court in Warsaw of February 1, 2022, Case No. II SA/Wa 2106/21, LEX No. 3392761). This is confirmed by the ruling of the Provincial Administrative Court in Warsaw of February 10, 2021, Case No. II SA/Wa 2378/20: “The principle of accountability is thus based on the controller’s legal responsibility for the proper fulfillment of its obligations and imposes on the controller the duty to demonstrate, both to the supervisory authority and to the data subject, evidence of compliance with all data processing rules.” The Provincial Administrative Court in Warsaw interprets the principle of accountability similarly in its judgment of August 26, 2020, case no. II SA/Wa 2826/19 (upheld by the judgment of the Supreme Administrative Court dated February 28, 2024, case no. III OSK 3839/21): “Taking into account the entirety of the provisions of Regulation 2016/679, it should be emphasized that the controller has considerable discretion regarding the security measures applied; at the same time, however, the controller bears responsibility for any data breach. It follows directly from the principle of accountability that it is the controller who must demonstrate—and thus prove—compliance with the provisions set forth in Article 5(1) of Regulation 2016/679.”
It should be noted that the obligation of accountability specifically shapes the principles for establishing objective truth. Art. 5(2) of Regulation 2016/679 is, in fact, the provision under which the burden of proof regarding compliance with the rules on data processing rests with the party to the proceedings acting as the controller. As explained by the Supreme Administrative Court in its judgment of January 8, 2025 (Case No. III OSK 4868/21), “The statement that the controller should be able to demonstrate compliance with the rules must be interpreted as imposing on the controller the burden of proof regarding compliance with data processing rules. In the event of a dispute with a data subject or a supervisory authority, the controller should be able to present evidence that it complies with the rules.” Furthermore, the Provincial Administrative Court in Warsaw, in its judgment of October 5, 2023, case no. II SA/Wa 502/23, stated that “the supervisory authority is not obligated to specify to the controller the technical and organizational measures that the controller should implement to ensure that the processing of personal data is carried out in accordance with the law. It is the controller’s responsibility to implement these measures and then —if necessary—to demonstrate that it complies with the rules for processing personal data set forth in Regulation 2016/679, in accordance with the principle of accountability (Art. 5(2) of the aforementioned Regulation).”
In the present case, the Controller failed to demonstrate (contrary to the obligation set forth in Article 5(2) of Regulation 2016/679) that it had taken steps necessary to conduct a thorough risk assessment, and thus it also violated the principle of accountability.
It should be emphasized that the provision set forth in Art. 32 of Regulation 2016/679 applies to both the controller and the processor. Furthermore, as follows from Article 28(3)(c) of Regulation 2016/679, the processor shall take all measures required under Article 32 of Regulation 2016/679. However, Guidelines 07/2020 issued by the European Data Protection Board (EDPB) on the concepts of controller and processor under the GDPR[4] (hereinafter also referred to as “Guidelines 07/2020”) outline the specific obligations of the controller and the processor regarding the provision of security measures for the personal data entrusted to them. In paragraph 135 of the aforementioned guidelines, the EDPB states that “Turning to specific obligations, the processor has, first, the obligation to assist the controller in fulfilling the obligation to implement appropriate technical and organizational measures to ensure the security of processing. Although this obligation may overlap to some extent with the requirement that the processor itself implement appropriate security measures, where the processing operations carried out by the processor fall within the scope of the GDPR, they remain two separate obligations, since one relates to the processor’s own measures and the other to the controller’s measures.” As the Supreme Administrative Court noted in its judgment of February 9, 2023, case no. III OSK 3945/21: “Under the GDPR, the legislator has moved away from a static definition of the technical and organizational measures required of the controller in favor of a dynamic assessment of the security measures adopted. This means that it is the responsibility of the controller and the processor to determine appropriate (adequate) security measures, while the supervisory authority retains the authority to verify the adopted level of security.”
The evidence on file shows that the processor conducted a risk assessment which, while it did take into account the risks to personal data in the event of theft or loss of data storage media, the security measures designed to maintain the risk level set by the processor were defined in very general terms. (…).
The security measures defined in this manner by the Processor, with the purpose of minimizing the risk associated with the theft or loss of data storage media, could, however, potentially be considered adequate, but only with respect to those data storage devices that do not leave the premises of the processor’s organization.
However, given that—in accordance with the “Policy (…)” of August 26, 2018— —the possibility of using laptops outside the premises of its organization is provided for and the rules for such use are specified (see point 10 of this decision), the processor should also define other security measures, i.e., measures that will minimize the risks to the personal data being processed associated with the theft or loss of storage media taken outside the organization, including those described in Art. 32(1)(a) of Regulation 2016/679.
In the case at hand, this generality of the risk analysis contributed significantly to the materialization of the risk. As the processor claimed, the computer (removed from its organization) was protected against unauthorized access (…). In the supervisory authority’s assessment, the Processor therefore failed to demonstrate that the safeguards it had implemented were adequate in light of the level of identified risk to the personal data processing operations related to the task entrusted to it by the Controller, related to the theft or loss of data storage media that had left the Processor’s premises. The assumption that “the data stored on the media is (…)” may constitute one element of the security measures. However, in a situation where the only additional mitigating measure is securing the computer (…), doubts arise as to whether such solutions can be considered adequate in the context of widely known vulnerabilities.
As noted above, the processor has permitted the use of laptops in the processing of personal data outside its organization. In light of the above, the Data Processor should implement additional security measures by enabling encryption of the data stored on such computers. This obligation stems from Art. 32(1)(a) of Regulation 2016/679, as previously cited. There is no doubt that taking portable computers used for the processing of personal data outside the organization constitutes precisely such a relevant case requiring the use of encryption.
Given the nature of the Processor’s activities, particularly in light of the fact that it also carries out these activities outside its organization’s premises, it is precisely the lack of surveillance over a computer (or other data storage medium) that poses a threat to the security of personal data processing. However, the mere fact that (…) does not guarantee security in the process of personal data processing.
Whether access to data processing software (such as Y.) was secured (…) is irrelevant to the resolution of the present proceedings. As already noted, the subject of the administrative proceedings is not to investigate the causes and effects of the data breach of January 22, 2023, relating to personal data. The processor should assume that personal data may also be contained in files stored on a computer’s memory, e.g., in the form of screenshots or text documents. It is irrelevant whether the practice of data storage outside a dedicated system (e.g., Y.) complies with the processor’s regulations or is the result of an employee’s actions.
As this case demonstrates, the processor cannot limit itself to merely assuming that an employee will use the computer entrusted to them in accordance with established regulations. Based on logic and real-world experience, it should be noted that the weakest link in a security system is the behavior of the system’s user. Very often, risks to personal data materialize, leading to data breaches resulting from an employee’s erroneous or intentional actions. For this very reason, the processor should conduct a risk analysis, identify vulnerabilities (in this case, an employee’s failure to follow established procedures), and implement adequate measures to ensure security in the processing of personal data. To illustrate this point by way of analogy, one could point out that a processor should use up-to-date antivirus software, precisely to protect the data in its systems in the event that a user fails to comply with the rules for using computer equipment (e.g., a ransomware attack resulting from downloading an infected file—sent to an employee’s private email account—onto a work computer). Conducting an analysis that takes into account the risk of employees failing to follow procedures, and subsequently implementing adequate security measures, should not impose an excessive organizational, technical, or financial burden on the processor.
In summary, with regard to portable computers taken outside the premises of the Controller and/or the processor, given the associated risks, for the purpose of mitigating the potential consequences of a breach and preventing any loss of confidentiality of personal data stored on such a device, the controller or processor, in accordance with the provisions of Regulation 2016/679 (in particular Art. 32(1)(a) of Regulation 2016/679), it is required to implement additional security measures, such as encrypting the data stored on the computers. The determination of these additional security measures should —as already indicated—be the result of a risk analysis, following the proper identification of threats to personal data processed using portable computers used outside the organization of the controller or processor. In the risk analysis, the processor did not foresee the implementation of encryption as a measure to ensure an adequate level of security and, consequently, did not implement it. The processor therefore failed to fulfill the obligation set forth in Article 32(1)(a) of Regulation 2016/679.
While it is not the role of the President of the Personal Data Protection Office (UODO) to specify for processors the particular technical and organizational measures intended to ensure security in the processing of personal data, it is evident from the explanations provided that The processor implemented a risk mitigation measure—encrypting the hard drives of laptops using software (…)—after the data breach had already occurred. It can be assumed that if this type of security measure had been implemented prior to the incident of January 22, 2023, the risk of serious consequences would have been mitigated; that is, if a laptop had been stolen because an employee failed to conduct surveillance over it, the likelihood of the data on the computer being accessed would have been significantly lower.
Failure to conduct a risk analysis in a manner that allows for the selection of adequate security measures means that the Controller has violated Article 24(1), Article 25(1), and Article 32(1) and (2) of Regulation 2016/679, which also results in the Controller’s breach of the principle of confidentiality (Art. 5(1)(f) of Regulation 2016/679) and the principle of accountability (Art. 5(2) of Regulation 2016/679). The Processor, on the other hand, violated Article 32(1) and (2) of Regulation 2016/679. III. The Role of the Controller and the Processor in the Personal Data Processing Process. III a. The Controller’s violation of Article 28(1) of Regulation 2016/679.
If processing is to be carried out on behalf of the controller, then in accordance with the provisions of Article 28(1) of Regulation 2016/679, the controller shall use only the services of processors that provide sufficient guarantees to implement appropriate technical and organizational measures so that the processing meets the requirements of Regulation 2016/679 and protects data subject rights. Pursuant to Article 28(3) of Regulation 2016/679, processing by a processor shall be based on a contract or other legal basis, which are governed by Union law or the law of a Member State and are binding on the processor and the controller, specifying the subject matter and duration of the processing, the nature and processing purpose, the type of personal data and the categories of data subjects, as well as the obligations and rights of the controller. That contract or other legal instrument shall provide, in particular, that the processor: a) processes personal data only on the documented instructions of the controller—which also applies to the transfer of personal data to a third country or an international organisation—unless such an obligation is imposed on the processor by Union law or the law of the Member State to which the processor is subject; in such a case, the processor shall inform the controller of that legal obligation before processing begins, unless such law prohibits the disclosure of such information on grounds of an important public interest; b) ensure that persons authorized to process personal data have committed to confidentiality or are subject to an appropriate statutory duty of confidentiality; c) take all measures required under Article 32; d) comply with the terms and conditions for the use of the services of another processor referred to in paragraphs 2 and 4; e) taking into account the nature of the processing, assists the controller, to the extent possible, through appropriate technical and organizational measures, in fulfilling the obligation to respond to requests from the data subject regarding the exercise of the data subject’s rights set forth in Chapter III; f) taking into account the nature of the processing and the information available to it, assist the controller in fulfilling the obligations set forth in Articles 32–36; g) upon completion of the provision of processing-related services, depending on the controller’s decision, deletes or returns all personal data to the controller and deletes any existing copies thereof, unless Union or Member State law requires storage of personal data; h) provide the controller with all information necessary to demonstrate compliance with the obligations set forth in this article and allow the controller or an auditor authorized by the controller to conduct audits, including inspections, and cooperate with such audits.
In connection with the obligation set forth in point (h) of the first paragraph, the processor shall immediately inform the controller if, in its opinion, an instruction given to it constitutes a violation of this Regulation or other Union or Member State data protection laws.
The use of a processor’s services does not relieve the controller of its obligation to ensure the security of personal data processing. Responsibility in this regard rests primarily with the controller. Guideline 07/2020 highlights the need to verify the processor. It states that “(…) the safeguards ‘provided’ by the processor are those that the processor is able to demonstrate to the controller’s satisfaction, as these are the only safeguards that the controller can effectively take into account when assessing compliance with its obligations. This will often require the exchange of relevant documentation [e.g., privacy policies, terms of service, records of processing activities, records management policies, information security policies, reports from external data protection audits, recognized international certifications such as the ISO 27000 standards] (…) The controller’s assessment of whether the safeguards are sufficient is a form of risk assessment that depends to a large extent on the type of processing entrusted to the processor and must be carried out on a case-by-case basis, taking into account the nature, scope, context, and processing purposes, as well as the risks to the rights and freedoms of natural persons. Consequently, the EDPB cannot provide an exhaustive list of documents or actions that a processor must demonstrate or prove in a given scenario, as this depends largely on the specific circumstances of the processing (…)”.
