UODO (Poland) - DKN.5131.27.2023
Facts — A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and information regarding whether certain individuals were subject to mandatory quarantine to prevent and combat the SARS-COV-2 virus. An employee of the controller posted a file containing this information on a private server in November 2020. An automated search engine indexing bot subsequently accessed the file and made its full contents available in search results to any Internet user. The supervisory authority received an electronic report concerning a potential data breach in February 2021. The controller had not notified the DPA or the data subjects of this incident, as it concluded it had not acted as a controller in the context of the processing operations at issue. The DPA launched an investigation into the unauthorised disclosure of personal data and initiated administrative proceedings against the controller in August 2023. Holding — The DPA issued the controller three separate fines amounting to PLN 33,700 (€7,800) in total, as it considered its GDPR violations were the result of three separate courses of conduct. It held that the social welfare unit had clearly determined the means and purposes of processing and acted as controller within the meaning of Article 4(7) GDPR – the employee responsible for the processing operations had acted with the unit’s authorisation, at its instruction, and on its behalf. First, the DPA held the controller had violated Articles 24(1), 25(1), 32(1), and 32(2) GDPR by failing to implement appropriate technical and organisational measures and imposed a fine of PLN 15,000 (€3,460) on the controller. This resulted in violations of the principles of integrity, confidentiality and accountability set out in Articles 5(1)(f) and 5(2) GDPR. There was an internal document in effect during the data breach that identified the risk level of processing as high. However, the DPA pointed out this document did not include, among other things, the number of data subjects, the periods for data storage, and the duration of the processing. The measures implemented were not reviewed or updated and also proved to be ineffective. Second, the DPA issued the controller a fine of PLN 5,500 (€1,270) for an infringement of Article 33(1) GDPR due to a failure to report the data breach to the supervisory authority. Finally, the DPA held that the controller had violated Article 34(1) GDPR by failing to notify the data subjects of the data breach and imposed a fine of PLN 13,200 (€3,060) on the controller. In addition, it ordered the controller to notify the data subjects of the breach in question.
How it connects
Related across sources
Full text 240 findings
27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)[3], hereinafter referred to as "Regulation 2016/679", after conducting ex officio administrative proceedings regarding the infringement of personal data protection provisions by the Social Welfare Center in D., hereinafter referred to as the "Center", the President of the Personal Data Protection Office, hereinafter referred to as the "President of the Personal Data Protection Office": I) finding that the Center has violated the provisions of Article 24(1), Article 25(1), and Article 32(1) of the Personal Data Protection Regulation, 1 and 2 of Regulation 2016/679, consisting in the failure to implement appropriate technical and organizational measures designed to effectively implement data protection principles and to provide the necessary safeguards for processing, including ensuring a level of security appropriate to the risk of violations of the rights and freedoms of natural persons of varying likelihood and severity, and resulting in a violation of the principles set out in Article 5 paragraph 1 letter f) and Article 5 paragraph 2 of Regulation 2016/679, imposes on the Center, for violation of the provisions of Article 5 paragraph 1 letter f) and 2, Article 25 paragraph 1, and Article 32 paragraphs 1 and 2 of Regulation 2016/679, an administrative fine of PLN 15,000 (in words: fifteen thousand zlotys); II) finding the Center to have violated the provisions of Article 33 paragraph 1 of Regulation 2016/679, consisting in failure to notify the supervisory authority of a personal data breach, imposes an administrative fine on the Center in the amount of PLN 5,500 (in words: five thousand five hundred zlotys); III) Finding that the Center has violated the provision of Article 34 paragraph 1 of Regulation 2016/679, consisting in failing to notify data subjects of a personal data breach:
Imposes an administrative fine on the Center in the amount of PLN 13,200 (in words: thirteen thousand two hundred zlotys); and 2 Orders the Center to notify data subjects of the personal data breach referred to in points 15-20 of the justification for the decision, in accordance with Article 34 paragraph 1 of Regulation 2016/679, including providing them with a clear and plain description of the nature of the personal data breach and the information and measures referred to in Article 33 paragraph 1. 3(b), (c), and (d) of Regulation 2016/679, in accordance with Article 34(2) of Regulation 2016/679, within 7 days of the date of notification of the decision. Justification 1 Introduction
President of the Personal Data Protection Office (UODO) 1 Pursuant to Article 34(1) and (2) of the Personal Data Protection Office (UODO), the President of the Personal Data Protection Office is the authority competent for personal data protection and the supervisory authority referred to in Article 4(21) of Regulation 2016/679.
Pursuant to Article 57(1)(a) and (h) of Regulation 2016/679, each supervisory authority in its territory monitors and enforces the application of this Regulation and conducts proceedings concerning its application.
Pursuant to Article 58(1)(b), Under Article 2 of Regulation 2016/679, each supervisory authority has the power to order the controller or processor to bring processing operations into compliance with the provisions of this Regulation, and, where appropriate, to specify the manner and deadline, and to impose, in addition to or instead of the measures referred to in this paragraph, an administrative fine pursuant to Article 83 of Regulation 2016/679, depending on the circumstances of the individual case. 1.2 Investigative Activities and Administrative Proceedings
The Center is a social welfare organizational unit operating under the Act of March 8, 1990, on Local Government[4], the Act of March 12, 2004, on Social Assistance[5], the Act of August 27, 2009, on Public Finances[6], and other acts defining the tasks of social assistance in municipalities, as well as Resolution No. (...) of the Municipal National Council in D. of April 26, 1990, on the establishment of the Social Welfare Center in D. and the Statute of the Social Welfare Center in D.
On February 3, 2021, the President of the Personal Data Protection Office received an electronic notification regarding a possible breach of personal data protection[7], hereinafter referred to as the "Notice of February 3, 2021." The case was registered under reference number DKN.5101.25.2021.
The described event, hereinafter referred to as the "incident," involved the unauthorized disclosure of personal data[9] processed[8] by the Center, including health data, of at least (...) residents of D., who may have required support from the Center in connection with their mandatory quarantine or home isolation due to the prevention and control of SARS-CoV-2 infection. The incident occurred on November 23, 2020, as a result of a list containing the aforementioned data being placed on a private server belonging to an employee of the Center, and then indexed by the C. search engine, which enabled it to be accessed by internet users.
The incident was not previously known to the President of the Personal Data Protection Office (UODO) and, until the date of the decision, had not been reported to the supervisory authority by the Center pursuant to Article 33(1) of Regulation 2016/679.
The information of February 3, 2021, prompted the President of the Personal Data Protection Office to verify the Center's compliance with its obligations as a controller.[10] Therefore, the President of the Personal Data Protection Office initiated actions aimed at investigating not only the circumstances of the incident, but also the lawfulness of the processing of the personal data covered by it.
Therefore, in order to obtain the information necessary to resolve the matter, the President of the Personal Data Protection Office contacted: – an employee of the Center, in letters dated March 1 and April 29, 2021, to which responses were provided in letters dated March 12 and May 19, 2021; – the Volunteer Fire Department in D., hereinafter referred to as the "Volunteer Fire Department," in a letter dated July 1, 2021, to which responses were provided in a letter dated July 9, 2021; – the Center, in letters dated July 1, 2021, and September 26, 2022, to which responses were provided in letters dated July 9, 2021, and September 30, 2022; and – the District Police Commander in D., in a letter dated September 21, 2022, to which responses were provided in a letter dated January 11, 2023.
Based on the findings made, on August 9, 2023, the President of the Personal Data Protection Office (UODO) initiated ex officio administrative proceedings concerning the possible violation by the Center of Article 5 paragraph 1 letter f) and paragraph 2, Article 24 paragraph 1, Article 25 paragraph 1, Article 32 paragraphs 1 and 2, Article 33 paragraph 1, and Article 34 paragraph 1. Articles 1 and 2 of Regulation 2016/679 as part of the processing of personal data referred to in point 6 of the explanatory memorandum. The proceedings in this case were registered under reference number DKN.5131.27.2023.
Simultaneously, in a letter dated August 9, 2023, the President of the Personal Data Protection Office requested the Center to provide additional clarifications in the matter, to which the Center responded in a letter dated August 10, 2023. 2 Facts Based on the evidence collected in the case, the President of the Personal Data Protection Office determined the following facts: 2.1 Processing Context
The Center processed the personal data of residents of D., including their first names, last names, telephone numbers, addresses, and information about the sanitary situation, i.e., the mandatory quarantine or home isolation of certain individuals in connection with the prevention and control of SARS-CoV-2 infection and the spread of the COVID-19 disease caused by it[11], in order to provide support to these individuals. – Evidence: information dated February 3, 2021; letters from the Center dated July 9, 2021, and September 30, 2022; orders of the Voivode (...) dated March 12, 2020, no. (...), and March 14, 2020, no. (...)[12].
The Center received information about individuals subjected to mandatory quarantine or home isolation from the District Sanitary and Epidemiological Station in D. (hereinafter referred to as the "District Station") and then took steps to assess the needs of these individuals (e.g., food or medication requirements). Based on the data thus compiled, an employee of the Center, hereinafter referred to as the "coordinator," coordinated operational activities performed by members of the Volunteer Fire Department, consisting of providing support within the specified scope and location. – Evidence: letter from the Center dated July 9, 2021; letter from the Volunteer Fire Department dated July 9, 2021; orders from the Voivode (...) dated March 12, 2020, no. (...), and March 14, 2020, no. (...); printout of a press article entitled "(…)", containing an interview with the coordinator and president of the Volunteer Fire Department, published on November 16, 2020, on the website "(…)"[13].
The Center, as the controller, included in its register of processing activities[14] the activity "List of persons in quarantine/isolation provided by the Sanitary and Epidemiological Station in D." On October 19, 2020, the Center authorized the coordinator to process the personal data covered by the aforementioned processing activity. – Evidence: letters from the Center dated July 9, 2021, and September 30, 2022. 2.2 Incident
On November 23, 2020, a file in the form of a spreadsheet in XLSX[15] format was posted on the coordinator's private server, containing the first and last names, telephone numbers, addresses, and information on the sanitary situation of at least (...) residents of D. (the file contained (...) records, including at least (...) unique ones). The file's metadata indicates that it was created on October 30, 2020, by a user with a first and last name identical to the coordinator's. It has not been determined how the file ended up on his server. – Evidence: information dated February 3, 2021; letters from a Center employee dated March 12 and May 19, 2021; Letter from the District Police Commander in D. dated January 11, 2023
The aforementioned file was posted on the server hosting the website "(…)" (operated by the coordinator), in a directory designated for storing files published within the X.[16] system (...). This directory – in its standard configuration – is publicly available and can be searched by automated search engine crawlers, including C. Consequently, C. downloaded the file, indexed its contents, and then made it available in search results for any internet user.[17] Not only the file name itself was disclosed, but also its full content, including data stored in a spreadsheet. – Evidence: information dated February 3, 2021; letter from a Center employee dated March 12, 2021.
On February 3, 2021, the President of the Personal Data Protection Office received information about a possible personal data breach. The file referred to in point 15 of the justification was attached to the message, along with information about its downloadability and a hyperlink leading directly to the directory referred to in point 16 of the justification. – Evidence: information dated February 3, 2021.
On February 9, 2021, the coordinator received information about the incident. It was sent to the editorial office address "(…)". On the same day, the coordinator deleted the file from his private server, thereby limiting its further exposure, and notified the relevant police unit "of a suspected server hack." – Evidence: letter from a Center employee dated March 12, 2021.
On February 10, 2021, the coordinator informed the Center of the incident. The Center's management conducted an analysis of the incident and concluded that it did not act as a controller in the context of the processing operations in which the incident occurred. – Evidence: letter from the Center dated July 9, 2021.
On May 29, 2021, the proceedings conducted by the District Police Headquarters in D. in the case referred to in point 18 of the justification concluded with the issuance of a decision to discontinue the investigation due to the lack of elements of a prohibited act. – Evidence: letter from the District Police Commander in D. dated January 11, 2023. 2.3 Technical and organizational measures to ensure the security of personal data processing at the time of the incident
The Center preceded the selection of technical and organizational measures to ensure the security of personal data processing affected by the incident with an analysis contained in a document referred to as "Assessment (...)" (the document was not dated, but it is assumed that it was in force at the time of the incident). The analysis indicates a "high" level of risk associated with the processing activity identified as "List of persons in quarantine/isolation provided by the Sanitary and Epidemiological Station in D." The document also includes, among other things: a) a partial description of the nature, scope, context, and purposes of the processing (including: the identification of the processing activity being analyzed; the name of the controller and its registered office address; the purpose of the processing; the processing operation performed as part of the aforementioned activity; data recipients; categories of data processed as part of the aforementioned activity; legal basis for processing); and b) a partial description of the possible negative consequences for data subjects (i.e., the identification of one consequence: "Processing may lead to the exclusion or discrimination of data subjects"). – Evidence: letter from the Center dated August 10, 2023.
However, the aforementioned document does not include, among other things: sources of risk; identified vulnerabilities; a reasonable degree of probability of a violation of the rights and freedoms of natural persons (the "Probability" criterion used only the indicator based on the question "When was the last time a violation occurred?", for which the answer was "Never") and a reasonable degree of seriousness of possible negative consequences for the rights and freedoms of natural persons. – Evidence: the Centre's letter of August 10, 2023.
In addition, the above-mentioned The document contains a list of recommended actions (including: "maintaining high-level technical security"; "maintaining employee cooperation with the Data Protection Officer to keep the risk associated with the processing of customer personal data to a minimum"; "monitoring the security of processed personal data to avoid breaches"; "particular attention should be paid to: compliance with equipment operating instructions and the rules for using it (copying, sending, sharing); strict compliance with personal data protection regulations; applying the Data Protection Policy procedures and the rules for using the IT system in which personal data is processed; using only company-issued IT equipment." However, these recommendations were not supplemented with information regarding the plan and deadlines for their implementation, the threats associated with individual solutions, and their potential impact on the existing risk to the rights and freedoms of natural persons. – Evidence: letter from the Center dated August 10, 2023.
At the time of the incident, the Center had the following technical and organizational security measures in place for the processing of the personal data involved: a) implementation "Policy (...)" – a document regulating the basic principles of personal data protection in the organization – and familiarizing employees with it; b) implementing the "Instruction (...)", a document regulating the basic principles of operating IT systems through which personal data are processed – and familiarizing employees with it; c) allowing only authorized employees, obligated to maintain confidentiality, to process the aforementioned personal data. 3 Legal Assessment In light of the established factual circumstances, after analyzing all the evidence, the President of the Personal Data Protection Office (UODO) considered the following: 3.1 Determining the Controller
Correctly determining the controller is crucial for appropriately assigning responsibility for compliance with personal data protection regulations. In analyzing this case, the President of the Personal Data Protection Office (UODO) first examined who is the controller of the personal data referred to in point 12 of the justification, including the personal data covered by the incident.
Pursuant to Art. Article 4(7) of Regulation 2016/679 defines "'controller' as a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be laid down in Union or Member State law."
As the European Data Protection Board (hereinafter referred to as the "EDPB") points out, the concept of "controller" is functional in nature and refers to the actual role of an entity, based on its actual actions in a specific situation, rather than a formal designation, for example, in a contract. Therefore, "the allocation of roles should normally result from an analysis of the factual elements or circumstances of the case and, as such, is not subject to agreement"[18]. The EDPB explains that this concept also has an autonomous nature, meaning that "while external legal sources may be helpful in determining who the controller is, the interpretation should primarily be made in accordance with data protection law"[19].
