# UODO (Poland) - DKN.5131.34.2023

- Type: Enforcement
- Source: UODO (Poland)
- Date: 2026-06-13
- Original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKN.5131.34.2023
- Canonical: https://overview.legal/posts/53104
- Topics: Data Breaches, Right of Access, Security, Notification Obligation, Fines, Controllers, Integrity and Confidentiality Principle, Accountability, Personal Data, Processing

## Summary

Facts — An unauthorised entity gained access to an email account belonging to an employee at an accounting, bookkeeping and tax consulting company (the controller). The account contained personal data of clients, their employees, and their children (the data subjects), including their names, dates of birth, salary information, and tax declarations. The controller notified the supervisory authority of a data breach in January 2021. The DPA initiated administrative proceedings regarding possible GDPR violations in December 2023. The controller argued that no personal data breach within the meaning of Article 4(12) GDPR had occurred as the unauthorised entity had only accessed and not obtained the personal data in question. Holding — The DPA held that the controller had violated Articles 5(1)(f) and 5(2), 24(1), 25(1), 32(1), and 32(2) GDPR and issued it a fine of € 2,760. First, it pointed out that mere unauthorised access to personal data processed via email constitutes a data breach under Article 4(12) GDPR. Second, the DPA held that the controller had failed to implement appropriate technical and organisational measures to ensure the security of this personal data – it had only taken measures to comply with the aforementioned provisions of the GDPR after the data breach had been notified to the DPA. The controller had not previously conducted a risk assessment. In addition, it had failed to regularly test, measure, and evaluate the effectiveness of the technical and organisational measures implemented. Finally, the DPA found that the processing posed a high risk to the rights and freedoms of data subjects: it affected a large number of individuals and concerned a broad scope of personal data. When determining the amount of the fine, the DPA took into account that there was a clear imbalance between the data subjects and the controller – the data subjects were required to provide personal data to the controller to fulfil obligations under labour law, social security law, and tax law and could not independently control the data. Consequently, the DPA considered the GDPR infringements to be of significant gravity.

## Sections (85)

### ¶0

27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.05.2016, p. 1, OJ L 127, 23.05.2018, p. 2, and OJ L 74, 4.03.2021, p. 35), hereinafter referred to as "Regulation 2016/679", after conducting ex officio administrative proceedings regarding the infringement of personal data protection provisions by N. D., conducting business under the name G. (...), ul. (…), (…)-(…) C., President of the Personal Data Protection Office, finding that N. D., conducting business under the name G. (…), ul. (…), (…)-(…) C., has violated Article 24 paragraph 1, Article 25 paragraph 1, and Article 32 paragraphs 1 and 2 of Regulation 2016/679, consisting of: a) failure to implement appropriate technical and organizational measures based on a risk analysis that takes into account the state of the art, the cost of implementation, the nature, scope, context, and purposes of processing, and the risk of infringement of the rights and freedoms of natural persons, ensuring the security of data processing via email, b) failure to implement appropriate technical and organizational measures to ensure the regular testing, measurement, and evaluation of the effectiveness of technical and organizational measures to ensure the security of personal data processed via email, resulting in a violation of Article 5 paragraph 1 letter b) of the GDPR. Pursuant to Article 5(1)(f) of Regulation 2016/679 (principle of integrity and confidentiality) and Article 5(2) of Regulation 2016/679 (principle of accountability), imposes on N. D., conducting business under the name G. (...), for violating the provisions of Article 5(1)(f), Article 5(2), Article 25(1), and Article 32(1) and (2) of Regulation 2016/679, an administrative fine of PLN 11,594 (in words: eleven thousand five hundred ninety-four zlotys). Justification

> Topics: Security, Processing, Personal Data, Accountability

### ¶1

N. D. conducts business under the name G. (...), ul. (...), (…)-(…) C. (hereinafter referred to as the "Controller"). According to the entry in the Central Register and Information on Business Activity of the Republic of Poland, the Controller's predominant business activity is accounting and bookkeeping activities and tax consultancy.

> Topics: Controllers

### ¶2

On January 22, 2021, the Controller submitted an initial notification to the President of the Personal Data Protection Office (hereinafter also referred to as the "President of the Personal Data Protection Office" or the "supervisory authority") of a personal data breach, which was detected on January 21, 2021. The notification was registered under reference number DKN.5130.719.2021. On January 25, 2021, the Controller submitted a supplementary notification containing updated information regarding the aforementioned breach. The personal data breach involved an unauthorized entity gaining access to an employee's email account, which contained personal data processed by the Controller. According to the notifications, the breach affected "clients (...) and their employees and their children registered by the Office for ZUS insurance." The compromised mailbox processed data of (...) individuals.

> Topics: Supervisory Authorities, Data Breaches, Minors, Insurance

### ¶3

The personal data breach notification prompted the President of the Personal Data Protection Office to assess the Controller's compliance with its obligations under Regulation 2016/679 regarding appropriate data security and the organization of the personal data protection system in the area of data management in electronic form, including via email. Therefore, the President of the Personal Data Protection Office conducted an ex officio investigation and then, on December 12, 2023, initiated administrative proceedings ex officio regarding the possible violation by the Controller of its obligations under Article 5 paragraph 1 letter f), Article 5 paragraph 2, Article 24 paragraph 1, Article 25 paragraph 1, and Article 32 paragraphs 1 and 2 of Regulation 2016/679. The supervisory authority made its findings based on the information provided in the personal data breach notification of January 22, 2021, and January 25, 2021, as well as the explanations and evidence provided in support of these findings, submitted by the Controller in letters dated September 27, 2021 (date of receipt by the Personal Data Protection Office), October 26, 2021, October 28, 2022, December 1, 2022, December 20, 2023, October 23, 2025, and April 22, 2026. Based on the aforementioned letters and the evidence attached thereto, the President of the Personal Data Protection Office determined the factual circumstances of the case. I. Facts

> Topics: Controllers, Notification Obligation, Supervision, Supervisory Authorities

### ¶4

As part of its business, the Controller also processes customers' personal data in electronic form. Email is used, among other methods, to process personal data.

> Topics: Personal Data, Controllers

### ¶5

On January 22, 2021, the Administrator submitted an initial report of a personal data breach, which was confirmed on January 21, 2021. According to the report, the personal data breach involved an unauthorized person gaining access to an email account (...). The Administrator indicated that the account was compromised on (...), at approximately (...). The breach concerned personal data in the form of: first and last name, parents' names, date of birth, bank account number, residential or stay address, PESEL number, email address, earnings data, ID card series and number, telephone number, image, and data contained in passports, employment certificates, PCC-3 forms (declarations regarding the tax on civil law transactions), and personal questionnaires. On January 25, 2021, the President of the Personal Data Protection Office received a supplementary report regarding the aforementioned personal data breach. The compromised mailbox processed the personal data of (...) data subjects, including G.'s clients (...), employees of these clients, and their children registered by the Controller for ZUS health insurance.

> Topics: Controllers, Personal Data, Insurance, Minors

### ¶6

In a letter dated December 1, 2022, the Controller explained that "Ultimately, no personal data processing violation was confirmed, either at the controller or service provider level." Further to the above statement, in a letter dated December 20, 2023, the Controller explained, among other things, that the IT services specialist did not identify any irregularities after the breach was disclosed, and that the mere sending of SPAM messages does not constitute data being obtained by a hacker.

> Topics: Personal Data, Controllers

### ¶7

The Controller's above statement contradicts the evidence collected during the proceedings, according to which an unauthorized entity gained access to the Controller's mailbox because: – In the personal data breach reports, the Controller indicated that the work account from which the spam was sent was used by the employee only occasionally. These reports indicate that the Administrator's employee did not log in to the account at the time the spam was being sent. – In a letter dated October 26, 2021, the hosting provider explained that the mailbox was blocked due to the activation of an automatic mechanism (...) protecting against spam (the letter from the hosting provider is attached to the Administrator's letter dated October 28, 2022). – The Administrator is unable to determine the circumstances under which spam was sent from his mailbox. The Administrator did not have access to logs or other technical means to determine whether data had been copied by an unauthorized entity. – The Administrator failed to document that no personal data breach had occurred. In an email dated January 22, 2021, the entity providing hosting services to the Controller explained that "Unfortunately, we do not know whether or how a hack or access to the mailbox could have occurred. Such information is not available on the mail server components, which only record details regarding sending or receiving messages" (the aforementioned email is an attachment to the Controller's letter dated October 26, 2021). - The statement of the IT services specialist dated January 22, 2021, to which the Controller refers, stating "I hereby inform you that the verification of all computers, passwords, and antivirus programs has revealed no irregularities. I also do not detect any password leaks," does not contain any reference to the scope or methods of the verification conducted, and the Controller also did not document how it was determined that the mailbox had not been taken over by an unauthorized entity.

> Topics: Personal Data, Controllers, Data Breaches, Notification Obligation

### ¶8

Before the personal data breach was identified, the Controller did not have separate regulations regarding personal data protection. In response to the request of the President of the Personal Data Protection Office (UODO) to provide a full description of the technical and organizational security measures adopted to ensure the security of processing, in a letter dated October 26, 2021, the Controller explained that " For the purpose of technical and organizational security measures to ensure the security of processing, the following measures have been taken: 1 (…), 2 (…), 3 (…), 4 (…), 5 (…)" 9.The Controller also presented a document entitled "Code of Conduct for Tax Advisors on Personal Data Protection," developed by the National Chamber of Tax Advisors. This document does not constitute a code of conduct within the meaning of Article 40 of Regulation 2016/679. The Controller did not indicate whether and to what extent this document was applied. In response to the question of whether the effectiveness of the technical measures used to ensure the security of processing was regularly tested, measured, and assessed by the Controller before the personal data breach was identified, in a letter dated October 26, 2021, the Controller explained that "The effectiveness of the technical measures used to ensure the security of processing was not regularly tested or measured by the Controller; however, it was tested and measured by V." (hosting service provider, including email).

