UODO reprimands mayor for disclosing data subject's data to company without legal basis
The data subject requested the mayor of their place of residence (the controller) to provide them scans of contracts the city had concluded with certain companies and invoices issued to these companies in February 2024.
Status Not cited by any decision here yet
Original title: UODO (Poland) - DS.523.2582.2024
Holding
The DPA issued the controller a reprimand for the disclosure of personal data to unauthorised entities without a legal basis. It held that the processing had not been lawful under Article 6(1)(c) GDPR, as the controller could have complied with its obligation to respond to the request for information without disclosing the data subject’s personal data. Furthermore, the DPA held that the controller had violated the principles of lawfulness and confidentiality laid down in Articles 5(1)(a) and 5(1)(f) GDPR respectively.
From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓
In April 2024, the controller responded that he did not possess the requested documents. This response contained the first and last name as well as the email address of the data subject and was forwarded to multiple recipients, including one of the companies the data subject’s request concerned. Following this, the data subject filed a complaint with the DPA. The controller argued it had processed the data subject’s personal data solely for responding to the request for access to public information. In addition, the controller was of the opinion that the processing had been necessary to fulfil a legal obligation. Since the request concerned multiple parties, the controller had determined there had been special grounds for disclosing the processed data.
Full text 7 findings
Machine translation of the decision, via GDPRhub — not the official text. Read the original
Warsaw, May 18, 2026 Illegitimate Decision DS.523.2582.2024 Pursuant to Article 104 § 1 of the Act of June 14, 1960—Code of Administrative Procedure (Journal of Laws of 2025, item 1691)—in conjunction with Article 7(1) and (2) of the Act of May 10, 2018, on the protection of personal data (Journal of Laws No. U. 2019, item 1781, as amended), Article 6(1) and Article 58(2)(b) of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (Journal of Laws No. EU L 119 of May 4, 2016, p. 1, OJ EU L 127, May 23, 2018, p. 2, and OJ EU L 74 of March 4, 2021, p. 35), following the administrative proceedings regarding Mr. T’s complaint. W., residing at ((...)-(...)) in (...), concerning irregularities in the processing of his personal data by the Mayor of the City of U. (U.U., Pl. (...), (...)-(...) U.), consisting in making available to Z. S.C. (ul. (...), (...)-(...) G.) personal data of Mr. T. W., specifically his first name, last name, and email address, in the letter from the Mayor of the City of U. dated (...) April 2024 (ref. (...)) and (...) April 2024 (ref. no.: (...)), which constitute a response to Mr. T. W.’s requests for public information dated (...) February 2024 and (...) April 2024, the President of the Personal Data Protection Authority issues a warning to the Mayor of the City of U. (U.U., Pl. (...), (...)-(...) U.) for violating Article 6(1) of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (Official Journal of the European Union No. L 119 of May 4, 2016, p. 1, Official Journal of the European Union No. L 127, May 23, 2018, p. 2, and OJ EU L 74, March 4, 2021, p. 35, which is made available without a legal basis to Z. S.C. (ul. (...), (...)-(...) G.) the personal data of Mr. T. W.—specifically, his first name, last name, and email address—in the letter from the Mayor of the City of U. dated (...) April 2024 (ref. (...)) and (...) April 2024 (ref. no.: (...)), which constitute the response to Mr. T. W.’s requests for public information dated (...) February 2024 and (...) April 2024. Justification The President of the Office for Personal Data Protection (hereinafter also referred to as the President of the Office for Personal Data Protection) received a complaint from Mr. T. W., residing at ((...)-(...)) at (...) (hereinafter referred to as the Complainant), regarding irregularities in the processing of his personal data by the Mayor of the City of U. (U.U., Pl. (...), (...)-(...) U.) (hereinafter referred to as the President), consisting in making available to Z. S.C. (ul. (...), (...)-(...) G.) personal data of the Complainant, specifically his first name, last name, and email address, in the President’s letters dated (...) April 2024 (ref. (...)) and (...) April 2024 (ref. no.: (...)), in response to the Complainant’s requests of (...) February 2024 and (...) April 2024 for the disclosure of public information. In the course of the investigation procedure in this case, the President of the Office of Economic Affairs established the following facts.
The applicant in the request of (...) February 2024, filed pursuant to Article 2(1) of the Act of September 6, 2001, on Access to Public Information (Journal of Laws No. U. of 2022, item 902, as amended) (hereinafter referred to as d.d.i.p.), requested that the President provide scans of contracts with Z. S.C. and Y. (...) as well as scans of all invoices issued to the aforementioned entities. In response to the above, the President, by letter dated (...) April 2024 (ref. (...)), informed the Complainant that he did not have the requested contracts and invoices. The aforementioned letter from the President dated (...) April 2024 was forwarded to Z.’s email address, as indicated by the phrase “They receive” (evidence: a copy of the Complainant’s application dated (...) February 2024, and a copy of the President’s letter dated (...) April 2024 attached to the Complainant’s complaint dated (...) April 2024).