In correspondence with the President of the Personal Data Protection Office (UODO), the Center maintained that it was not a controller within the meaning of Article 4(7) of Regulation 2016/679 in relation to the personal data covered by the incident – the improper processing of which is the subject of these proceedings.[20] However, the President of the UODO does not share this position, as it does not reflect the Center's actual role in the processing of the aforementioned data and is inconsistent with the provisions of Regulation 2016/679.
It should be emphasized that the Center did not deny that it acted as a controller in relation to the personal data received from the District Station within the scope and for the purposes referred to in paragraphs 12-14 of the explanatory memorandum. At the same time, however, the Center argued that it did not act as a controller in relation to the personal data contained in the file referred to in paragraph 15 of the explanatory memorandum, and therefore was not a controller of the data covered by the incident.[21]
The Center's explanations indirectly indicate that its role as a controller ended no later than the moment the coordinator was provided with the personal data referred to in point 12 of the justification and commenced the performance of its tasks in cooperation with the Volunteer Fire Department.[22] This position contradicts the findings of the President of the Personal Data Protection Office (UODO), according to which, at the time of the incident, the coordinator remained an employee of the Center and performed tasks within the scope of the processing, the purposes and methods of which were determined by the Center.
It should be emphasized here that the Center's explanations in this regard are inconsistent. In its letter dated July 9, 2021, the Center indicated that, according to its analysis, "the Controller of the Personal Data concerned by the incident is the District Sanitary and Epidemiological Station in D." and that "the incident occurred at the processor – the Volunteer Fire Department."[23] In a letter dated August 10, 2023, the Center stated that "the Controller of the Personal Data affected by the incident is the Volunteer Fire Department in D."[24]
Regardless of the above, the Center's argument to justify its position that it did not act as a controller with respect to the personal data covered by the incident was based on three main assumptions.
First, the Center indicated that the District Fire Station transferred personal data to two separate entities: the Center and the Volunteer Fire Department. The Center's explanation therefore indicates that, in practice, the Volunteer Fire Department provided assistance independently of the Center.[25]
The findings of the President of the Personal Data Protection Office do not support this version of events. In the report submitted to the Police, the coordinator indicated that the aforementioned The personal data "was received (...) from the Social Welfare Center in D., which in turn received data from the District Sanitary and Epidemiological Station in D."[26]. In a letter dated July 9, 2021, the Volunteer Guard stated that it had never received the aforementioned personal data from the District Sanitary and Epidemiological Station, and that only the coordinator, as an employee of the Center, had access to it. The Volunteer Guard's role was to be limited to operational activities within the scope determined by the coordinator on a case-by-case basis.[27]
The Voivode (…) similarly defined the nature of cooperation between social welfare centers and other entities, including in the food assistance instruction constituting Annex 1 to the order of March 14, 2020, No. (...), specifying, for example: "The Social Welfare Center verifies whether a given person requires food assistance"; "(...) contacts the local Volunteer Fire Department, Territorial Defence Force, or Police unit to determine where to pick up the food and where it should be delivered."[28] This is also confirmed by information published through official government channels by the Ministry of Family, Labor, and Social Policy, for example, in the brochure "What Can Persons Under Quarantine Count On?"[29].
Secondly, the Center indicated that the coordinator was not only an employee of the Center but also an employee of the Volunteer Fire Department – and as part of the tasks performed for the latter entity, he carried out the processing operations that resulted in the incident. As evidence supporting this position, the Center pointed out that the coordinator carried out the aforementioned operations at the Volunteer Fire Department headquarters, using its equipment.
In this context, it is worth emphasizing that volunteer fire departments are associations within the meaning of the Act of April 7, 1989 – Law on Associations[30], whose activities are generally based on the voluntary work of their members, not their employees[31]. The above distinction is important in determining the nature of the relationship between the coordinator and the aforementioned entities. The employee-employer relationship is stronger than the member-association relationship, as it is based on statutory subordination and day-to-day management, under which the employer organizes work and bears responsibility for the execution of assigned tasks, whereas membership in the association is voluntary and does not entail a similar level of control or organizational responsibility.
In attempting to justify the position that the coordinator "performed (…) employee duties for the Volunteer Fire Department in D."[32] the Center pointed out that he performed these duties at the Volunteer Fire Department's headquarters using its technical tools. However, this circumstance remains irrelevant for the proper determination of the controller of the personal data affected by the incident. The essence of the controller's role is not the infrastructure used to perform individual data operations, but the actual determination of the purposes and means of processing.
This understanding of the definition of "controller" was confirmed by the CJEU, stating that an entity that participated in determining the purposes and means of processing may be considered a controller within the meaning of Article 4(7) of Regulation 2016/679, "even if that entity did not itself carry out the processing of such data" or "did not expressly consent to the implementation of specific processing operations."[33]
It should also be noted that the Center's claims are inconsistent with the explanations provided by the coordinator and the Volunteer Guard, as well as with the documentation submitted by the Center. During the investigation, the coordinator stated that it performed the activities referred to in point 13 of the justification "for [the Center]."[34] In its letter of July 9, 2021, the Volunteer Guard indicated that it had not found any traces of the processing of the data covered by the incident on its devices, and that, according to its findings, the coordinator "performed the processing of the above-mentioned data on its private laptop, which it likely also used for other purposes."[35]
It is also noteworthy that the Center, as the controller, authorized the coordinator, as its employee, to perform the tasks within the processing in question on October 19, 2020, while the file referred to in point 15 of the justification was created on October 30, 2020, i.e., just 11 days later.
This fact is partially related to the Center's third argument, according to which the list containing personal data it received from the District Station and the aforementioned file (created based on that list) constituted two separate data sets, for which separate controllers were responsible: the Center and the Volunteer Fire Department. The Center justified its position by arguing that the aforementioned file was merely a "official memo" created by the coordinator "as an employee" of the Volunteer Fire Department.[36]
In this case, too, the Center's claims abstract from the essence of the concept of controller, reducing it to a purely technical criterion. The creation by an employee of a new file containing the same personal data, as part of the same processing process and for the same purpose, does not constitute either the creation of a new, independent data set or a change in the entity responsible for processing. The Center continued to exercise actual and legal control over the data, and the coordinator acted with its authorization, at its direction, and on its behalf.
In summary, the evidence collected in the case indicates that the Center, despite its denials, actually determined the purposes and means of processing the personal data referred to in point 6 of the explanatory memorandum, and was therefore their controller within the meaning of Article 4(7) of Regulation 2016/679, from the time of their collection until at least the incident occurred. This is indicated both by the organizational and legal context surrounding the processing process and the practices of the participants in that process, which clearly indicate that the Center decided why and how the personal data were processed, i.e., it determined both the purposes and the relevant means of their processing.[37]
In particular, the Center determined the purpose for which personal data were collected, i.e., to identify individuals requiring support due to the restrictions imposed by the epidemic, to determine the scope of such assistance, and to ensure its implementation. Therefore, the Center determined why the data of specific individuals were processed at all, including why it was necessary to determine who needed what assistance (e.g., provision of food, medicine, or other essential items).
Simultaneously, the Center determined the methods of data processing, understood as essential elements of the process of their use, including how these purposes were to be achieved. This manifested itself, in particular, in the Center determining which categories of data were necessary to provide assistance, from what sources the data were obtained, to whom and to what extent they could be disclosed, and in what form the assistance was to be provided.
In practice, the Center made decisions on the eligibility of a specific individual for assistance, defined its scope, and decided on the use of other entities as executors of actual activities, such as delivering assistance to a specified address. This meant that the Volunteer Guard's actions occurred solely within the scope and for the purpose previously defined by the Center, constituting part of the Center's adopted task implementation model, and not the result of the Volunteer Guard's independent decisions.
In this context, the fact that the implementation activities were coordinated by a person employed and designated for this task by the Center is also significant. The EDPB points out that "[i]n principle, it can be assumed that any processing of personal data by employees that takes place within the framework of the organization's activities takes place under the control of that organization"[38].
With this in mind, in the opinion of the President of the Personal Data Protection Office (UODO), the Center acted as a controller in relation to the personal data referred to in point 12 of the justification, at least from the time they were obtained from the District Station or other sources, including the personal data covered by the incident, until at least March 28, 2022, i.e., the date of lifting the general obligation to quarantine and home isolation pursuant to the Regulation of the Council of Ministers of March 25, 2022.[39] Until that date, there was a legal basis for social welfare centers to perform tasks related to providing assistance to individuals subject to quarantine or isolation, which objectively and systematically involved the processing of data concerning these individuals. For the purposes of the proceedings in question, the President of the UODO therefore assumed that this period began no later than October 19, 2020 and ended no earlier than March 28, 2022. 3.2 Responsibility for processing and accountability (Article 24(1) of Regulation 2016/679)
In Article 5(1) of Regulation 2016/679, the legislator has formulated fundamental principles regarding the processing of personal data. These principles play a special role in Regulation 2016/679, as they are given priority over other provisions of that regulation.[40] According to Article 5(2) of Regulation 2016/679, "the controller shall be responsible for, and must be able to demonstrate, compliance with the provisions of paragraph 1 ("accountability")."
The general responsibility of the controller for compliance with the provisions of Regulation 2016/679 is further clarified in Article 24(1). 1, according to which, "taking into account the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organizational measures to ensure that processing is carried out in accordance with this Regulation and to be able to demonstrate that it is carried out." Implementing the aforementioned measures should therefore result in the controller's actions being adapted to the requirements of Regulation 2016/679, including data security appropriate to the level of risk, and the ability to demonstrate that processing is carried out in compliance with those requirements.[41]
Of particular importance, in Article 24(1) of Regulation 2016/679, second sentence, the EU legislator further specifies that "those measures shall be reviewed and updated, whenever necessary." Controllers should therefore continuously adapt the measures used to the changing circumstances surrounding the processing. This means that implementing appropriate measures should not be a one-off action, but a dynamic process.[42]
Recital 74 of Regulation 2016/679 confirms that the controller bears full responsibility for the processing of personal data and should therefore be able to demonstrate that the measures it has implemented comply with the provisions and are effective.
The CJEU also emphasized the crucial importance of the accountability principle in its judgment of 14 December 2023, reference C-340/21, stating that "[i]t is clear from the wording of Article 5(2), Article 24(1) and Article 32(1) [of Regulation 2016/679] that the burden of proving that personal data are processed in a manner that ensures appropriate security of those data within the meaning of Article 5(1)(f) and Article 32 of that Regulation rests with the controller concerned."[43]
This position is consistent with the case law of national administrative courts. In its judgment of March 17, 2022, file reference II SA/Wa 2516/21, the Regional Administrative Court in Warsaw noted that "[Regulation 2016/679] does not imply any 'presumption' of the correctness of data processing by the controller."[44]
Considering the above, the President of the Personal Data Protection Office assessed the activities of the Center, as the controller, in light of the principle of accountability and the obligations arising therefrom: implementing measures to ensure compliance with personal data protection regulations and demonstrating that these measures have been implemented and are effective. The examination of the lawfulness of personal data processing by the Center therefore consisted in particular in verifying whether the Center had demonstrated during the proceedings, in accordance with Article 5(2) of Regulation 2016/679, that it had applied appropriate technical and organizational measures to ensure the implementation of the principles set out in Article 5(1) of Regulation 2016/679. 3.3 Security of Processing (Article 25(1) and Article 32(1) and (2) of Regulation 2016/679) 3.3.1 Legal Analysis
Pursuant to Article 5(1)(f) of Regulation 2016/679, "personal data must be processed in a manner that ensures appropriate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures ("integrity and confidentiality")."
Consequently, controllers are obliged to secure the personal data being processed in order to protect data subjects against threats to their rights and freedoms. The principle of integrity and confidentiality is further detailed in, among others, Article 32(1). Articles 1 and 2 of Regulation 2016/679, which require controllers and processors to implement technical and organizational measures to ensure a level of security of personal data appropriate to the risk posed by processing.
Pursuant to Article 32(1) of Regulation 2016/679, “Taking into account the state of the art, the cost of implementation, the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including, among others, where appropriate: a) pseudonymization and encryption of personal data; b) the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services; c) the ability to promptly restore the availability and access to personal data in the event of a physical or technical incident; d) regularly testing, measuring, and evaluating the effectiveness of technical and organizational measures to ensure the security of processing.”
According to paragraph 2 of the provision in question, "when assessing the appropriate level of security, particular account shall be taken of the risks inherent in processing, in particular those arising from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed." The controller should therefore pay particular attention to the risk of an event constituting a personal data breach within the meaning of Article 4(12) of Regulation 2016/679.
At the same time, pursuant to Article 25(1) of the GDPR, 1 of Regulation 2016/679, "taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons posed by the processing, the controller shall, both when determining the means for processing and at the time of the processing itself, implement appropriate technical and organizational measures, such as pseudonymization, designed to implement data protection principles, such as data minimization, effectively and to incorporate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects."
An analysis of Article 25(1) and Article 32(1) and (2) of Regulation 2016/679 leads to the conclusion that these provisions are complementary. Comparing them with Article 24(1) of Regulation 2016/679 provides a clear understanding of the provisions. Article 1 of Regulation 2016/679, which imposes a general obligation on the controller to ensure and demonstrate compliance with the Regulation, clearly demonstrates that the requirement to apply data protection measures appropriate to the existing risks – both prior to processing and continuously throughout the processing, with regular reviews of their effectiveness – is crucial to ensuring the protection of the rights and freedoms of natural persons.
It follows from the above that the EU legislator adopted a risk-based approach in Regulation 2016/679, imposing on the controller an obligation to conduct a risk analysis of the personal data processing risks. This analysis forms the basis for the proper selection of appropriate technical and organizational measures.[45]
According to Recital 74 of Regulation 2016/679, the data protection measures selected by the controller “should take into account the nature, scope, context and purposes of the processing, as well as the risk to the rights and freedoms of natural persons.” In other words, these measures should be proportionate to the processing model adopted and the associated risks for data subjects.
According to Recital 75 of Regulation 2016/679, this risk can take various forms and lead to various negative consequences. The legislator cites, for example, the possibility of physical harm, material or non-material damage, including discrimination, identity theft or fraud, financial loss, damage to reputation, or loss of confidentiality of data protected by professional secrecy. Therefore, as part of the risk analysis, the controller should identify all (foreseeable and identifiable) potential negative consequences that may affect the data subjects whose data are being processed.
In Recital 76 of Regulation 2016/679, the legislator specified how the risk analysis should be conducted. The likelihood and severity of the risk should be determined by reference to four key elements: the nature, scope, context, and purposes of the processing. Importantly, the risk should be assessed based on objective factors, not subjective assumptions.
In turn, Recital 83 of Regulation 2016/679 states the purpose of the risk analysis, which is to maintain data security and prevent incompatible processing. The controller should assess the risk inherent in the processing and, on that basis, implement measures to mitigate that risk. These measures should ensure an appropriate level of security, including data confidentiality, while taking into account the state of the art and the costs of implementation in relation to the nature of the data being processed and the level of risk identified.