> Topics: Personal Data, Controllers, Security, Codes of Conduct

### ¶10

Before the personal data breach was identified, the Controller did not conduct a risk analysis for the processing of personal data via the systems affected by the breach. The Controller's explanations in this regard were contained in a letter dated October 28, 2022.

> Topics: Controllers, Data Breaches, Notification Obligation, Personal Data

### ¶11

After identifying a personal data breach, an audit of the IT infrastructure was conducted on November 15, 2021, at the Controller's request. As a result of the audit, among other things, the IT infrastructure was cataloged and recommendations were developed to improve its performance in specific areas (the audit report is attached to the Controller's letter dated December 1, 2022).

> Topics: Controllers, Data Breaches, Notification Obligation, Personal Data

### ¶12

On November 10, 2022, the Controller conducted a risk analysis related to personal data processing. The analysis identified, among other things, threats that may occur in the personal data processing process. The risk for each threat was assessed in accordance with the adopted methodology, taking into account the effects and probability of the threat's occurrence (the "Analysis (...)" document is attached to the Controller's letter dated December 20, 2023).

> Topics: Personal Data, Controllers

### ¶13

Simultaneously with the risk analysis, the (...) Policy was developed and implemented. Additionally, on March 15, 2023, a password assignment procedure and a clean desk and screen policy were implemented. The Controller also conducted employee training related to the security of personal data processing (documents: "Procedure (...)", "Procedure (...)", and training cards from (...) 2023 constitute annexes to the Controller's letter dated December 20, 2023).

> Topics: Personal Data, Controllers

### ¶14

In response to the question of whether the effectiveness of the technical measures used to ensure processing security was regularly tested, measured, and assessed by the Controller following a personal data breach, in a letter dated December 20, 2023, the Controller presented the actions taken to test, measure, and evaluate the technical measures used. The Controller documented, among other things, Inspections of the use of antivirus software and inspections of the device protecting against the effects of power failures (reports of the inspections performed are attached to the Controller's letter dated December 20, 2023).

> Topics: Data Breaches, Notification Obligation, Personal Data, Controllers

### ¶15

In the letter dated December 20, 2023, the Controller also stated that, as part of the regular testing, measurement, and evaluation of the technical measures used, an audit of the implemented procedures and documentation was conducted by an independent auditor to ensure proper compliance with Regulation 2016/679 (the audit report dated (…) 2023 is attached to the Controller's letter dated December 20, 2023). In these circumstances, after reviewing all the evidence collected in this case, the President of the Personal Data Protection Office considered the following: II. General information.

> Topics: Personal Data, Controllers

### ¶16

Pursuant to Art. Article 4(7) of Regulation 2016/679 - "controller" means a natural or legal person, public authority, agency, or other entity that, alone or jointly with others, determines the purposes and means of processing personal data. Where the purposes and means of such processing are determined by Union or Member State law, a controller may also be designated by Union or Member State law, or specific criteria for its designation may be laid down. In the present case, the controller is N. D., conducting business under the name G. (...) with its registered office in C.. The Controller, in accordance with the subject of its business activity described in the CEIDG, conducts accounting and bookkeeping activities and provides tax consultancy. As part of this activity, the Controller processes the personal data of clients, employees, and other individuals whose data are necessary to perform the services provided (clients' employees and their children registered for insurance), specifying the purposes and means of such processing.

> Topics: Insurance, Public Sector, Public Authority, Personal Data

### ¶17

Pursuant to Article 34 of the Personal Data Protection Act[1], the President of the Personal Data Protection Office is the competent authority for data protection and the supervisory authority within the meaning of Regulation 2016/679. Pursuant to Article 57(1)(a) and (h) of Regulation 2016/679, without prejudice to other tasks specified under that Regulation, each supervisory authority in its territory shall monitor and enforce the application of this Regulation and conduct investigations into infringements of this Regulation, including on the basis of information received from another supervisory authority or other public authority.

> Topics: Supervision, Personal Data, Public Authority, Public Sector

### ¶18

Article 5 of Regulation 2016/679 lays down principles relating to the processing of personal data which must be respected by all controllers, i.e. entities that, alone or jointly with others, determine the purposes and means of the processing of personal data. Pursuant to Article 5(1)(f) of Regulation 2016/679, personal data must be processed in a manner that ensures appropriate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures ("confidentiality and integrity"). Pursuant to Article 5(1)(f), Under Article 24(2) of Regulation 2016/679, the controller is responsible for compliance with the provisions of paragraph 1 and must be able to demonstrate compliance (“accountability”).

> Topics: Controllers, Processing, Integrity and Confidentiality Principle, Personal Data

### ¶19

The principle of confidentiality referred to in Article 5(1)(f) of Regulation 2016/679 is further specified in that legislation. Pursuant to Article 24(1) of Regulation 2016/679, taking into account the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organizational measures to ensure that processing is performed in accordance with this Regulation and to be able to demonstrate this. These measures shall be reviewed and updated as necessary.

> Topics: Security, Controllers

### ¶20

Pursuant to Article 25(1) of Regulation 2016/679, Article 32(1) of Regulation 2016/679 states that, taking into account the state of the art, the cost of implementation, the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons posed by the processing, the controller – both when determining the means of processing and at the time of processing itself – shall implement appropriate technical and organizational measures, such as pseudonymization, designed to effectively implement data protection principles, such as data minimization, and to incorporate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects.

> Topics: Pseudonymization, Controllers, Security

### ¶21

Article 32(1) of Regulation 2016/679 states that the controller is required to apply technical and organizational measures appropriate to the risk of varying likelihood and severity for the rights and freedoms of natural persons. The provision specifies that when deciding on technical and organizational measures, the state of the art, the cost of implementation, the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, should be taken into account. The cited provision indicates that determining appropriate technical and organizational measures is a two-stage process. First, it is important to determine the level of risk posed by personal data processing, taking into account the criteria set out in Article 32(1) of Regulation 2016/679. Second, it is necessary to determine which technical and organizational measures will be appropriate to ensure a level of security appropriate to that risk. These arrangements, where appropriate, should include measures such as pseudonymization and encryption of personal data; the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services; the ability to promptly restore the availability and access to personal data in the event of a physical or technical incident; and regular testing, measurement, and evaluation of the effectiveness of technical and organizational measures to ensure the security of processing. Pursuant to Article 32(1) of Regulation 2016/679, Pursuant to Article 2 of Regulation 2016/679, when assessing the appropriate level of security, the controller shall take into account, in particular, the risks inherent in processing, in particular those arising from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.

> Topics: Security, Right of Access, Personal Data, Controllers

### ¶22

As indicated in Article 24(1) of Regulation 2016/679, the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, are factors that the controller must take into account when building a data protection system, also in particular from the perspective of the other obligations set out in Article 25(1), Article 32(1), and Article 32(2) of Regulation 2016/679. These provisions further specify the principle of confidentiality set out in Article 5(1)(a). f) of Regulation 2016/679, and compliance with this principle is necessary for the proper implementation of the principle of accountability resulting from Article 5(2) of Regulation 2016/679.

> Topics: Controllers, Accountability

### ¶23

One of the legal foundations for personal data protection introduced by Regulation 2016/679 is the obligation to ensure the security of processed data, specified, among others, in Article 32(1) of Regulation 2016/679. This provision introduces a risk-based approach, specifying the criteria based on which the controller should select appropriate technical and organizational measures to ensure a level of security appropriate to that risk. In addition to the risk of infringement of the rights and freedoms of natural persons, the state of the art, the cost of implementation, and the nature, scope, context, and purposes of processing should be taken into account.

> Topics: Security, Controllers, Personal Data

### ¶24

Regulation 2016/679 therefore introduced an approach in which risk management is the foundation of activities related to personal data protection and is a continuous process. Entities processing personal data are obligated not only to ensure compliance with the guidelines of the aforementioned regulation through the one-time implementation of organizational and technical security measures, but also to ensure continuous monitoring of the level of threats and ensure accountability regarding the level and adequacy of the implemented security measures. This means that it is essential to be able to prove to the supervisory authority that the solutions implemented to ensure personal data security are adequate to the level of risk and take into account the nature of the given organization and the mechanisms used for personal data processing. The controller must independently conduct a detailed analysis of the data processing processes and conduct a risk assessment, and then implement measures and procedures that are appropriate to the assessed risk. This approach results in the abandonment of lists of security requirements imposed by the legislator in favor of the independent selection of security measures based on a threat analysis. Regulation 2016/679 generally does not provide a closed list of specific security measures and procedures, leaving their selection to the controller, who should be guided by the results of the risk analysis.

> Topics: Controllers, Security, Accountability, Monitoring

### ¶25

In light of the above, it should be noted that the risk analysis conducted by the controller should be documented and justified based primarily on the factual circumstances existing at the time of its conduct. In particular, the characteristics of the ongoing processes, assets, vulnerabilities, threats, and existing security measures within the ongoing personal data processing processes should be taken into account. During this process, the scope and nature of personal data processed in the course of the controller's activities cannot be ignored, as the potential negative consequences for an individual in the event of a personal data breach will depend on the scope and nature of the disclosed data.

