UODO fines controller for refusing to cooperate and provide information in two data
The DPA received two complaints against the same company (the controller) due to the unauthorised access to the data subjects’ personal data.
Original title: UODO (Poland) - DKE.561.1.2026
Holding
The DPA held that the controller had violated Articles 31, 58(1)(a), and 58(1)(e) GDPR and issued it a reprimand. According to the DPA, the controller had refused to cooperate with the supervisory authority by failing to respond to the requests for information sent to it. Denying access to the information prevented a comprehensive and timely examination of the case, which in turn resulted in an unjustified prolongation of the proceedings. Furthermore, the DPA held that a reprimand was a sufficient sanction in the present case: the controller had submitted detailed explanations and demonstrated a proactive attitude and willingness to continue cooperation with the DPA and clarify the issues at hand after being contacted electronically. Therefore, the DPA concluded that the controller’s failure to respond to the letters was not intended to deliberately obstruct the handling of the pending complaints.
From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓
The first complaint concerned processing that had taken place in January 2025, while the events giving rise to the second complaint had occurred in May 2025. During the proceedings initiated following the second complaint, the DPA requested certain information related to the processing operations at issue from the controller by sending the controller two letters in July and August respectively. The request included information on the scope of personal data processed, the sources from which the data were obtained, the legal basis and the purposes of processing. The controller never collected the first letter from the post office and failed to respond to the second one despite having received it. The DPA initiated administrative proceedings against the controller for refusal to cooperate due to the controller’s failure to respond to the request for information. The controller was requested to provide information on its income for 2025 for the purposes of determining an administrative fine, which it also failed to do. It was then discovered that the controller had also engaged in similar conduct in the proceedings related to the first complaint. Following this, the DPA contacted the controller electronically, and the controller provided information related to both complaint cases.
Full text 24 findings
Machine translation of the decision, via GDPRhub — not the official text. Read the original
Emblem of the Republic of Poland Office for Personal Data Protection Rulings Portal Decision logo Warsaw, June 1, 2026 not final Decision DKE.561.1.2026 Pursuant to Art. 104 § 1 of the Act of June 14, 1960, Code of Administrative Procedure[1] (hereinafter referred to as: “k.p.a.”) in conjunction with Article 7(1) and (2) and Article 60 of the Act of May 10, 2018, on data protection[2] (hereinafter referred to as: “PDPA”), as well as pursuant to Article 57(1)(a) and (h), Article 58(2)(b) in conjunction with Article 31, and Article 58(1)(a) and ( e) of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as “Regulation 2016/679”[3], following an ex officio administrative proceeding concerning the imposition of an administrative fine on Ms. H. D., who conducts business under the name W. (…) with its registered office in K. at (…), The President of the Personal Data Protection Office (hereinafter: “the President of the PDPA” or “the supervisory authority”), issues a warning to Ms. H. D., who operates a business under the name W. (…) with its registered office in K. at (…), for violating the provisions of Article 31 and Article 58(1)(a) and (e) of Regulation 2016/679, consisting of a failure to cooperate with the President of the UODO in the performance of his duties and a failure to provide the President of the UODO with access to the personal data and information necessary for the performance of his duties in the proceedings bearing case numbers DS.523.613.2025 and DS.523.853.2025. Statement of Reasons I. Facts of the Case.
The President of the Personal Data Protection Office (UODO) received a complaint from Ms. G. T., residing in A. at (…) Street, regarding irregularities in the processing of her personal data by Dr. H. D. (number (…), address: (…) Street, (…)-(…) K.) (hereinafter referred to as: “the Business Operator” or “the Party”) consisting of the unauthorized access on May 25, 2025, to her personal data located at (…). In connection with the above, the President of the Personal Data Protection Office (UODO) initiated an investigative proceeding, case no. DS.523.613.2025.