Recital 84 of Regulation 2016/679 specifies that, in the case of processing operations that may involve a high risk to the rights and freedoms of natural persons, the controller should conduct an in-depth assessment to assess the source, nature, specificity, and severity of that risk. The results of this assessment then form the basis for determining appropriate measures to demonstrate compliance of the processing with the provisions of the aforementioned Regulation.
The aforementioned regulations indicate that the selection of appropriate data protection measures should be preceded by a risk analysis that takes into account a number of specific elements. First, the controller must provide a detailed description of the processing itself, specifying its nature (what operations are performed on the data), scope (what categories of data are processed and how many individuals are affected), context (under what circumstances and using what tools the processing takes place), and purposes (what the data are used for).
Next, the controller should identify potential risks and their negative impact on data subjects, taking into account both external and internal threats. Particular attention should be paid to the risks associated with accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data, and therefore the occurrence of events that may constitute a personal data breach within the meaning of Article 4(12) of Regulation 2016/679. For each identified threat, the controller should estimate the likelihood of its occurrence and the severity of the potential consequences for data subjects. This assessment should be objective and based on currently available knowledge.
The role of the aforementioned criteria in the process of conducting a risk analysis with respect to implemented data protection measures was also clarified by the CJEU in its judgment of 14 December 2023, file ref. C-340/21, stating that "the adequacy of such technical and organizational measures must be assessed in two stages. First, the risk of personal data protection arising from the processing in question and its possible consequences for the rights and freedoms of natural persons must be identified. This assessment must be made specifically, taking into account the likelihood of the risk identified and its degree of seriousness. Second, it must be verified whether the measures implemented by the controller address that risk, taking into account the state of the art, the cost of implementation, and the nature, scope, context, and purposes of the processing. (...) Therefore, in order to verify the adequacy of technical and organizational measures implemented under Article 32 [of Regulation 2016/679], the national court should not limit itself to ascertaining how the controller intended to comply with its obligations under that article, but should examine the substance of those measures in the light of all the criteria set out in that article, as well as the circumstances of the case and the evidence available to it in that regard"[46]. 3.3.2 Analysis of the Facts
In assessing the compliance of the processing of personal data by the Center with the principle of integrity and confidentiality referred to in Article 5(1)(f) of Regulation 2016/679, in the context of the controller's obligations set out in Article 24(1), Article 25(1), and Article 32(1) and (2) of that Regulation, the President of the Personal Data Protection Office (UODO) examined during the proceedings whether the Center had thoroughly and completely analyzed the risks associated with the processing and whether, on that basis, it had implemented appropriate technical and organizational measures to ensure compliance with the data protection principles, including data security, and to demonstrate compliance with the provisions of the Regulation.
As evidence of conducting the risk analysis, the Center submitted the document referred to in paragraphs 21-23 of the explanatory memorandum. However, in the opinion of the President of the UODO, its content, scope, and manner of preparation do not allow for the conclusion that it constitutes effective implementation of the obligations arising from Article 24(1). 1 of Regulation 2016/679, according to which the controller should implement appropriate technical and organizational measures, taking into account risks of varying likelihood and severity for the rights and freedoms of natural persons, and be able to demonstrate compliance of the processing with the provisions of the Regulation.
First, this document is a one-off document and is not part of an ongoing risk management process, whereas Article 24(1), Article 25(1), and Article 32(1) and (2) of Regulation 2016/679 stipulate that risk analysis should accompany the processing of personal data at all stages, and the data protection measures applied should be regularly reviewed and updated in light of changing processing conditions and the associated threats. This was confirmed by the Regional Administrative Court in Warsaw in its judgment of June 21, 2023, file ref. II SA/Wa 150/23, noting that "regularly testing, measuring, and assessing the effectiveness of technical and organizational measures to ensure the security of processing is a fundamental obligation of every controller (...) arising from Article 32(1)(d) [of Regulation 2016/679]"[47].
The explanations provided by the Center indicate that such activities were not carried out. When asked about regular testing, measuring, and assessing the effectiveness of the measures in place, the Center only referred to "cyclical information security audits," but did not provide any evidence of their actual performance or their actual connection with the implementation of the obligations set out in Regulation 2016/679[48].
Secondly, in the opinion of the President of the Personal Data Protection Office, the characterization of the processing presented in the document (i.e., the description of the nature, scope, context, and purposes of processing) is incomplete, and its content does not allow for a proper understanding of the adopted processing model or the correct identification of potential threats.
The description of the nature of the processing was limited to the name of the process, a very general list of resources ("computer, email, printing devices, shredder, file encryption program"), and a single activity performed as part of the process ("updating the list of individuals in quarantine/isolation, provided by the Sanitary and Epidemiological Station in D."). However, such a description does not illustrate how the processing was carried out throughout the entire data lifecycle, i.e., from acquisition, through recording, use, sharing, storage, and deletion. It also does not indicate the stages of processing and data flows, or the roles of individual persons with access to the data. Consequently, the Center did not formulate a description of the nature of the processing sufficiently to assess what specific operations and solutions create a risk environment and what vulnerabilities may arise at each stage of processing. According to the President of the Personal Data Protection Office, proper consideration of the above-mentioned elements could have enabled the Center to minimize the risk of an incident, particularly given that the incident occurred as part of an operation that was not anticipated in the analysis.
The description of the scope of processing does not allow for determining the full scale of the process, as it merely identifies the categories of personal data being processed, while simultaneously declaring that the processing is not carried out on a large scale. However, the document lacks, among other things, the number of data subjects, the frequency of obtaining and updating the list, the periods and principles of data retention, and the duration of processing. These omissions are crucial for assessing the likelihood and severity of potential consequences of violating the rights and freedoms of natural persons and for selecting security measures appropriate to the processing model.
The description of the context of processing is largely general in nature. The Center identified the recipients of the data using the formula: "The data will be disclosed only to entities authorized under the law or a data processing agreement concluded with the Center," which did not allow for the identification of either the actual categories of recipients, the specific entities or roles of the individuals to whom the data were disclosed, or the channels of disclosure or the principles of control over further processing. At the same time, although the table indicates that the list was provided to the Center by the District Station, the description did not clarify the organizational and legal relationships between the aforementioned entities. entities, the method of transferring personal data (e.g., communication channel), the security measures used during the transfer, and whether—and how—the data is subsequently shared with other entities. Consequently, the description of the context did not allow for a reliable assessment of the conditions under which processing was carried out or for the correct identification of factors increasing or decreasing the level of risk to the rights and freedoms of data subjects.
In turn, the description of the processing purposes is framed as: "Fulfillment of legal obligations imposed on the controller," while simultaneously failing to specify the specific obligations being fulfilled, the provisions under which they arise, and the activities and results to be achieved through the processing of personal data. Such a description not only hinders the assessment of the associated risks but also, for example, links specific processing operations to the principles of data minimization and adequacy, or adapts data protection measures to actual needs and the manner of performing tasks.
Third, the submitted document does not address any specific threats and indicates only one potential impact on the rights and freedoms of natural persons, demonstrating the Center's superficial approach to identifying risks associated with data processing within the discussed process. Furthermore, the analysis does not identify sources of risk or vulnerabilities, particularly those related to work organization, human factors, adopted procedures, IT systems used, or access security measures, which made it impossible to determine how a potential breach of personal data protection could occur.
Fourth, under the "Likelihood" criterion, the Center limited itself to using a single indicator based on the question "When was the last time a breach occurred," accepting the answer "Never," without reference to any objective risk factors. This approach cannot be considered a reliable assessment of the likelihood of a violation of the rights or freedoms of natural persons because it relies solely on historical events, ignoring the possibility of specific threats materializing in the future, which is contrary to the risk-based approach and the principle of data protection by design.
Fifth, the assessment of the severity of the potential impact on the rights or freedoms of natural persons was also not adequately considered in the analysis, and the document does not contain any references to the type of data processed, the categories of data subjects, or the possible material and non-material consequences that could arise in the event of an undesirable event.
Sixth, although the Center formulated a list of recommended actions in its analysis, they are largely general and declarative in nature, not linked to specific threats or vulnerabilities, and therefore do not allow for an assessment of whether—and how—they could contribute to ensuring a higher level of security for processed personal data. Furthermore, these recommendations were not supplemented with information regarding their implementation plan, implementation schedule, responsibility for their implementation, or an assessment of the impact of individual measures on reducing the risk level, which prevents them from being considered an element of a well-considered and systematic selection of technical and organizational data protection measures.
Consequently, the risk analysis conducted by the Center did not constitute a genuine basis for selecting appropriate data protection measures, as referred to in Articles 24, 25, and 32 of Regulation 2016/679, due to the lack of a reliable, complete, and documented link between the processing model, the identification of associated threats, the assessment of the likelihood and severity of the potential impact on data subjects, and the recommended and implemented security measures.
In the opinion of the President of the Personal Data Protection Office, this procedure did not ensure adequate control over the processing. As demonstrated above, the technical and organizational data protection measures used by the Center were not designed in accordance with the risk-based approach that underlies Regulation 2016/679. The Center also failed to review or update them in any way. Ultimately, these measures also proved ineffective, as revealed in this case by the circumstances of the incident (see paragraphs 15-20 of the justification).
It should be emphasized here that the EU legislator does not specify the specific technical and organizational measures that should be implemented by the Center in the circumstances of this case. A risk-based approach means that the controller is responsible for properly specifying the legal obligations, which, in the case of Articles 24, 25, and 32, were based on risk criteria. In this context, the principle of accountability is of particular importance, according to which the controller is obliged not only to ensure compliance with the provisions of Regulation 2016/679, but also to demonstrate the correctness of its actions to the supervisory authority.
The task of the President of the Personal Data Protection Office was not to independently and thoroughly assess the adequacy of the data protection measures applied by the Center, but primarily to verify whether it properly conducted the risk analysis process and, on that basis, selected appropriate technical and organizational measures.[49]
In the present case, the Center failed to fulfill this obligation because it failed to conduct the risk analysis properly, and the solutions it used proved ineffective.
This position has been confirmed in case law. The Supreme Administrative Court, in its judgment of February 9, 2023, file ref. III OSK 3945/21, pointed out that "[u]nder [Regulation 2016/679], the legislator has moved away from a static definition of the technical and organizational measures required of the controller in favor of a dynamic assessment of the security measures adopted. This means that the controller (...) is responsible for determining appropriate (adequate) security measures, while retaining the supervisory authority's authority to verify the adopted level of security. (...) Consequently, the applicable law does not specify a catalog of appropriate security measures, and the controller is responsible for assessing this matter and selecting measures that are adequate, among other things, to the current state of technical knowledge and the scale of the risk of infringement."[50]
At the same time, it should be noted that both potential irregularities on the part of the Center's employees and potential unlawful actions by third parties that may have been the source of the incident do not, in principle, release the Center from liability for omissions in the scope of the obligations described above. This view is confirmed by established case law.
In the aforementioned In its judgment, the Supreme Administrative Court (NSA) stated that "administrative sanctions for breach of the obligations specified in Article 32 [of Regulation 2016/679] are imposed not on the controller who (...) allowed the unauthorized processing of personal data, but only on the entity that failed to maintain an appropriate standard of security measures under the circumstances. An individual is not subject to sanctions for the illegal actions of a third party (e.g., a hacker) involving unauthorized access to the data processed by them, but for allowing such access due to an inadequate level of security applied."[51]
In its judgment of June 12, 2025, file reference III OSK 1394/22, the SAC also stated that "the controller is also liable for the actions of persons and entities dependent on it through which it processes personal data."[52]
Considering the above, it must be concluded that the Center has failed to demonstrate that, when processing the personal data referred to in point 12 of the justification, it has provided appropriate technical and organizational measures designed to effectively implement data protection principles and to provide the necessary safeguards for the processing, including ensuring a level of security appropriate to the risk of varying likelihood and severity of violations of the rights and freedoms of natural persons. This action violated Article 24(1), Article 25(1), and Article 32(1) and (2) of Regulation 2016/679, and consequently, the principle of integrity and confidentiality set forth in Article 5(1)(f), and the principle of accountability set forth in Article 5(2) of that Regulation. 3.4 Notification of a personal data breach to the supervisory authority and communication of a personal data breach to data subjects (Article 33(1) and Article 34(1) of Regulation 2016/679) 3.4.1 Legal Analysis
Article 4(12) of Regulation 2016/679 states that "'personal data breach' means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed."
Pursuant to Article 33(1) of Regulation 2016/679, Article 34(1) of Regulation 2016/679 states that "[i]n the event of a personal data breach, the controller shall notify the breach to the supervisory authority competent pursuant to Article 55 without undue delay, where possible, but no later than 72 hours after becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Any notification submitted to the supervisory authority after 72 hours shall be accompanied by an explanation of the reasons for the delay."
Under Article 34(1) of Regulation 2016/679, "[i]f the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall notify the data subject of the breach without undue delay."
According to Recital 85 of Regulation 2016/679, "[i]f an adequate and timely response is not given, a personal data breach may result in physical, material or non-material harm to natural persons, such as the loss of control over their own personal data or restriction of rights, discrimination, identity theft or fraud, financial loss, unauthorized reversal of pseudonymization, damage to reputation, a breach of the confidentiality of personal data protected by professional secrecy, or any other significant economic or social harm. Therefore, immediately upon becoming aware of a personal data breach, the controller should notify the supervisory authority without undue delay, and where feasible, no later than 72 hours after becoming aware of the breach, unless the controller can demonstrate, in accordance with the accountability principle, that the breach is unlikely to result in a risk to the rights and freedoms of natural persons. If the notification cannot be made within 72 hours, the notification should be accompanied by an explanation of the reasons for the delay, and the information may be provided in a phased manner without further undue delay."
According to Recital 86 of the Regulation, "[t]he controller should inform a data subject without undue delay of a personal data breach where it is likely to result in a high risk to the rights and freedoms of that data subject, in order to enable that data subject to take the necessary preventive measures. This information should include a description of the nature of the personal data breach and recommendations to the individual concerned on how to mitigate the potential adverse effects. Information should be provided to data subjects as soon as reasonably possible, in close cooperation with the supervisory authority, and respecting any guidance provided by that authority or other relevant authorities, such as law enforcement authorities. For example, the need to minimize an imminent risk of harm will require informing data subjects without delay, while the implementation of appropriate measures against the same or similar data breaches may justify delayed notification."
The obligations referred to in Articles 33(1) and 34(1) of Regulation 2016/679 are risk-based. This means that their updating is correlated with the likelihood of a risk (in the case of Article 33(1)) and the likelihood of a high risk (in the case of Article 34(1)) to the rights and freedoms of data subjects. The controller of data affected by a personal data breach should therefore assess the risk that may result from it. This is a prerequisite for properly responding to such an event.[53]
Recital 87 of Regulation 2016/679 states that "[t]he controller should ensure that all appropriate technical protection measures and all appropriate organizational measures are implemented to immediately identify the personal data breach and promptly inform the supervisory authority and the data subject. Whether notification was made without undue delay should be determined taking into account, in particular, the nature and gravity of the personal data breach, its consequences and adverse effects for the data subject. Such notification may result in intervention by the supervisory authority, in accordance with its tasks and powers as set out in this Regulation."