> Topics: Personal Data, Notification Obligation, Data Breaches, Security

### ¶26

For a proper risk analysis to be conducted, the threats that may arise in data processing processes should be defined for each asset. The concept of assets is used to indicate everything that constitutes value to the data controller. Certain assets will have a higher value than others, and should be assessed and secured from this perspective as well. The interconnectedness of the assets is also crucial; for example, the confidentiality of assets (personal data) will depend on the type and method of processing. Determining the value of assets is necessary to estimate the effects of a potential incident (personal data breach). It is obvious that a broad scope of personal data or the processing of personal data referred to in Article 9(1) or Article 9(1) of the GDPR may constitute a significant risk. 10 of Regulation 2016/679, may cause (in the event of a personal data breach) far-reaching negative consequences for data subjects. Therefore, these data should be assessed as high-value assets, and therefore their level of protection should be appropriately high.

> Topics: Processing, Personal Data, Notification Obligation, Data Breaches

### ¶27

Determining existing or applied security measures is necessary, among other things, to avoid duplication. It is also essential to verify the effectiveness of these measures, because the existence of an untested security measure may, firstly, eliminate its value, and secondly, it may create a false sense of security and may result in the omission (undetection) of a critical vulnerability, which, if exploited, would have very negative consequences, including, in particular, a personal data breach.

> Topics: Data Breaches, Personal Data, Security, Notification Obligation

### ¶28

The need for a risk analysis is also emphasized in case law. The Provincial Administrative Court in Warsaw (hereinafter referred to as the "Provincial Administrative Court") addressed this issue in its judgment of October 5, 2023, file ref. II SA/Wa 502/23, where it stated that "(...) The data controller should therefore conduct a risk analysis and assess what threats it is dealing with" (the Regional Administrative Court expressed a similar opinion in its judgments of 13 May 2021, file reference II SA/Wa 2129/20, 27 February 2024, file reference II SA/Wa 1404/23, and 10 April 2025, file reference II SA/Wa 1266/24). In turn, in the judgment of 18 March 2026, file reference Case No. II SA/Wa 807/25, the Regional Administrative Court emphasized that "(...) without conducting a risk analysis, the Company cannot effectively identify and manage threats, nor demonstrate that its data processing security measures are appropriate to the existing threats," and that "A properly conducted risk analysis allows for the identification of gaps in the data protection system that go unnoticed in everyday work and the adoption of appropriate security measures."

> Topics: Controllers, Security, Data Controller, Identification

### ¶29

The Regional Administrative Court, in its justification of the judgment of August 26, 2020, file ref. II SA/Wa 2826/19 (upheld by the Supreme Administrative Court in its judgment of 28 February 2024, file reference III OSK 3839/21), indicated that "(...) This provision [Article 32 of Regulation 2016/679] does not require the controller to implement any technical and organizational measures that are intended to constitute personal data protection measures, but requires the implementation of adequate measures. Such adequacy should be assessed in terms of the manner and purpose for which personal data are processed, but the risk associated with the processing of these personal data, which may vary in level, should also be taken into account. The adopted measures must be effective; in specific cases, some measures will have to be measures that mitigate low risk, others must mitigate high risk. However, it is important that all measures (and each of them individually) are adequate and proportionate to the degree of risk (...) technical and organizational activities are the responsibility of the controller of personal data, but they cannot be selected in a completely free and voluntary manner, without taking into account the degree of risk and the nature of the protected personal data (...)". Furthermore, in its judgment of 5 October 2023, file reference II SA/Wa 502/23, the Regional Administrative Court stated that "the supervisory authority is not obliged to indicate to the Controller the technical and organizational solutions that he should implement to ensure that the processing of personal data is carried out in accordance with the law. It is the Controller's task to introduce these measures and then - if necessary - demonstrate that he complies with the principles of personal data processing set out in Regulation 2016/679, in accordance with the principle of accountability (Article 5 paragraph 2 of the aforementioned Regulation)". The Regional Administrative Court expressed a similar opinion in its judgment of 27 November 2024, file reference II SA/Wa 251/24, further stating that "The task of the President of the Personal Data Protection Office is to verify the adequacy of these measures, which the authority conducts based on documents submitted by the controller, such as, among others, a risk analysis, security policy, or a data processing agreement." III. Infringement of the provisions of Regulation 2016/679 regarding the implementation of appropriate technical and organizational measures based on a risk analysis that takes into account the state of the art, the cost of implementation, the nature, scope, context, and purposes of processing, and the risk of infringement of the rights and freedoms of natural persons, ensuring the security of data processing via email.

> Topics: Supervision, Processing, Controllers, Data Processor

### ¶30

Applying the above considerations to the facts of the case, it should be noted that the Controller was obligated to take measures ensuring an adequate level of personal data protection by implementing appropriate technical and organizational measures. These measures should take into account the nature of personal data processing related to the business purpose, the large number of individuals, potentially all employees and customers, and the broad scope of personal data (first and last names, parents' names, dates of birth, bank account numbers, residential or stay addresses, PESEL numbers, email addresses, earnings data, ID card series and number, telephone number, image, and data contained in passports, employment certificates, PCC-3 forms, and personal questionnaires), the disclosure or loss of which could pose a high risk to the rights and freedoms of natural persons. The selection of these measures should, however, be based on a risk analysis conducted, taking into account the criteria described in Article 32(1) of Regulation 2016/679.

> Topics: Controllers, Personal Data, Security

### ¶31

According to the findings of fact (point 10 of the justification of the decision), the Controller did not conduct a risk analysis related to personal data processing before the personal data breach. Due to the failure to conduct such an analysis, the Controller was unable to demonstrate to the supervisory authority that the security measures it applied at the time were adequate. 32.Only after the personal data breach was discovered, during the proceedings conducted by the President of the Personal Data Protection Office, did the Controller take steps to implement the requirements of Regulation 2016/679 and conduct a risk analysis on November 10, 2022. In conducting the risk analysis, the Controller considered, among other things, threats related to hacking, unauthorized access to personal data, and disclosure of personal data to unauthorized persons. The risk for each threat was assessed, taking into account both the probability and the consequences for personal data protection if it materialized. The criteria for the assessment were defined. As indicated by the Regional Administrative Court in Warsaw in its judgment of February 27, 2024, file reference II SA/Wa 1404/23, "(...) there is no doubt that for the risk analysis to be properly conducted, the controller must properly define the threats that may arise during data processing."

> Topics: Data Breaches, Security, Integrity and Confidentiality Principle, Notification Obligation

### ¶33

Along with conducting a risk analysis, the Controller implemented the (...) Policy. Subsequently, a password allocation procedure and a clean desk and screen policy were implemented. Employee training was also conducted on the security of personal data processing. IV. Infringement of the provisions of Regulation 2016/679 regarding the implementation of appropriate technical and organizational measures to ensure the regular testing, measurement, and evaluation of the effectiveness of technical and organizational measures to ensure the security of personal data processed via email.

> Topics: Controllers, Personal Data, Security

### ¶34

Another aspect of personal data protection relevant to the decision in question is the need to regularly test, measure, and evaluate the effectiveness of technical and organizational measures to ensure the security of personal data processed. Risk management is a fundamental element of the personal data protection system and is an ongoing process. After conducting a risk analysis and implementing appropriate security measures based on it, both the adequacy and effectiveness of the security measures applied should be periodically verified, in accordance with the requirement set out in Article 32(1)(a) of the GDPR. d) Regulation 2016/679. The data controller should therefore regularly test, measure and assess the effectiveness of technical and organizational measures intended to ensure the security of processing. As indicated by the Regional Administrative Court in its judgment of 6 June 2023, file reference II SA/Wa 1939/22 (final judgment), "(…) the obligation to regularly test technical and organizational measures to secure the processing of personal data in order to ensure a level of security appropriate to that risk, within the meaning of Article 32 paragraph 1, introductory sentence, of the GDPR, results directly from the wording of letter d of the indicated Article 32 paragraph 1, while the obligation to document activities in a given scope is established by the principle of accountability (Article 5 paragraph 2 of the GDPR)." The Regional Administrative Court ruled similarly in its judgment of 21 June 2023, file reference II SA/Wa 150/23, indicating that "It should be emphasized that regularly testing, measuring, and assessing the effectiveness of technical and organizational measures designed to ensure the security of processing is a fundamental obligation of every controller and processor under Article 32(1)(d) of the GDPR. The Controller is therefore obligated to verify both the selection and the level of effectiveness of the technical measures used at each stage of processing. The comprehensiveness of this verification should be assessed in terms of adequacy to the risks and proportionality in relation to the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing."

> Topics: Processors, Integrity and Confidentiality Principle, Data Controller, Security

### ¶35

In this regard, the Controller provided explanations (point 9 of the justification for the decision) indicating that, before the personal data breach, the obligations under Article 32(1)(d) of Regulation 2016/679 had not been fulfilled by the Controller. The Controller indicated that, with respect to technical measures, their effectiveness had been measured and tested by the hosting service provider, including email. It should therefore be emphasized that the provisions of Article 32(1)(d) of the GDPR apply. Articles 1 and 2 of Regulation 2016/679 impose an obligation on the controller to implement appropriate technical and organizational measures (including their regular testing, measurement, and evaluation) regardless of the processor's obligations. This means that the controller's liability is autonomous – it stems from the controller's own actions or omissions. The controller cannot exonerate itself from liability by invoking the actions of an entity entrusted with the processing of personal data, such as the actions of a hosting provider.