The applicant in the request dated (...) April 2024, pursuant to Article 2(1) of the Civil Code, asked the President to provide information on whether the Municipal Office in U. and the municipal companies subordinate to him had entered into agreements with Z. S.C. and Y. (...) (point 1 of the Complainant’s aforementioned application). In response to the above, the President, by letter dated (...) April 2024 (ref. (...)), informed the Complainant that the Municipal Office in U. had not entered into agreements with the aforementioned entities. At the same time, he noted that the scope of the questions contained in points 2–5 of the Complainant’s request does not constitute public information. The aforementioned letter from the President dated (...) April 2024 was forwarded to Z.’s email address, as indicated by the use of the phrase “They receive” (evidence: a copy of the Complainant’s application dated (...) April 2024, a copy of the President’s letter dated (...) April 2024 attached to the complaint dated (...) April 2024).
The President stated that the Applicant’s personal data are processed solely for the purpose of reviewing the request for access to public information pursuant to the provisions of the d.d.i.p., and that such processing is necessary to comply with the legal obligation incumbent upon the data controller (evidence: clarifications from the President dated (...) June 2024).
On (...) April 2024, the President received a request from Mr. B. D. to provide public information regarding the following: “Did the Municipal Office in U. provide information on the lack of contracts concluded with the companies Z. and Y. (...)? If so, I will request a scan of the responses provided.” (evidence: the President’s explanations dated (...) August 2024).
The President stated that “the first name, last name, and email address of the Complainant were provided in the response to the request for public information submitted by Mr. B. D., i.e., pursuant to the Act of September 6, 2001, on access to public information (...) On (...) April 2024, the U.G. City Hall sent a response to Mr. T. W. to the email address indicated in the request for public information, i.e., (...) and to Mr. B. D. at the email address indicated in the application for public information, i.e. (...) a letter responding to the requests submitted by the aforementioned applicants for public information” (evidence: explanations from the President dated (...) June 2024, a copy of the President’s letter dated (...) April 2024.
The President stated that “In the course of the ongoing administrative proceedings, the Authority conducted the assessment on its own, and since the case involved more than one applicant, the Councilor considered that there was a special prerequisite for providing processed information. In view of the above, by letter dated (...) April 2024, he replied to the complainant and the party at the email address indicated in Mr. B’s application. D.” (evidence: the President’s explanations of (...) August 2024). After reviewing all of the evidence gathered, the President of the Office of Economic Services weighed the following. It should first be emphasized that the controller is obligated to ensure that personal data are processed in accordance with the law. This means that the controller, when processing personal data, must meet at least one of the conditions set forth in Article 6(1) of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (Official Journal of the EU L 119 of May 4, 2016, p. 1, OJ EU L 127, May 23, 2018, p. 2, and OJ EU L 74 of March 4, 2021, p. 35), hereinafter referred to as the GDPR. The list of conditions set forth in Article 6(2)(1) of the GDPR is exhaustive. Each of the grounds justifying the processing of personal data is autonomous and independent. This means that these conditions are, in principle, equal, and therefore the fulfillment of at least one of them constitutes lawful processing of personal data. The above provision stipulates that processing is lawful only in cases where—and to the extent that—at least one of the following conditions is met: (c) the processing is necessary to comply with a legal obligation to which the controller is subject. At the same time, it should be emphasized that any personal data processing operation must comply with the general principles of data processing set forth in Article 5(1) of the GDPR, and in accordance with Article 5( 2 The controller is responsible for compliance with the provisions of paragraph 1 and must be able to demonstrate compliance with them (“accountability”). In addition, Article 5(1)(f) of the GDPR imposes an obligation on the data controller to process personal data in accordance with the principles of integrity and confidentiality. This means that the controller must ensure adequate security of personal data, including protection against unauthorized or unlawful processing and accidental loss, destruction, or damage, through appropriate technical or organizational measures. In accordance with Article 4(1)(d.d.i.p), public authorities and other entities performing public tasks—in particular public authorities—are required to make public information available. Pursuant to Article 7(1)(2) of the d.d.i.p., public information shall be made available through the access procedures referred to in Articles 10 and 11 However, as indicated in Article 10(1) of the d.d.i.p., public information that has not been made available in the Public Information Bulletin or the data portal is made available upon request. At this point, it is necessary to note the restrictions imposed by Article 5(2) of the d.d.i.p., which stipulates that the right to public information is subject to restrictions due to the privacy of a natural person or a business secret. This limitation does not apply to information regarding persons performing public functions, as it relates to the performance of those functions—including the terms of appointment and performance of duties—or in cases where a natural person or entrepreneur waives their right. The evidence gathered in this case shows that the Complainant