Similarly to the requirement to conduct a risk assessment, the processor’s obligation to verify is ongoing. The consequences of the controller’s failure to fulfill the obligation of continuous verification of the safeguards referred to in Art. 28(1) of Regulation 2016/679 may directly affect natural persons whose personal data has been entrusted to the processor. The need for continuous verification of the processor is clearly indicated in Guidelines 07/2020, which state that “(…) 99: The obligation to use only the services of processors that “provide sufficient safeguards,” as set forth in Art. 28(1) of the GDPR, is a continuing obligation. It does not end upon the conclusion of a contract or other legal instrument between the controller and the processor. Rather, the controller should verify the processor’s safeguards at appropriate intervals, including, where appropriate, through audits and inspections (…)”.
It should therefore be noted that, pursuant to Article 28(3)(h) of Regulation 2016/679, the controller has the right to conduct audits, including inspections, at the processor’s premises. The purpose of these actions by the controller should be to continuously verify whether the processor is fulfilling all the obligations set forth in Art. 28(3) of Regulation 2016/679. The application of the aforementioned measures is linked to the controller’s obligation under Article 28(1) of Regulation 2016/679. This means that the performance of control activities is also intended to confirm whether the processor continues to provide guarantees that appropriate technical and organizational measures have been implemented so that the processing complies with the requirements of Regulation 2016/679 and protects data subject rights.
Therefore, given that the verification of the processor must be an ongoing process, the failure to conduct periodic and systematic audits or inspections leads to a situation in which the controller will not know whether the processor is performing its tasks in accordance with legal requirements and the provisions of the data processing agreement.
In the supervisory authority’s view, this obligation does not imply the need for permanent and comprehensive auditing of the processor’s entire operations, but rather requires the undertaking of adequate, demonstrable verification measures relating to the outsourcing process and the risks relevant to the processing in question
The authority under Article 28(3)(h) of Regulation 2016/679 thus provides the controller with tools, through which it can ensure that the processing of data subject to outsourcing complies with the standards set forth in Regulation 2016/679, and the submission of evidence confirming the performance of such control measures—in accordance with the principle of accountability — may demonstrate that the controller has taken steps to verify that the processor has implemented appropriate technical and organizational measures to ensure that the processing complies with the requirements of Regulation 2016/679 and protects data subject rights. This right of the controller should be regarded as one of the most important safeguards that the controller should implement for the purpose of properly fulfilling its obligations under Article 32(1) of Regulation 2016/679. This is because, when using the services of a processor, the controller should know whether and how the entity to which it has entrusted the processing of personal data complies with the requirements set forth in Regulation 2016/679.
In the case at hand, a personal data processing agreement was concluded because the processor was responsible for developing the project (…). However, the Controller did not verify whether the Processor provided sufficient guarantees that appropriate technical and organizational measures would be implemented so that the processing would comply with the requirements of Regulation 2016/679 and protect data subject rights. The Controller justified its inaction in this regard by stating that the processor is a specialized entity established to perform the tasks entrusted to it (see the Controller’s letter dated April 7, 2023).
In the supervisory authority’s assessment, the argument presented by the Controller is not convincing. The Controller should not assume a priori that the processor has implemented adequate security measures simply because it is an entity specialized in performing specific tasks. The legal requirement set forth in Article 28(1) of Regulation 2016/679 imposes on the Controller the obligation to take specific actions aimed at ensuring that adequate security measures are implemented in the processing of personal data. When entrusting the processing of personal data to another entity, the controller may not rely solely on its own beliefs unless those beliefs are supported by a verification process conducted on that entity.
The Provincial Administrative Court expressed a similar view; in its judgment of July 3, 2025, case no. II SA/Wa 2056/24, it ruled that “(…) Every controller is subject to the requirement set forth in Art. 28(1) of the GDPR to use only the services of processors that provide sufficient guarantees that appropriate technical and organizational measures will be implemented so that the processing complies with the requirements of the GDPR and protects data subject rights. The obligation to conduct such an assessment is not waived by the fact of long-standing cooperation and the use of a given processor’s services prior to May 25, 2018, i.e., before the GDPR came into effect. (…) Furthermore, merely signing a personal data processing agreement without conducting an appropriate assessment of the processor cannot be viewed as the Controller’s proper fulfillment of the obligation to verify that the processor meets the requirements of the GDPR. Long-term cooperation between the parties, unsupported by periodic, systematic audits or inspections, does not guarantee that the processor will properly perform the tasks required by law and arising from the concluded data processing agreement.”
Not only did the Controller fail to carry out a continuous verification process of the processor, but it also failed to conduct any verification of that entity, not even a one-time one. It should be emphasized that the status of the processor, as an entity specialized in performing tasks commissioned by the controller, if not supported by periodic, systematic audits or inspections, does not guarantee that the Processor has implemented adequate technical and organizational measures to ensure the security of the personal data processing process.
The lack of regular audits, including inspections, at the processor therefore constitutes a violation by the controller not only of Article 28(1) of Regulation 2016/679, but also Article 25(1) of Regulation 2016/679, which requires the Controller to implement appropriate technical and organizational measures, both when determining the means of processing and during the processing itself. The continuity inherent in this obligation may therefore manifest itself in practice, among other things, in the need to ensure regular monitoring of the security measures in place and to maintain ongoing surveillance of the processor through, for example, audits and inspections referred to in Art. 28 para 2. 3(h) of Regulation 2016/679, and which were lacking in the circumstances of this case.
According to Guidelines 07/2020, 135: Turning to specific obligations, the processor is required, first, to assist the controller in fulfilling the obligation to implement appropriate technical and organizational measures to ensure the security of processing. Although this may overlap to some extent with the requirement that the processor itself implement appropriate security measures when the processing operations carried out by the processor fall within the scope of the GDPR, these remain two distinct obligations, as one relates to the processor’s own measures and the other relates to the controller. 138: The obligation to assist does not amount to a transfer of liability, as these obligations are imposed on the controller. For example, although a data protection impact assessment may in practice be carried out by the processor, the controller remains responsible for the obligation to conduct the assessment, and the processor is required to assist the controller “where necessary and upon request.” Consequently, it is the controller who must take the initiative to conduct a data protection impact assessment, not the processor.
It follows from Article 32 of Regulation 2016/679, interpreted in light of the guidelines cited above, that the obligations to implement organizational and technical measures are imposed on both processors and controllers. The fact of entering into a contract and entrusting certain personal data processing activities to a processor does not, therefore—and this must be reiterated— from the obligation to implement appropriate technical and organizational measures referred to in Art. 32 of Regulation 2016/679; nor does it relieve the controller of the obligation to exercise ongoing surveillance over the processor in this regard.
Consequently, in the opinion of the President of the Personal Data Protection Office (UODO), the technical and organizational measures applied by the Controller met the requirements set forth in Art. 32 of Regulation 2016/679 only to a very limited extent, given that the Controller did not enforce the processor’s compliance with the provisions of their data processing agreement and did not verify the processor’s compliance with personal data protection requirements.
It was only after the data breach occurred that the Controller undertook verification measures that can be considered sufficient (see point VI of the description of the facts). The fact that the Controller properly conducted audits after the data breach occurred does not affect the negative assessment by the President of the Personal Data Protection Office (UODO) of the Controller’s actions to date, but merely constitutes grounds for refraining from issuing an order to bring the personal data processing operations into compliance with the requirements set forth in Regulation 2016/679. The irregularities described above indicate that the Controller violated Article 28(1) of Regulation 2016/679. III b. Violation by the Processor of Article 32(1) and (2) of Regulation 2016/679 in conjunction with Article 28(3)(c) of Regulation 2016/679.
At the same time, it should be noted that the failure to implement adequate security measures resulting from a lack of proper cooperation between the controller and the processor does not mean that liability for the violation of the provisions of Regulation 2016/679 should be attributed solely to the controller. According to the judgment of the Provincial Administrative Court in Warsaw dated October 5, 2021, case no. II SA/Wa 528/21, “(…) the controller’s representative is a separate legal entity acting on behalf of the controller, based on the authority granted in the agreement on data processing concluded with the controller. If the processing activities are performed by the processor rather than the controller, then, as a general rule, the provisions defining the obligations related to processing would apply to the actions of that representative. Regulation No. 2016/679, however, allocates these obligations between the controller and the processor, which means that the controller, when entrusting data processing to another entity, is not completely relieved of liability for failure to comply with the legal requirements regarding processing. The provisions of the Regulation assign certain obligations to the controller (Art. 5(2)), while others are addressed simultaneously to both the controller and the processor (Art. 32(1) and (2)). In addition, the processor has separate obligations in this regard (Article 28 of the Regulation). Admittedly, these obligations of the processor should be set forth in a data processing agreement concluded between the parties. Nevertheless, the fact that the parties are required to include them in the agreement does not deprive them of their public-law nature or render them purely contractual obligations; this is, of course, of fundamental importance for determining liability for their breach and is confirmed by Art. 83 para. 4(a) of the Regulation. It should be emphasized that the processor is obligated to cooperate with the controller and even to assist the controller in fulfilling its obligations set forth in Articles 32–36 (Article 28 of the Regulation). Imposing a fairly general obligation on both the controller and the processor to ensure data security (Article 32(1)) does not, of course, imply that these entities must take the same types of actions, nor does it give rise to liability on their part for breaches, regardless of which of them is responsible for them. There is no question here of any joint and several liability, in the legal sense, on the part of the parties with respect to their obligations to ensure the security of data processing or of joint and several liability for a breach of those obligations (…)”.
In the case at hand, the processor not only failed to assist the Controller in fulfilling its obligations set forth in Articles 32–36 of Regulation 2016/679, but, in fact, through its unreliability—as described earlier—contributed to the Controller’s violation of the provisions of Regulation 2016/679.
The result of this lack of reliability is the processor’s violation of Article 32(1) and (2), in conjunction with Article 28(3)(c) and (f) of Regulation 2016/679. IV. The obligation to regularly test, measure, and evaluate the effectiveness of security measures for the processing of personal data. A violation of Article 32(2)(d) of Regulation 2016/679, which also results in the Controller’s violation of Article 5(1)(f) and Article 5(2) of Regulation 2016/679.
Continuing the discussion on security measures, it should be noted that the role of the controller and the processor is not limited solely to the one-time development and implementation of organizational and technical measures intended to ensure that the processing of personal data complies with the principles set forth in Regulation 2016/679. The need for ongoing verification of the adequacy of these measures is particularly important when personal data is processed outside the premises of the processor. In the event of an incident such as the one that occurred in the case at hand (the theft of a laptop containing personal data), it is crucial to analyze the accuracy of the Controller and the Processor's compliance with their obligations under Article 32(1)( d) of Regulation 2016/679, i.e., regularly testing, measuring, and evaluating the effectiveness of technical and organizational measures designed to ensure the security of processing. Regularly testing, measuring, and evaluating the effectiveness of technical and organizational measures designed to ensure the security of processing is a fundamental obligation of every controller and processor under Article 32(1)(d) of Regulation 2016/679. Each of them is therefore required to verify both the selection and the level of effectiveness of the technical measures used at every stage of processing. The comprehensiveness of this verification should be assessed in light of its adequacy in relation to the risks and its proportionality with respect to the state of the art, implementation costs, and the nature, scope, context, and processing purposes. Testing, measuring, and evaluating—in order to fulfill the requirement set forth in Article 32(1)(d) of Regulation 2016/679—must be conducted on a regular basis, in a deliberately planned, organized, and documented manner (in connection with the principle of accountability—Art. 5(2) of Regulation 2016/679) at specified intervals, regardless of changes in the organization and conduct of data processing operations.
New risks or threats may also materialize or be revealed spontaneously, in a manner entirely independent of the controller, and this is a fact that should also be taken into account both when designing a system for protecting personal data and during its implementation. This, in turn, highlights the need to conduct regular reviews of the entire system of personal data protection, assessing both the adequacy and effectiveness of the organizational and technical measures implemented. An assessment of the likelihood of a given event occurring should not be based solely on the frequency of such events within a given organization, as the fact that a particular event has not occurred in the past does not mean that it cannot occur in the future.