> Topics: Processors, Security, Controllers, Processing

### ¶36

In Guidelines 07/2020 (version 2.0 adopted on July 7, 2021) on the concepts of controller and processor in the GDPR, issued by the European Data Protection Board, paragraph 135 clearly states: "Moving on to specific obligations, the processor is, firstly, obliged to assist the controller in fulfilling the obligation to adopt appropriate technical and organizational measures to ensure the security of processing. Although this obligation may overlap to some extent with the requirement for the processor to adopt appropriate security measures itself, where the processing operations carried out by the processor fall within the scope of the GDPR, they remain two separate obligations, as one relates to the processor's own measures and the other to the controller's measures."

> Topics: Controllers, Processors, Security, Integrity and Confidentiality Principle

### ¶37

In addition, it should be noted that the described testing, measurement, and evaluation must cover not only the technical measures implemented, but also those of an organizational nature, including procedures defining the principles for processing personal data. In the present case, however, the testing, measurement, and evaluation carried out by the hosting service provider related only to technical measures.

> Topics: Personal Data

### ¶38

In the present circumstances, it should therefore be concluded that, prior to the personal data breach being identified, the Controller, due to the lack of evidence of its own actions in this regard, failed to fulfill its obligation to regularly test, measure, and evaluate the effectiveness of technical and organizational measures designed to ensure the security of personal data processing, which constitutes a violation of Article 32(1) of Regulation 2016/679.

> Topics: Controllers, Personal Data, Notification Obligation, Data Breaches

### ¶39

Only after the personal data breach was discovered did the Controller take steps to fulfill its obligations under Article 32(1)(d) of Regulation 2016/679 to regularly test, measure, and evaluate the effectiveness of technical and organizational measures designed to ensure the security of personal data being processed. According to the collected evidence, following the personal data breach, the Controller conducted an audit of the IT infrastructure on November 15, 2021. A Policy (…) was also implemented, which was subsequently supplemented with further provisions following a review of the regulations. Following the aforementioned breach, the Controller documented that it independently performs control activities to ensure the security of personal data processing (e.g., ongoing monitoring of the current status of anti-virus protection). As part of the regular testing, measurement, and evaluation of the measures applied, an audit of the implemented procedures and documentation was also conducted in February 2023 (report from (…) 2023). V. Summary of identified violations of the provisions of Regulation 2016/679

> Topics: Controllers, Personal Data, Notification Obligation, Data Breaches

### ¶40

Regarding the Controller's assertion that "ultimately, no personal data processing breach was confirmed, either at the controller or service provider level," it should be noted that whether a personal data breach occurred within the meaning of Article 10 of the GDPR is a matter of personal data protection. 4 point 12) of Regulation 2016/679 is not determinative for the resolution in the present case, because (as indicated at the beginning of the decision) the proceedings in question were not conducted regarding the personal data breach reported by the Controller. Therefore, the above explanations by the Controller in this respect do not change the findings made by the President of the UODO regarding his infringement of the obligations arising from Article 24 paragraph 1, Article 25 paragraph 1 and Article 32 paragraphs 1 and 2 of Regulation 2016/679, and consequently also the infringement of Article 5 paragraph 1 letter f) and Article 5 paragraph 2 of Regulation 2016/679. As indicated by the Supreme Administrative Court in its judgment of 9 February 2023, file reference no. III OSK 3945/21, "Administrative sanctions for breach of the obligations specified in Article 32 of Regulation (EU) 2016/679 of the European Parliament and of the Council (...) shall not apply to the person who, as a controller or processor, has allowed unauthorized processing of personal data, but only to the entity that has failed to maintain an appropriate standard of security measures under the circumstances."

> Topics: Processing, Security, Processors, Data Breaches

### ¶41

Incidentally, the President of the Personal Data Protection Office (UODO) points out that, in accordance with Article 4(12) of Regulation 2016/679, a "personal data breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed. The fact, relied on by the Controller, that the acquisition of personal data by an unauthorized entity has not been confirmed does not constitute a failure to ensure that a personal data breach has not occurred. The evidence collected indicates that the correspondence was not sent by an employee of the Administrator, but rather that the mailbox belonging to the Administrator was used by an unauthorized entity. The mere fact of unauthorized access to the data stored in this mailbox constitutes a personal data breach.

> Topics: Personal Data, Data Breaches, Integrity and Confidentiality Principle, Controllers

### ¶42

Consequently, the findings do not provide a basis for concluding that the technical and organizational measures used by the Controller to ensure the security of personal data processed via email were adequate to the state of the art, implementation costs, and the nature, scope, context, and purposes of processing. This is primarily due to the lack of a risk analysis related to personal data processing and the lack of regular testing, measurement, and evaluation of the effectiveness of the security measures implemented. The lack of a risk analysis resulted in the Controller arbitrarily selecting various organizational and technical measures, which could have increased the likelihood of a personal data breach. Only during the proceedings conducted by the President of the Personal Data Protection Office, on November 10, 2022, did the Controller conduct a risk analysis related to personal data processing.

> Topics: Data Breaches, Security, Controllers, Personal Data

### ¶43

In the absence of the Controller's determination and implementation of adequate technical and organizational measures to minimize the risk of data security breaches based on a risk analysis conducted between May 25, 2018, and November 10, 2022, as well as the lack of regular testing, measurement, and evaluation of the effectiveness of the security measures applied in this area (the first action to implement the aforementioned obligation was the IT infrastructure audit of November 15, 2021, while the overall implementation of the aforementioned obligation was the audit of implemented procedures and documentation conducted in February 2023 – a report from (...) 2023, as the required testing covered both technical and organizational measures at that time), it should be concluded that the Controller failed to ensure a level of data security appropriate to the risk. Therefore, it cannot be deemed that the Controller, taking into account the state of technical knowledge, the cost of implementation, the nature, scope, context, and purposes of processing, as well as the risk of infringement of the rights and freedoms of natural persons with varying likelihood and severity, has implemented appropriate technical and organizational measures to ensure a level of security appropriate to that risk, which constitutes a violation by the Controller of Article 32 paragraphs 1 and 2 of Regulation 2016/679. The above circumstances also constitute a failure by the Controller to implement appropriate technical measures, both when determining the means of processing and during the processing of personal data, to ensure that the processing is carried out in accordance with Regulation 2016/679 and to provide the necessary safeguards for the processing, and a failure to update the security measures, to which it was obligated pursuant to Article 24 paragraph 1 and Article 25 paragraph 1 of Regulation 2016/679.

> Topics: Processing, Controllers, Security, Personal Data

### ¶44

The violation of the aforementioned provisions of Regulation 2016/679 also constitutes a violation of the principle of integrity and confidentiality expressed in Article 32 paragraph 1 and 2 of Regulation 2016/679. 5 paragraph 1 letter f) of Regulation 2016/679, of which the aforementioned provisions are a detail. The consequence of a breach of this principle by the Controller is a breach of the principle of accountability referred to in Article 5 paragraph 2 of Regulation 2016/679. As results from the ruling of the Regional Administrative Court of 10 February 2021, reference II SA/Wa 2378/20, "The principle of accountability is therefore based on the legal responsibility of the controller for the proper fulfilment of obligations and imposes on the controller the obligation to demonstrate, both to the supervisory authority and to the data subject, evidence of compliance with all data processing principles." The issue of the principle of accountability is interpreted similarly by the Regional Administrative Court in its judgment of 26 August 2020, reference number II SA/Wa 2826/19 (upheld by the Supreme Administrative Court in its judgment of February 28, 2024, file reference III OSK 3839/21), "Considering all the provisions of Regulation 2016/679, it should be emphasized that the controller has significant discretion in the scope of security measures applied, but at the same time is liable for any violation of personal data protection provisions. The principle of accountability clearly states that the controller should demonstrate, and therefore prove, compliance with the provisions specified in Article 5(1) of Regulation 2016/679." VI. Administrative Fine

> Topics: Supervisory Authorities, Security, Accountability, Controllers

### ¶45

The administrative proceedings conducted by the President of the Personal Data Protection Office (UODO) are aimed at verifying the compliance of data processing with personal data protection provisions and are aimed at issuing an administrative decision to exercise the remedial powers specified in Article 58(2) of Regulation 2016/679.

> Topics: Personal Data

### ¶46

Taking into account the above, as well as the infringement of personal data protection provisions found in these proceedings, the President of the Personal Data Protection Office – exercising the authority specified in Article 58 paragraph 2 letter i) of Regulation 2016/679, pursuant to which each supervisory authority has the power to impose an administrative fine, in addition to or instead of the measures referred to in Article 58 paragraph 2 letters a) to h) and letter j) of that Regulation – found that in the case at hand, there were grounds for imposing an administrative fine on the Controller.

> Topics: Controllers, Supervisory Authorities, Personal Data, Supervision

### ¶47

Pursuant to Article 83 paragraph 4 letter a) of Regulation 2016/679, infringements of the provisions concerning the obligations of the controller and the processor referred to in Articles 8, 11, 25-39, 42 and 43 are subject to, in accordance with paragraph 1. 2, an administrative fine of up to EUR 10,000,000, or in the case of an enterprise, up to 2% of its total annual worldwide turnover in the preceding financial year, whichever is higher.

> Topics: Processors, Controllers

### ¶48

In turn, pursuant to Article 83(5)(a) of Regulation 2016/679, infringements of the provisions concerning the basic principles of processing, including the conditions for consent, referred to in Articles 5, 6, 7, and 9, shall be subject to an administrative fine of up to EUR 20,000,000, or in the case of an enterprise, up to 4% of its total annual worldwide turnover in the preceding financial year, whichever is higher.

> Topics: Consent

### ¶49

Article 83(5)(a) of Regulation 2016/679 Article 83(3) of Regulation 2016/679 provides that if a controller or processor, intentionally or negligently, infringes, within the same or linked processing operations, several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount of the fine for the most serious infringement.