The EDPB emphasizes that "the ability to prevent breaches where possible and to promptly respond to breaches in situations where they nevertheless occur is a key element of any data security policy."[54] An appropriate response to personal data breaches is essential for the effective protection of data subjects from the negative consequences of processing.[55]
Furthermore, as the EDPB points out, "[w]here controllers fail to comply with their obligation to notify a data breach to the supervisory authority or to data subjects, or to both the supervisory authority and data subjects, despite having met the requirements set out in Article 33 or 34 [of Regulation 2016/679], the supervisory authority may exercise the option of considering all corrective measures at its disposal, which would entail the possibility of imposing an administrative fine (...)"[56]. 3.4.2 Analysis of the Facts
In assessing the possibility that the Center violated the obligations set out in Article 33 paragraph 1 and Article 34 paragraph 1 of Regulation 2016/679 through omission, the President of the Personal Data Protection Office (UODO) examined during the proceedings whether the incident described in paragraphs 15–20 of the justification constituted a personal data breach within the meaning of Article 4 paragraph 12 of Regulation 2016/679 and, if so, whether the event could have caused a risk or a high risk to the rights and freedoms of natural persons.
First, it should be noted that an incident consisting of the unintentional (accidental or unlawful) placement of a file containing personal data on the private server of an employee of the controller, as a result of which such data became potentially accessible to an unlimited number of unauthorized recipients, meets the criteria set out in the definition of a "personal data breach" set out in Article 4 paragraph 12 of Regulation 2016/679. This event was a "security breach," i.e., a security incident[57] leading to the unauthorized disclosure of personal data processed by the Center.
At the same time, the lack of identification of the perpetrator (i.e., the person who placed the personal data file on the coordinator's private server) is irrelevant to the recognition of the aforementioned incident as a personal data breach. According to the President of the Personal Data Protection Office, none of the versions of events presented during the proceedings were convincingly substantiated (see, for example, point 20 of the justification), but this fact does not affect the Center's responsibility for fulfilling the obligations related to the personal data breach.
Furthermore, according to the President of the Personal Data Protection Office, the probability that the incident would result in a risk of infringement of the rights or freedoms of natural persons was higher than low, and therefore there was no basis for a possible waiver of the obligation to immediately report a personal data breach to the supervisory authority[58].
The EDPB indicates that when assessing the risk resulting from a personal data breach, account should be taken, in particular, of the type, nature, sensitivity, and amount of personal data, the ease of identifying individuals, the severity of the consequences for individuals, the characteristics of individuals, the characteristics of the controller, and the number of individuals affected by the breach.[59]
In analyzing the above factors, the President of the Personal Data Protection Office (UODO) considered that the incident constituted a breach of confidentiality of information that allowed the identification of at least (...) specific individuals, as well as revealing their exact location, telephone numbers, and the fact that they were in mandatory quarantine or isolation in connection with the prevention and control of infection with the SARS-CoV-2 virus. This means that health data[60] – classified by the EU legislator as one of the so-called special categories of data referred to in Article 9(1) of Regulation 2016/679 – were also disclosed. These data allowed the identification of individuals diagnosed with SARS-CoV-2 infection (individuals in isolation) and individuals with a reasonable suspicion of such infection (individuals in quarantine).
As the CJEU pointed out, the processing of special categories of data requires a higher level of protection due to the risk of a serious interference with the fundamental rights to respect for private life and the protection of personal data, guaranteed by Articles 7 and 8 of the Charter of Fundamental Rights of the European Union[61].
The circumstances of disclosing health data of such a specific nature are also of particular importance in this context. Breaching the confidentiality of information about SARS-CoV-2 infection in the case of specific, identifiable individuals, combined with additional information, for example, about their location, could have led to a significantly increased risk of violation of their rights and freedoms.
The President of the Personal Data Protection Office also took into account that the aforementioned The personal data was included in a file hosted on the coordinator's private server, and then—due to the indexing mechanism performed by Company C—was included in search engine results, which in turn resulted in their public exposure. It is worth emphasizing that the risk associated, for example, with limiting individuals' autonomy in controlling their own personal data actually materialized, as evidenced by the data being acquired by a third party (see point 17 of the justification).
In these circumstances, the President of the Personal Data Protection Office (UODO) assessed that the incident could have posed a high risk of violating the rights and freedoms of natural persons. This position was influenced in particular by the type of personal data breach that occurred, in conjunction with the nature, sensitivity, and scope of the personal data involved in the incident (i.e., in particular, the breach of confidentiality of health data, combined with identification and contact data), the ability to easily identify the data subjects, the large number and specific nature of these individuals—most of whom were ill or at risk of illness at the time of the incident—as well as the significant gravity of the potential consequences these individuals could face as a result of the incident. The Center's failure to detect the incident early enough to prevent further dissemination of the aforementioned personal data and third parties from accessing it was also significant.[63]
It should be emphasized that when assessing the existence of the obligations under Article 33(1) and Article 34(1) of Regulation 2016/679, it is irrelevant whether negative consequences for data subjects have actually materialized. The Supreme Administrative Court confirmed this, pointing out that "[i]t is not necessary for a high risk to materialize and for an actual violation of rights or freedoms to occur. Therefore, it is irrelevant whether or not they ultimately are violated. The mere occurrence of a high risk of violation is sufficient. When assessing whether a risk of violation exists, the controller should consider all possible damages and harms that may result from a given event for individuals. These may include, in particular, loss of control over one's own personal data, negative image consequences, the possibility of another person entering into contracts using another individual's personal data, financial losses, or, finally, negative public perception that may result from the publication of certain personal data. For a risk to exist, it is not necessary for damage or harm to ultimately occur as a result of a given personal data breach"[64].
In this situation, the President of the Personal Data Protection Office was not responsible for verifying the actual violation of the rights or freedoms of data subjects, but only for an objective assessment of the likelihood of such a risk occurring and its scale.[65]
In view of the above, in the opinion of the President of the Personal Data Protection Office (UODO), the incident described in points 15–20 of the explanatory memorandum constituted a personal data breach within the meaning of Article 4(12) of Regulation 2016/679, giving rise to the obligation to notify the supervisory authority pursuant to Article 33(1) of Regulation 2016/679 and to notify data subjects pursuant to Article 34(1) of Regulation 2016/679.
At the same time, since the Center considered that it did not act as a controller in relation to the personal data covered by the incident, it should be considered that it did not, in fact, "determine" the aforementioned personal data breach within the meaning of Article 33(1) of Regulation 2016/679 after receiving the first information about the incident, and refrained from conducting a detailed analysis (see point 19 of the explanatory memorandum). During the investigation, among others, In connection with the exchange of correspondence regarding the incident between the Center and the President of the Personal Data Protection Office (including presenting the Center with the findings of the President of the Personal Data Protection Office), the Center had the opportunity – and at the same time the obligation – to verify its position and determine a personal data breach. The EDPB indicates that "(...) the controller should be deemed to have established the occurrence of a breach at the time when it obtained sufficient certainty that a security incident had occurred that led to the compromise of personal data"[66]. However, even under the assumption most favorable to the Center – i.e. assuming that, despite being informed of the event, it could not immediately qualify it as a personal data breach – the latest moment at which the Center should have established such a breach was the receipt of the letter from the President of the Personal Data Protection Office dated 1 July 2021, in which the supervisory authority presented the Center with its findings regarding the incident. From that moment on – regardless of the Center's assessment of its previous doubts regarding its status – it had sufficient knowledge to unequivocally establish a personal data breach and was obliged to submit the notification referred to in Article Article 33(1) of Regulation 2016/679, without undue delay – no later than 72 hours.
According to the President of the Personal Data Protection Office, the erroneous assumption by the Personal Data Protection Office that it is not a controller, in a situation in which it actually played such a role in relation to the above-mentioned personal data (see paragraphs 25–49 of the explanatory memorandum), cannot relieve it of its responsibility for fulfilling its obligations under Article 33(1) and Article 34(1) of Regulation 2016/679. According to recital 87 of that regulation, "[t]he controller should be ensured that all appropriate technical protection measures and all appropriate organizational measures are in place to immediately identify a personal data breach and promptly inform the supervisory authority and the data subject." The EDPB further states that "the controller has a clear obligation to act on any alerts received at an early stage and to determine whether a breach has actually occurred in a given case"[67]. The fundamental condition for determining personal data breaches is the awareness of the fact that the controller is acting as such.
Due to the fact that the Center failed to fulfill the aforementioned obligations by the date of the decision, the order formulated in point III.2 of the operative part remains fully justified in light of the above findings, as well as Article 34(4) of Regulation 2016/679, which states that "[w]here the controller has not yet communicated the personal data breach to the data subject, the supervisory authority, taking into account the likelihood that the personal data breach will result in a high risk, may require the controller to do so (…)" and Article 58(2)(e) of that regulation, under which the supervisory authority has the remedial power to order the controller to communicate the personal data breach to the data subject.
It should also be emphasized that in formulating the order referred to in point III.2 of the operative part of the judgment, the President of the Personal Data Protection Office did not take into account the time that had elapsed since the personal data breach occurred and the potential risk to the rights and freedoms of data subjects, agreeing with the Supreme Administrative Court's position that "[i]t is not permissible to apply directives of functional interpretation to the provisions of Article 33 paragraph 1 and Article 34 paragraph 1 [of Regulation 2016/679], i.e., the provisions specifying the obligations of controllers in the scope in which they act as guarantors of the rights and freedoms of natural persons. The application of directives of functions leading to a limitation of the application of such provisions would lead to a limitation of the protection of civil rights and freedoms, which can only occur on the basis of the provisions of the Act (Article 30 paragraph 3 of the Constitution of the Republic of Poland) interpreted using linguistic directives."[68] 3.5 Summary
In summary, the President of the Personal Data Protection Office (UODO) believes that the findings presented above provide sufficient grounds to conclude that the Center processed the personal data of at least (...) residents of D., including first names, last names, telephone numbers, residence addresses, and information on the sanitary situation, i.e., mandatory quarantine or home isolation in connection with the prevention and control of SARS-CoV-2 infection and the spread of the COVID-19 disease caused by it, in order to provide these individuals with support, in the absence of appropriate technical and organizational measures designed to effectively implement data protection principles and to provide the necessary safeguards for the processing, including ensuring a level of security appropriate to the risk of infringement of the rights and freedoms of natural persons of varying likelihood and severity.
Furthermore, the Center failed to comply with its obligation to notify the supervisory authority without undue delay of a personal data breach and to notify data subjects without undue delay of a personal data breach, despite the fact that it could have resulted in a high risk of infringement of the rights and freedoms of these individuals.
In light of the above, the President of the Personal Data Protection Office found that the Center had violated the provisions of Regulation 2016/679, i.e., Article 24 paragraph 1, Article 25 paragraph 1, and Article 32 paragraphs 1 and 2 of Regulation 2016/679, consequently violating Article 5 paragraph 1 letter f) and paragraph 2 of Regulation 2016/679, as well as Article 33 paragraph 1 and Article 34 paragraph 1 of Regulation 2016/679. 4 Administrative Fines 4.1 Legal Basis
The administrative proceedings conducted by the President of the Personal Data Protection Office are aimed at verifying the compliance of data processing with personal data protection regulations and are aimed at issuing an administrative decision to exercise the remedial powers specified in Article 58 paragraph 2 of Regulation 2016/679.
Considering the above, as well as the violations of personal data protection provisions identified in these proceedings, the President of the Personal Data Protection Office – exercising the authority specified in Article 58 paragraph 2 letter i) of Regulation 2016/679, pursuant to which each supervisory authority has the power to impose, in addition to or instead of the measures referred to in Article 58 paragraph 2 letters a) to h) and letter j) of that Regulation, an administrative fine under Article 83 of Regulation 2016/679 – found that in the case at hand, the conditions for the imposition of administrative fines on the Centre under Article 83 paragraph 4 letter a) and Article 83 paragraph 5 letter a) of Regulation 2016/679 had materialized.
Pursuant to Article 83 paragraph 4 letter b) of Regulation 2016/679, Article 13(1)(a) of Regulation 2016/679, infringements of the provisions relating to the obligations of the controller and the processor referred to in Articles 8, 11, 25 to 39 and 42 and 43 shall be subject to administrative fines of up to EUR 10 000 000 in accordance with paragraph 2, or in the case of an undertaking, of up to 2% of its total annual worldwide turnover in the preceding financial year, whichever is higher.
In accordance with Article 83(5)(a) of Regulation 2016/679, infringements of the provisions concerning the basic principles of processing, including the conditions for consent, referred to in Articles 5, 6, 7, and 9, are subject to an administrative fine of up to EUR 20,000,000, or in the case of an enterprise – up to 4% of its total annual global turnover from the previous financial year, whichever is higher.
Article 102(1)(1) of the Personal Data Protection Act provides that the President of the Personal Data Protection Act may impose, by decision, administrative fines of up to PLN 100,000 on public finance sector entities referred to in Article 9(1)-(12) and (14) of the Act of 27 August 2009 on Public Finances[69]. This limit will undoubtedly apply in this case to the Centre, as a budgetary entity. The President of the Office imposes the administrative fines referred to in paragraphs 1 and 2 on the basis of and under the conditions specified in Article 83 of Regulation 2016/679 (Article 102 paragraph 3 of the Personal Data Protection Act).
It should also be noted that, pursuant to Article 83 paragraph 1 of Regulation 2016/679, each supervisory authority shall ensure that the administrative fines imposed under this Article for infringements of the Regulation referred to in paragraphs 4, 5, and 6 are effective, proportionate, and dissuasive in each individual case.
Pursuant to Article 83 paragraph 2 of Regulation 2016/679, administrative fines shall be imposed, depending on the circumstances of each individual case, in addition to or instead of the measures referred to in Article 58 paragraph 2 (a)–(h) and (j). When deciding whether to impose an administrative fine and determining its amount, due regard shall be given in each individual case to: a) the nature, gravity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing in question, the number of data subjects affected, and the extent of the damage suffered by them; b) the intentional or unintentional nature of the infringement; c) the actions taken by the controller or processor to mitigate the damage to data subjects; d) the degree of responsibility of the controller or processor, taking into account the technical and organizational measures implemented by them pursuant to Articles 25 and 32; e) any relevant previous infringements by the controller or processor; f) the degree of cooperation with the supervisory authority to remedy the infringement and mitigate its possible adverse effects; g) the categories of personal data concerned by the infringement; h) how the supervisory authority became aware of the breach, in particular whether and to what extent the controller or processor has notified the breach; i) where measures referred to in Article 58(2) have previously been applied to the controller or processor concerned in respect of the same matter, compliance with those measures; j) application of approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42; and k) any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial benefits gained directly or indirectly from the breach or losses avoided. 4.2 Conduct subject to administrative fines and application of Article 83(3) of Regulation 2016/679
According to the wording of Article 83(3), Pursuant to Article 3 of Regulation 2016/679, if a controller or processor intentionally or negligently, within the same or related processing operations, infringes several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount of the fine for the most serious infringement.