The President of the Personal Data Protection Office (UODO)—in letters dated July 25, 2025, and August 26, 2025—requested explanations regarding the matter, in particular concerning: 1) whether, and if so, on what legal basis (please specify the specific legal provision), for what purpose, and to what extent (please list the personal data) and from what source did you obtain the Complainant’s personal data (including her PESEL number) used for the purpose of gaining access on May 25, 2025, to her personal data located at (…); 2) whether, and if so, on what legal basis (please specify the specific legal provision), for what purpose, and to what extent (please list the personal data) are you currently processing the Complainant’s personal data referred to in point 1 above; 3) whether, and if so, on what legal basis (please specify the specific legal provision), for what purpose, and to what extent (please list the personal data) did you obtain, on May 25, 2025, access to the Complainant’s personal data stored in (…); 4) whether, and if so, on what legal basis (please specify the specific legal provision), for what purpose, and to what extent (please list the personal data) are you currently processing the Complainant’s personal data referred to in point 3 above. Letter from the President of the Personal Data Protection Office dated July 25, 2025, addressed to the address for service of process disclosed in the Central Information and Register of Business Activity, was returned to the Office for Personal Data Protection after two valid attempts at service, with the annotation: “not picked up within the time limit,” although it was to be considered—pursuant to Article 44 of the Code of Administrative Procedure—as having been properly served. In connection with the return of the unclaimed letter, on August 26, 2025, the President of the Personal Data Protection Office (UODO) again requested that the Party submit an explanation. The summons dated August 26, 2025, was effectively served and received. Despite receiving the aforementioned correspondence, the Party did not respond in any way to the request addressed to it, nor did it provide any justification for its failure to act.
In the correspondence in question (see point 2 of the rationale for this decision) the business operator was informed that failure to provide an explanation regarding the aforementioned matter may result in the imposition of an administrative fine pursuant to Art. 83(5)(e) of Regulation 2016/679. The President of the Personal Data Protection Office (UODO) established the above facts of this case based on the entirety of the official correspondence that the President of the UODO sent to the Business Entity, which is contained in the case file numbered DS.523.613.2025. This correspondence fully and comprehensively documents all attempts by the President of the Personal Data Protection Office (UODO) to obtain the information necessary to perform his duties—in this case, to examine case no. DS.523.613.2025—and, on the other hand, reflects the business’s failure to respond to the UODO President’s requests. II. Proceedings.
Since the Business Entity failed to provide the information necessary to resolve case no. DS.523.613.2025, the President of the Personal Data Protection Office (UODO) initiated these proceedings ex officio against the Party—pursuant to Art. 83 para. 4(a) and Article 83(5)(e) of Regulation 2016/679—the present administrative proceeding, case no. DKE.561.1.2026.(…) concerning the imposition of an administrative fine on the Business for violating Article 31 and Article 58(1)(a) and (e) of Regulation 2016/679. The Party was notified of the initiation of the proceedings by a letter dated February 2, 2026. In that letter, the Business Operator was requested, for the purpose of determining the basis for calculating the administrative fine pursuant to Article 101a(1) of the Personal Data Protection Act, to provide information on its income for 2025, such as a PIT tax return. The Party was informed of the nature of the alleged violation. The party was also informed of the penalties for this violation, as well as of the continuing opportunity to submit explanations requested by the President of the Personal Data Protection Office (UODO) in proceeding No. DS.523.613.2025, which could serve as a mitigating factor in determining the amount of the administrative fine imposed in this case or result in the fine not being imposed. This letter was sent to the current address of the business’s permanent place of business. The mail was not picked up from the post office.
In the course of the proceedings under case no. DKE.561.1.2026.(…) it was established that the Party’s conduct—consisting of a failure to cooperate with the President of the Personal Data Protection Office (UODO) and a refusal to provide information necessary for the supervisory authority to perform its statutory duties—was not incidental in nature and was not limited solely to a single administrative proceeding. The evidence gathered indicates that the Party exhibited similar conduct in another proceeding conducted by the President of the Personal Data Protection Office (UODO), in which the Party failed to provide the authority with access to personal data and information necessary for the authority to exercise its supervisory powers.