> Topics: Processors, Controllers

### ¶50

When assessing whether, and if so, the amount of, an administrative fine should be imposed, the supervisory authority is required to take into account the following circumstances (conditions for the assessment of the fine) set out in Article 83(3) of the GDPR: 2 Regulation 2016/679: a) the nature, gravity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing in question, the number of data subjects affected, and the extent of the damage they suffered, b) the intentional or unintentional nature of the infringement, c) the actions taken by the controller or processor to minimize the damage suffered by data subjects, d) the degree of responsibility of the controller or processor, taking into account the technical and organizational measures implemented by them pursuant to Art. 25 and 32, e) any relevant prior breaches by the controller or processor, f) the degree of cooperation with the supervisory authority to remedy the breach and mitigate its potential adverse effects, g) the categories of personal data concerned, h) how the supervisory authority became aware of the breach, in particular whether and to what extent the controller or processor notified the breach, i) if the controller or processor concerned has previously been subject to measures referred to in Article 58(2) in the same matter, compliance with those measures, j) the application of approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42, k) any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial benefits gained directly or indirectly from the breach or losses avoided.

> Topics: Supervisory Authorities, Security, Processors, Certification

### ¶51

Furthermore, the supervisory authority – in accordance with Article 58(2) – shall, in accordance with Article 58(2), Article 83(1) of Regulation 2016/679 ensures that the administrative fines imposed are effective, proportionate, and dissuasive in each individual case (principles of imposing penalties).

> Topics: Supervision, Fines, Supervisory Authorities

### ¶52

In order to determine the basis for assessing an administrative fine, in accordance with Article 101a of the Personal Data Protection Act, the entity against which proceedings are pending regarding the imposition of an administrative fine is obligated, at the request of the President of the Personal Data Protection Office, to provide the President, within 30 days of receiving the request, with the data necessary to determine the basis for assessing the administrative fine. If the entity referred to in this provision fails to provide the data, or if the data provided by the entity makes it impossible to determine the basis for assessing the administrative fine, the President of the Personal Data Protection Office shall determine the basis for assessing the administrative fine on an estimated basis, taking into account the size of the entity, the specific nature of its business, or publicly available financial data concerning the entity.

> Topics: Personal Data

### ¶53

The equivalent of the amounts expressed in euros referred to in Article 101a of the Personal Data Protection Act shall be calculated based on the amount of the administrative fine. 83 of Regulation 2016/679, are calculated in zlotys at the average euro exchange rate announced by the National Bank of Poland in the exchange rate table as of 28 January each year, and if in a given year the National Bank of Poland does not announce the average euro exchange rate on 28 January - at the average euro exchange rate announced in the next exchange rate table of the National Bank of Poland after that date, as provided for in Art. 103 of the Act on Personal Data Protection. VI.A. Conduct of the Controller leading to an infringement of the provisions of Regulation 2016/679 - assessment of the application of Article 83(3) of Regulation 2016/679.

> Topics: Personal Data, Controllers

### ¶54

Article 83(3) of Regulation 2016/679 provides that if a controller or processor, intentionally or negligently, infringes several provisions of this Regulation within the framework of the same or related processing operations, the total amount of the administrative fine shall not exceed the amount of the fine for the most serious infringement. However, in accordance with Guidelines 04/2022 of the European Data Protection Board (hereinafter referred to as the "EDPB") on the calculation of administrative fines under the GDPR, adopted on May 24, 2023 (hereinafter referred to as the "Guidelines 04/2022")[2], the term "total amount" means that all infringements committed should be taken into account when assessing the amount of the fine, and the phrase "amount of the fine for the most serious infringement" refers to the statutory maximum amounts of fines (e.g., Article 83 paragraphs 4-6 of the GDPR).

> Topics: Controllers, Processors, Fines

### ¶55

Given that the Controller has violated numerous provisions of Regulation 2016/679 in the circumstances under review (i.e., Article 24 paragraph 1, Article 25, Article 32 paragraphs 1 and 2, and consequently also Article 5 paragraph 1 letter f) and Article 5 paragraph 1), 2), the President of the Personal Data Protection Office was obliged to take into account the regulation cited in the aforementioned point in order to consider whether the circumstances of this case determine the supervisory authority's use of only one or several corrective measures provided for in Article 58 paragraph 2 of Regulation 2016/679 – or more precisely, whether the authority should impose only one administrative fine on the Controller, in response to all infringements committed by it, or separate and independent penalties for each of these infringements considered separately.

> Topics: Supervision, Controllers, Personal Data, Supervisory Authorities

### ¶56

In determining the specific sanctions for the infringements found in this case, the President of the Personal Data Protection Office (UODO) used the methodology for calculating administrative fines adopted by the EDPB in Guidelines 04/2022, according to which the first step in further calculations is to "assess the application of Article 83(3) [of Regulation 2016/679]" by determining: a) whether the circumstances indicate a single conduct or multiple conducts subject to sanctions, b) in the case of a single conduct, whether this conduct constitutes a single infringement or multiple infringements, and c) in the case of a single conduct that constitutes multiple infringements, whether the attribution of one infringement precludes the attribution of another infringement, or whether they should be attributed in parallel[3].

> Topics: Personal Data, Fines

### ¶57

The term "single conduct" should be interpreted in conjunction with Article 83(3) of Regulation 2016/679, which refers to "the same or related processing operations." According to the interpretation adopted by the EDPB, "[t]he term 'related' refers to the principle according to which one conduct may consist of several parts that are carried out as a result of a single act of will and are contextually (in particular with regard to the identity of the data subject, the purpose and nature of the processing), spatially and temporally so closely linked that, from an objective point of view, they can be considered to constitute one coherent conduct."[4]

> Topics: Personal Data

### ¶58

Applying the above to the circumstances of the case at hand, the President of the Personal Data Protection Office found that the Controller's identified omissions – consisting in the failure to implement appropriate technical and organizational measures to ensure the security of data processed in electronic form, including via email, and consisting in the failure to regularly test, measure, and evaluate the effectiveness of the security measures applied in this area and the protection of the rights of data subjects intended to ensure the security of processing – constitute "one coherent conduct" within the meaning presented by the EDPB. This interpretation is supported by the fact that the Controller's inactivity in the above-mentioned area (resulting in a violation of Article 24 paragraph 1, Article 25 and Article 32 paragraphs 1 and 2 of Regulation 2016/679, and consequently also Article 5 paragraph 1 letter f) and Article 5 paragraph 2 of Regulation 2016/679), although not the result of a single specific act of will on the part of the Controller, is the result of long-term negligence in implementing personal data protection measures that would be adequate to the identified threats. These negligences appeared already at the stage of defining the means of processing – as evidenced by the failure to conduct a risk analysis for the processing of personal data via the systems affected by the breach – and then continued during the processing itself. The Controller's lack of appropriate action in the analyzed scope, as a continuous and long-term process resulting in the violation of fundamental principles of personal data processing, led to the Controller's inability to demonstrate to the supervisory authority the compliance of the processing with the provisions of Regulation 2016/679. Besides the long duration of the identified violations of the provisions of Regulation 2016/679, considered as a single, coherent act of the Controller, the purpose, nature, and scope of the processing carried out by this Controller are also identical. It should be noted that all aspects of the identified violation in this case and the Controller's conduct leading to this violation (lack of risk analysis, lack of adequate technical and organizational measures, lack of regular testing, measurement, and evaluation of the effectiveness of the security measures applied) concern the same processing processes, i.e., the processing of personal data arising from the nature of personal data processing in connection with the Controller's business activities, which include accounting, bookkeeping, and tax consultancy.

> Topics: Law Enforcement, Security, Supervisory Authorities, Supervision

### ¶59

All of the Controller's omissions identified by the President of the Personal Data Protection Office also concern (and affect the security of) the same personal data (the same scope and the same categories). They negatively impact the security of all personal data processed by the Controller. It should be emphasized that regardless of whether the risk of a personal data security breach materializes or not, it exists; and its existence results from the violation of the provisions of Article 24 paragraph 1, Article 25 paragraph 1, Article 32 paragraphs 1 and 2, as well as Article 5 paragraph 1 letter f) and Article 5 paragraph 2 of Regulation 2016/679, found in this case.

> Topics: Controllers, Security, Personal Data

### ¶60

Assuming, therefore, that the Controller's omissions consisting in the failure to apply (both at the design stage and during processing) appropriate technical and organizational measures ensuring a level of security appropriate to the risk of data processing within email, and the failure to regularly test, measure, and evaluate the effectiveness of the security measures applied in this area, constitute one coherent act, and that this conduct violates several provisions of Regulation 2016/679 (Article 24 paragraph 1, Article 25 paragraph 1, Article 32 paragraphs 1 and 2, and consequently also Article 5 paragraph 1 letter f) and Article 5 paragraph 2), it should be further stated that none of these violations excludes the possibility of attributing another of them to the Controller. In particular, the finding of an infringement of the provisions defining the basic, general principles of processing referred to in Article 5 of Regulation 2016/679 does not exclude the possibility of attributing to the Controller an infringement of the specific provisions concretizing these principles, i.e. Article 24 paragraph 1. 1, Article 25, paragraph 1, and Article 32, paragraphs 1 and 2 of Regulation 2016/679. However, it should be clearly emphasized that the legal basis for imposing an administrative fine is the infringement of the provisions listed in Article 83, paragraphs 4-6 of Regulation 2016/679, i.e., in this case, Article 25, paragraph 1, Article 32, paragraphs 1 and 2, and Article 5, paragraph 1, letter f) and Article 5, paragraph 2. The finding of an infringement of Article 24, paragraphs 1 and 2 constitutes, in this respect, an element of the description and assessment of the Controller's conduct, closely related to the sanctioned infringements.

