Enforcement · Polish National Personal Data Protection Office (UODO) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
24/7 Communication Sp. z o.o.: Insufficient technical and organisational measures to ensure information security
The Polish DPA has imposed a fine of EUR 43,000 on 24/7 Communication Sp.
Full text
The Polish DPA has imposed a fine of EUR 43,000 on 24/7 Communication Sp. z o.o. The fined entity acted as the data processor for McDonald’s Polska Sp. z o.o. (see ETid: 2757). The processor failed to implement sufficient technical and organisational measures to ensure data security, resulting in a data breach. The controller additionally infringed the principle of data minimisation and failed to adequately involve the DPO in relevant activities.
Industry: Employment
How it connects
Related across sources
Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Jul 7, 2021 Controllers Processors IP Address
C-60/22 UZ v Bundesrepublik Deutschland In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik… CJEU ·Fifth Chamber May 4, 2023 Right to Restriction Right to be Forgotten Integrity and Confidentiality Principle
14/2021 Cypriot court backs DPA fines of €40,000 each on football clubs and €25,000 on processor On 26 July 2021, a journalist informed the Cypriot DPA of a security vulnerability on an online platform. This online platform hosted ticket purchase sites of two Cypriot football… Administrative Court of Cyprus May 12, 2026 Controllers Processors Supervisory Authorities
C-252/21 Meta Platforms v noyb C-252/21 (Meta Platforms (noyb)) CJEU Jan 12, 2023 IP Address Integrity and Confidentiality Principle Supervisory Authorities
C-136/17 GC and Others v CNIL C-136/17 (GC and Others) CJEU Sep 24, 2019 Right to be Forgotten Child Consent Right to Object
Guidelines 9/2022 personal data breach notification under GDPR Guidelines ·EDPB Apr 4, 2023 Notification Obligation Data Breaches Personal Data