submitted two requests to the Mayor for public information concerning, among other things, Z. S.C. At the same time, the President received a request from Mr. B. D. for public information regarding whether the President had provided public information concerning the absence of contracts concluded with the companies Z. and Y. (…), and if so, Mr. B. D. requested that scanned copies of the responses provided be sent to him. The President, acting for the purpose of responding to Mr. B. D., forwarded to him letters addressed to the Complainant without anonymizing the Complainant’s personal data. As indicated above, pursuant to Article 5(2) of the GDPR, the controller is responsible for compliance with the provisions of paragraph 1 and must be able to demonstrate such compliance. It should be noted that the Mayor, as the controller of personal data, has specific obligations arising from applicable data protection laws, including Art. 5(1)(c) of the GDPR, according to which personal data must be adequate, relevant, and limited to what is necessary for the purposes for which they are processed. This provision requires a restriction of processing to the minimum necessary and the processing of only such data without which the purpose cannot be achieved. Furthermore, reference was also made to the restrictions imposed by Article 5(2) of the Act on Access to Public Information, which provides that the right to public information is subject to restrictions based on the privacy of a natural person or business secrecy. This restriction does not apply to information about individuals holding public office that is related to the performance of those functions, including the conditions under which such functions are entrusted and performed, nor does it apply when a natural person or business entity waives their right. It should be noted that the Complainant’s personal data—specifically, his first name, last name, and email address—as the person who submitted a request to the authority under the public information access procedure, were protected. The evidence gathered in this case does not provide grounds for concluding that the Complainant waived his right to privacy with respect to the Mayor’s responses to his requests that were made available. Furthermore, the circumstances cited by the Mayor do not indicate that the Complainant is a person holding public office within the meaning of Article 5(2) of the Act on Access to Public Information. Furthermore, in the explanations submitted to the President of the Personal Data Protection Office (UODO), the President did not cite a specific provision of substantive law serving as the basis for conducting a single administrative proceeding resulting from the requests of the Complainant and Mr. B. D., to which Z. S.C. was deemed a party. The Authority notes that the procedure for reviewing a request for access to public information is not an administrative proceeding within the meaning of the provisions of the Act of June 14, 1960, Code of Administrative Procedure, but rather a separate procedure of an informational nature, based on the provisions of the Act on Access to Public Information. The submission of two or more requests for access to public information, even if they concern the same or similar scope of information, does not result in a single, joint procedure. Each request for access to public information constitutes a separate request, subject to independent consideration. The provisions of the Act on Access to Public Information do not provide for the possibility of combining several requests into a single procedure or “aggregating” them based on the similarity of the subject matter of the requests. Accordingly, the disclosure of the Complainant’s personal data—specifically, his first name, last name, and email address—to Z. S.C. or to Mr. B. D., was not necessary to fulfill the obligation under Article 4(1)(1) of the d.d.i.p., which the Mayor could have fulfilled without hindrance without disclosing the Complainant’s aforementioned personal data. It must therefore be concluded that the Mayor, by disclosing the Complainant’s aforementioned personal data in the letters dated (…) April 2024 and (…) April 2024—which constituted a response to the Complainant’s request filed pursuant to Article 2(1) of the d.d.i.p.—disclosed the Complainant’s personal data without a legal basis, thereby violating Article 6(1) of the GDPR. The Mayor failed to demonstrate that he was subject to a legal obligation requiring him to disclose the Complainant’s data in the manner contested by the Complainant (Art. 6(1)(c) of the GDPR). Furthermore, in this case, there was a violation of the requirements set forth in Article 5(1)(a) and (f) of the GDPR. The disclosure of the Complainant’s personal data to an unauthorized entity undoubtedly constitutes unlawful processing of data; furthermore, this violated the principle requiring the controller to process personal data in accordance with the principle of confidentiality. The assessment conducted by the President of the Personal Data Protection Office in each case serves to examine the validity of issuing a decision to a specific entity in accordance with the provisions of Art. 58(2) of the GDPR has the purpose of restoring compliance with the law in the data processing process—and is therefore justified and necessary to the extent that irregularities in the processing of personal data exist. In light of the foregoing, and taking into account the gravity and irreversible nature of the identified violation, the President of the Personal Data Protection Office deemed it appropriate to apply in this case the remedial measure provided for in Art. 58(2)(b) b of the GDPR and issued a warning to the Mayor in connection with the violation of Article 6(1) of the GDPR. In the opinion of the President of the Personal Data Protection Office, the application of this legal instrument in this case is proportionate to the severity of the established violation Given these factual and legal circumstances, the President of the Personal Data Protection Office ruled as stated in the operative part.