Having found that the Center, in the circumstances under review, has infringed multiple provisions of Regulation 2016/679 (i.e., Article 5(1)(f) and (2), Article 24(1), Article 25(1), Article 32(1) and (2), Article 33(1), and Article 34(1) of Regulation 2016/679), the President of the Personal Data Protection Office was obliged to take into account the regulation cited in the preceding paragraph in order to consider whether the circumstances of this case determine the exercise by the supervisory authority of only one or several corrective measures provided for in Article 58(1) of Regulation 2016/679. 2 of Regulation 2016/679 – or more precisely, whether the authority should impose only one administrative fine on the controller, constituting a response to all infringements committed by that entity, or separate and independent fines for each of these infringements considered separately. For this purpose, the President of the UODO used the methodology for calculating administrative fines adopted in Guidelines 04/2022[70], according to which the first step for further calculations is "assessment of the application of Article 83 paragraph 3 [of Regulation 2016/679]" (see point 17 of Guidelines 04/2022). Pursuant to Guidelines 04/2022, the President of the Personal Data Protection Office (UODO) analyzed the following issues (see point 24 of Guidelines 04/2022): a) whether the circumstances indicate a single conduct or multiple conducts subject to penalty, b) in the case of a single conduct, whether this conduct constitutes a single infringement or multiple infringements, c) in the case of a single conduct that constitutes multiple infringements, whether the attribution of one infringement precludes the attribution of another infringement, or whether they should be attributed in parallel.
Interpretation of the concept of "single conduct," in reference to Article 83, paragraph 1, of the Personal Data Protection Regulation. Article 3 of Regulation 2016/679, which refers to "the same or related processing operations," is presented in paragraph 28 of Guidelines 04/2022, which states that "[t]he term 'related' refers to the principle that a single act of conduct may consist of several parts that are carried out by a single act of will and are contextually (in particular as regards the identity of the data subject, the purpose and nature of the processing), spatially and temporally so closely linked that, from an objective point of view, they can be considered to constitute a single, coherent act."
The term "processing operations" referred to in Article 83(3) of Regulation 2016/679 is explained in Article 83(3) of Regulation 2016/679. Article 4(2) of the Regulation defines "processing" as "an operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction." Therefore, a processing operation will constitute any action to which data are subjected until they are deleted, lost, or destroyed.
In accordance with Guidelines 04/2022, the supervisory authority analyzed the factual circumstances of this case, which allowed the identification of three separate and independent acts on the part of the Center, leading to infringements of various provisions of Regulation 2016/679.
The first conduct of the Centre identified in this case was the failure to implement appropriate technical and organizational measures to ensure the security of personal data processing, leading to the materialization of the infringements attributed to it of Article 24(1), Article 25(1), and Article 32(1) and (2), and consequently also of Article 5(1)(f) and Article 5(2) of Regulation 2016/679. While this conduct consisted of several elements (see point 28 of Guidelines 04/2022), as indicated in points 74-85 of the explanatory memorandum, the controller first improperly prepared a risk analysis and then failed to regularly test, measure, and assess the effectiveness of the technical and organizational measures in place, all of these elements constitute "one coherent conduct" within the meaning presented by the EDPB in Guidelines 04/2022. The identity of the conduct leading to the infringements is demonstrated by the fact that "multiple infringements arose from 'the same or related processing operations'" (see point 39 of Guidelines 04/2022). The close connection between the processing operations that constituted an infringement of Article 24(1), Article 25(1), and Article 32(1) and (2), and consequently also Article 5(1)(f) and Article 5(2) of Regulation 2016/679, is confirmed by the identity of: – data subjects – the infringements in question occurred as part of the processing of personal data of residents of D. subject to isolation or quarantine; – data scope – the processing activities were performed on data provided by the District Station; – and the purpose of the processing – it was carried out for the purpose of providing support to data subjects in connection with the restrictions resulting from isolation or quarantine.
It should be noted here that the conduct identified above is distinct from the two subsequent conducts, which consisted of failing to report a data protection breach to the supervisory authority (which constituted a violation of Article33 sec. 1 of Regulation 2016/679), as well as the failure to notify data subjects of a personal data breach (constituting an infringement of Art. 34 sec. 1 of Regulation 2016/679), is demonstrated primarily by the difference in objectives pursued by the legislator in imposing each of these obligations on controllers. In the case of the controller's obligation to implement appropriate technical and organizational measures, this objective was to ensure the security of data processing and to minimize the risk of a personal data breach. In the case of the obligation to notify a data breach to the supervisory authority, the legislator aimed to ensure the exercise of the supervisory authority's competences and control powers. By introducing the obligation to notify data subjects of a breach, the legislator was guided by the need to provide data subjects with relevant information about the event and recommended precautionary measures. The distinction between the controller's first conduct, described in point 136 of the explanatory memorandum, and the two subsequent conducts resulting in an infringement of Art. 33 sec. 1 and Art. 34 sec. Article 1 of Regulation 2016/679 also confirms the temporal context of the breaches. A breach consisting in the failure to implement appropriate technical and organizational measures to ensure the security of personal data processing is prior to a data protection incident, which may result from omissions on the part of the controller. Breaches consisting in failing to notify a data protection breach to the supervisory authority and failing to communicate the breach to data subjects are, on the other hand, subsequent to a data protection incident – these obligations only become effective after it has been determined that the incident may entail an appropriate level of risk to the rights and freedoms of natural persons. A significant difference between the conduct described in paragraph 136 of the explanatory memorandum and the two subsequent conducts of the controller (resulting in a breach of Article 33(1) and Article 34(1) of Regulation 2016/679) is also the fact that it occurred as part of the processing operations carried out by the Data Protection Centre, while the other two breaches are "detached" from the operations in connection with which the personal data breach was identified (see paragraph 142 of the explanatory memorandum).
Taking into account the arguments presented above, it should be assumed that the Centre's infringement of the provisions of Article 24(1), Article 25(1), and Article 32(1 and 2), and consequently also of Article 5(1)(f) and Article 5(2) of Regulation 2016/679, was caused by "a single, consistent act" within the meaning presented by the EDPB in Guidelines 04/2022. It should also be emphasized that none of these infringements excludes the possibility of attributing another infringement to the Centre. In particular, the finding of an infringement of the provisions defining the basic, general principles of processing referred to in Article 5 of Regulation 2016/679 does not exclude the possibility of attributing to the controller (and imposing a financial penalty for it) an infringement of the specific provisions concretizing these principles, i.e. Article 24(1), Article 25(1), and Article 32(1). 1 and 2 of Regulation 2016/679. However, an administrative fine is not imposed for a breach of the obligation specified in Article 24 paragraph 1, as it is not listed in Article 83 paragraphs 4-6 of Regulation 2016/679. The President of the Personal Data Protection Office (UODO) has therefore determined that, in the case of the first identified conduct, the Center's liability should be calculated cumulatively in relation to all infringements of the above-mentioned provisions of Regulation 2016/679, i.e., applying the provision of Article 83 paragraph 3 of that legal act.
Consequently, it is necessary to determine which infringement is the "most serious" within the meaning of Article 83 paragraph 3 of Regulation 2016/679. Guidance on identifying the "most serious infringement" is included in Guidelines 04/2022. According to the position expressed therein, "the phrase 'amount of the penalty for the most serious infringement' refers to the statutory maximum amounts of fines" specified in Article 83 paragraphs 4-6 of Regulation 2016/679 (see point 43 of Guidelines 04/2022). Therefore, the most serious infringement in an individual case will be the one for which the EU legislator has provided a higher threshold for the maximum threat of an administrative fine.
The Centre's alleged violations of Article 25 paragraph 1 and Article 32 paragraphs 1 and 2 of Regulation 2016/679 are typified in Article 83 paragraph 4(a) of Regulation 2016/679, while the violations of Article 5 paragraph 1(f) and Article 5 paragraph 2 of Regulation 2016/679 are typified in Article 83 paragraph 4(b) of Regulation 2016/679. 5(a) of this Regulation. The administrative fine imposed jointly for a violation of all of the above provisions – pursuant to Article 83(3) of Regulation 2016/679 – cannot exceed the amount of the fine for the most serious of them. However, bearing in mind the limit of fines specified in Article 102(1)(1) of the Personal Data Protection Act, it should be noted that the administrative fine imposed on the Center cannot exceed PLN 100,000.
As indicated in paragraph 137 of the justification, the Center's two further acts of conduct, identifiable in the circumstances of the present case, were: – failing to report the data protection breach to the supervisory authority (which constituted a violation of Article 33(1) of Regulation 2016/679); – failing to notify data subjects of a personal data breach (constituting an infringement of Article 34(1) of Regulation 2016/679).
In light of the interpretation of the concept of a single act of conduct referred to in paragraph 133 of the explanatory memorandum, it should be stated that it cannot be assumed that the infringements of Article 33(1) and Article 34(1) of Regulation 2016/679 were the result of a single act of conduct by the Centre. It should be noted, first of all, that these acts do not constitute "the same or related processing operations" referred to in Article 83(3) of Regulation 2016/679. The conduct in question constitutes an omission to comply with the controller's obligations imposed on it by Regulation 2016/679, which are no longer related to any specific processing operations – they are "detached" from the operations in connection with which the personal data breach was identified. This means that, in their essence, these conducts (and the obligations, the non-compliance with which leads to a breach of both provisions in question) do not concern any processing operations (neither the same, nor related, nor independent of each other). Using the terminology of Article 83(3) of Regulation 2016/679, it should be stated that these conducts do not occur (which follows from the nature of infringements of the provisions of Articles 33 and 34 of Regulation 2016/679) "as part of the same or related processing operations."
In the opinion of the President of the Personal Data Protection Office, the impossibility of assuming that an infringement of Article 33(1) and an infringement of Article 34(1) of Regulation 2016/679 constitute "a single conduct" is clearly demonstrated by the fact that these provisions pursue completely different purposes. As indicated in Guidelines 04/2022 (see point 34 of Guidelines 04/2022), "where two provisions pursue autonomous objectives, this constitutes a differentiating factor that justifies the imposition of separate fines." Applying the above to the present case, it should be emphasized that the notification of a personal data breach is intended to provide the supervisory authority with the necessary information about the incident, which allows the authority to respond appropriately to the breach, e.g., assess whether the controller has taken appropriate action, and thus, in cooperation with the supervisory authority, minimize the consequences of the breach.[71] This means that, using the mechanism set out in Article 33(1) of Regulation 2016/679, the controller can limit the potential damage to the individuals affected by the breach, and the supervisory authority can monitor whether the controller is properly fulfilling its obligations. The purpose of notifying data subjects of a breach is to provide them with relevant information about the incident and recommended precautionary measures, which may limit the potential damage caused by the breach.[72] The implementation of this obligation is intended to ensure that individuals affected by a breach are aware of its effects and have the ability to take appropriate action to prevent the materialization or further development of the consequences of the breach. In conclusion, Article 34(1) of Regulation 2016/679 directly protects the rights and actual interests of data subjects, allowing them to prevent the negative effects of a breach of their personal data protection, while Article 33(1) of Regulation 2016/679 ensures or facilitates the exercise of the supervisory authority's powers and oversight powers in the form of monitoring whether the controller is properly fulfilling its personal data protection obligations.
The distinctiveness of conduct resulting in violations of Article 33(1) and Article 34(1) of Regulation 2016/679 is also evidenced by the different categories of entities towards which the controller's actions should be directed – in the case of the obligation referred to in Article 33(1), In the case of the obligation under Article 34(1) of Regulation 2016/679, this is the supervisory authority, and in the case of the obligation under Article 34(1) of the aforementioned legal act, it is the data subjects. Furthermore, the controller bears the burden of making two separate decisions regarding the implementation of each of these obligations – it is possible that, in the event of an incident likely to result in a high risk to the rights and freedoms of natural persons, the controller fails to comply with both obligations and thus violates Article 33(1) and Article 34(1) of Regulation 2016/679 (as is the case in the present case), as well as, for example, a situation in which the controller decides to notify the supervisory authority and decides not to notify data subjects of the breach, and then only violates Article 34(1) of Regulation 2016/679. Therefore, fulfilling one of the above obligations does not constitute fulfillment of the other, as these are two separate decisions (acts of will) of the controller.
The interpretation of the concept of "single conduct" presented in point 28 of Guidelines 04/2022 also emphasizes the assessment of the spatial and temporal context of the conduct. The obligation set out in Article 33(1) of Regulation 2016/679 should be fulfilled without undue delay, if possible, but no later than 72 hours after the infringement is discovered. In the case of Article 34(1), this deadline is also defined as "without undue delay," but it is not limited to 72 hours from the moment the infringement is discovered. In Guidelines 9/2022, the term "without undue delay" is defined as "(…) as soon as possible" (see point 83 of Guidelines 9/2022). However, it does not mean an immediate deadline.[73] Pursuant to recital 87 of Regulation 2016/679, in the case of Article 34(1), Under Article 34(1) of Regulation 2016/679, this time limit is determined taking into account, in particular, the nature and gravity of the personal data breach, its consequences, and the adverse effects on data subjects. This means that the controller should comply with the obligation provided for in Article 34(1) of Regulation 2016/679 as soon as possible, but taking into account the individual characteristics of a specific personal data breach. Therefore, the time limit for compliance with the obligations in question may be the same, but does not have to be, as it depends on the individual characteristics of the specific case and whether a breach has occurred that is likely to result in a high risk to the rights and freedoms of natural persons.
Therefore, taking into account the arguments presented in paragraphs 142-145 of the explanatory memorandum, it must be concluded that two different conducts of the Centre led to the infringement of Article 33(1) and Article 34(1) of Regulation 2016/679. Since these are distinct conducts of the controller that do not concern "the same or related processing operations," the provision of Article 83(1) of Regulation 2016/679 applies. Article 3 of Regulation 2016/679 will not apply to their confluence in a single administrative decision.