In the administrative proceeding pending before the President of the UODO, case no. DS.523.853.2025, initiated by a complaint filed by Ms. S. C., residing in U. (…)-(…) at (…), regarding irregularities in the processing of her personal data by Dr. H. D., consisting of unauthorized access on January 19, 2025, to the Complainant’s personal data located at (…), The President of the Personal Data Protection Office (UODO)—in letters dated October 3, 2025, and November 27, 2025—requested explanations regarding the matter, within the same scope as set forth in point 2, subpoints 1–4 of this statement of reasons.
The letters from the President of the Data Protection Office (UODO), sent to the address for service of process listed in the Central Information and Register of Business Activity, were returned to the Data Protection Office after two valid attempts at service, with the annotation: “not collected within the prescribed time,” and they were to be deemed—pursuant to Article 44 of the Code of Administrative Procedure—to have been properly served.
In the authority’s assessment, the Party’s actions described in points 7–8—consisting of a failure to provide the requested information and a failure to grant access to the personal data and information required by the President of the Personal Data Protection Office—meet the criteria for a violation of Art 58(1)(a) and (e) of Regulation 2016/679, which justifies including them within the scope of these proceedings. Consequently, since the Party’s conduct—consisting of failing to provide access to personal data and information necessary for the President of the Personal Data Protection Office (UODO) to perform his duties—in the matter at hand involved similar conduct, these proceedings, file no. DKE.561.1.2026.(…)—has been expanded to include the circumstances of the Party’s conduct in the proceedings bearing reference number DS.523.853.2025.
The business operator was notified of the expansion of the proceedings under file no. DKE.561.1.2026.(…) by a letter dated February 20, 2026. The mail was not picked up from the post office.
Given the failure to successfully deliver the correspondence via the postal service, the authority took steps to contact the Party electronically. As a result, the Party submitted explanations regarding the subject matter of the proceeding, file no. DS.523.613.2025 (received by the supervisory authority on April 15, 2026) and subsequently also in the proceeding referenced as DS.523.853.2025 (received by the supervisory authority on May 19, 2026). These explanations were included in the evidence and taken into account in the resolution of these cases.
After reviewing all the evidence gathered in the case, the President of the Office for Personal Data Protection concluded as follows. III. Legal Provisions.
Pursuant to Article 57(1)(a) of Regulation 2016/679, the President of the Personal Data Protection Office (UODO), as the supervisory authority within the meaning of Article 51 of Regulation 2016/679, monitors and enforces the application of this Regulation within its territory. Within the scope of his or her powers, the President of the UODO, among other things, conducts proceedings regarding the application of this Regulation, including on the basis of information received from another supervisory authority or another public authority (Art 57(1)(h) of Regulation 2016/679).
To enable the President of the Personal Data Protection Office (UODO) to carry out these tasks, the President is granted a range of powers specified in Art. 58(1) of Regulation 2016/679 with respect to ongoing proceedings, including the power to order a controller and a processor to provide any information necessary for the performance of his or her tasks (Article 58(1)(a) of Regulation 2016/679) and the power to obtain from the controller and the processor access to any personal data and any information necessary for the performance of its tasks (Article 58(1)(e) of Regulation 2016/679).
A violation of the provisions of Regulation 2016/679 resulting in a breach of the authority’s powers specified in Article 58(1) is subject—pursuant to Article 83(5)(e) of Regulation 2016/679—an administrative fine of up to 20,000,000 EUR, or, in the case of an enterprise, up to 4% of its total worldwide annual turnover from the preceding fiscal year, whichever is higher.
In addition, both the controller and the processor are required, upon request by the supervisory authority, to cooperate with it in the performance of its tasks, as provided for in Article 31 of Regulation 2016/679. Failure to comply with this obligation is punishable, pursuant to Article 83(4)(a) of Regulation 2016/679, by an administrative fine of up to 10,000,000 EUR, and in the case of an enterprise, up to 2% of its total annual global turnover from the previous fiscal year, whichever is higher.