The Provincial Administrative Court in Warsaw also highlighted the need for controllers and processors to fulfill this obligation; in its judgment of October 21, 2021, case no. II SA/Wa 272/21, noted that “(…) the President of the Personal Data Protection Office (UODO) was also correct in pointing out, in the reasoning for the contested decision, that the absence in the Company’s procedures of provisions ensuring regular testing, measuring, and evaluating the effectiveness of the technical and organizational measures implemented to ensure the security of data processing contributed to the occurrence of a data breach. The authority also correctly points out that the proceedings demonstrated that the Company did not conduct tests aimed at verifying the security of the application (…) and the system’s WebAPI (…), regarding the IT system’s vulnerability related to the personal data breach that occurred (…) Conducting tests only when a threat arises, without establishing a procedure that would set a schedule for activities ensuring regular testing, measurement, and evaluation of the effectiveness of the implemented measures, is insufficient. Indeed, as evidenced by the collected material, despite the solutions adopted, the Company was unable to detect the vulnerability due to the lack of regular testing of the system implemented by the Company (…) In this context, therefore, there is no basis to question the assessment of the President of the Personal Data Protection Office (UODO) that regular testing, measuring, and evaluating the effectiveness of technical and organizational measures intended to ensure the security of processing is a fundamental obligation of every controller and processor under Art. 32(1)(d) of the GDPR (…)”. In turn, in its judgment of June 6, 2023, case no. II SA/Wa 1939/22, the Provincial Administrative Court in Warsaw noted that “(…) the obligation to regularly test technical and organizational measures to secure the processing of personal data in order to ensure a level of security appropriate to the risk, within the meaning of the introductory sentence of Article 32(1) of the GDPR, follows directly from the wording of subparagraph (d) of the aforementioned Art 32(1), while the obligation to document activities in this regard is established by the principle of accountability (Article 5(2) of the GDPR).” The Provincial Administrative Court in Warsaw expressed a similar view in its judgment of June 21, 2023, case no. II SA/Wa 150/23. The Provincial Administrative Court in W. also draws attention to the above in its judgment of February 27, 2024, case no. II SA/Wa 1404/23, noting that “(…) the implementation of (…) technical and organizational measures is not a one-time action, but should take the form of a process in which the controller [and the processor] reviews and, if necessary, updates the security measures previously adopted” and “(…) the implementation of security measures is intended to be an ongoing process, not a one-time action (…)”.
In the case at hand, the processor declared that it had carried out activities as part of the regular testing, measurement, and evaluation of the effectiveness of security measures for the processing of personal data. However, these activities were limited solely to verifying technical measures. Despite a request from the supervisory authority, the processor failed to demonstrate that it had regularly tested, measured, and evaluated the effectiveness of organizational measures aimed at ensuring an appropriate level of security in the processing of personal data. Its explanations indicate, among other things, that it did not verify whether the laptops used in the processing of personal data were in fact under surveillance by an authorized User. In this particular case, conducting such verification was especially important, as the processor’s risk analysis had specified that the computers should be supervised by authorized persons and stored in locked rooms. Furthermore, the processor’s security policy stated that “(…) (…) (…) (…) (…)”. Since the Processor defined, in both the risk analysis and the security policy, organizational measures aimed at mitigating the risk of a data breach (including a prohibition on removing computer equipment from the processing area without its knowledge and consent, and a prohibition on leaving devices unattended and unsecured), it should regularly test, measure, and evaluate their effectiveness. However, it failed to do so. Regularly testing, measuring, and evaluating the effectiveness of technical and organizational measures designed to ensure the security of processing is one of the obligations of the processor under Article 32(1)(d) of Regulation 2016/679, an obligation which it failed to fulfill properly.
The Controller also provided explanations in this regard. The Controller stated that it did not regularly test, measure, and evaluate the effectiveness of the technical and organizational measures ensuring the security of personal data processing for the process in question.
Regardless of the fairness of the actions taken by the processor in this regard, the Controller was not relieved of its obligation to independently conduct regular testing, measurement, and evaluation of the effectiveness of technical and organizational measures. The Controller should, at a minimum, verify whether the processor’s activities in this regard were carried out correctly. As already noted, the Controller—pursuant to Article 28(3)(h) of Regulation 2016/679—should conduct audits or inspections at the processor, which the Controller failed to do in the present case.
It follows from the foregoing, therefore, that the Controller failed to demonstrate (contrary to the obligation set forth in Article 5(2) of Regulation 2016/679) either the fact that tests were conducted on a regular basis to verify the security of the IT systems used for personal data processing, nor the manner in which such tests were conducted. The findings do not provide grounds for concluding that the technical and organizational measures implemented by the Controller to ensure the security of personal data were appropriate to the state of the art, the costs of implementation, and the nature, scope, context, and processing purposes; in the opinion of the President of the Personal Data Protection Office (UODO), these measures were not adequately reviewed and updated, which consequently failed to ensure the effective implementation of data protection principles.
Consequently, the Controller and the processor failed to comply with the obligation referred to in Art. 32(1)(d) of Regulation 2016/679, and, at the same time, the Controller also violated the principle of confidentiality (Art. 5(1)(f) of Regulation 2016/679) and the principle of accountability (Art. 5(2) of Regulation 2016/679).
It should be added that the supervisory authority does not question the technical reviews themselves. The issue is that the reviews focused primarily on technical safeguards, while no evidence was provided that the effectiveness of organizational measures—such as surveillance of mobile devices, rules governing the removal of equipment from the processing area, or the prohibition on leaving devices unattended—had been tested. V. Summary of the identified violations of Regulation 2016/679.
In the present case, there are no grounds to conclude that the technical and organizational measures applied by the Controller and the Processor to ensure the security of personal data were adequate in light of the state of technical knowledge, for the purpose of processing personal data, the costs of implementation, and the nature, scope, context, and processing purposes, which consequently failed to ensure the effective implementation of data protection principles.
The Controller did not conduct a risk assessment for the process in question, while the general risk assessment conducted by the processor did not provide for appropriate security measures related to the processing of personal data outside the organization’s premises, including those specified in Article 32(1)( (a) of Regulation 2016/679. This means that the Controller violated Article 24(1), Article 25(1), and Article 32(1) and (2) of Regulation 2016/679, which also results in the Controller’s violation of the principle of confidentiality (Art. 5(1)(f) of Regulation 2016/679) and the principle of accountability (Art. 5(2) of Regulation 2016/679).
The Controller and the Processor did not regularly test, measure, and evaluate the effectiveness of the security measures for the processing of personal data. This means that the Controller and the processor violated Article 32(1)(d) of Regulation 2016/679, and, in addition, the Controller also violated the principle of confidentiality (Art. 5(1)(f) of Regulation 2016/679) and the principle of accountability (Art. 5(2) of Regulation 2016/679).
The processor failed to faithfully fulfill its obligations under the agreement on personal data processing. Thus, it violated Article 32(1) and (2) in conjunction with Article 28(3)(c) and (f) of Regulation 2016/679.
The Controller, however, failed to verify the adequacy of the technical and organizational measures implemented by the processor, which were intended to ensure the security of the personal data processing, meaning that the Controller violated Art 28(1) of Regulation 2016/679.
The obligations to implement appropriate technical and organizational measures to ensure that processing is carried out in accordance with Regulation 2016/679 and to provide the necessary safeguards for processing so as to meet the requirements of Regulation 2016/679, with the purpose of ensuring that processing complies with Regulation 2016/679, were imposed on the Controller (and only on the Controller) by the provisions of Article 24(1) and Article 25(1) of Regulation 2016/679. Given the Controller’s failure to implement adequate security measures, as mentioned above, it must be concluded that the Controller has also violated these provisions of Regulation 2016/679. As a consequence of this violation, it must be concluded that the Controller has also violated the principle of confidentiality set forth in Art. 5(1)(f) of Regulation 2016/679, and, consequently, the principle of accountability referred to in Article 5(2) of Regulation 2016/679.
The proper and effective protection of personal data has been elevated to the status of a general principle in Regulation 2016/679, which demonstrates that the issue of ensuring data confidentiality should be treated as a matter of particular importance and priority by the Controller. However, as already demonstrated in the recitals of this decision, the Controller and the Processor failed to implement appropriate technical and organizational measures to ensure the security of personal data processing.
The explanations submitted by the Controller and the processor indicate that the implementation of appropriate procedures and solutions took place only after the data breach in question had occurred (see Section VI of the factual grounds). The fact that changes were made to the security measures for laptops used to process personal data does not alter the negative assessment of this aspect of the personal data processing carried out by the Processor on behalf of the Controller, but merely constitutes grounds for refraining from ordering the aforementioned entities to make changes in this area to achieve the purpose of bringing data processing operations into compliance with the requirements of Regulation 2016/679.
The supervisory authority emphasizes that the mere formal establishment of policies, procedures, access passwords, and periodic technical reviews does not in itself determine the adequacy of security measures within the meaning of Article 32 of Regulation 2016/679. Such adequacy requires an assessment of whether the measures adopted were commensurate with the specific risks associated with the processing in question, including, in this case, the use of laptops and the possibility of losing control over such a device. The issue in this case is therefore not to assume that the mere fact of a laptop theft proves a violation of Regulation 2016/679, but rather that the evidence gathered demonstrated a lack of measures commensurate with that risk, in particular the lack of disk encryption on the laptops and the lack of effective verification of compliance with organizational measures regarding the removal and supervision of equipment. VI. Administrative Fines.
The administrative proceedings conducted by the President of the Personal Data Protection Office (UODO) serve to verify the compliance of data processing with personal data protection regulations and have the purpose of issuing an administrative decision to apply the remedial powers specified in Art 58(2) of Regulation 2016/679.
In view of the foregoing, as well as the data breaches established in these proceedings, the President of the Personal Data Protection Office (UODO)—exercising the authority set forth in Art. 58(2)(i) of Regulation 2016/679, pursuant to which each supervisory authority has the power to impose, in addition to or in lieu of the measures referred to in Article 58(2)(a)–(h) and (j) of that Regulation, an administrative fine pursuant to Article 83—has determined that, in the case at hand, the conditions justifying the imposition of an administrative fine on both the Controller and the processor have been met.
Pursuant to Article 83(4)(a) of Regulation 2016/679, infringements of the provisions concerning the obligations of the controller and the processor referred to in Articles 8, 11, 25–39, and 42 and 43, are subject, pursuant to para 2, an administrative fine of up to 10,000,000 EUR, and in the case of an enterprise, up to 2% of its total worldwide annual turnover from the preceding fiscal year, whichever is higher.
In turn, pursuant to Article 83(5)(a) of Regulation 2016/679, violations of the provisions concerning the fundamental principles of processing, including the conditions for consent, as set forth in Articles 5, 6, 7, and 9, are subject, pursuant to para 2, an administrative fine of up to 20,000,000 EUR, and in the case of an enterprise, up to 4% of its total worldwide annual turnover from the preceding fiscal year, whichever is higher.
Art. 102(1)(1) of the Personal Data Protection Act provides, however, that the President of the Personal Data Protection Office may, by way of a decision, impose administrative fines of up to 100,000 zlotys, on public finance sector entities referred to in Article 9, points 1–12 and 14, of the Act of August 27, 2009, on Public Finance (Journal of Laws of 2025, item 1483). This limit will undoubtedly apply in the present case both to the County Administrator, as a public authority (specifically, a government administrative body), and to R. (…) as a local government budgetary entity. The President of the Office imposes the administrative fines referred to in paragraphs 1 and 2 on the basis of and under the conditions set forth in Article 83 of Regulation 2016/679 (Article 102(3) of the Personal Data Protection Act).
At the same time, it should be noted that, pursuant to Article 83(1) of Regulation 2016/679, each supervisory authority shall ensure that the administrative fines referred to in para 4, imposed pursuant to this article for infringements of the Regulation, 5, and 6, are effective, proportionate, and dissuasive in each individual case.
However, pursuant to Article 83(2) of Regulation 2016/679, administrative fines shall be imposed, depending on the circumstances of each individual case, in addition to or in lieu of the measures referred to in Article 58(2)( (a) through (h) and (j). When deciding whether to impose an administrative fine and determining its amount, due consideration shall be given in each individual case to: (a) the nature, gravity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing in question, the number of data subjects affected, and the extent of the damage suffered by them; b) whether the violation was intentional or unintentional; c) the measures taken by the controller or processor to minimize the damage suffered by the data subjects; d) the degree of responsibility of the controller or processor, taking into account the technical and organizational measures implemented by them pursuant to Articles 25 and 32; e) any relevant prior breaches by the controller or processor; f) the extent of cooperation with the supervisory authority for the erasure of the breach and to mitigate its potential adverse effects; g) the categories of personal data affected by the breach; h) how the supervisory authority became aware of the breach, in particular whether and to what extent the controller or processor reported the breach; i) if measures referred to in Article 58(2) have previously been imposed on the controller or processor concerned in the same case—compliance with those measures; j) the application of approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42; and k) any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial gains obtained directly or indirectly in connection with the infringement or losses avoided. VII. Conduct Subject to Administrative Fines and the Application of Article 83(3) of Regulation 2016/679.
Pursuant to Article 83(3) of Regulation 2016/679, if a controller or processor intentionally or unintentionally infringes several provisions of this Regulation in the course of the same or related processing operations, the total amount of the administrative fine shall not exceed the amount of the fine for the most serious infringement.