> Topics: Controllers, Security

### ¶61

As a consequence of the above, it is determined that the provision of Article 83, paragraph 3 of Regulation 2016/679 will apply to the Controller's liability in these proceedings. Its conduct, which constituted a violation of several of the provisions of Regulation 2016/679 indicated above, took place "within the framework of the same processing operations" – operations involving the same processes and methods of data processing and the same sets (scopes and categories) of personal data.

> Topics: Controllers, Personal Data

### ¶62

In summary, it should be stated that the administrative fine against the Controller was imposed for the infringement of Article 25 paragraph 1 and Article 32 paragraphs 1 and 2 of Regulation 2016/679 on the basis of the aforementioned Article 83 paragraph 4 letter a) of Regulation 2016/679, while for the infringement of Article 5 paragraph 1 letter f) and Article 5 paragraph 2 of Regulation 2016/679 – on the basis of Article 83 paragraph 5 letter a) of that Regulation. At the same time, the administrative fine of PLN 11,594 was imposed on the Controller jointly for the infringement of all of the above provisions – pursuant to the provisions of Article 83 paragraph 4 letter a) of that Regulation. 3 of Regulation 2016/679 - does not exceed the amount of the fine for the most serious infringement found in this case, i.e. infringement of Article 5 paragraph 1 letter f) and Article 5 paragraph 2 of Regulation 2016/679, which, pursuant to Article 83 paragraph 5 letter a) of Regulation 2016/679, is subject to an administrative fine of up to EUR 20 000 000, and in the case of an undertaking - of up to 4% of its total annual worldwide turnover in the previous financial year. VI.B. Conditions for imposing a fine - application of Article 83 paragraph 2 of Regulation 2016/679

> Topics: Controllers

### ¶63

In deciding to impose an administrative fine on the Controller, the President of the Personal Data Protection Office - pursuant to Article 83 paragraph 2 letters a)-k) of Regulation 2016/679 - took into account the following circumstances (points 64-66 below), which constitute the necessity of applying such a sanction in this case and have an aggravating effect on the amount of the administrative fine imposed:

> Topics: Controllers, Personal Data

### ¶64

The nature, gravity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing in question, the number of data subjects affected, and the extent of the damage they suffered (Article 83 paragraph 2 letter a) of Regulation 2016/679). The violation found in this case is serious because it concerns the controller's obligations that directly implement the fundamental objective of Regulation 2016/679, which is to protect the fundamental rights and freedoms of natural persons, in particular their right to personal data protection. An individual's right to the protection of their personal data means that their personal data processed by the controller will be protected by technical and organizational measures ensuring a standard of security that reduces to a reasonable minimum the risk of data breach (loss, alteration, unauthorized disclosure, or other infringement resulting in negative consequences for the data subject). This standard is set by the provisions of Articles 24, 25, and 32 of Regulation 2016/679, which were violated by the Controller. The foundation of the organization's security system, framed by these provisions, is the controller's obligation to conduct a thorough and thorough analysis of the risk of violation of the rights and freedoms of data subjects, based on which the controller implements appropriate technical and organizational solutions to at least minimize this risk (see paragraphs 24-29 of the justification for this decision). The Controller's failure to comply with this obligation therefore directly violated the fundamental right of the individuals whose data it processed in its email system, namely, the right to the protection of their personal data. The Controller's failure to ensure adequate security of this data through adequate technical and organizational measures constitutes a violation of the fundamental principle of "integrity and confidentiality" referred to in Article 5(1)(f) of Regulation 2016/679, which underscores the serious nature of the violation committed by the Controller. In assessing the violation found in this case, the President of the Personal Data Protection Office (UODO) attaches great importance to it. This stems from the nature and purpose of the processing within which the violation occurred. It should be noted that the Controller processes personal data provided to it by clients of its law firm in order to fulfill obligations under labor law, social security law, tax law, etc. The data subjects did not voluntarily provide it (directly or through their employers) with their data; they were legally obliged to do so. Therefore, these individuals could not independently and fully dispose of this data (in particular, request the cessation of its processing or its deletion). This indicates a clear imbalance between them and the Controller, which – in accordance with Guidelines 04/2022 (see point 53(a)(iii) of these Guidelines) – provides grounds for assigning greater seriousness to the breach. This seriousness is further increased by the wide scope of data processed by the Controller (see point 66 of the justification for this decision), as well as the large number of individuals whose data the Controller processes (including children, whose data are subject to special protection[5]) and who were potentially affected by the breach. In the personal data breach notification, the Controller indicated that the email address "taken over" by an unauthorized person was processing personal data of (...) individuals (see point 4 of the justification for this decision). This number (representing the number of people served by the Controller at a single point in time and using a single email address) should, however, be considered only a minimum number of people affected by the breach identified in this case. This breach was "systemic" in nature; it had a potential negative impact on the security of the personal data of all individuals whose data was processed by the Controller in the email system. It covers personal data processed in all email addresses used by the Controller and applies to personal data processed by the Controller throughout the duration of the breach (during the incident of (...), before that incident, as well as afterward—until the date the breach was resolved), that is, for a period of approximately five years (see the comments regarding the duration of the breach below in this section of the justification for the decision). The number of individuals potentially negatively affected by the breach should therefore be considered large, which constitutes an aggravating factor in the assessment of the breach. The President of the Personal Data Protection Office (UODO) did not find that the breach, which is the subject of this decision, resulted in any actual damage to the individuals whose data the Controller processed without providing them with appropriate security measures. Nevertheless, the risk this breach posed to the rights and freedoms of these individuals, as well as the scope of the negative consequences that could have occurred if this risk had materialized, justify assessing the seriousness of the breach. The breach could have resulted in, for example, identity theft, attempted fraud or extortion, or the malicious use of personal data to establish legal relationships or incur obligations on behalf of the individuals whose data had been obtained, which could have resulted in actual and tangible financial damage to them. It could also have resulted in non-financial damage resulting from a breach of privacy, reputational damage, breach of the confidentiality of correspondence, fear resulting from loss of control over one's data, or discrimination based on unauthorized access to information. The Controller was also adversely affected by the long duration of the identified breach. The evidence gathered during the proceedings suggests that the non-compliance of the processing with the provisions of Regulation 2016/679 lasted continuously from May 25, 2018 (i.e., the date of application of Regulation 2016/679) until (...) 2023 (the date of the audit report on the implemented procedures and documentation regarding the correct compliance with Regulation 2016/679 – at which time the required testing covered both technical and organizational measures). The fact that the infringement persisted for a period of approximately five years should be considered a factor significantly influencing both the supervisory authority's decision to impose an administrative fine in this case and the amount of the fine imposed. Taking into account the above-mentioned circumstances, the condition specified in Article 83(2)(a) of the GDPR is met. The supervisory authority assessed the infringement of Article 83(2)(a) of Regulation 2016/679, considered as a whole, as significantly burdening the Controller.

> Topics: Security, Integrity and Confidentiality Principle, Minors, Data Breaches

### ¶65

Unintentional nature of the infringement (Article 83(2)(b) of Regulation 2016/679). In analyzing this premise, the President of the Personal Data Protection Office took into account the position expressed by the EDPB, according to which intentionality "includes both knowledge and deliberate action, in connection with the characteristics of a prohibited act"[6]. In light of the above, the supervisory authority concluded that the Controller, when processing personal data, was aware that it should ensure an appropriate level of security for such processing, including via email. This is reinforced by the fact that the provisions of Regulation 2016/679, adopted on April 27, 2016, only became applicable on May 25, 2018, giving controllers time to adapt the existing procedures and implemented technical and organizational measures related to personal data processing to the new legal regulations. Therefore, there is no doubt that a Controller, when processing the personal data of clients, their employees, and the children of employees, must have knowledge of personal data protection. However, the supervisory authority did not find that the violation of Regulation 2016/679 in this case was intentional – it resulted from gross negligence on the part of the Controller. This does not change the fact that the requirement of Article 83 paragraph 2 letter b) of Regulation 2016/679 should be taken into account as an aggravating circumstance when assessing the administrative fine.

> Topics: Controllers, Personal Data, Supervisory Authorities, Security

### ¶66

Categories of personal data affected by the infringement (Article 83 paragraph 2 letter g) of Regulation 2016/679). It should be noted first that the infringement of Regulation 2016/679 at issue in this case concerns all personal data (and all categories thereof) processed by the Controller in the email system. It is significant that the Controller, as an entity conducting accounting, bookkeeping, and tax consultancy activities, processes personal data in this system to a very broad extent, both in terms of the categories of data subjects and the categories of such personal data. In this case, it was undisputedly established that personal data were processed in a manner inconsistent with the provisions of Regulation 2016/679, at least to the extent covered by the personal data breach reported by the Controller on January 22, 2021. The personal data concerned by the infringement of the provisions of Article 24(1), Article 25(1), Article 32(1) and (2), and Article 5(1)(f) and Article 5(2) of Regulation 2016/679 do not fall within the special categories of personal data referred to in Article 9 of Regulation 2016/679, nor within the data listed in Article 10 of Regulation 2016/679. However, their broad scope (i.e., at least: first name and last name, parents' names, date of birth, bank account number, address of residence or stay, PESEL number, email address, earnings data, ID card series and number, telephone number, image, data contained in passports, employment certificates, PCC-3 forms, and personal questionnaires) is associated with a high risk of violating the rights and freedoms of the natural persons affected by the infringement. It should be emphasized in particular that the breach affected the PESEL (Personal Identification Number), the unauthorized disclosure of which (in combination with the name and surname) could have a real and negative impact on the protection of a natural person's rights and freedoms. The PESEL (Personal Identification Number), an eleven-digit numerical symbol that uniquely identifies a natural person, containing, among other things, their date of birth and gender, and therefore closely linked to the individual's private sphere and also subject, as a national identification number, to exceptional protection under Article 87 of Regulation 2016/679, is data of a special nature and requires such special protection. With the above in mind, and taking into account the broad range of data categories covered by the breach and the broad range of affected individuals, including children, the supervisory authority assessed the factor discussed here as an aggravating circumstance, significantly affecting the amount of the administrative fine imposed.