The President of the Personal Data Protection Office (UODO) is also entitled to a number of corrective powers specified in Art 58(2) of Regulation 2016/679, including the right to issue a warning to a controller or processor in the event of a violation of the provisions of Regulation 2016/679 through processing operations. In accordance with Recital 148 of Regulation 2016/679, to ensure more effective enforcement of its provisions, sanctions—including administrative fines—should be imposed for violations thereof —in addition to or in lieu of the relevant measures imposed under Regulation 2016/679 by the supervisory authority. If the violation is minor, a monetary fine may be replaced by a warning. However, consideration should be given to the nature, gravity, and duration of the violation; whether the violation was intentional; the measures taken by the controller to minimize the damage; the degree of liability; and any relevant prior violations, the manner in which the supervisory authority became aware of the violation, compliance with measures imposed on the controller or processor, adherence to codes of conduct, and any other aggravating or mitigating factors.
Pursuant to Article 60 of the Personal Data Protection Act, proceedings concerning data breaches are conducted by the President of the Personal Data Protection Office (UODO). In turn, Art. 7(1) of the Personal Data Protection Act provides that in matters not regulated by this Act, administrative proceedings before the President of the Personal Data Protection Office (including proceedings concerning the imposition of an administrative fine, as referred to in Chapter 11 of the Personal Data Protection Act) the provisions of the Code of Administrative Procedure shall apply. Pursuant to Art. 7(2) of the Personal Data Protection Act, these proceedings are single-instance proceedings.
Pursuant to Article 44 of the Code of Administrative Procedure, if it is impossible to serve a document in the manner specified in Articles 42 and 43 of the Code of Administrative Procedure, the postal operator, as defined in the Act of November 23, 2012, The Postal Law provides for storage of the document for a period of 14 days at its postal outlet—in the case of delivery by a postal operator (§ 1). A notice of the letter’s deposit, along with information regarding the possibility of its pickup within seven days from the date the notice was left at the location specified in § 1, shall be placed in the recipient’s mailbox or, if this is not possible, on the door of the addressee’s residence, office, or other premises where the addressee conducts business, or in a visible location at the entrance to the addressee’s property (§ 2). If the item is not collected within this period, a second notice is left informing the recipient that the item may be collected within a period not exceeding fourteen days from the date of the first notice (§ 3). Service is deemed to have been effected upon the expiration of 14 days from the date of the first attempt at service, and the document is placed on file (§ 4). IV. Legal Assessment.
Applying the provisions of Regulation 2016/679 cited above to the facts established in this case, it must be concluded that the party to the proceedings under case nos. DS.523.613.2025 and DS.523.853.2025, by failing to respond to the requests from the President of the Personal Data Protection Office (UODO) to provide explanations, violated the obligation to cooperate with the supervisory authority and the obligation to provide the President of the UODO with access to personal data and information necessary for the performance of his duties, that is, the obligations arising from Article 31 and Article 58(1)(a) and (e) of Regulation 2016/679. In this case, the information relevant to the further course of the proceedings consisted of all data concerning the circumstances of the processing of the Complainants’ personal data in both proceedings conducted by the authority. Denying access to the aforementioned information—which the President of the Personal Data Protection Office (UODO) had requested from the Party and which was undoubtedly in the Party’s possession—prevented a comprehensive and timely review of the case, resulting in an unjustified prolongation of the proceedings, which in turn violated the fundamental principles governing administrative proceedings—specifically, the principles of thoroughness and expediency set forth in Art. 12(1) of the Code of Administrative Procedure.
In the course of the complaint proceedings under case nos. DS.523.613.2025 and DS.523.853.2025, the President of the Personal Data Protection Office (UODO) requested the Party to submit the information necessary to assess the merits of the allegations raised by the Complainants regarding irregularities in the processing of their personal data. None of the letters sent to the Party received a response. The fact that one of the letters was delivered (in the proceedings under case no. DS.523.613.2025—the request dated August 26, 2025) justifies the conclusion that the Party had an objective opportunity to review its content and respond to it within the deadline set by the supervisory authority. It was only after contact via email that the Party agreed to cooperate with the supervisory authority. The Party’s failure to act, which is undisputed in light of the evidence gathered in this case, necessitated the initiation of these proceedings regarding the imposition of an administrative fine, as a result of which the Party finally provided the requested explanations—which allowed the President of the Personal Data Protection Office (UODO) to continue proceedings in cases No. DS.523.613.2025 and DS.523.853.2025.