Given the finding that both the Controller and the processor committed violations of multiple provisions of Regulation 2016/679 in the facts of the case under review (i.e., in the case of the Controller—Art 24(1), Art 25(1), Article 28(1), and Article 32(1) and (2), which also resulted in a violation of Article 5(1)(f) and Article 5(2) of Regulation 2016/679, and, in the case of the processor—Article 32(1) and (2) in conjunction with Article 28(3)(c) and (f) of Regulation 2016/679), The President of the Personal Data Protection Office (UODO) was required to take into account the provisions cited in the preceding paragraph in order to determine whether the circumstances of this case warrant the supervisory authority’s application of only one or several of the corrective measures provided for in Art. 58(para). 2 of Regulation 2016/679—and, more precisely, whether the authority should impose only one administrative fine on each of the Controller and the processor, addressing all violations committed by those entities, for each of these violations considered individually, the President of the Personal Data Protection Office (UODO) applied the methodology for calculating administrative fines set forth in Guidelines 04/2022[5], according to which the first step in further calculations is “an assessment of the application of Article 83(3) [of Regulation 2016/679]” (see point 17 of Guidelines 04/2022). In accordance with Guidelines 04/2022, the President of the UODO therefore attempted to answer the following questions (see point 24 of Guidelines 04/2022): a) whether the circumstances indicate a single act or multiple acts subject to penalties, b) in the case of a single act, whether that act constitutes a single violation or multiple violations, c) in the case of a single act constituting multiple violations, does the attribution of one violation preclude the attribution of another violation, or should they be attributed concurrently?
The interpretation of the term “a single act” was presented, with reference to Art. 83(3) of Regulation 2016/679, which refers to “the same or related processing operations,” in Guidelines 04/2022. As indicated in paragraph 28 of Guidelines 04/2022, “[t]he term ‘related’ refers to the principle that a single conduct may consist of several parts that are carried out as a result of a single act of will and are contextually (in particular with regard to the identity of the data subject, the processing purpose, and the nature of the processing), spatially and temporally so closely linked that, from an objective point of view, they can be considered a single coherent set of actions.”
The term “processing operations” referred to in Article 83(3) of Regulation 2016/679 is clarified in Article 4(2) of the Regulation, in which “processing” is defined as “any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adapting or modifying, retrieving, consulting, using, disclosing by transmission, dissemination, or otherwise making available, aligning or combining, restricting, erasing, or destroying.” In light of the above, processing shall constitute any action to which the data is subjected until its erasure, loss, or destruction. VII a. Application of Art 83(3) of Regulation 2016/679 to the violations attributed to the Controller.
Referring to the interpretation of the concept of “a single course of conduct” set forth in paragraph 117 of the recitals to this decision, as applied to the violations of Regulation 2016/679 attributed to the Controller, the President of the Personal Data Protection Office (UODO) concluded that the omissions found on the part of the County Administrator constitute “a single coherent course of conduct” within the meaning set forth by the EDPB in Guidelines 04/2022. In justifying this position, it should be noted that, while it cannot be assumed that the discussed violations of Regulation 2016/679 result from a single act of will on the part of the Controller (since the County Administrator made a separate decision regarding the failure to verify the processor with respect to guarantees of the security of the processing of entrusted data, as well as a decision not to conduct a risk analysis, aimed at implementing appropriate technical and organizational measures to ensure the security of processing, as well as a decision not to regularly test, measure, and evaluate the effectiveness of the solutions used), however, all decisions made by the Controller, which are the source of the violations attributed to it, are so closely interrelated in context that, from an objective point of view, they can be considered a single course of conduct. It is therefore reasonable to conclude that the separate decisions (acts of will) constitute successive stages of a decision-making process that was intended to lead to a specific purpose—ensuring the security of the processing of personal data entrusted to the processor. The above position regarding the unity of the Controller’s conduct, leading to the materialization of the violations attributed to it under Article 24(1), Article 25(1), Article 28(1), and Article 32(1) and (2), and, consequently, also Article 5(1)(f) and Article 5(2) of Regulation 2016/679, is confirmed by the fact that these violations occurred within the framework of related processing operations. This is evidenced by the identity of the processing purpose, scope, and nature of the processing. All aspects of the violations identified in this case (failure to verify the processor, failure to conduct a risk assessment taking into account the possibility of a breach of confidentiality of personal data stored on a laptop in connection with its processing outside the processor’s organization’s premises, which resulted in the failure to implement adequate technical and organizational measures, as well as the failure to regularly test, measure, and evaluate the effectiveness of the security measures implemented) are, in fact, considered in relation to the processing of personal data on behalf of the Controller by the processor for the purpose of conducting a merger proceeding, in accordance with the personal data processing agreement dated January 21, 2022. The violations of Regulation 2016/679 identified in this case also relate to the same scope of data, i.e., the personal data of landowners or those in possession of land (…) necessary to conduct the land consolidation proceedings.
The supervisory authority also took into account the fact that the identified violations of Regulation 2016/679 are directly related to the specific method of data processing (which is one of the factors constituting the nature of the processing), namely, the processing of personal data on laptops outside the premises of the Processor’s organization. The Controller’s decision to verify the processor with regard to the security guarantees for data processing and to conduct a risk analysis taking into account the risks associated with the improper performance of the data processing agreement (e.g., the use of portable work computers by the processor’s employees outside its premises in a manner inconsistent with the rules adopted by that entity), would have allowed for the adoption of appropriate technical and organizational measures, followed by monitoring their effectiveness, and thereby potentially avoiding incidents such as the one that initiated these proceedings or at least significantly minimizing the risks associated with them.
In the supervisory authority’s assessment, the source of all violations attributed to the Controller is also the same—for they were caused by a failure to exercise effective control over the processor. The reason for failing to take steps to verify the processor, as well as for failing to implement appropriate technical and organizational measures and for failing to regularly test their effectiveness, was the Controller’s belief that R. (…) “as a highly specialized entity established for this type of task, possesses all the necessary procedures to ensure data protection,” as well as the fact that a personal data processing agreement had been concluded, in which the processor “clearly and unambiguously guaranteed compliance with the rules for the processing of personal data” (see point 17 of the recitals of this decision). Consequently, the a priori assumption that the Processor had implemented technical and organizational measures ensuring the security of personal data processing led to the decision not to verify that entity, not to conduct a risk analysis with the purpose of implementing appropriate technical and organizational measures to ensure the security of processing, and to refrain from regularly testing, measuring, and evaluating the effectiveness of the technical and organizational measures. The Controller’s erroneous belief was therefore the common underlying recital for all of the decisions it made that led to the violations attributed to it. In light of the arguments presented above, it must be concluded that the Controller’s violation of the provisions of Article 24(1), Article 25(1), Article 28(1), and Article 32(1) and (2), and, consequently, also Article 5(1)(f) and Article 5(2) of Regulation 2016/679, was caused by “a single coherent course of conduct” as defined by the EDPB in Guidelines 04/2022. It should also be emphasized that none of these violations precludes the possibility of attributing another violation to the County Administrator. In particular, a finding of a violation of the provisions setting forth the fundamental, general principles of processing referred to in Art. 5 of Regulation 2016/679 does not preclude the possibility of attributing to the Controller (and imposing a financial penalty for) a violation of the specific provisions that elaborate on these principles, i.e., Art. 24(1), Art. 25(1), Art. 28(1), and Art. 32(1) and (2) of Regulation 2016/679. An administrative fine is not imposed, however, for a violation of the obligation set forth in Article 24(1), as it is not listed in Article 83(4)–(6) of Regulation 2016/679. The President of the Personal Data Protection Office (UODO) therefore determined that the County Administrator’s liability in these proceedings should be assessed “concurrently” with respect to all violations committed, i.e., pursuant to Article 83(3) of Regulation 2016/679.
As a result, it is necessary to determine which of the violations is the “most serious” within the meaning of Article 83(3) of Regulation 2016/679. Guidance on identifying the “most serious violation” is set forth in Guidelines 04/2022. According to the position expressed therein, “the phrase ‘the amount of the fine for the most serious violation’ refers to the statutory maximum amounts of administrative fines” specified in Art. 83(4)–(6) of Regulation 2016/679 (see paragraph 43 of Guidelines 04/2022). Thus, the most serious violation in an individual case will be the one for which the EU legislator has established a higher threshold for the maximum administrative fine.
The alleged violations by the Controller of Article 25(1), Article 28(1), and Article 32(1) and (2) of Regulation 2016/679 are specified in Article 83(4)( (a) of Regulation 2016/679, while the violations of Article 5(1)(f) and Article 5(2) of Regulation 2016/679 are specified in Article 83(5)(a). The total administrative fine imposed for the violation of all the above provisions—in accordance with the wording of Article 83(3) of Regulation 2016/679—may not exceed the amount of the fine for the most serious of these violations. However, bearing in mind the penalty limit specified in Art. 102(1)(1) of the Personal Data Protection Act, it should be noted that the administrative fine imposed on the County Administrator may not exceed 100,000 PLN. VII b. Application of Art 83(3) of Regulation 2016/679 to violations attributed to the processor.
When examining the violations of Regulation 2016/679 attributed to the processor in light of the interpretation of the concept of “a single course of conduct,” as set forth in paragraph 117 of the recitals to this decision, it should be noted that R.’s (…) omissions also constitute “a single coherent course of conduct” within the meaning set forth by the EDPB in Guidelines 04/2022. This interpretation is supported by the fact that the violations—consisting, on the one hand, of a failure to implement appropriate technical and organizational measures to ensure the security of personal data processed using laptops and to protect data subject rights, and, on the other hand, in the failure to implement appropriate technical and organizational measures to ensure the regular testing, measurement, and evaluation of the effectiveness of the aforementioned measures intended to ensure the security of processing—although, in the supervisory authority’s assessment, they are not the result of a single act of will on the part of the processor, they result from long-standing negligence not only in the implementation but also in the enforcement of measures for data protection during the processing of personal data by employees using laptops, which would be adequate to the identified risks. These acts of negligence on the part of R. (…) had already committed at the stage of determining the methods of processing, as evidenced by the flawed manner in which the risk analysis related to the processing procedures used in connection with the use of laptops outside the processor’s premises was conducted. These failures continued during the processing itself.
The fact that the violations materialized within the same processing operations also attests to the common nature of the conduct leading to the identified violations of Regulation 2016/679. In the present case, the common factor is, above all, the method of processing—the violations concern the processing of personal data using laptops outside the processor’s premises.
In the supervisory authority’s assessment, the cause of the violations of Regulation 2016/679 attributed to the processor is also common. This was due to an incorrectly conducted risk analysis, which assumed that, for the risk of theft or loss of data storage media (including laptops), an appropriate security measure would be (…). The belief that such a security measure would be sufficient to ensure the security of the processed data resulted in a failure to implement appropriate technical and organizational measures to ensure the security of processing using laptops outside the organization’s premises, as well as the failure to implement appropriate technical and organizational measures to achieve the purpose of regular testing of the effectiveness of the solutions used.
In summary, it must be concluded that the failure to implement appropriate technical and organizational measures to ensure the security of processing, as well as the lack of measures to ensure the regular testing, measurement, and evaluation of the technical and organizational solutions in use, constitutes a single act by R. (…) (relating to the same—within the meaning of Article 83(3) of Regulation 2016/679 —processing operations) that violates the provisions of Article 32(1) and (2) in conjunction with Article 28(3)(c) of Regulation 2016/679. The alleged violations of Article 32(1) and (2), in conjunction with Article 28(3)(c) and (f) of Regulation 2016/679, attributed to the processor are set forth in Article 83( 4(a) of Regulation 2016/679. However, bearing in mind the penalty limit specified in Art. 102(1)(1) of the Personal Data Protection Act, it should be noted that the administrative fine imposed on R. (…) may not exceed 100,000 PLN. VIII. Justification for Imposing and Determining the Amount of the Administrative Fine Imposed on the Controller. VIII a. Grounds for Determining the Amount of the Administrative Fine Imposed on the Controller.
In deciding to impose an administrative fine on the County Administrator, the President of the Personal Data Protection Office—pursuant to Article 83(2)(a) through (k) of Regulation 2016/679 — took into account the following circumstances, which justify the application of this type of sanction in this case and weigh against the amount of the administrative fine imposed.