> Topics: Special Categories of Data, Controllers, Personal Data, Notification Obligation

### ¶67

In determining the amount of the administrative fine, the President of the Personal Data Protection Office took into account in the Controller's favor, as part of the criterion concerning any other aggravating or mitigating factors applicable to the circumstances of the case (Article 83 paragraph 2 letter k) of Regulation 2016/679), the fact that the Controller had undertaken actions aimed at improving the level of personal data security, both in terms of implementing appropriate technical and organizational measures and regularly testing, measuring, and evaluating them, which contributed to improving the security of personal data processed in electronic form, including via email (see paragraphs 11-15 of the justification of the decision). Therefore, this factor was treated as having a significant impact on reducing the amount of the fine imposed (see paragraph 81 of the justification of the decision).

> Topics: Personal Data, Security, Controllers

### ¶68

Other circumstances referred to in Article 83 paragraph 2, indicated below (in paragraphs 69-77 of the justification of the decision), are also taken into account. 2 of Regulation 2016/679, after assessing their impact on the infringement of Regulation 2016/679 found in this case, were deemed neutral by the President of the Personal Data Protection Office (UODO), meaning that they had neither an aggravating nor a mitigating effect on the amount of the imposed administrative fine.

> Topics: Personal Data

### ¶69

Actions taken to minimize the harm suffered by data subjects (Article 83 paragraph 2 letter c) of Regulation 2016/679). In the context of this condition, the purpose of the controller's action, namely, minimizing the harm suffered by data subjects, is relevant. The President of the Personal Data Protection Office (UODO) did not note such actions by the Controller in this case. However, since no harm was found in this case to have occurred to the individuals affected by the infringement, no such actions were required of the Controller and were not even possible. Therefore, the President of the UODO considered this condition as having no impact on the assessment of the infringement.

> Topics: Controllers, Personal Data

### ¶70

The degree of responsibility, taking into account the technical and organizational measures implemented by the Controller pursuant to Articles 25 and 32 of Regulation 2016/679 (Article 83 paragraph 2 letter d) of Regulation 2016/679). In this case, the President of the Personal Data Protection Office found, among other things, a violation of Article 25 paragraph 1 and Article 32 paragraphs 1 and 2 of Regulation 2016/679. The Controller undoubtedly bears a high degree of responsibility for failing to implement appropriate technical and organizational measures that could have contributed to preventing a personal data breach. It is also clear that, in the context of the nature, purpose, and scope of personal data processing, the Controller did not do everything that could be expected of it; its failure resulted in a breach of the principle of data integrity and confidentiality. In the present case, however, this circumstance constitutes the essence of the infringement of the provisions of Regulation 2016/679, which leads to the conclusion that it is not solely a mitigating or aggravating factor in its assessment. Therefore, the lack of appropriate technical and organizational measures referred to in Articles 25 and 32 of Regulation 2016/679 cannot be considered in this case as a circumstance that could further influence the more severe assessment of the infringement and the amount of the administrative fine imposed on the Controller.

> Topics: Data Breaches, Security, Notification Obligation, Controllers

### ¶71

Any relevant prior infringements by the Controller (Article 83 paragraph 2 letter e) of Regulation 2016/679) The President of the Personal Data Protection Office (UODO) did not identify any prior infringements of personal data protection provisions on the part of the Controller, and therefore there is no basis to treat this circumstance as an aggravating factor. At the same time, however, every controller is obligated to comply with the law, and therefore, the absence of prior infringements cannot be considered a mitigating circumstance when imposing sanctions. This assessment is consistent with the position expressed by the EDPB in Guidelines 04/2022, according to which "[t]he absence of prior infringements cannot be considered a mitigating circumstance, as compliance with the provisions of [Regulation 2016/679] is the norm. The absence of prior infringements can be considered a neutral circumstance."[7]

> Topics: Controllers, Personal Data

### ¶72

Degree of cooperation with the supervisory authority to remedy the infringement and mitigate its potential negative effects (Article 83(2)(f) of Regulation 2016/679) After identifying a personal data breach, the Controller took a number of measures to improve the security of personal data processing (see paragraphs 11-15 of the justification for the decision). However, these actions were undertaken by the Controller independently and spontaneously, without prior action or any intervention from the supervisory authority. The President of the Personal Data Protection Office (UODO) did not issue any recommendations, guidelines, or instructions to the Controller regarding the solutions it uses to secure personal data processing, in particular regarding the processing of personal data in electronic form, including via email. Therefore, there is no "cooperation with the authority," which could be treated as a mitigating circumstance under Article 83(2)(f) of Regulation 2016/679. However, the Controller's actions referred to above were treated by the President of the UODO as "other mitigating factors" referred to in Article 83(2)(k) of Regulation 2016/679 (see point 67 of the justification for the decision).

> Topics: Notification Obligation, Processing, Controllers, Data Breaches

### ¶73

How the supervisory authority learned of the breach, in particular whether and to what extent the controller or processor reported the breach (Article 83 paragraph 2 letter h) of Regulation 2016/679) The President of the Personal Data Protection Office (UODO) found the Controller to have violated personal data protection regulations ex officio – as a result of proceedings initiated by the Controller's notification of a personal data breach on January 22, 2021, subsequently supplemented on January 25, 2021. By submitting the notification, the Controller fulfilled its legal obligation; therefore, there is no basis to conclude that this fact should be considered to its advantage. As the EDPB rightly points out in Guidelines 04/2022, "[t]his circumstance is irrelevant where the controller is subject to specific breach notification obligations (e.g., the obligation to notify a personal data breach under Article 33 of [Regulation 2016/679]). In such cases, the fact of filing a notification should be considered a neutral circumstance."[8]

> Topics: Supervisory Authorities, Notification Obligation, Supervision, Controllers

### ¶74

If the controller concerned has previously been subject to measures referred to in Article 58(2) in the same case – compliance with those measures (Article 83(2)(i) of Regulation 2016/679) Before issuing this decision, the President of the Personal Data Protection Office did not apply any measures referred to in Article 58(2) to the Controller in the case at hand. 2 of Regulation 2016/679, and therefore the Controller was not obliged to take any action related to their application, and such actions, assessed by the supervisory authority, could have an aggravating or mitigating effect on the assessment of the identified infringement. Therefore, this premise has no impact on either the decision to impose an administrative fine or its amount.

> Topics: Controllers, Supervisory Authorities, Supervision, Personal Data

### ¶75

Application of approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42 (Article 83(2)(j) of Regulation 2016/679) As of the date of the decision, the Controller did not apply approved codes of conduct or approved certification mechanisms referred to in the provisions of Regulation 2016/679. Although the Controller presented a document titled "Code of Conduct for Tax Advisors on Personal Data Protection," developed by the National Chamber of Tax Advisors, it did not indicate whether and to what extent it applied it. Furthermore, the document in question does not constitute a code of conduct within the meaning of Article 40 of Regulation 2016/679. However, as provided in Regulation 2016/679, the adoption, implementation, and application of codes of conduct are not mandatory for controllers, and therefore, their failure to apply them cannot be considered to the Controller's detriment in this case. However, the adoption and application of such instruments as means guaranteeing a higher than standard level of protection for personal data processing could be considered to the Controller's advantage. However, such a circumstance did not occur in the present case.

> Topics: Certification, Codes of Conduct, Controllers, Personal Data

### ¶76

Financial benefits obtained directly or indirectly in connection with the infringement or losses avoided (Article 83 paragraph 2 letter k) of Regulation 2016/679) During the proceedings, no impact of the infringement of Regulation 2016/679 on the Controller's financial benefits or the avoidance of such losses was found. Therefore, there is no basis to treat this circumstance as an aggravating factor. The finding of tangible financial benefits resulting from the infringement of Regulation 2016/679 should be assessed decisively negatively. The Controller's failure to obtain such benefits, as a natural state, independent of the infringement and its effects, is a circumstance that, by its very nature, cannot be considered mitigating. This interpretation is confirmed by the very wording of Article 83 paragraph 2 letter k) of Regulation 2016/679, which requires the supervisory authority to pay due attention to "obtained" benefits – those incurred by the entity committing the infringement.

