Skip to content
Enforcement · Polish National Personal Data Protection Office (UODO) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Company: Insufficient technical and organisational measures to ensure information security

The Polish DPA fined a company in the banking sector EUR 135,600.

€135,600 Fine
Company
POLAND
Art. 38 GDPR Art. 30 GDPR Art. 35 GDPR

Full text

The Polish DPA fined a company in the banking sector EUR 135,600. The DPA inspected the fined company and found several violations of the GDPR. First, the company failed to ensure that the DPO could report directly to top management and that the DPO did not receive instructions on the performance of the tasks given to the DPO. Second, the company failed to include profiling in the list of data processing operations. Third, the company failed to conduct a privacy impact assessment regarding the use of profiling. The violation regarding the DPO resulted in a fine of EUR 61,600. The violation regarding the unlawful use of profiling resulted in a fine of EUR 74,000.

Industry: Finance, Insurance and Consulting

How it connects

15625/2026 Cass.Civ. - 15625/2026 Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its… Supreme Court May 21, 2026 Privacy by Design & Default Privacy by Design DPIA
W256 2227693-1 Austrian FAC: DPA rightly found loyalty program consent for profiling invalid under GDPR On 05.09.2019, the Austrian DPA (DSB) notified the controller of a customer loyalty program that they were initiating an ex officio investigation. The controller responded by… Federal Administrative Court Sep 28, 2023 Marketing Profiling Automated Decision-Making
SAN 3154/2026 National court annuls DPA sanction against KFC Spain over website privacy information In May 2021, a data subject lodged a complaint with the DPA against KFC Restaurants Spain, S.L.U., the controller, concerning the processing of personal data through its website.… Jul 16, 2026 Supervisory Authorities Personal Data Controllers