The nature, gravity, and duration of the infringement, taking into account the nature, scope, or processing purpose of the processing in question, the number of data subjects affected, and the extent of the damage suffered by them (Article 83(2)(a) of Regulation 2016/679). An administrative fine is imposed on the Controller for violating Article 5(1)(f), Article 5(2), Article 25(1), Article 28(1), and Article 32(1) and (2) of Regulation 2016/679. In the opinion of the President of the Personal Data Protection Office (UODO), the identified violations are of significant weight and serious nature. When analyzing the grounds set forth in Article 83(2)(a) of Regulation 2016/679, it should first be noted that even when the processing of personal data is outsourced, The Controller remains responsible for implementing appropriate technical and organizational measures to ensure that processing is carried out in accordance with the provisions of Regulation 2016/679. In this case, the Controller failed to exercise effective surveillance over the processor, which occurred not only in the phase preceding the outsourcing of data processing (with regard to the failure to verify the processor in terms of processing security guarantees), but also persisted throughout the entire period of data processing by R. (…) (with regard to the failure to implement appropriate technical and organizational measures to ensure the security of data processing, as well as the failure to verify the effectiveness of the measures applied). When assessing the nature and severity of the violation of the aforementioned provisions of Regulation 2016/679, it is necessary to take into account that the County Administrator’s omissions led to a breach of the basic principles of personal data processing, which are fundamental within the entire data protection system defining its framework. Legal doctrine indicates that “the general principles of data processing play a special role among the legal norms concerning data protection. These principles are not merely ideas, values, or postulates derived from the body of regulations on personal data protection; rather, they are normative in nature—they are binding legal norms that prescribe a specific course of action. (…) They are of particular importance for the application and interpretation of personal data protection laws. From the fact that a normative act designates certain legal norms as principles, one can conclude that the legislature intended thereby to emphasize their importance and to make them, in a sense, norms that take precedence over the other norms set forth in those provisions”[6]. The significance of the principles governing the processing of personal data—including the principles of confidentiality and accountability, which the Controller violated—is confirmed by the fact that the legislature has established a higher maximum threshold for administrative fines for their violation, i.e., a fine of up to 20,000,000 EUR, and in the case of an enterprise, up to 4% of its total annual global turnover from the previous fiscal year. Another aggravating factor in this case is the nature of the processing carried out by the public authority, which took place within the scope of its public administration duties. As a public administration body, the Controller should demonstrate knowledge of the law and guarantee respect for citizens’ rights and freedoms. Despite the County Administrator’s obligation to take a proactive approach to the security of personal data processing, the Controller, by entrusting the data processing to the processor, failed to take any measures to ensure that the processing complied with Regulation 2016/679. The number of data subjects affected should also be considered an aggravating factor. As indicated above, all violations of Regulation 2016/679 identified in this case relate to the processing of personal data entrusted to the Processor for the purpose of conducting a consolidation procedure, in accordance with the personal data processing agreement dated January 21, 2022. In light of the evidence gathered, it must be concluded that the Controller entrusted the Processor with the personal data of at least (…) individuals. This is because the incident of January 22, 2023, involved that number of individuals (evidence: the Controller’s letter dated February 9, 2023). The incident of January 22, 2023 (which may have been caused by the Controller’s omissions under consideration in this case) entailed a high risk of adverse consequences for the data subjects. During the proceedings, the County Administrator did not present evidence allowing for the conclusion that no unauthorized party had accessed the data processed on the stolen laptop, which could potentially result in its unlawful use in the future. At the same time, although no evidence emerged during the proceedings indicating that the individuals whose data may have been accessed by third parties suffered financial loss; nevertheless, it must be recognized that the mere potential for a breach of the confidentiality of their personal data constitutes non-pecuniary harm (injury) to them, e.g., through a violation of their personal rights, such as mental well-being or the right to privacy. Individuals whose personal data may have been obtained without authorization as a result of a data breach may indeed feel fear of losing control over their personal data or of identity theft and related fraud to their detriment. Meanwhile, as the Court of Justice of the European Union has pointed out, “the fear of possible misuse of personal data by third parties, which the data subject harbors as a result of a breach of this Regulation, may in itself constitute ‘non-pecuniary damage’”[7] within the meaning of Article 82(1) of Regulation 2016/679. Another factor working against the County Administrator is the prolonged duration of the violations of Regulation 2016/679 found in these proceedings. The evidence gathered in this case supports the conclusion that the non-compliance of the processing with the provisions of Regulation 2016/679 lasted from January 21, 2022, (i.e., from the date of conclusion of the personal data processing agreement—see point 14 of the reasoning in this decision) until December 2023. Although the controller provided information and evidence establishing that on March 24, 2023, it instructed R. (…) to complete the checklist for the organization acting as a processor to achieve the purpose of conducting an audit in accordance with Article 28(3)(h) of Regulation 2016/679 with regard to Article 32 of Regulation 2016/679 (see recital 19 of this decision); however, in the supervisory authority’s assessment, the time at which the infringements of Regulation 2016/679 attributed to the Controller ceased, should be linked to the moment when the appropriate technical and organizational measures ensuring the security of data processing entrusted under the agreement of January 21, 2022, were implemented. Such measures, consisting, among other things, of (…), were completed in December 2023. (see paragraph 32 of the recitals of this decision). The infringement therefore persisted for nearly 2 years, which should be considered an aggravating factor significantly influencing both the authority’s decision to impose an administrative fine in this case and the amount of the fine. Taking into account the circumstances outlined above, the authority assessed the criterion set forth in Article 83(2)(a) of Regulation 2016/679, considered as a whole, as a significantly aggravating factor.
The unintentional nature of the infringement (Art 83 para 2(b) of Regulation 2016/679). In analyzing the criterion set forth in Art. 83(2)(b) of Regulation 2016/679, the President of the Personal Data Protection Office (UODO) took into account the position expressed by the European Data Protection Board (EDPB), according to which intent “covers both knowledge and deliberate action, in connection with the characteristics of the prohibited act” (see paragraph 55 of Guidelines 04/2022). Applying the above to the present case, it should be emphasized that the County Administrator explained his failure to verify the processor by his conviction that R. (…)—as a highly specialized entity—had all the necessary procedures in place to ensure data protection, as well as by the fact that a personal data processing agreement had been concluded, in which the processor guaranteed compliance with the rules of processing (see point 17 of the reasoning in this decision). In explaining the failure to conduct a risk analysis for the data processing of data entrusted to R. (…), the Controller stated that it had relied on the processor’s assurances that the latter had conducted such an analysis. The Controller also justified the decision not to conduct a risk analysis by stating that its employees do not work remotely, and that work computers and laptops do not leave the area where personal data is processed, i.e., the organization’s headquarters. The Controller also stated that the reason for not considering the risk of theft of computer equipment located outside the processing area was that neither the Controller’s employees nor the Processor’s employees were authorized to engage in personal data processing outside the organizations’ headquarters with consent (see paragraph 55 of the recitals of this decision). The circumstances indicated above were also the reason for the failure to implement appropriate technical and organizational measures to ensure the security of data processing, as well as the failure to implement technical and organizational measures with the purpose of regularly testing, measuring, and evaluating the effectiveness of the solutions in use. Thus, it must be concluded that the element of “knowledge,” necessary to attribute liability for the violations of Regulation 2016/679, was present on the part of the Controller. The County Administrator did not deny his awareness of the need to verify the processor with regard to guarantees of the security of the processed data. Nor did the Controller deny that he was aware of the need to implement technical and organizational measures to ensure the security of data processing and to test them regularly. At the same time, however, given the established facts, the supervisory authority found no grounds to attribute to the Data Controller the intent to violate the provisions of Regulation 2016/679. In the opinion of the President of the Personal Data Protection Office (UODO), the County Administrator did not act intentionally and did not have the purpose of violating Regulation 2016/679; nevertheless, he committed numerous omissions resulting in a significant increase in the risk to the security of personal data processing, which indicates gross negligence and constitutes a material circumstance weighing against him in determining the amount of the administrative fine.
Categories of personal data affected by the violation (Art. 83(2)(g) of Regulation 2016/679). The violations of Regulation 2016/679 identified in this case concern all personal data transferred by the Controller to the Processor for the purpose of conducting the merger proceedings. Therefore, these were at least the data whose confidentiality was potentially compromised as a result of the incident on January 22, 2023. As indicated in the report submitted by the County Administrator to the President of the Personal Data Protection Office (UODO), the breach of January 22, 2023, concerned the following personal data: last names and first names, parents’ first names, date of birth, residential or temporary address, PESEL identification number, series and number of the national ID card, and other data (land registry numbers) (see point 4 of the reasoning in this decision). As already indicated in paragraph 132 of the reasoning for this decision, there is no evidence in this case that the confidentiality of the data was breached, but the very fact of a breach involving such a wide range of personal data necessitates that this circumstance be considered an aggravating factor. In this context, it is particularly significant that the breach involved, among other things, the PESEL identification number—an 11-digit numerical code that uniquely identifies a natural person and includes, among other things, the date of birth and gender designation— and is therefore closely linked to the natural person’s private sphere and, as a national identification number, is also subject to exceptional protection under Art 87 of Regulation 2016/679. At this point, it is worth referring to Guidelines 04/2022, which state: “[w]ith regard to the requirement to take into account the categories of personal data affected by the breach (Art. 83(2)(g) of the GDPR), the GDPR explicitly identifies the types of data that are subject to special protection and, consequently, to a more stringent response when imposing administrative fines. This applies at least to the types of data covered by Articles 9 and 10 of the GDPR, as well as to data not covered by those articles, the disclosure of which immediately causes harm or distress to the data subject (e.g., location data, data relating to private communications, national identification numbers, or financial data such as transaction statements or credit card numbers). Generally speaking, the greater the number of such categories of data affected by the breach or the more sensitive the data, the greater the weight the supervisory authority may assign to this factor. The amount of data concerning each data subject is also relevant, as the scale of the infringement of the right to privacy and the data breach of personal data increases with the amount of data concerning each data subject” (see paragraphs 57–58 of Guidelines 04/2022). Importantly, the unauthorized disclosure of data such as a PESEL identification number—which, together with a person’s first and last name, uniquely identifies a natural person—can have a real and negative impact on the protection of that person’s rights or freedoms. As the Provincial Administrative Court in Warsaw noted in its judgment of July 1, 2022, case no. II SA/Wa 4143/21 (upheld by the Supreme Administrative Court’s judgment of December 3, 2025, case no. III OSK 2416/22), “in the event of a breach involving data such as first name, last name, and PESEL number, identity theft or forgery is possible, resulting in negative consequences for the data subjects.”
In determining the amount of the administrative fine, the President of the Personal Data Protection Office (UODO) took into account, in favor of the Controller, “other mitigating factors applicable to the circumstances of the case” (Art. 83(2)(k) of Regulation 216/679), the fact that measures were taken to enhance the security of data processing, and the fact that the breach of Regulation 2016/679 had ceased prior to the issuance of this decision. The explanations provided by the County Administrator during the proceedings indicate that, following the data protection breach, the Controller required the processor to complete a checklist for the purpose of conducting an audit and requested information on What measures had been taken to strengthen data security, and also organized cybersecurity training for employees of the County Office in Z. (see points 19–20 and 26 of the reasoning section of this decision). It should be noted, however, that the erasure of the breach of Regulation 2016/679 was largely due to actions taken by the processor, which in February 2023 conducted a risk reassessment and then, between May and December 2023, implemented technical and organizational measures based on that assessment to mitigate the risk of data theft outside the processing site, such as (…). Therefore, given that the erasure of the breach of Regulation 2016/679 required the Controller to take only a very limited scope of actions (i.e., sending a checklist to the Processor and conducting employee training), and since a number of actions that contributed to the cessation of the breach—including those on the part of the County Administrator—were undertaken by the processor, this circumstance was considered to warrant a reduction in the amount of the fine imposed on the controller, albeit to a limited extent.
The circumstances other than those listed below, referred to in Article 83(2) of Regulation 2016/679, after assessing their impact on the violations established in this case, were deemed by the President of the Personal Data Protection Office (UODO) to be neutral in his assessment—that is, having neither an aggravating nor a mitigating effect on the amount of the administrative fine imposed.
Measures taken for the purpose of minimizing the damage suffered by data subjects (Article 83(2)(c) of Regulation 2016/679). In the context of this criterion, what matters is the purpose of the controller’s action, namely to minimize the harm suffered by the data subjects. The President of the Personal Data Protection Office did not note any such actions by the County Administrator in this case. The mere instruction to the processor to provide information about the incident to the data subjects affected by it (evidence: the controller’s letter dated February 9, 2023) cannot be considered, in this case, as an action aimed at minimizing the harm suffered by those individuals. Such an action constitutes merely the fulfillment of a legal obligation incumbent upon the Controller, in accordance with Art. 34(1) of Regulation 2016/679, and failure to comply with which is subject to sanctions under Article 83(4)(a) of Regulation 2016/679. In this context, it must be emphasized that the mere fulfillment by the Controller of the aforementioned obligation to inform data subjects of a data breach cannot be considered a mitigating factor that would reduce the amount of the administrative fine imposed.
