Enforcement · Polish National Personal Data Protection Office (UODO) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Virgin Mobile Polska: Insufficient technical and organisational measures to ensure information security
The Polish DPA (UODO) fined Virgin Mobile Polska EUR 443,000 due to a data leak that allowed unauthorized third parties to access personal data stored by Virgin Mobile Polska as a result of inadequate security measures.
Full text
The Polish DPA (UODO) fined Virgin Mobile Polska EUR 443,000 due to a data leak that allowed unauthorized third parties to access personal data stored by Virgin Mobile Polska as a result of inadequate security measures. The DPA notes that the company did not conduct regular and extensive tests on the effectiveness of the measures applied to ensure data security. Indeed, activities in this regard were conducted only in the event of a suspected security leak.
Industry: Media, Telecoms and Broadcasting
How it connects
Related across sources
C-119/12 Judgment of the Court (Third Chamber), 22 November 2012.#Josef Probst v mr.nexnet GmbH.#Reference for a preliminary ruling from the Bundesgerichtshof.#Electronic communications — Directive 2002/58/EC — Article 6(2) and (5) — Processing of personal data — Traffic data necessary for billing and debt collection — Debt collection by a third company — Persons acting under the authority of the providers of public communications networks and electronic communications services.#Case C‑119/12. In Case C-119/12, the Court of Justice of the European Union interpreted Article 6(2) and (5) of Directive 2002/58/EC (the ePrivacy Directive) in proceedings between Josef Probst… CJEU Nov 22, 2012 Personal Data Processing Telecommunications
Us I-4772/2023-10 A utility and municipal services enterprise, Zagrebački Holding d.o.o (the controller) provided users of its services with the option to request a copy of their bill via email. Where the name appearing in the email address differed from the user’s… US Zagreb - Us I-4772/2023-10 ·Administrative Court of Zagreb Jul 22, 2026 Personal Data Retention Period Controllers
3 O 762/19 LG Rostock: Pre-ticked cookie consent boxes invalid under Art 6(1)(a) GDPR The German consumer organisation Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V. (vzbv, the claimant) filed a lawsuit… Sep 15, 2020 Consent Legitimate Interest Controllers
C-293/12 Digital Rights Ireland Ltd v Minister for Communications C-293/12 (Digital Rights Ireland) CJEU Apr 8, 2014 IP Address Storage Limitation Right to be Forgotten
Guidelines 9/2022 personal data breach notification under GDPR Guidelines ·EDPB Apr 4, 2023 Notification Obligation Data Breaches Personal Data
Opinion 2/2026 EDPB-EDPS Joint opinion 2/2026 on the Proposal for a Regulation as regards the simplification of the digital legislative framework ( EDPB, EDPB-EDPS Joint opinion 2/2026 on the Proposal for a Regulation as regards the simplification of the digital legislative framework (Digital Omnibus) Opinion Feb 11, 2026 Notified Body Reporting and Notification Obligations Notification Obligation Data Breaches