Enforcement Β· Polish National Personal Data Protection Office (UODO) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this documentβs text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal β legal information, not advice.
Bank Millennium S.A: Insufficient fulfilment of data breach notification obligations
How it connects
Related across sources
Guidance EDPB Annual Report 2021 Guidance Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Literature GDPR Implementation Series β Hungary: Introduction to the GDPR Application and a Brief History of Data Protection Literature GDPR Implementation Series β United Kingdom: Heading Towards Brexit but with a Data Protection Bill Implementing GDPR Literature GDPR Implementation Series β Spain: Preparations for a New Law on Data Protection to Implement the GDPR Guidance EDPB Annual Report 2023
Full text
The Polish DPA (UODO) has imposed a fine of EUR 78,000 on Bank Millennium S.A.. The UODO had become aware of a data protection breach following a complaint against the bank. It turned out that correspondence sent by the bank through a courier service containing personal data such as first name, last name, PESEL number, home address, account numbers and identification numbers of customers, had been lost. In this regard, the UODO found that the bank had failed to report the incident to the DPA and provide adequate notice to the data subjects.
Industry: Finance, Insurance and Consulting
Original document at the source uodo.gov.pl