In summary, the analysis of the evidence gathered in the case led to the finding that the infringements attributed to the Centre are the consequence of three separate acts. This is a situation to which the so-called "multiple acts principle" applies (see paragraphs 44 and 45 of Guidelines 04/2022): "(...) the reason why these infringements may be considered in a single decision is that they coincidentally came to the attention of the supervisory authority at the same time, and they did not constitute the same or related processing operations within the meaning of Article 83(3) [of Regulation 2016/679]." The consequence of this is that "[i]n the decision imposing a penalty, the authority will impose individual fines for each of them, provided that a single legally defined maximum fine will not apply to their total" (see Example 3 to point 45 of Guidelines 04/2022). As a result, the supervisory authority will impose three separate fines on the controller for the identified violations. However, due to the limit of PLN 100,000 set out in Article 102(1)(1) of the Personal Data Protection Act for fines imposed on budgetary entities (which is the Center), none of the fines imposed on the controller in these proceedings may exceed this statutory limit. 4.3 Justification for the imposition and determination of the amount of the administrative fine for the violation of Article 5(1)(f) and (2), Article 25(1), and Article 32(1) Articles 1 and 2 of Regulation 2016/679 4.3.1 Conditions for imposing an administrative fine
In deciding to impose an administrative fine on the Center for violating Article 5 paragraph 1 letter f) and paragraph 2, Article 25 paragraph 1, and Article 32 paragraphs 1 and 2 of Regulation 2016/679, the President of the Personal Data Protection Office – pursuant to Article 83 paragraph 2 letters a)–k) of Regulation 2016/679 – took into account the following circumstances that constituted the necessity of applying this type of sanction in this case and had an aggravating effect on the amount of the imposed administrative fine. The nature, gravity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing in question, the number of data subjects affected, and the extent of the damage they suffered (Article 83(2)(a) of Regulation 2016/679)
When analyzing the requirement of Article 83(2)(a) of Regulation 2016/679, it should be noted that the Center's omissions led to a violation of the fundamental principles of personal data processing, which are fundamental and define the framework of the entire data protection system. The doctrine indicates that "[g]eneral principles of data processing play a special role among the legal norms concerning data protection. These principles are not merely ideas, values, or postulates derived from the entirety of personal data protection regulations, but are normative in nature – they are binding legal norms, defining a specific course of action. (...) They are of particular importance for the application and interpretation of personal data protection regulations. The fact that certain legal norms are recognized as principles in a normative act indicates that the legislator intended to emphasize their importance and make them norms of a kind that prevail over other norms set forth in these regulations."[74]
The importance of the principles concerning personal data processing, including the principles of confidentiality and accountability, is confirmed by the fact that the legislator has provided for a higher maximum administrative fine for their violation, i.e., a fine of up to €20,000,000, or in the case of an enterprise – up to 4% of its total annual global turnover from the previous financial year. While the indicated maximum threshold for the administrative fine will not apply in the present case due to the limitation provided for in Article 102(1)(1) of the Personal Data Protection Act, when assessing the nature and gravity of the infringement attributed to the Centre, it is impossible to ignore the fact that in the event of a breach of data processing principles, the EU legislator, in abstracto, provided for a higher threshold for the fine that may be imposed. Therefore, it should be taken into account that "by establishing two different maximum amounts of the administrative fine (EUR 10/20 million), the Regulation indicates that the infringement of certain provisions of the Regulation may be more serious than the infringement of other provisions."[75]
In analyzing the requirement of Article 83(2)(a) of Regulation 2016/679, the President of the Personal Data Protection Act took into account that the processing operations that constituted the infringement of the provisions of Regulation 2016/679 were performed, among others, on health data, which constitute one of the so-called Special categories of data referred to in Article 9(1) of Regulation 2016/679. In the supervisory authority's opinion, however, the assessment of the degree of data sensitivity in this specific case should additionally take into account the fact that during the COVID-19 pandemic, the flow of health information regarding the disease was widespread and massive. This fact therefore influenced the perception of this type of data and the actual level of intrusion into the privacy of the individuals concerned. Consequently, although these data certainly had the status of special category data, their degree of sensitivity – assessed through the prism of a real risk of violation of the rights and freedoms of natural persons – was relatively lower than in the case of health information of a more individual, intimate, or stigmatizing nature, a fact taken into account by the supervisory authority in the penalty imposed on the controller.
In the opinion of the President of the Personal Data Protection Office (UODO), the purpose for which the personal data were processed is also significant in this case – it was to provide support to individuals subject to mandatory quarantine or isolation at home in connection with the prevention and control of SARS-CoV-2 infection. Therefore, the processing was not carried out for commercial purposes, with the aim of achieving financial gain or pursuing the controller's economic interest. It also did not serve the purpose of implementing the controller's authoritative actions directed at personal data subjects, i.e., actions aimed at enforcing the law – through administrative coercion – against these individuals. This processing served the purpose of providing assistance to protect public health and was carried out in the interest of the individuals whose data were subject to such processing. This purpose of processing, which is of a socially and individually significant nature, was taken into account by the supervisory authority as a mitigating circumstance when imposing the penalty on the Center.
In assessing the analyzed premise, the supervisory authority also considered the specific temporal context in which the infringement in question occurred. The breach occurred during the COVID-19 pandemic, a period characterized by an extraordinary dynamic of legislative changes and a high level of regulatory uncertainty. During this time, due to the intensification of normative changes, numerous, often urgent, obligations were imposed on controllers to counteract the spread of the virus, necessitating the immediate implementation of new processing processes or modifying existing ones. In determining the penalty, the supervisory authority therefore considered that, due to time pressure and the need to ensure the continuity of the assigned tasks, the Center had a significantly limited ability to comprehensively analyze all aspects of the compliance of the processing process with legal requirements. These circumstances support the conclusion that the identified breach did not result from the controller's disregard for its obligations regarding data processing compliance with the law, but was the result of operating under pressure and an exceptionally volatile legal environment.
The President of the Personal Data Protection Office also took into account the fact that the identified violation concerned only a specific data processing process carried out by the Center, i.e., the processing of data of individuals subjected to mandatory quarantine or isolation for the purpose of providing them with emergency assistance. Therefore, the violation was not "systemic" in nature across the entire scope of the Center's operations and did not impact other data processing processes carried out by the Center. The limited and incidental nature of the violation significantly influenced the amount of the fine imposed.
The President of the Personal Data Protection Office (UODO) considered as an aggravating circumstance the fact that the incident, which resulted from the controller's negligence, led to a breach of the confidentiality of a wide range of data (including, as already indicated above, health data) concerning at least (...) residents of D. The President of the UODO also took into account that, as a result of placing a file containing personal data on the controller's employee's private server and then – as a result of the indexing mechanism performed by company C – including it in search engine results, this data became potentially accessible to an unlimited number of unauthorized recipients. This file could potentially have been accessed by all internet users, which further increases the seriousness of the breach in question.
While no evidence emerged during the proceedings indicating that the entities whose data could have been accessed by third parties suffered material damage, the mere potential breach of the confidentiality of their personal data constitutes non-material damage (harm) for them, for example, through the infringement of their personal rights, such as their mental well-being or the right to privacy. Individuals whose data has potentially been obtained unauthorized as a result of a personal data breach may fear loss of control over their personal data or identity theft and related fraud to their detriment. However, as the CJEU pointed out, "the fear of the possible misuse of personal data by third parties, which a data subject has as a result of an infringement of this regulation, may in itself constitute 'non-material damage'"[76] within the meaning of Article 82(1) of Regulation 2016/679. It is particularly important to emphasize that in the present case, the risk related, for example, to the limitation of individuals' autonomy in controlling their own personal data actually materialized, as evidenced by the acquisition of such data by a third party (see paragraph 17 of the explanatory memorandum).
The Centre's detriment also includes the long duration of the infringement. The center acted as a controller in relation to the personal data referred to in point 12 of the justification (including personal data covered by the incident) at least from the moment they were obtained from the District Station or from other sources and at least until 28 March 2022, i.e. the date of abolition of the general obligation to quarantine and home isolation pursuant to the Regulation of the Council of Ministers of 25 March 2022. Until that date, there was a legal basis for social welfare centers to carry out tasks related to providing assistance to persons subject to quarantine or isolation, which in an objective and systemic manner involved the processing of data relating to these persons (see point 49 of the justification). For the purposes of the proceedings in question, the President of the Personal Data Protection Office assumed that this period began no later than October 19, 2020 (i.e., on the date the coordinator, as his employee, was authorized to perform the tasks within the processing in question) and ended no earlier than March 28, 2022. The infringement therefore persisted for over 17 months, which should be considered an aggravating factor, significantly affecting both the authority's decision to impose an administrative fine and its amount. Unintentional nature of the infringement (Article 83 paragraph 2 letter b) of Regulation 2016/679)
Analyzing the ground of Article 83 paragraph 2 letter b) of Regulation 2016/679, b) of Regulation 2016/679, the President of the Personal Data Protection Office took into account the position expressed by the EDPB, according to which intention "involves both knowledge and deliberate action, in connection with the characteristics of a prohibited act" (see point 55 of Guidelines 04/2022).
Applying the above to the present case, it should be noted that the Center, while processing, among other things, personal data to which the provisions of Regulation 2016/679 grant a special level of protection, was aware that it should guarantee an appropriate level of security of processing, i.e., among other things, ensuring compliance with the principle of confidentiality set out in Article 5(1)(f) of Regulation 2016/679. The documents submitted by the Center in these proceedings, in particular the document titled "Assessment (...)" (see point 21 of the justification), although clearly failing to meet the requirements of Regulation 2016/679, undoubtedly indicate that the controller was aware of its obligation to take measures to ensure the security of the processed data. Therefore, it should be assumed that the controller possessed the necessary "knowledge" to attribute responsibility for the infringements committed.
At the same time, however, in the opinion of the President of the Personal Data Protection Office, there is no basis for attributing to the Center the will (intent) to violate the provisions of Regulation 2016/679. In the opinion of the supervisory authority, the Center did not act intentionally; nevertheless, it committed omissions that significantly increased the risk of breaching the confidentiality of the processed data, which demonstrates gross negligence on its part and constitutes a significant factor aggravating the amount of the administrative fine. The Controller failed to conduct a proper risk analysis (see paragraphs 74–85 of the justification), which would have allowed for the identification of potential threats and vulnerabilities and the selection of appropriate technical and organizational measures based on that analysis to ensure the lawfulness of processing. In the present case, however, the Controller could and should have foreseen that the solutions it adopted did not ensure an adequate level of personal data security. A proper risk analysis would have enabled the identification of potential threats and vulnerabilities, the elimination of which would have significantly increased the security of the processed data.
In the opinion of the President of the Personal Data Protection Office, the Center did not act intentionally and did not intend to violate Regulation 2016/679. However, it did commit omissions that significantly increased the risk to the security of personal data processing, which constitutes gross negligence and constitutes a significant factor aggravating the amount of the administrative fine. Categories of personal data affected by the breach (Article 83 paragraph 2 letter g) of Regulation 2016/679)
The Centre's negligence resulted in the breach of a wide range of data. A file hosted on the coordinator's private server, which became publicly available in search engine results after being indexed, contained data such as names, surnames, telephone numbers, addresses, and information about the health situation, i.e., mandatory quarantine or home isolation in connection with the prevention and control of SARS-CoV-2 infection and the spread of the COVID-19 disease caused by it.
Information about the health situation constitutes health data, which is considered highly sensitive data under Article 9 paragraph 1 of Regulation 2016/679. In addition to health data, the incident also included, among other things, data concerning: The first and last names and place of residence of the data subjects were disclosed, which allowed not only for the unique identification of individuals but also for their location. Quarantine or isolation necessitated the data subjects remaining in the location indicated in a file posted on the controller's employee's private server, which, as a result of being indexed, became publicly available in search engine results. In this case, the scope of the disclosed data should therefore be considered broad.
In deciding to impose an administrative fine and determining its amount, the President of the Personal Data Protection Office found no grounds to consider mitigating circumstances that would reduce the final fine imposed on the Centre.
Other circumstances, referred to below, referred to in Article 83, paragraph 1, of the Personal Data Protection Act. Article 2 of Regulation 2016/679, after assessing their impact on the violations identified in this case, were deemed neutral by the President of the Personal Data Protection Office (UODO), meaning they had neither an aggravating nor a mitigating effect on the amount of the administrative fine imposed. Actions taken to minimize the harm suffered by data subjects (Article 83 paragraph 2 letter c) of Regulation 2016/679)
In the context of this premise, the purpose of the controller's action, namely, minimizing the harm suffered by data subjects, is important. The President of the UODO did not note such actions in this case. This assessment is not altered by the fact that the employee deleted the data file from the private server and reported the incident to the relevant police unit (see point 18 of the justification). It should be emphasized that these actions occurred independently of any instructions from, for example, the management of the Center. After the coordinator reported the breach, the Center's management conducted an analysis of the incident and concluded that it did not act as a controller in the context of the processing operations that led to the incident (see point 19 of the justification). This position was consistently maintained throughout the proceedings leading to this decision. Therefore, the Center cannot be accused of intending to take any action to minimize the damage suffered by the data subjects, as in its opinion, it was not responsible for the incident and was not obligated to take any action in this regard. The fact that the employee deleted the data file from the private server and reported the incident to the relevant police unit should therefore be considered a circumstance that has no impact on the penalty. These actions were undertaken by the coordinator on his own initiative, before informing the controller of the breach. However, after learning of the incident, the controller decided that he was not obligated to take any action. The degree of responsibility of the controller, taking into account the technical and organizational measures implemented by the controller pursuant to Articles 25 and 32 of Regulation 2016/679 (Article 83(2)(d) of Regulation 2016/679)
In assessing the requirement of Article 83(2)(d) of Regulation 2016/679, it should be noted that the Centre is undoubtedly responsible for failing to implement appropriate technical and organizational measures to prevent the personal data breach that occurred on November 23, 2020. The legislator provided in recital 74 of Regulation 2016/679 that "[t]he controller should be subject to obligations and be legally liable for any processing of personal data carried out by the controller or on its behalf. In particular, the controller should be required to implement appropriate and effective measures and should be able to demonstrate that processing activities comply with this Regulation and are effective." In the present case, the Center failed to do everything that could be expected of it (see Chapter III, letter d) of Guidelines WP 253), which demonstrates a failure to fulfill the obligations set forth in Articles 25 and 32 of Regulation 2016/679. However, in the present case, this circumstance constitutes the very essence of the infringement of the provisions of Regulation 2016/679, which leads to the conclusion that it is not solely a mitigating or aggravating factor in its assessment. Therefore, the lack of appropriate technical and organizational measures referred to in Articles 25 and 32 of Regulation 2016/679 cannot be considered in this case as a circumstance that could additionally influence the more severe assessment of the infringement and the amount of the administrative fine. Any relevant prior infringements by the controller (Article 83 paragraph 2 letter e) of Regulation 2016/679)
The President of the Personal Data Protection Office (UODO) has not identified any prior infringements of personal data protection provisions on the part of the Center, therefore there is no basis to treat this circumstance as an aggravating factor. At the same time, however, every controller is obliged to comply with the law, and therefore the absence of prior infringements cannot be treated as a mitigating circumstance when imposing sanctions. This assessment is consistent with the position expressed by the EDPB in Guidelines 04/2022, according to which "[t]he absence of prior infringements cannot be considered a mitigating circumstance, as compliance with the provisions of [Regulation 2016/679] is the norm. The absence of prior infringements can be considered a neutral circumstance" (see point 94 of Guidelines 04/2022). Degree of cooperation with the supervisory authority to remedy the infringement and mitigate its potential negative effects (Article 83(2)(f) of Regulation 2016/679)
When analyzing this condition, particular attention should be paid to the position expressed by the EDPB in Guidelines 04/2022, which states that "the general obligation to cooperate rests with the controller and the processor pursuant to Article 31 of [Regulation 2016/679], and failure to do so may result in the imposition of a fine pursuant to Article 83(4)(a) of [Regulation 2016/679]. Therefore, the simple obligation to cooperate should be considered mandatory and, therefore, should be considered a neutral (and not a mitigating) circumstance" (see paragraph 96 of Guidelines 04/2022).