The degree of the controller’s liability, taking into account the technical and organizational measures implemented by the controller pursuant to Articles 25 and 32 of Regulation 2016/679 (Article 83(2)(d) of Regulation 2016/679). In this case, the President of the Personal Data Protection Office (UODO) found, among other things, that the Controller had violated Article 25(1) and Article 32(1) and (2) of Regulation 2016/679. Undoubtedly, the County Administrator bears responsibility for failing to implement appropriate technical and organizational measures that could potentially have prevented the data breach that occurred on January 22, 2023. The legislator provided in Recital 74 of Regulation 2016/679 that “[t]he controller should be subject to obligations and legal liability for the processing of personal data carried out by the controller or on the controller’s behalf. In particular, the controller should be required to implement appropriate and effective measures and should be able to demonstrate that the processing operations comply with this Regulation and are effective.” It is clear that, in the context under consideration—namely, the nature, purpose, and scope of the processing of personal data, including processing carried out on behalf of the Controller by the processor—the County Administrator did not do everything that could reasonably be expected of him (see Chapter III(d) of the Guidelines on the Application and Determination of Administrative Fines for the Purpose of Regulation No. 2016/679, adopted on October 3, 2017, hereinafter also referred to as “Guidelines WP 253”), which indicates a failure to fulfill the obligations set forth in Articles 25 and 32 of Regulation 2016/679. In the facts of the case under review, however, this circumstance constitutes the very essence of the violation of the provisions of Regulation 2016/679, which leads to the conclusion that it is not merely a factor that mitigates or aggravates the assessment of the violation. For this reason, the lack of appropriate technical and organizational measures referred to in Articles 25 and 32 of Regulation 2016/679 cannot be considered in this case as a circumstance that could further contribute to a more severe assessment of the violation and the amount of the administrative fine imposed on the County Administrator.
Any relevant prior infringements by the controller (Art 83(2)(e) of Regulation 2016/679). The President of the Personal Data Protection Office (UODO) did not find any prior data breaches on the part of the Controller; therefore, there are no grounds for treating this circumstance as an aggravating factor. At the same time, however, it is the duty of every controller to comply with the law; therefore, the absence of prior violations cannot be treated as a mitigating circumstance when imposing sanctions. This assessment is consistent with the position expressed by the EDPB in Guidelines 04/2022, according to which “[t]he absence of prior violations cannot (…) be considered a mitigating circumstance, since compliance with the provisions [Regulation 2016/679] is the norm. The absence of prior infringements may be considered a neutral factor” (see paragraph 94 of Guidelines 04/2022).
The degree of cooperation with the supervisory authority for the purpose of erasing the infringement and mitigating its potential negative effects (Article 83(2)(f) of Regulation 2016/679). In analyzing this criterion, the supervisory authority took into account the fact that corrective measures (consisting of providing the processor with a checklist and conducting employee training) had been implemented even before the initiation of these administrative proceedings. At the same time, in the case at hand, the President of the Personal Data Protection Office (UODO) did not issue any recommendations, guidelines, or advice to the County Administrator regarding the measures he had implemented in the area of personal data processing security, and all actions taken by the Controller—in response to the data breach —was undertaken voluntarily and independently of the supervisory authority’s position. Given these facts, there are no grounds to consider the Controller’s aforementioned actions in the context of cooperation with the supervisory authority. However, the President of the Personal Data Protection Office (UODO) did take into account—in the Controller’s favor—the fact that the Controller had taken the aforementioned corrective measures to enhance the security of personal data processing —as part of the assessment of the condition set forth in Article 83(2)(k) of Regulation 2016/679 (see paragraph 135 of the reasoning in this decision).
The manner in which the supervisory authority became aware of the breach, in particular, whether and to what extent the controller reported the breach (Articles 83(2)(h) and 83(2)(i) of Regulation 2016/679). The President of the Personal Data Protection Office (UODO) found that the County Administrator had violated personal data protection regulations ex officio—as a result of proceedings initiated by the data controller’s report of a personal data breach on January 26, 2023. By making the notification, the Controller fulfilled its legal obligation. There are therefore no grounds to consider that this fact should be taken into account in its favor. As the EDPB rightly points out in Guidelines 04/2022 “[t]his circumstance is irrelevant when the controller is subject to specific obligations regarding the reporting of breaches (e.g., the obligation to report a data breach set forth in Art. 33 [of Regulation 2016/679]). In such cases, the fact that a report was filed should be considered a neutral circumstance” (see paragraph 98 of Guidelines 04/2022).
If measures referred to in Article 58(2) have previously been imposed on the controller concerned in the same case—compliance with those measures (Article 83(2)(i) of Regulation 2016/679). Prior to issuing this decision, the President of the Personal Data Protection Office (UODO) had not imposed on the Controller, in the case at hand, the measures specified in Art. 58(2) of Regulation 2016/679. This means that the Controller was not required to take any actions related to the application of those measures. In a different situation, the supervisory authority would have assessed such actions, which could have had an aggravating or mitigating effect on the assessment of the established violation of the provisions of Regulation 2016/679.
The application of approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42 (Article 83(2)(j) of Regulation 2016/679). As of the date of this decision, the County Administrator does not apply the approved codes of conduct or approved certification mechanisms referred to in the provisions of Regulation 2016/679. However, as provided by the provisions of Regulation 2016/679, the adoption, implementation, and application of the above measures are not mandatory for the controller. This means that the fact that they are not applied cannot be held against the controller. The situation would be different if the controller had adopted and applied such a mechanism that guarantees a higher-than-standard level of data protection for the personal data being processed. In that case, this circumstance could be assessed in the controller’s favor.
Any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial gains obtained directly or indirectly in connection with the violation or losses avoided (Article 83(2)(k) of Regulation 2016/679). The President of the Personal Data Protection Office (UODO), having thoroughly examined the case, did not identify any circumstances other than those described above that could influence the assessment of the violation of Regulation 2016/679 or the amount of the administrative fine imposed. Nor was it found that the Controller derived any financial benefit or avoided any financial loss as a result of the violation of the provisions of Regulation 2016/679. There are therefore no grounds for treating this circumstance as an aggravating factor. b. VIII b. Determination of the amount of the administrative fine imposed on the Controller in accordance with Guidelines 04/2022.
In determining the amount of the administrative fine imposed on the County Administrator, the President of the Personal Data Protection Office (UODO) applied, to a limited extent, the methodology adopted by the European Data Protection Board (EDPB) in Guidelines 04/2022. The limited scope of application of these guidelines to the calculation of fines imposed on public authorities and entities stems from the inability to use such an entity’s turnover (revenue) as a measure of its size to determine the amount of the fine, so that the fine is effective, proportionate, and dissuasive. As the EDPB indicates in point 10 of its guidelines, if, under national law, supervisory authorities have the power to impose administrative fines on public authorities and entities, these guidelines apply to the calculation of such fines, with the exception of Chapter 4.3 of this document (“Enterprise’s Turnover for the Purpose of Imposing an Effective, Deterrent, and Proportionate Fine”). However, where national law provides for statutory maximum fine amounts for public authorities and entities (other than those resulting from Art. 83(4)–(6) of Regulation 2016/679), Chapter 6 of the guidelines (“Legally Determined Maximum Amount of the Administrative Fine and Liability of Enterprises”) shall not apply. In light of the foregoing, the President of the Personal Data Protection Office (UODO) carried out the calculation process set forth below to determine the fine to be imposed on the Controller.
As the legally prescribed maximum fine that may be imposed on the County Administrator, the President of the Personal Data Protection Office (UODO) adopted—pursuant to Art. 102(1)(1) of the Personal Data Protection Act— - the amount of 100,000 PLN, which applies regardless of which provision of Regulation 2016/679 the infringement concerns.
The President of the Personal Data Protection Office (UODO) classified the violation of the provisions of Regulation 2016/679 identified in this case (see Chapter 4.1 of Guidelines 04/2022). Violations of Article 25(1), Article 28(1), and Article 32(1) and (2) of Regulation 2016/679 fall—pursuant to Article 83( 4(a) of Regulation 2016/679—to the category of infringements punishable by a fine of up to 10,000,000 EUR or up to 2% of the enterprise’s turnover from the previous fiscal year. In turn, violations of Article 5(1)(f) and (2) of Regulation 2016/679 fall (pursuant to Article 83(5)(a) of Regulation 2016/679) fall into the category of infringements subject to the higher of the two penalty amounts provided for in that legal act (with a maximum of up to 20,000,000 EUR or up to 4% of the enterprise’s turnover from the previous fiscal year —and are therefore, in abstracto, the “most serious” of the infringements provided for in Regulation 2016/679.
The supervisory authority assessed the violation of Regulation 2016/679 identified in this case as a violation of a high degree of seriousness (see Chapter 4.2 of Guidelines 04/2022). As part of this assessment, the supervisory authority took into account those factors listed in Article 83(2) of Regulation 2016/679 that pertain to the specific infringement in question (and constitute the “seriousness” of the infringement), namely: the nature, severity, and duration of the breach (Article 83(2)(a) of Regulation 2016/679), the unintentional nature of the breach (Art. 83(2)(b) of Regulation 2016/679), and the categories of personal data affected by the breach (Art. 83(2)(g) of Regulation 2016/679). A detailed assessment of these circumstances is set forth above (see paragraphs 132–134 of the recitals to this decision). At this point, it should be noted that considering their combined impact on the assessment of the violation of Regulation 2016/679 established in this case—viewed as a whole—leads to the conclusion that the level of its seriousness (as understood in accordance with Guidelines 04/2022) is high. Consequently, the starting amount for calculating the fine should be set within the range of 20% to 100% of the maximum fine that may be imposed on the County Administrator (see point 60, third indent, of Guidelines 04/2022), that is—given the maximum amount of 100,000 PLN set for public authorities and entities—from 20,000 PLN to 100,000 PLN. The President of the Personal Data Protection Office (UODO) deemed PLN 30,000 (30% of the legally prescribed maximum fine that may be imposed on the County Administrator) to be an appropriate starting amount, justified by the circumstances of this case.
The supervisory authority assessed the impact on the established violation of Regulation 2016/679 of the other (in addition to those considered above in the assessment of the seriousness of the infringement) circumstances set forth in Art. 83(2) of Regulation 2016/679 (see Chapter 5 of the EDPB Guidelines 04/2022). These circumstances, which may have an aggravating or mitigating effect on the assessment of the infringement, relate to the subjective aspect of the infringement (i.e., the entity that committed the infringement itself and its conduct before, during, and after the infringement) and, where applicable, to other circumstances that may be relevant to its assessment. A detailed analysis and justification of the impact of each of these factors on the assessment of the violation are presented above (see paragraphs 135–144 of the decision’s reasoning). The President of the Personal Data Protection Office (UODO) determined that the mitigating circumstance in this case is the factor provided for in Article 83(2)(k) of Regulation 2016/679, manifested in the Controller’s adoption of measures aimed at enhancing the security of personal data processing (see paragraph 135 of the recitals of this decision). In conducting its analysis in this case, the supervisory authority did not take into account any aggravating circumstances that would have increased the severity of the sanction. It should be emphasized that, although the breach of Regulation 2016/679 had ceased prior to the issuance of this decision—which indicates that one of the main purposes of the penalty, namely restoring compliance with the law, no longer applies— However, the punitive purpose (punishment for unlawful conduct) and the preventive purpose (effectively deterring both the County Administrator and other data controllers from committing future violations of Regulation 2016/679) in the future. Given the existence of the mitigating circumstance indicated above, the President of the Personal Data Protection Office (UODO), in assessing its impact on the established violation of the provisions of Regulation 2016/679 (taking into account that the erasure involved the Controller undertaking a limited scope of actions, i.e., sending a checklist to the processor and conducting employee training, while a number of measures that contributed to the cessation of the infringement on the part of the County Administrator were undertaken by the processor—see paragraph 135 of the reasoning for this decision), deemed it appropriate to reduce the fine amount determined above by 30% (see paragraph 148 of the reasoning for this decision)—to the amount of 21,000 PLN.
Pursuant to Article 83(1) of Regulation 2016/679, each supervisory authority shall ensure that administrative fines imposed for infringements of this Regulation are, in each individual case, effective, proportionate, and dissuasive. However, Guidelines 04/2022 indicate that the final step in calculating a fine in accordance with the methodology set forth therein should be to analyze whether the final amount of the calculated administrative fine meets these requirements and to increase or decrease the fine accordingly (see Chapter 7 of the Guidelines). In conducting such an analysis in this case, the President of the Personal Data Protection Office (UODO) determined that the amount of the fine determined in accordance with the above principles does not require further adjustment in light of the effectiveness, proportionality, and deterrent nature of the fine (Art. 83(1) of Regulation 2016/679).
The President of the Personal Data Protection Office (UODO) concluded that an administrative fine in the amount of 21,000 PLN, imposed under the specific, individual circumstances of this case, would be effective because it would achieve its preventive purpose, which is to prevent future violations of Regulation 2016/679—identical or similar to the one found in this case—committed by both the Controller and other entities. Additionally, the imposed fine, as a punitive measure, will effectively penalize the County Administrator for his unlawful, long-standing conduct.
