Enforcement · Polish National Personal Data Protection Office (UODO) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Enea S.A.: Insufficient fulfilment of data breach notification obligations
How it connects
Related across sources
Guidance Guidelines 07/2022 on certification as a tool for transfers Guidance Guidelines 10/2020 on restrictions under Article 23 GDPR Guidance Guidelines 04/2022 on the calculation of administrative fines under the GDPR Guidance EDPB Annual Report 2021 Guidance Guidelines 01/2021 Guidance Guidelines 2/2020 on articles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies
Full text
The Polish DPA (UODO) fined Enea S.A. EUR 30,000 for the controller's failure to report a personal data breach, in violation of Art. 33 (1) GDPR. The DPA received information about a personal data breach from a person who had become an unauthorized recipient of personal data. The breach consisted of sending an email with an unencrypted, non-password protected attachment that contained personal data of several hundred individuals. The sender of the email was an employee of the sanctioned controller.
Industry: Transportation and Energy
Original document at the source www.uodo.gov.pl