In the present case, the controller's actions were limited to providing explanations in response to the supervisory authority's requests. The President of the Personal Data Protection Office did not note any other actions by the Center that could be considered to its advantage under Article 83(2)(f) of Regulation 2016/679. Therefore, as follows from point 96 of Guidelines 04/2022 cited above, this circumstance should be considered neutral in the context of the penalty imposed for the infringement of Article 5(1)(f) and (2), Article 25(1), and Article 32(1) and (2) of Regulation 2016/679. The manner in which the supervisory authority learned of the infringement, in particular whether and to what extent the controller reported the infringement (Article 83(2)(h) of Regulation 2016/679)
The President of the Personal Data Protection Office found the Center to have violated Article 83(2)(h) of Regulation 2016/679. Article 5(1)(f) and (2), Article 25(1), and Article 32(1) and (2) of Regulation 2016/679 were taken ex officio as a result of proceedings conducted following a notification from a third party about a possible personal data breach (see point 17 of the explanatory memorandum). According to Guidelines 04/2022, "[w]here the supervisory authority has become aware of the breach, for example, as a result of a complaint or in the course of proceedings, this should, in principle, also be considered a neutral factor" (see point 99 of Guidelines 04/2022). Therefore, the ground of Article 83(2)(h) of Regulation 2016/679, as a neutral factor, did not affect the amount of the fine imposed on the Centre. If the controller concerned had previously been subject to measures referred to in Article 58(1) of Regulation 2016/679 in the same case, the measures referred to in Article 58(1) and (2) of Regulation 2016/679 were applied to the controller in question in the same case. 2 – compliance with these measures (Article 83 paragraph 2 letter i) of Regulation 2016/679)
Prior to the issuance of this decision, the President of the Personal Data Protection Office did not apply the measures specified in Article 58 paragraph 2 of Regulation 2016/679 to the controller in the case at hand. This means that the Data Protection Office was not obliged to take any action related to the application of these measures. Otherwise, the supervisory authority would have assessed such actions that could have an aggravating or mitigating effect on the assessment of the identified infringement. Application of approved codes of conduct under Article 40 or approved certification mechanisms under Article 42 (Article 83 paragraph 2 letter j) of Regulation 2016/679)
The Data Protection Office does not apply approved codes of conduct or approved certification mechanisms referred to in the provisions of Regulation 2016/679. However, the adoption, implementation, and application of the above measures are not mandatory for the controller – as provided for in Regulation 2016/679. This means that failure to apply them cannot be considered to the controller's detriment. The situation would be different if the Data Protection Office adopted and applied such an instrument, which guarantees a higher than standard level of protection for processed personal data. In such a case, this circumstance could be assessed in its favor. Any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial benefits gained directly or indirectly in connection with the infringement or losses avoided (Article 83 paragraph 2 letter k) of Regulation 2016/679)
The President of the Personal Data Protection Office, in his comprehensive review of the case, noted no circumstances other than those described above that could have affected the assessment of the infringement and the amount of the administrative fine imposed. It was also not established that the controller gained any financial benefits or avoided such losses in connection with the infringement. Therefore, there are no grounds to treat this circumstance as an aggravating factor. 4.3.2 Determining the amount of the administrative fine in accordance with Guidelines 04/2022
In determining the amount of the administrative fine imposed on the Center, the President of the Personal Data Protection Office (UODO) applied, in a limited manner, the methodology adopted by the EDPB in Guidelines 04/2022. The limited scope of application of these guidelines for calculating fines imposed on public authorities and entities results from the impossibility of using the turnover (revenue) of such an entity as a measure of its size, allowing for the moderation of the fine to ensure it is effective, proportionate, and dissuasive. As the EDPB indicates in point 10 of Guidelines 04/2022, if supervisory authorities have the power to impose administrative fines on public authorities and entities under national law, these guidelines apply to their calculation, with the exception of Chapter 4.3 of this document ("Turnover for the purpose of imposing an effective, dissuasive, and proportionate fine"). However, where national law provides for statutory maximum fines for public authorities and entities (other than those resulting from Article 83 paragraphs 4-6 of Regulation 2016/679), Chapter 6 of the Guidelines (“Legally Determined Maximum Fine and Liability of Businesses”) will not apply. Considering the above, the President of the Personal Data Protection Office (UODO) conducted the calculation process for the fine imposed on the Center, as presented below.
The President of the Personal Data Protection Office (UODO) has established – pursuant to Article 102 paragraph 1 item 1 of the UODO – the amount of PLN 100,000 as the legally determined maximum fine that can be imposed on the controller. This amount applies regardless of the provision of Regulation 2016/679 that the infringement concerns.
The President of the Personal Data Protection Office (UODO) has categorized the infringement of Regulation 2016/679 found in this case (see Chapter 4.1 of Guidelines 04/2022). Infringements of the provisions of Article 102 paragraph 1 item 1 of the UODO Infringements of the provisions of Article 25(1) and Article 32(1) and (2) of Regulation 2016/679 fall – in accordance with Article 83(4)(a) of Regulation 2016/679 – within the category of infringements punishable by fines of up to EUR 10 000 000 or up to 2% of the undertaking's turnover in the previous business year. Infringements of the provisions of Article 5(1)(f) and (2) of Regulation 2016/679 fall (in accordance with Article 83(5)(a) of Regulation 2016/679) within the category of infringements punishable by the higher of the two fines provided for in that act, with a maximum fine of up to EUR 20 000 000 or up to 4% of the undertaking's turnover in the previous business year – they are therefore, in abstracto, the “most serious” infringements provided for in Regulation 2016/679.
The supervisory authority assessed the infringement found in this case as a high-serious infringement (see Chapter 4.2 of Guidelines 04/2022). This assessment took into account the factors listed in Article 83(2) of Regulation 2016/679 that relate to the subject matter of the infringement (the "seriousness" of the infringement), namely: the nature, gravity, and duration of the infringement (Article 83(2)(a) of Regulation 2016/679), the unintentional nature of the infringement (Article 83(2)(b) of Regulation 2016/679), and the categories of personal data affected by the infringement (Article 83(2)(g) of Regulation 2016/679). A detailed assessment of these circumstances is presented above (see paragraphs 149–163 of the justification). It should be noted here that considering their combined impact on the assessment of the infringement found in this case, taken as a whole, leads to the conclusion that its seriousness (understood in accordance with Guidelines 04/2022) is high. Consequently, the starting amount for calculating the penalty should be between 20% and 100% of the maximum penalty that can be imposed on the Centre (see point 60, third indent, of Guidelines 04/2022). This means that, considering the maximum amount of PLN 100,000 set for public bodies and entities, between PLN 20,000 and PLN 100,000. The President of the Personal Data Protection Office (UODO) considered PLN 25,000 (25% of the legally defined maximum penalty that can be imposed on the Centre) to be an adequate starting amount, justified by the circumstances of this case.
The supervisory authority assessed the impact of the remaining circumstances (apart from those considered above in assessing the seriousness of the infringement) indicated in Article 83(2) of Regulation 2016/679 on the established infringement (see Chapter 5 of the EDPB Guidelines 04/2022). These circumstances, which may have an aggravating or mitigating effect on the assessment of the infringement, relate to the entity responsible for the infringement (i.e., the entity committing the infringement and its conduct before, during, and after the infringement) and, if applicable, to other circumstances that may be relevant to its assessment. A detailed analysis and justification of the impact of each of them on the assessment of the infringement are presented above (see paragraphs 166–174 of the justification). Each of these circumstances was assessed by the supervisory authority as neutral, therefore, they had neither an aggravating nor a mitigating effect on the sanction. Therefore, there were no grounds to adjust the amount of the fine set at PLN 25,000.
Pursuant to Article 83(1) of Regulation 2016/679, each supervisory authority shall ensure that administrative fines imposed for infringements of this Regulation are effective, proportionate, and dissuasive in each individual case. Guidelines 04/2022, however, indicate that the final step in calculating the fine in accordance with the methodology presented therein should be an analysis of whether the final amount of the calculated fine meets these requirements and an increase or reduction of the fine accordingly (see Chapter 7 of Guidelines 04/2022). In conducting such an analysis in this case, the President of the Personal Data Protection Office (UODO) concluded that the amount determined in accordance with the above principles requires an additional adjustment in accordance with the principle of proportionality established in Article 83(1) of Regulation 2016/679, as one of the three sentencing guidelines. Undoubtedly, a fine of PLN 25,000 would be an effective penalty (due to its severity, it would achieve the repressive objective of punishing unlawful conduct) and a deterrent penalty (i.e., it would effectively discourage both the Center and other controllers from committing future infringements of the provisions of Regulation 2016/679). At the same time, however, in the opinion of the President of the Personal Data Protection Office, such a penalty would be disproportionate due to its excessive severity. The principle of proportionality requires, among other things, that the measures adopted by the supervisory authority do not go beyond what is appropriate and necessary to achieve the legitimate objectives (see paragraphs 137 and 139 of Guidelines 04/2022). In other words, "[a] sanction is proportionate if it does not exceed the threshold of severity determined by taking into account the circumstances of the specific case"[77].
In the present case, in the context of the proportionality of the penalty, it is significant that the infringement was limited and incidental in nature – it concerned only a specific processing process, not the controller's entire business. Therefore, the infringement did not result from persistent and systemic negligence in the organization of personal data protection. Of particular importance, the processing process in which the infringement was found arose from new obligations imposed on the controller during the COVID-19 pandemic. The Center had to immediately implement this personal data processing for objective reasons beyond its control, i.e., due to the need to comply with the imposed obligations related to counteracting the spread of the virus. The amount of the fine imposed must therefore take into account the fact that, under the conditions prevailing at the time of the infringement, the ability to comprehensively and fully adequately analyze all aspects of the processing process' compliance with legal requirements and to implement appropriate technical and organizational measures was significantly limited.
Taking into account the above-mentioned circumstances and the proportionality of the fine, the President of the Personal Data Protection Office (UODO) reduced the fine amount established above (see point 179 of the justification) by 40%, i.e., to PLN 15,000. In the supervisory authority's opinion, the final amount of the fine imposed will not reduce its effectiveness and deterrent nature. This amount constitutes a threshold above which an increase in the fine amount will not result in an increase in its effectiveness and deterrent nature. On the other hand, a further reduction in the fine amount could come at the expense of its effectiveness and deterrent nature, as well as the consistent application and enforcement of Regulation 2016/679 and the principle of equal treatment of entities in the EU and EEA internal market.
In the opinion of the President of the Personal Data Protection Office, an administrative fine of PLN 15,000, imposed in these specific, individual circumstances, will be effective because it will achieve its preventive objective of preventing future infringements – identical or similar to the one identified in this case – committed by both the controller and other entities. Furthermore, the imposed fine, as a punitive measure, will effectively punish the Center for its unlawful conduct.
In the opinion of the supervisory authority, the imposed fine will also be proportionate to the identified infringements of Regulation 2016/679, particularly their nature and gravity. The proportionality of the sanction also reflects the fact that the amount of the fine determined by the supervisory authority will not constitute an excessive burden on the Center. In particular, its payment will not affect the controller's ability to fulfill its statutory duties. According to the President of the Personal Data Protection Office, the Center should and is capable of bearing the consequences of its negligence in the area of personal data protection, therefore, imposing an administrative fine of PLN 15,000 on it is justified.
In the opinion of the President of the Personal Data Protection Office, an administrative fine of PLN 15,000 will also serve a preventive function in these specific circumstances, as it will demonstrate to both the Center and other controllers (in particular, other entities in the public finance sector) that the supervisory authority – acting as guardian of personal data protection regulations – will vigorously enforce the liability of the aforementioned entities for any identified violations of Regulation 2016/679. Therefore, the sanction applied in these proceedings will deter both the controller itself and other similar controllers from committing the same or similar violations in the future. 4.4 Justification for the imposition and determination of the amount of the administrative fine for the violation of Article 33, paragraph 1, of the Personal Data Protection Regulation. 1 of Regulation 2016/679 4.4.1 Conditions for imposing an administrative fine
In deciding to impose an administrative fine on the Center for infringement of Article 33 paragraph 1 of Regulation 2016/679, the President of the Personal Data Protection Office – pursuant to Article 83 paragraph 2 letters a)–k) of Regulation 2016/679 – took into account the following circumstances, which constitute the necessity of applying such a sanction in this case and have an aggravating effect on the amount of the administrative fine imposed: The nature, gravity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing in question (Article 83 paragraph 2 letter a) of Regulation 2016/679)
The Center violated the obligation set out in Article 33 paragraph 1 of Regulation 2016/679 by failing to notify the President of the Personal Data Protection Office of the personal data breach. This obligation is closely linked to the system designed to protect one of the fundamental rights of individuals, namely the right to the protection of their personal data, or more broadly, the protection of their privacy. A crucial element of this system, the framework of which is defined by Regulation 2016/679, are supervisory authorities, which are entrusted with the tasks of protecting and enforcing the rights of individuals in this regard. In the case of Article 33(1) of Regulation 2016/679, supervisory authorities, through the personal data breach notification mechanism, are able to respond appropriately to a reported breach, for example, by assessing whether the controller properly analyzed the impact of the breach on the rights and freedoms of the individuals whose data are affected, and consequently, whether there is a high risk to the rights and freedoms of such individuals and whether notification of a data breach is necessary. In this case, the President of the Personal Data Protection Office was deprived of this ability because the controller failed to provide the legally required notification. The breach is therefore of significant importance and serious nature, because the mechanism for reporting personal data breaches is an effective tool contributing to a real improvement in the security of personal data processing and to the achievement of the main objective of Regulation 2016/679, which is the protection of the rights and freedoms of natural persons, in particular the right to the protection of personal data.
Regarding the duration of the infringement, it should be emphasized that, as indicated above, the latest time at which the Center should have identified a personal data breach within the meaning of Article 33(1) of Regulation 2016/679 was the receipt of the letter from the President of the Personal Data Protection Office dated July 1, 2021 (see point 117 of the justification). The infringement of Article 33(1) of Regulation 2016/679 therefore lasts from the expiry of 72 hours from the identification of the personal data breach. This identification should have been made no later than July 5, 2021 (i.e., on the date of receipt of the letter from the President of the Personal Data Protection Office dated July 1, 2021). Therefore, the infringement of Article 33(1) of Regulation 2016/679 has lasted since July 8, 2021 and has not been remedied by the Center to date, which also constitutes an aggravating factor. Intentional nature of the breach (Article 83 paragraph 2 letter b) of Regulation 2016/679)
In assessing this ground, the President of the Personal Data Protection Office (UODO) took into account that the Center failed to comply with the obligation under Article 33 paragraph 1 of Regulation 2016/679 due to the finding that it did not act as a controller in relation to the personal data covered by the incident. However, in the supervisory authority's opinion, the Center should review this position after receiving the letter from the President of the Personal Data Protection Office dated July 1, 2021, in which the supervisory authority presented the findings regarding the incident (see paragraph 117 of the justification). However, since the Center was mistaken about its status as a controller, and this mistake was the reason for the failure to notify the personal data breach, the President of the Personal Data Protection Office (UODO) assumed that the breach was unintentional at that time. It should be noted, however, that on August 9, 2023, the supervisory authority sent a notice of initiation of the proceedings to the party, in which it explicitly stated that the Center acts as a data controller and outlined its obligations in this regard, which, in light of the evidence collected, were breached, including the obligation provided for in Article 33(1) of Regulation 2016/679. Therefore, it should be assumed that from that moment on, the failure to report the personal data breach to the supervisory authority was conscious, because despite being aware of the findings made by the body, the Center did not take any action to fulfill its obligation.