In light of the above findings, there is no doubt that the Party, through its conduct, violated the provisions of Regulation 2016/679. The Party’s failure to receive the correspondence does not relieve it of liability for the established omission. This stems from the fact that the Party bears the burden of ensuring a correspondence workflow that allows for the effective and timely fulfillment of the obligations imposed upon it, including those arising from personal data protection regulations. The organizational risk associated with the functioning of the internal document circulation system rests solely with the Party and may not be shifted to other entities or lead to a reduction in the effectiveness of applicable legal provisions. Consequently, the failure to receive correspondence from a post office, regardless of the reasons, has no bearing on the assessment of the Party’s conduct in this case, as this circumstance stems solely from the improper organization of the mail collection process and cannot serve as a justification for the failure to perform or the untimely performance of the obligations incumbent upon it.
Despite the obvious negligence on the part of the Business, the President of the Personal Data Protection Office (UODO) took the position that the established violation—consisting of a failure to cooperate with the President of the UODO in the performance of his duties and a failure to provide the President of the UODO with access to the personal data and information necessary for the performance of his duties—however reprehensible — the erasure had been performed by the Party while these proceedings regarding the imposition of an administrative fine were still ongoing, i.e., upon receipt by the UODO of explanations in both complaint proceedings conducted by the authority. By submitting detailed explanations, the Party demonstrated a proactive attitude and a willingness to continue cooperating with the supervisory authority to achieve a comprehensive clarification of the allegations made against it. This leads to the conclusion that the Party’s failure to respond to the UODO President’s requests did not stem from bad faith and had no purpose other than to deliberately obstruct the proceedings conducted by the supervisory authority. In the opinion of the President of the Personal Data Protection Office (UODO), the mere initiation of proceedings regarding the imposition of an administrative fine and the real prospect of a financial penalty being imposed served as a clear signal to the Party further evasion of the obligations imposed by Regulation 2016/679 would inevitably lead to the imposition of the most severe sanction provided for by those provisions.
In light of the foregoing, the President of the Personal Data Protection Office (UODO) deemed it justified to issue a warning to the Party regarding the established violation of Article 31 and Article 58(1)(a) and (e) of Regulation 2016/679, while also concluding that, in light of the criteria set forth in Article 83(2) of Regulation 2016/679, such a warning will be effective and sufficient. It should be noted, however, that should a similar incident occur in the future, any warning issued by the President of the Personal Data Protection Office (UODO) to the Party will be taken into account when assessing the grounds for imposing an administrative penalty, in accordance with the principles set forth in Article 83(2) of Regulation 2016/679, and will be considered to its disadvantage. Given these factual and legal circumstances, the President of the Personal Data Protection Office (UODO) has ruled as stated in the operative part of this decision. [1] Journal of Laws of 2025, item 1691. [2] Journal of Laws of 2019, item 1781. [3] Official Journal of the EU L 119, p. 1; Official Journal of the EU L 127 of 2018, p. 2; Official Journal of the EU L 74 of 2021, p. 35. phone UODO Hotline 606-950-000, open on business days from 10:00 a.m. to 2:00 p.m. uodo© UODO 2018–2025 All rights reserved. arrow-ui-linkUODO Home Page arrow-ui-linkReport an Error Accessibility Public Information Bulletin (BIP) Office for Personal Data Protection 1A Stanisława Moniuszki St., 00-014 Warsaw kancelaria@uodo.gov.pl Hours of operation: 8:00 a.m.–4:00 p.m. Public Information Bulletin | Privacy Policy UODO Portal 1.2.9 uses NeuroLex technology from Neurosoft Sp. z o.o.