> Topics: Supervisory Authorities, Controllers, Supervision

### ¶77

Other aggravating or mitigating factors applicable to the circumstances of the case (Article 83 paragraph 2 letter k) of Regulation 2016/679) The President of the Personal Data Protection Office, in his comprehensive review of the case, did not note any circumstances other than those described above that could have affected the assessment of the infringement and the amount of the administrative fine imposed. VI.C. Determining the amount of the fine using the Guidelines 04/2022 It is important to note that in determining the amount of the administrative fine in this case, the President of the Personal Data Protection Office applied the methodology adopted by the EDPB in the Guidelines 04/2022. In accordance with the guidelines presented in that document, the President of the Personal Data Protection Office conducted the following process for calculating the amount of the fine:

> Topics: Personal Data

### ¶78

The President of the Personal Data Protection Office categorized the infringement of the provisions of Regulation 2016/679 found in this case (see Chapter 4.1 of the Guidelines 04/2022). The provisions of Regulation 2016/679 violated by the Controller include Article 5(1)(f) and Article 5(2) of Regulation 2016/679, which define the fundamental principles of processing. In accordance with Article 83(5)(a) of Regulation 2016/679, infringements of these provisions fall within the category of infringements punishable by the higher of the two penalties provided for in Regulation 2016/679 (with a maximum penalty of up to EUR 20,000,000 or up to 4% of the enterprise's total annual turnover in the previous financial year). Therefore, in abstracto, they are more serious than other infringements (specified in Article 83(4) of Regulation 2016/679).

> Topics: Controllers, Personal Data

### ¶79

The President of the Personal Data Protection Office (UODO) assessed the infringement found in this case as a medium-level infringement (see Chapter 4.2 of Guidelines 04/2022). This assessment took into account the factors listed in Article 83(2) of Regulation 2016/679 that relate to the subject of the infringement (they constitute the "seriousness" of the infringement), namely: the nature, gravity, and duration of the infringement (Article 83(2)(a) of Regulation 2016/679), the intentional or negligent nature of the infringement (Article 83(2)(b) of Regulation 2016/679), and the categories of personal data affected by the infringement (Article 83(2)(g) of Regulation 2016/679). A detailed assessment of these circumstances has been presented above. It should be noted here that considering their combined impact on the assessment of the infringement found in this case, taken as a whole, leads to the conclusion that its level of seriousness (understood in accordance with Guidelines 04/2022) is medium. As a consequence, the starting amount for calculating the fine is assumed to be between 10% and 20% of the maximum fine that can be imposed on the Controller, i.e., taking into account the limit specified in Article 83(5) of Regulation 2016/679, between EUR 2,000,000 and EUR 4,000,000 (see Subsection 4.2.4 of Guidelines 04/2022). The President of the Personal Data Protection Office (UODO) determined that the starting amount of PLN 10,082,160 (the equivalent of EUR 2,400,000) was adequate and justified by the circumstances of this case.

> Topics: Personal Data, Controllers, Fines

### ¶80

The President of the Personal Data Protection Office adjusted the starting amount corresponding to the average seriousness of the identified infringement to the Controller's turnover, as a measure of its size and economic power (see Chapter 4.3 of Guidelines 04/2022). Pursuant to Guidelines 04/2022, in the case of enterprises with an annual turnover of up to EUR 2 million, the supervisory authority may consider further calculating the fine based on a value between 0.2% and 0.4% of the starting amount. Given that the Controller's revenue in 2025 amounted to PLN (…), i.e. EUR (…) (at the average EUR exchange rate of January 28, 2026, being: EUR 1 = PLN 4.2009), the President of the Personal Data Protection Office deemed it appropriate to adjust the calculated fine amount to a value corresponding to 0.23% of the starting amount, i.e. PLN (…) (equivalent to EUR (…)).

> Topics: Controllers, Supervisory Authorities, Personal Data, Supervision

### ¶81

The President of the Personal Data Protection Office assessed the impact of the remaining circumstances (apart from those considered above in the assessment of the seriousness of the infringement) specified in Article 83, paragraph 1, on the established infringement. 2 of Regulation 2016/679 (see Chapter 5 of Guidelines 04/2022). These circumstances, which may have an aggravating or mitigating effect on the assessment of the infringement, relate – as assumed by Guidelines 04/2022 – to the subjective aspect of the infringement, that is, the entity itself committing the infringement and its conduct before, during, and after the infringement. A detailed assessment and justification of the impact of each of these premises on the assessment of the infringement of the provisions of Regulation 2016/679 are presented above. The President of the Personal Data Protection Office (UODO) found that one of them, in the President's opinion, had a mitigating effect on the penalty – the Controller's undertaking of actions aimed at increasing the level of security of the data it processes (assessed under the ground of Article 83 paragraph 2 letter k) of Regulation 2016/679). The remaining conditions for imposing the fine (indicated in Article 83 paragraph 2 letters c), d), e), f), h), i), and j) of Regulation 2016/679) – as indicated above – had neither a mitigating nor aggravating effect on the assessment of the infringement and, consequently, on the amount of the fine. Therefore, due to the existence of one additional circumstance in this case affecting the assessment of the infringement, namely, the Controller's voluntary actions that led to the remediation of the infringement, the President of the Personal Data Protection Office deemed it justified to adjust the amount of the fine determined based on the assessment of the seriousness of the infringement and the Controller's turnover, and significantly reduce it – by 50% – to PLN 11,594 (the equivalent of EUR 2,760). This significant reduction in the amount of the fine results from the fact that, as a result of the Controller's actions, one of the primary objectives of the administrative fine – restoring compliance with the regulations – has become obsolete[9].

> Topics: Personal Data, Law Enforcement, Controllers

### ¶82

The President of the Personal Data Protection Office (UODO) found that the amount of the fine determined in accordance with the above principles does not require further adjustment. Pursuant to Article 83(1) of Regulation 2016/679, each supervisory authority shall ensure that administrative fines imposed for infringements of this Regulation are effective, proportionate, and dissuasive in each individual case. However, Guidelines 04/2022 indicate that the final step in calculating the fine in accordance with the methodology presented therein should be an analysis of whether the final amount of the calculated fine meets these requirements and (if necessary) an appropriate increase or reduction of the fine.[10] In conducting such an analysis in this case, the President of the UODO found that the administrative fine of PLN 11,594, imposed in these specific, individual circumstances, will be effective because – due to its severity – it will achieve its preventive objective, which is to prevent future infringements – identical or similar to the one found in this case – committed by both the Controller and other entities. Additionally, the imposed fine, as a repressive measure, will allow for the effective punishment of the Controller for its unlawful, long-term conduct.

> Topics: Supervision, Supervisory Authorities, Fines, Personal Data

### ¶83

In the opinion of the President of the Personal Data Protection Office, the imposed fine will also be proportionate to the identified violations of Regulation 2016/679, particularly their nature and gravity. The proportionality of the sanction imposed is also reflected in the fact that the amount of the fine determined by the authority will not constitute an excessive burden on the Controller. The amount of the fine was set at a level that, on the one hand, constitutes an adequate response by the supervisory authority to the degree of the Controller's violation of obligations, while on the other hand, does not result in a situation in which the obligation to pay it would result in negative consequences in the form of a significant deterioration of the Controller's financial situation. In the opinion of the President of the Personal Data Protection Office, the Controller should and is able to bear the consequences of its negligence in the area of data protection, therefore, the imposition of an administrative fine is fully justified.

> Topics: Supervisory Authorities, Supervision, Personal Data, Controllers

### ¶84

In the opinion of the President of the Personal Data Protection Office, the administrative fine of PLN 11,594 will also serve a preventive function in these specific circumstances, as it will indicate to both the Controller and other controllers that the supervisory authority – acting as guardian of personal data protection regulations – will fully enforce the liability of the aforementioned entities for any identified violations of Regulation 2016/679. Therefore, the sanction applied in these proceedings will deter both the Controller itself and other similar controllers from committing the same or similar violations in the future.

> Topics: Supervision, Supervisory Authorities, Personal Data, Controllers

### ¶85

In the opinion of the President of the Personal Data Protection Office, the imposition of an administrative fine in this case was necessary. Applying any other corrective measure to the Controller provided for in Article 58, paragraph 1, of the Personal Data Protection Regulation (GDPR) is prohibited. 2 of Regulation 2016/679, in particular limiting it to a warning (Article 58 paragraph 2 letter b) of Regulation 2016/679), would not meet the requirement of proportionality, understood as the need for the supervisory authority to apply a measure that is appropriate, in particular, to the seriousness of the irregularities found. Refraining from imposing an administrative fine would also not guarantee that the Controller would not commit further personal data protection infringements in the future. In the opinion of the supervisory authority, only an administrative fine will allow for the effective enforcement of the provisions of Regulation 2016/679 in this case.

> Topics: Personal Data, Supervisory Authorities, Supervision, Controllers

### ¶86

Furthermore, regarding the amount of the administrative fine imposed, it should be emphasized that the amount of the administrative fine imposed, i.e., PLN 11,594, is only 0.0138% of the maximum fine that the President of the Personal Data Protection Office could have imposed on the Controller for the violations found in this case, applying Article 83 paragraph 5 of Regulation 2016/679. Under these factual and legal circumstances, the President of the Personal Data Protection Office ruled as set out in the operative part. [1] Personal Data Protection Act of 10 May 2018, hereinafter referred to as "Personal Data Protection Act." [2] Guidelines 04/2022 on the calculation of administrative fines under the GDPR. Version 2.1 Adopted on 24 May 2023, p. 9, paragraph 17, available online: https://edpb.europa.eu/system/files/2024-01/edpb_guidelines_042022_calculationofadministrativefines_pl_0.pdf [accessed: 22/09/2025]. [3] Ibid., p. 10, paragraph 24. [4] Ibid., p. 12, paragraph 28. [5] See Recital 75 of Regulation 2016/679 and Guidelines 04/2022, p. 18, paragraph 53(b)(i). [6] See Guidelines 04/2022..., p. 20, paragraph 55. [7] See ibid., p. 30, paragraph 94. [8] See ibid., p. 31, point 98. [9] See ibid., p. 42, point 135. [10] See ibid., p. 9, point 17.

> Topics: Personal Data, Controllers, Fines

---
Generated by overview.legal · https://overview.legal/posts/53104 · 2026-08-22
