# 24/7 Communication Sp. z o.o.: Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: Polish National Personal Data Protection Office (UODO)
- Date: 2025-07-21
- Original: https://www.enforcementtracker.com/ETid-2758
- Canonical: https://overview.legal/posts/48873
- Topics: Data Breaches, Controllers, Processors, Security, Processing Agreement, IP Address, Retention Period, Employees, Processing, Data Processor

## Summary

The Polish DPA has imposed a fine of EUR 43,000 on 24/7 Communication Sp. z o.o. The fined entity acted as the data processor for McDonald’s Polska Sp. z o.o. (see ETid: 2757). The processor failed to implement sufficient technical and organisational measures to ensure data security, resulting in a data breach. The controller additionally infringed the principle of data minimisation and failed to adequately involve the DPO in relevant activities.

## Full text

The Polish DPA has imposed a fine of EUR 43,000 on 24/7 Communication Sp. z o.o. The fined entity acted as the data processor for McDonald’s Polska Sp. z o.o. (see ETid: 2757). The processor failed to implement sufficient technical and organisational measures to ensure data security, resulting in a data breach. The controller additionally infringed the principle of data minimisation and failed to adequately involve the DPO in relevant activities.

GDPR Articles: Art. 5 (1) c) GDPR, Art. 25 (1) GDPR, Art. 38 (1) GDPR
Industry: Employment

---
Generated by overview.legal · https://overview.legal/posts/48873 · 2026-08-22