In the supervisory authority’s view, the penalty imposed will also be proportionate to the established violations of Regulation 2016/679, particularly with regard to their nature and severity. In this context, it should first and foremost be noted that the County Administrator violated the basic principles of personal data processing, which are fundamental to the entire data protection system and define its framework. The proportionality of the sanction imposed is also reflected in the fact that the amount of the fine determined by the supervisory authority will not constitute an excessive burden on the County Administrator. In particular, payment of the fine will not affect the Controller’s ability to fulfill its statutory duties. In the opinion of the President of the Personal Data Protection Office (UODO), the County Administrator should and is able to bear the consequences of his negligence in the area of personal data protection; therefore, it is justified to impose an administrative fine of 21,000 PLN on him.
In the opinion of the President of the Personal Data Protection Office (UODO), an administrative fine of 21,000 PLN will also serve a preventive function in the specific circumstances of this case, as it will signal to both the County Administrator and other data controllers (and in particular other entities in the public finance sector) that the supervisory authority—as the guardian of personal data protection regulations—will vigorously enforce the liability of the aforementioned entities for established data breaches of Regulation 2016/679. Thus, the sanction imposed in these proceedings will deter both the Controller itself and other similar controllers from committing the same or substantively similar violations in the future.
In the supervisory authority’s view, the imposition of an administrative fine in this case was necessary. The application of any other corrective measure provided for in Article 58(2) of Regulation 2016/679 against the County Administrator—in particular, limiting the action to a warning (Article 58(2)( (b) of Regulation 2016/679), would not meet the requirement of proportionality, understood as the necessity for the supervisory authority to apply a measure that is, in particular, commensurate with the gravity of the identified violations. Refraining from imposing an administrative fine would also not guarantee that the Controller would not commit further data breaches of personal data protection in the future. In the supervisory authority’s assessment, only an administrative fine will allow for the effective enforcement of the provisions of Regulation 2016/679 in this case. IX. Justification for Imposing and Determining the Amount of the Administrative Fine Imposed on the Processor. IX a. Grounds for Determining the Amount of the Administrative Fine Imposed on the Processor
In deciding to impose an administrative fine on R. (…), the President of the Personal Data Protection Office (UODO)—pursuant to Article 83(2)(a) through (k) of Regulation 2016/679— — took into account the following circumstances, which necessitated the application of this type of sanction in the present case and weighed against the amount of the fine imposed.
The nature, gravity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing in question, the number of data subjects affected, and the extent of the damage suffered by them (Article 83(2)(a) of Regulation 2016/679). An administrative fine is imposed on the processor for violating Article 32(1) and (2) in conjunction with Article 28(3)(c) and (f) of Regulation 2016/679. In assessing the grounds set forth in Article 83(2)(a) of Regulation 2016/679, it should be emphasized that the provisions violated by R. (…) provisions set forth the fundamental obligations incumbent upon every processor, which confirms the significant gravity and serious nature of the violation. In considering the case at hand, the supervisory authority took into account that the obligation set forth in Article 32(1) and (2) of Regulation 2016/679 “is not an obligation to achieve a specific result”[8], since “the selection of appropriate measures is based on an assessment of the risk to the rights or freedoms of natural persons, taking into account the varying likelihood and severity of the threat, as well as the principle of proportionality, which considers the state of technical knowledge, the cost of implementation, and the nature, scope, context, and processing purposes”[9]. In the opinion of the President of the Personal Data Protection Office (UODO), however, nothing precludes holding R. (…) liability for the violation of this provision, since the processor, in its risk analysis, identified a threat in the form of personal data theft outside the data processing site, which, as it claimed, referred “to the loss of personal data, which may be stored and processed on various types of media, including laptops, outside the processing area” (see point 6 of the reasoning in this decision), failed to implement technical measures adequate to the identified threat. Importantly, the technical measure (…) located on a laptop should be considered adequate in such a situation and not exceeding the principle of proportionality—such a solution was explicitly provided for by the legislator in Art. 32 para. 1.1(a) of Regulation 2016/679 and cannot be considered to exceed the capabilities (e.g., financial) of the processor, since it was implemented immediately following the incident of January 22, 2023. The number of affected data subjects should also be considered an aggravating circumstance. The violation of the provisions of Regulation 2016/679, as established in these proceedings on the part of the processor (consisting, on the one hand, of a failure to implement appropriate technical and organizational measures to ensure the security of personal data processed using laptops and to protect data subject rights, and, on the other hand, on the failure to implement appropriate technical and organizational measures to ensure the regular testing, measurement, and evaluation of the effectiveness of the aforementioned measures) occurred in the course of processing operations carried out on behalf of the County Administrator. The evidence gathered indicates that the Controller entrusted the processor with the personal data of at least (…) individuals—as this was the number of individuals affected by the incident of January 22, 2023. (evidence—letter from the controller dated February 9, 2023). The number of affected data subjects was therefore significant. For the assessment of the analyzed criterion in terms of the extent of the harm suffered by the data subjects, the reasoning presented in paragraph 132 of the recitals of this decision remains valid. As the supervisory authority has already noted, although no evidence emerged during the proceedings to suggest that the individuals whose data may have been accessed by third parties suffered financial damage; however, it must be recognized that the mere potential for a breach of the confidentiality of their personal data constitutes non-financial damage (harm) to them, e.g., through a violation of their personal rights, such as mental well-being or the right to privacy. Another aggravating circumstance in this case is the long duration of the violation. It must be assumed that the non-compliance of the processing with the provisions of Regulation 2016/679 lasted from January 21, 2022, (i.e., from the date of conclusion of the personal data processing agreement—see paragraph 14 of the recitals of this decision) until December 2023, when, according to the Processor’s explanations, the activities implementing technical and organizational measures to ensure the security of data processing were completed (see paragraph 32 of the recitals of this decision). The fact that the violation of the provisions of Regulation 2016/679 for a period of nearly two years should be regarded as a criterion that weighs heavily against the authority’s decision to impose an administrative fine, as well as against the amount of the fine itself. Taking into account the circumstances indicated above, the authority assessed the criterion set forth in Article 83(2)(a) of Regulation 2016/679, considered as a whole, as a factor weighing heavily against the authority.
The unintentional nature of the violation (Art 83 para 2 letter b of Regulation 2016/679). In analyzing this criterion, the President of the Personal Data Protection Office took into account the fact that the processor had conducted a risk assessment (which, as it ultimately turned out, was prepared incorrectly—see point 61 –70 of the recitals to this decision), which identified a risk specified as “theft of personal data outside the location where personal data is processed.” Importantly, the processor itself did not deny during the proceedings that it was aware of the risks arising from the processing of personal data, including on laptops outside its organization, stating that “the risk analysis conducted relates to the loss of personal data that may be stored and processed on various types of media, including laptops outside the processing area” (see paragraph 6 of the recitals of this decision). Thus, the element of “knowledge” necessary to attribute fault to the processor for the committed violations was present. At the same time, however, given the actions taken by R. (…), there are no grounds for attributing to him the intent to violate the provisions of Regulation 2016/679. As noted above, The processor conducted a risk assessment in which it took into account the threat to the security of the processed data in the form of a potential loss of confidentiality resulting from the theft of portable data storage devices outside the processing area; however, this assessment was conducted incorrectly. The only safeguard provided for the identified risk was (…). The assumption that such technical and organizational measures would be adequate demonstrates gross negligence on the part of R. (…), especially considering that the EU legislator explicitly referred in Art. 32(1)(a) to, among other things, the security measure (…). The flawed risk analysis also resulted in a failure to implement technical and organizational measures that would have enabled the effective testing, measurement, and evaluation of the effectiveness of the solutions employed. The omissions committed by the processor may have contributed to an increased risk of a breach of data confidentiality (in the present case, this risk materialized, as evidenced by the incident of January 22, 2023). The flawed risk analysis—which is the first step in the process of identifying, assessing, and managing risks associated with data processing—led to further irregularities in this area. In the supervisory authority’s view, the circumstances outlined above indicate that, in the case in question, R. (…) could and should have foreseen that the measures adopted did not ensure an adequate level of security for personal data processed using laptops outside the organization’s premises. In the supervisory authority’s assessment, however, the purpose of the processor—R.—was not to violate Regulation 2016/679. The processor acted under the mistaken belief that the technical and organizational measures implemented would be sufficient. This demonstrates the unintentional nature of the violations of Regulation 2016/679 attributed to the processor—the entity did not have the purpose of violating Regulation 2016/679, but, as a result of its gross negligence, failed to implement adequate technical and organizational measures that would ensure the security of data processing and the ability to regularly assess the solutions in place. This constitutes an aggravating circumstance affecting the amount of the administrative fine.
Categories of personal data affected by the breach (Art. 83(2)(g) of Regulation 2016/679) Applying the criterion set forth in Article 83(2)(g) of Regulation 2016/679 to the violations of Regulation 2016/679 attributed to the processor, it should be noted that they concerned all personal data transferred by the Controller to the Processor for the purpose of conducting the merger proceedings. These were therefore, at a minimum, the data whose confidentiality was potentially compromised as a result of the incident on January 22, 2023. As indicated in the report submitted by the County Administrator to the President of the Personal Data Protection Office (UODO), the breach of January 22, 2023, concerned the following personal data: first and last names, parents’ names, date of birth, residential or temporary address, PESEL identification number, ID card series and number, and other data (land registry numbers) (see point 4 of the reasoning in this decision). In this context, all considerations set forth in point 134 of the reasoning in this decision remain valid.
In determining the amount of the administrative fine, the President of the Personal Data Protection Office (UODO) took into account, in favor of the processor, under the provision regarding “other mitigating factors applicable to the circumstances of the case” (Article 83(2)(k) of Regulation 216/679), the fact that the Data Processor took measures that led to the erasure of the violation of Regulation 2016/679. After identifying the data breach, the processor took a number of measures aimed at improving the security of personal data processing, as indicated in paragraphs 26–32 of the recitals of this decision. In particular, attention should be drawn to the fact that the processor conducted a risk reassessment and implemented (…). These measures were taken by the processor on its own initiative and resulted in the erasure of the breach of Regulation 2016/679.
The circumstances other than those listed below, referred to in Article 83(2) of Regulation 2016/679, after an assessment of their impact on the violation of Regulation 2016/679 committed by the processor, were deemed by the President of the Personal Data Protection Office (UODO) to be neutral in his assessment, meaning they have neither an aggravating nor a mitigating effect on the amount of the administrative fine imposed.
Measures taken to minimize the damage suffered by data subjects (Article 83(2)(c) of Regulation 2016/679). In the context of this criterion, what matters is the purpose of the processor’s action, namely to minimize the harm suffered by the data subjects. The President of the Personal Data Protection Office did not identify any such circumstances in this case. The notification sent by R. (…) at the controller’s instruction to the data subjects regarding a data breach (evidence — the Controller’s letter dated February 9, 2023) cannot be considered in this case as an action with the purpose of minimizing the harm suffered by those individuals. Such an action constitutes merely a form of assistance provided to the Controller in fulfilling its obligations, in accordance with Article 28(3)(f) of Regulation 2016/679, and as such cannot be considered a mitigating factor that would reduce the amount of the administrative fine imposed.
The degree of liability of the processor, taking into account the technical and organizational measures implemented by it pursuant to Articles 25 and 32 of Regulation 2016/679 (Article 83(2)(d) of Regulation 2016/679) In this case, the President of the Personal Data Protection Office (UODO) found that the processor had violated Article 32(1) and (2) in conjunction with Article 28(3) of Regulation 2016/679. In the supervisory authority’s assessment, the Processor bears a high degree of responsibility for failing to implement appropriate technical and organizational measures that could potentially have prevented the data breach of January 22, 2023. It is clear that, given the nature, purpose, and scope of the personal data processing in question, the processor did not “do everything that could reasonably be expected of it” (see paragraph 77 of Guidelines 04/2022), and thus failed to fulfill the obligations imposed on it by Art. 32 of Regulation 2016/679. In the present case, however, this circumstance constitutes the very essence of the violation of Regulation 2016/679, rather than merely a factor influencing—mitigating or aggravating—its assessment. For this reason, the lack of appropriate technical and organizational measures referred to in Art. 32 of Regulation 2016/679 cannot be considered by the President of the Personal Data Protection Office in this case as a circumstance that could further contribute to a more severe assessment of the violation and the amount of the administrative fine imposed on the processor.
Any relevant prior infringements by the processor (Art 83(2)(e) of Regulation 2016/679). The President of the Personal Data Protection Office (UODO) did not find any prior data breaches of personal data protection regulations on the part of the processor; therefore, there are no grounds to treat this circumstance as an aggravating factor. At the same time, however, it is the obligation of every processor to comply with the law; for this reason, the absence of prior violations cannot be treated as a mitigating circumstance when imposing sanctions (see point 94 of Guidelines 04/2022).
The degree of cooperation with the supervisory authority for the purpose of erasing the violation and mitigating its potential negative effects (Article 83(2)(f) of Regulation 2016/679) In analyzing this criterion, the supervisory authority took into account the fact that that corrective measures had been taken by the processor prior to the delivery of the letter from the President of the Personal Data Protection Office (UODO), in which the processor was informed of the ongoing preliminary investigation, and prior to the initiation of these proceedings. At the same time, in the case at hand, the President of the UODO did not issue any recommendations, guidelines, or advice to R. (…) regarding best practices in the area of personal data processing security, and all actions taken by the processor — taken in response to the data breach — was undertaken voluntarily and independently of the supervisory authority’s position. Given these facts, there are no grounds to consider the aforementioned actions in the context of cooperation with the supervisory authority. The fact that the Data Processor spontaneously took measures with the purpose of enhancing data protection, which led to the erasure of the breach of Regulation 2016/679, was, however, taken into account by the President of the Personal Data Protection Office (UODO) in favor of the processor as part of the assessment of the condition set forth in Art. 83(2)(k) of Regulation 2016/679. The manner in which the supervisory authority became aware of the breach, in particular, whether and to what extent the processor reported the breach (Article 83(2)(h) of Regulation 2016/679) The President of the Personal Data Protection Office (UODO) found, ex officio, that the processor had violated personal data protection regulations—as a result of proceedings initiated by a data breach notification submitted by the controller on January 26, 2023. According to Guidelines 04/2022, “[w]hen a supervisory authority becomes aware of a breach, for example as a result of a complaint or in the course of proceedings, this element should, as a rule, be considered […] a neutral circumstance” (see paragraph 99 of Guidelines 04/2022).
If measures referred to in Article 58(2) have previously been imposed on the processor concerned in the same case — compliance with those measures (Art. 83(2)(i) of Regulation 2016/679) Prior to issuing this decision, the President of the Personal Data Protection Office (UODO) had not imposed on the processor in the case at hand the measures specified in Art. 58(2) of Regulation 2016/679. This means that the processor was not required to take any actions related to the application of those measures. In a different situation, the supervisory authority would have assessed such actions, which could have had an aggravating or mitigating effect on the assessment of the identified infringement.
Application of approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42 (Article 83(2)(j) of Regulation 2016/679) R. (…) as of the date of this decision, does not apply the approved codes of conduct or approved certification mechanisms referred to in the provisions of Regulation 2016/679. However, as provided by Regulation 2016/679, the adoption, implementation, and application of the above measures are not mandatory for the controller. This means that the fact that they are not applied cannot be held against the controller. The situation would be different if the processor adopted and applied such a mechanism that guarantees a higher-than-standard level of data protection for the personal data being processed. In that case, this circumstance could be assessed in its favor
Any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial gains obtained directly or indirectly in connection with the breach or losses avoided (Article 83(2)(k) of Regulation 2016/679). The President of the Personal Data Protection Office (UODO), having comprehensively reviewed the case, did not identify any circumstances other than those described above that could influence the assessment of the violation of Regulation 2016/679 or the amount of the administrative fine imposed. Nor was it found that the processor, in connection with the violation of the provisions of Regulation 2016/679, derived any financial benefit or avoided any such losses. There are therefore no grounds for treating this circumstance as an aggravating factor. IX b. Determination of the amount of the administrative fine imposed on the processor in accordance with Guidelines 04/2022.
In determining the amount of the administrative fine imposed on R. (…), the President of the Personal Data Protection Office (UODO) applied, to a limited extent, the methodology adopted by the European Data Protection Board (EDPB) in Guidelines 04/2022—see point 145 of the reasoning in this decision.
As the legally defined maximum penalty that may be imposed on R. (…), the President of the Personal Data Protection Office (UODO) set—pursuant to Art. 102(1)(1) of the Personal Data Protection Act— — the amount of 100,000 PLN, which applies regardless of which provision of Regulation 2016/679 the infringement concerns.
The President of the Personal Data Protection Office (UODO) classified the violation of the provisions of Regulation 2016/679 identified in this case (see Chapter 4.1 of Guidelines 04/2022). The violation of Article 32(1) and (2), in conjunction with Article 28(3)(c) and (f) of Regulation 2016/679, identified in this case should—pursuant to Article 83( 4(a) of Regulation 2016/679—be classified as an infringement punishable by the lower of the two penalty amounts provided for in Regulation 2016/679 (with a maximum amount of up to 10,000,000 EUR or up to 2% of the enterprise’s total annual turnover from the previous fiscal year). It was therefore considered in abstracto (in the abstract, without regard to the individual circumstances of the specific case) by the EU legislator to be less serious than the infringements specified in Articles 83(5) and (6) of Regulation 2016/679.
The supervisory authority assessed the violation of Regulation 2016/679 identified in this case as a violation of a high degree of seriousness (see Chapter 4.2 of Guidelines 04/2022). As part of this assessment, the supervisory authority took into account those factors listed in Article 83(2) of Regulation 2016/679 that relate to the specific aspects of the infringement of Regulation 2016/679 (which constitute the “seriousness” of the infringement), namely: the nature, gravity, and duration of the infringement (Art. 83(2)(a) of Regulation 2016/679), the unintentional nature of the infringement (Article 83(2)(b) of Regulation 2016/679), and the categories of personal data affected by the breach (Article 83(2)(g) of Regulation 2016/679). A detailed assessment of these circumstances is set forth above (see paragraphs 156–158 of the recitals to this decision). At this point, it should be noted that considering their combined impact on the assessment of the violation of Regulation 2016/679 established in this case, viewed as a whole, leads to the conclusion that the level of its seriousness (as understood in accordance with Guidelines 04/2022) is high. Consequently, the starting amount for calculating the fine should be set within the range of 20% to 100% of the maximum fine that may be imposed on R. (…) (see point 60, third indent, of Guidelines 04/2022), that is—given the maximum amount of 100,000 PLN set for public authorities and entities—from 20,000 PLN to 100,000 PLN. The President of the Personal Data Protection Office (UODO) considered PLN 25,000 (25% of the legally specified maximum fine that could be imposed on R. (…)) to be an appropriate starting amount, justified by the circumstances of this case.
The supervisory authority assessed the impact on the established violation of Regulation 2016/679 of the other (other than those already considered above in the assessment of the seriousness of the infringement) circumstances set forth in Article 83(2) of Regulation 2016/679 (see Chapter 5 of the EDPB Guidelines 04/2022). These circumstances, which may have an aggravating or mitigating effect on the assessment of this violation, relate to its subjective aspect (i.e., to the entity itself that committed the infringement and to its conduct prior to, during, and after the infringement of the provisions of Regulation 2016/679) and, where applicable, to other circumstances that may be relevant to its assessment. A detailed analysis and justification of the impact of each of these factors on the assessment of the infringement are set forth above (see paragraphs 159–168 of the decision’s reasoning). The President of the Personal Data Protection Office (UODO) determined that the mitigating circumstance in this case is the factor provided for in Article 83(2)(k) of Regulation 2016/679, manifested in the processor’s undertaking of measures aimed at enhancing the security of personal data processing, which led to the erasure of the breach of Regulation 2016/679 (see paragraph 159 of the recitals to this decision). In conducting its analysis in this case, the supervisory authority did not take into account any aggravating circumstances that would have increased the severity of the sanction. The erasure of the breach indicates that one of the main purposes of the penalty—restoring compliance with the law—has been achieved. However, the punitive purpose (punishment for unlawful conduct) and the preventive purpose (effectively deterring both R. (…) and other processors from committing future violations of Regulation 2016/679). Given the existence of the mitigating circumstance indicated above (the implementation of measures aimed at improving the security of processing, which led to the erasure of the violation of Regulation 2016/679), and thus the elimination of one of the fundamental purposes of the penalty—namely, restoring compliance with the law—the President of the Personal Data Protection Office (UODO) deemed it appropriate to reduce the penalty amount determined above by 50% (see paragraph 172 of the reasoning in this decision) —to 12,500 PLN.
Pursuant to Article 83(1) of Regulation 2016/679, each supervisory authority shall ensure that administrative fines imposed for infringements of this Regulation are, in each individual case, effective, proportionate, and dissuasive. However, Guidelines 04/2022 indicate that the final step in calculating a fine in accordance with the methodology set forth therein should be to analyze whether the final amount of the calculated administrative fine meets these requirements and, if necessary, to increase or decrease the fine accordingly (see Chapter 7 of the Guidelines). In conducting such an analysis in this case, the President of the Personal Data Protection Office (UODO) determined that the amount of the fine determined in accordance with the above principles does not require further adjustment in light of the effectiveness, proportionality, and deterrent nature of the fine (Art. 83(1) of Regulation 2016/679).
The President of the Personal Data Protection Office (UODO) concluded that an administrative fine in the amount of 12,500 PLN, imposed under the specific, individual circumstances of this case, will be effective because it will achieve its preventive purpose, which is to prevent future violations of the provisions of Regulation 2016/679—identical or similar to the one found in this case—committed by both the processor and other entities. Additionally, the imposed fine, as a punitive measure, will allow for the effective punishment of R. (…) for his unlawful, long-standing conduct.
In the supervisory authority’s view, the penalty imposed will also be proportionate to the established violations of Regulation 2016/679, in particular to their nature and gravity. The proportionality of the sanction imposed is also reflected in the fact that the amount of the fine set by the supervisory authority will not constitute an excessive burden on R. (…). In particular, payment of the fine will not affect the processor’s ability to fulfill its assigned tasks. In the opinion of the President of the Personal Data Protection Office (UODO), R. (…) should and is able to bear the consequences of its negligence in the area of personal data protection; therefore, the imposition of an administrative fine in the amount of 12,500 PLN is justified.
In the opinion of the President of the Personal Data Protection Office (UODO), an administrative fine of 12,500 PLN will also serve a preventive function in the specific circumstances of this case, as it will send a clear message to both R. (…), as well as to other processors (in particular, other entities in the public finance sector), that the supervisory authority — acting as the guardian of personal data protection regulations — will vigorously enforce the liability of the aforementioned entities for established data breaches of Regulation 2016/679. Thus, the sanction imposed in these proceedings will deter both the processor itself and other similar entities from committing the same or substantively similar violations in the future.
In the supervisory authority’s view, the imposition of an administrative fine in this case was necessary. The application to R. (…) of any other corrective measure provided for in Article 58(2) of Regulation 2016/679—in particular, limiting the action to a warning (Article 58(2)( (b) of Regulation 2016/679), would not satisfy the requirement of proportionality, understood as the necessity for the supervisory authority to apply a measure that is, in particular, commensurate with the gravity of the identified violations. Refraining from imposing an administrative fine would also not guarantee that the processor would not commit further data breaches of personal data protection in the future. In the supervisory authority’s assessment, only an administrative fine would allow for the effective enforcement of the provisions of Regulation 2016/679 in this case. Given these factual and legal circumstances, the President of the Data Protection Office has ruled as stated in the operative part. [1] Act of June 14, 1960, Code of Administrative Procedure, hereinafter referred to as Kpa. [2] Act of May 10, 2018, on Data Protection, hereinafter referred to as the Personal Data Protection Act. [3] The definition of “vulnerability” can be found in the document “PN-EN ISO/IEC 27000” approved by the President of the Polish Committee for Standardization and in the “Glossary of Key Cybersecurity Terms of the National Cybersecurity Standard” (https://www.gov.pl/attachment/48226cb6-29d4-49f9-860f-acd703072e60). [4] https://edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-072020-concepts-controller-and-processor-gdpr_pl. [5] EDPB Guidelines on the Calculation of Administrative Fines under the GDPR (Version 2.1), adopted on May 24, 2023 (hereinafter referred to as “Guidelines 04/2022”). [6] P. Fajgielski [in:] Commentary on Regulation No. 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) [in:] General Data Protection Regulation. Personal Data Protection Act. Commentary, 3rd ed., Warsaw 2025, Art. 5. [7] Judgment of the CJEU of December 14, 2023, in Case C-340/21. [8] P. Barta, M. Kawecki, P. Litwiński [in:] P. Litwiński (ed.), Act on the Protection of Personal Data. Commentary [in:] General Data Protection Regulation. Act on the Protection of Personal Data. Selected Sectoral Provisions. Commentary, 2nd ed., 2025, Article 32, Nb 2. [9] D. Lubasz [in:] GDPR. General Data Protection Regulation. Commentary, ed. E. Bielak-Jomaa, Warsaw 2018, Art. 32. phone