Therefore, for the period from July 8, 2021 (i.e., from the expiry of 72 hours from the date of delivery of the letter from the President of the Personal Data Protection Office dated July 1, 2021) to August 8, 2023 (i.e., the day preceding the delivery of the notification of initiation of the proceedings dated August 9, 2023), the infringement should be deemed unintentional due to the fact that during this period the Centre was mistaken about not fulfilling the role of data controller and was therefore unaware of its obligation under Article 33(1) of Regulation 2016/679. However, from August 9, 2023, i.e., from the date of delivery of the notification of initiation of these proceedings, the infringement became intentional. At this point, the Center was clearly informed of the incorrect position regarding its failure to act as a data controller in the context of the incident and was aware of its obligation to report the personal data breach to the supervisory authority, which it has not yet done. Degree of cooperation with the supervisory authority to remedy the breach and mitigate its potential negative effects (Article 83 paragraph 2 letter f) of Regulation 2016/679)
During the investigation and administrative proceedings, the Center responded to the supervisory authority's requests. However, this circumstance cannot be treated by the President of the Personal Data Protection Office as a mitigating factor, but rather as an expression of compliance with the legal obligations incumbent on the controller.
Despite correspondence sent to it during the proceedings indicating the supervisory authority's position regarding its performance as a data controller in the context of the identified breach, the Center did not take the required steps under Article 33 paragraph 2 of the Personal Data Protection Regulation. 1 of Regulation 2016/679, i.e., it failed to report the personal data breach to the President of the Personal Data Protection Office. Throughout the proceedings, the Personal Data Protection Office consistently maintained its position that it could not be assigned the role of controller with respect to the processing operations in which the incident occurred, challenging the position of the President of the Personal Data Protection Office. This means that the level of cooperation between the controller and the supervisory authority in resolving the breach of Article 33(1) of Regulation 2016/679 and mitigating its potential effects should be assessed as unsatisfactory, which constitutes an aggravating circumstance when determining the amount of the administrative fine.
In determining the amount of the administrative fine, the President of the Personal Data Protection Office found no grounds to take into account mitigating circumstances that would reduce the final amount of the fine imposed on the controller.
Other circumstances, referred to in Article 83(1) of Regulation 2016/679, indicated below, 2 of Regulation 2016/679, after assessing their impact on the infringement found in this case, were deemed neutral by the President of the Personal Data Protection Office (UODO), meaning they had neither an aggravating nor a mitigating effect on the amount of the imposed administrative fine. Any relevant prior infringements by the controller (Article 83 paragraph 2 letter e) of Regulation 2016/679)
With respect to the infringement under review, the assessment presented in paragraph 168 of the explanatory memorandum remains valid. The manner in which the supervisory authority became aware of the infringement, in particular whether and to what extent the controller reported the infringement (Article 83 paragraph 2 letter h) of Regulation 2016/679)
The President of the Personal Data Protection Office was not informed of the personal data breach in accordance with the procedure prescribed for such situations, as set out in Article 33 of Regulation 2016/679. The supervisory authority was informed of a personal data breach involving the placement on an employee's private server of a file containing the personal data of at least (...) residents of D., which, as a result of being indexed, became publicly available in search engine results. On February 3, 2021, a third party informed the supervisory authority (see point 5 of the explanatory memorandum). The failure to notify the supervisory authority of the personal data breach is the subject of these proceedings, and in the circumstances of the facts under consideration, the President of the Personal Data Protection Office (UODO) has determined that this factor will not be treated as an aggravating circumstance, as it constitutes the substance of the breach in question. If the controller concerned has previously been subject to measures referred to in Article 58(2) in the same matter, compliance with these measures (Article 83(2)(i) of Regulation 2016/679)
With respect to the breach under review, the assessment presented in point 172 of the explanatory memorandum remains valid. The application of approved codes of conduct pursuant to Article 58(2) of the Regulation (EC) No 1079/2009 shall apply. 40 or approved certification mechanisms under Article 42 (Article 83(2)(j) of Regulation 2016/679)
With respect to the infringement in question, the assessment presented in paragraph 173 of the justification remains valid. Any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial benefits obtained directly or indirectly in connection with the infringement or losses avoided (Article 83(2)(k) of Regulation 2016/679)
The President of the Personal Data Protection Office, in his comprehensive examination of the case, did not note any circumstances other than those described above that could affect the assessment of the infringement and the amount of the administrative fine imposed. It was also not established that the controller gained any financial benefits or avoided such losses in connection with the infringement. Therefore, there is no basis to treat this circumstance as an aggravating circumstance.
The remaining circumstances listed in Article 83(2)(k) of Regulation 2016/679 2 of Regulation 2016/679, could not be taken into account by the President of the Personal Data Protection Office due to the nature of the breach (concerning the controller's relationship with the supervisory authority, not with the data subjects). These include: a) the number of affected individuals and the extent of the damage they suffered (Article 83 paragraph 2 letter a) of Regulation 2016/679) – because the breach consisting in failing to notify the President of the Personal Data Protection Office of a personal data breach constitutes an omission of an obligation that the controller was obliged to fulfill towards the supervisory authority. This means that it does not, by its nature, affect data subjects and therefore cannot, by its nature, cause damage to them; b) the actions taken by the controller to minimize the damage suffered by data subjects (Article 83 paragraph 2 letter c) of Regulation 2016/679) – due to the nature of the breach, which cannot result in damage to natural persons. Since the breach does not result in any damage to data subjects, the controller is unable to take any action to minimize such damage, which could be assessed by the supervisory authority as mitigating or aggravating circumstances; c) the degree of responsibility of the controller, taking into account the technical and organizational measures implemented by the controller pursuant to Articles 25 and 32 (Article 83(2)(d) of Regulation 2016/679) – because the breach, by its very nature, does not relate to the technical and organizational measures implemented by the controller to ensure the protection of personal data and the security of their processing; d) the categories of personal data affected by the breach (Article 83(2)(g) of Regulation 2016/679) – because the breach, by its very nature, does not concern any personal data, and therefore no categories of personal data. It consists of a failure to comply (with respect to the supervisory authority) with an obligation that is separate from any processing operations. 4.4.2 Determining the amount of the administrative fine in accordance with Guidelines 04/2022
In determining the amount of the administrative fine imposed on the Center, the President of the Personal Data Protection Office (UODO) applied, in a limited manner, the methodology adopted by the EDPB in Guidelines 04/2022 (see point 175 of the justification). Considering the above, the President of the Personal Data Protection Office (UODO) carried out the calculation process for the fine imposed on the controller, as follows:
The President of the Personal Data Protection Office (UODO) has established – pursuant to Article 102, paragraph 1, item 1 of the Personal Data Protection Act – the amount of PLN 100,000 as the legally defined maximum fine that can be imposed on the Center. This amount applies regardless of the provision of Regulation 2016/679 that the infringement concerns.
The President of the Personal Data Protection Office (UODO) categorized the infringement of Regulation 2016/679 found in this case (see Chapter 4.1 of Guidelines 04/2022). The infringement of Article 33(1) of Regulation 2016/679 found in this case falls – in accordance with Article 83(4)(a) of Regulation 2016/679 – into the category of infringements punishable by the lower of the two penalties provided for in Regulation 2016/679, with a maximum penalty of EUR 10,000,000 or 2% of the company's total annual turnover in the previous financial year. Therefore, in abstracto (isolated from the individual circumstances of a specific case) it was considered by the EU legislature to be less serious than the infringements indicated in Article 83(5) and (6) of Regulation 2016/679.
The supervisory authority assessed the infringement found in this case as a low-serious infringement (see Chapter 4.2. of Guidelines 04/2022). This assessment took into account the factors listed in Article 83(2) of Regulation 2016/679 that relate to the subject of the infringement (the "seriousness" of the infringement), namely: the nature, gravity, and duration of the infringement (Article 83(2)(a) of Regulation 2016/679) and the intentional nature of the infringement (Article 83(2)(b) of Regulation 2016/679). The categories of personal data concerned by the infringement (Article 83(2)(g) of Regulation 2016/679) were not taken into account due to the nature of the infringement (concerning the controller's relationship with the supervisory authority, not with data subjects). A detailed assessment of these circumstances has been presented above (see paragraphs 187–190 and 200 of the justification). It should be noted here that considering their combined impact on the assessment of the infringement found in this case, taken as a whole, leads to the conclusion that its seriousness (understood in accordance with Guidelines 04/2022) is low. Consequently, the starting amount for calculating the fine should be set at between 0% and 10% of the maximum fine that can be imposed on the Centre (see paragraph 60, third indent, of Guidelines 04/2022). This means that, given the maximum amount of PLN 100,000 set for public bodies and entities, the starting amount should be between PLN 0 and PLN 10,000. The President of the Personal Data Protection Office (UODO) considered PLN 5,000 (5% of the legally defined maximum fine that can be imposed on the Centre) to be an adequate starting amount, justified by the circumstances of this case.
The supervisory authority assessed the impact of the remaining circumstances (apart from those considered above in assessing the seriousness of the infringement) indicated in Article 83(2) of Regulation 2016/679 on the established infringement (see Chapter 5 of the EDPB Guidelines 04/2022). These circumstances, which may have an aggravating or mitigating effect on the assessment of the infringement, relate to the subjective aspect of the infringement (i.e., the entity committing the infringement and its conduct before, during, and after the infringement) and, if applicable, to other circumstances that may be relevant to its assessment. A detailed analysis and justification of the impact of each of these circumstances on the assessment of the infringement are presented above (see paragraphs 191–200 of the justification). The President of the Personal Data Protection Office (UODO) found that the aggravating circumstance in this case is the circumstance provided for in Article 83(2)(a) of the GDPR. Article 83(1)(f) of Regulation 2016/679, i.e., the degree of cooperation with the supervisory authority in order to remedy the infringement and mitigate its potential negative effects (see paragraphs 191-192 of the justification). In conducting the analysis in this case, the supervisory authority did not take into account any mitigating circumstances that would reduce the amount of the sanction. Due to the existence of the aggravating circumstance indicated above, the President of the Personal Data Protection Office, assessing its impact on the established infringement, deemed it justified to increase the amount of the fine established above by 10% (see paragraph 204 of the justification) – to PLN 5,500.
Pursuant to Article 83(1) of Regulation 2016/679, each supervisory authority shall ensure that administrative fines imposed for infringements of this Regulation are effective, proportionate, and dissuasive in each individual case. However, Guidelines 04/2022 indicate that the final step in calculating the fine in accordance with the methodology presented therein should be to analyze whether the final amount of the calculated fine meets these requirements and to increase or reduce the fine accordingly (see Chapter 7 of the Guidelines). In conducting such an analysis in this case, the President of the Personal Data Protection Office (UODO) found that the amount of the fine determined in accordance with the above principles does not require additional adjustment for reasons of effectiveness, proportionality, and deterrence (Article 83 paragraph 1 of Regulation 2016/679).
It should be emphasized here that the circumstances referred to in paragraph 181 of the explanatory memorandum do not affect the amount of the imposed fine. It should be noted that the obligation provided for in Article 33 paragraph 1 of Regulation 2016/679 is different in nature from the obligations arising from Article 24 paragraph 1, Article 25 paragraph 1, and Article 32 paragraph 1. Articles 1 and 2 of Regulation 2016/679 – the obligation to notify a personal data breach to the supervisory authority does not require prior, lengthy planning or advanced organizational preparation, but rather simply takes specific informational actions in response to the event. This obligation is updated after the breach occurs, and is therefore independent of any prior difficulties with organizing the processing process. In this particular case, the failure to comply was not due to time pressure or the dynamics of regulatory changes, but rather to the adopted position that the controller did not fulfill its role in the processing. Therefore, the breach was not caused by temporary organizational difficulties, but rather by an erroneous classification of its role in the personal data processing, unrelated to these circumstances. In the supervisory authority's opinion, the timing of the COVID-19 pandemic had no impact on this error, and therefore should not result in a reduction of the fine imposed on the Centre for violating Article 33(1) of Regulation 2016/679.
The President of the Personal Data Protection Office (UODO) determined that the administrative fine of PLN 5,500 imposed in these specific, individual circumstances will be effective because it will achieve its preventive objective of preventing future infringements – identical or similar to the one found in this case – committed by both the controller and other entities. Furthermore, the imposed fine, as a punitive measure, will effectively punish the Center for its unlawful, persistent omission.
In the opinion of the supervisory authority, the imposed fine will also be proportionate to the identified infringement of the provisions of Regulation 2016/679, particularly its nature and gravity. The proportionality of the sanction also reflects the fact that the amount of the fine determined by the supervisory authority will not constitute an excessive burden on the Center. In particular, its payment will not affect the controller's ability to fulfill its statutory duties. According to the President of the Personal Data Protection Office, the Center should and is capable of bearing the consequences of its negligence in the area of personal data protection, therefore, imposing an administrative fine of PLN 5,500 on it is justified.
In the opinion of the President of the Personal Data Protection Office, an administrative fine of PLN 5,500 will also serve a preventive function in these specific circumstances, as it will demonstrate to both the Center and other controllers (in particular, other entities in the public finance sector) that the supervisory authority – acting as guardian of personal data protection regulations – will vigorously enforce the liability of the aforementioned entities for any identified violations of Regulation 2016/679. Therefore, the sanction applied in these proceedings will deter both the Center and other similar controllers from committing the same or similar violations in the future. 4.5 Justification for the imposition and determination of the amount of the administrative fine for the violation of Article 34, paragraph 1 of the Personal Data Protection Regulation. 1 of Regulation 2016/679 4.5.1 Conditions for imposing an administrative fine
In deciding to impose an administrative fine on the Data Protection Office for violating Article 34 paragraph 1 of Regulation 2016/679, the President of the Personal Data Protection Office – pursuant to Article 83 paragraph 2 letters a)–k) of Regulation 2016/679 – took into account the following circumstances, which constitute the necessity of applying such a sanction in this case and have an aggravating effect on the amount of the administrative fine imposed: The nature, gravity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing in question, the number of data subjects affected, and the extent of the damage they suffered (Article 83 paragraph 2 letter a) of Regulation 2016/679) 212.In the opinion of the President of the Personal Data Protection Office (UODO), the violation of Article 34(1) of Regulation 2016/679 (consisting of the failure to notify data subjects of a personal data breach without undue delay) found in this case is of significant gravity and seriousness. The purpose of the obligation imposed on the controller in this provision is to provide data subjects with relevant information about the incident and recommended precautionary measures, which may limit the potential damage caused by the breach.[78] Fulfillment of this obligation is intended to ensure that the individuals affected by the breach are aware of its effects and are able to take appropriate actions that may prevent the consequences of the breach presented by the controller from materializing or developing further. The Center's failure to comply with the obligation imposed on it by this provision has led to a situation in which data subjects remain unaware of the incident and, consequently, unable to take any remedial action.
The large number of individuals affected by the breach was also deemed to be detrimental to the controller – the incident described in point 15 of the justification concerned the data of at least (...) individuals, none of whom had received information about the data breach from the controller to date. In the context of the premise under analysis, it should be emphasized, however, that the evidence collected in the case does not provide grounds to assume that the breach in question resulted in any damage to data subjects. During the proceedings, it was not established that any of the individuals affected by the incident, in respect of which the controller failed to comply with the information obligation, suffered financial damage as a result of the controller's failure to comply with this obligation. Importantly, a violation of Article 34(1) of Regulation 2016/679 cannot be linked to even the potential for non-financial damage to data subjects, such as stress, anxiety, or a sense of threat related to the possible unauthorized use of their personal data. Such negative consequences require awareness of the occurrence of an event resulting in a personal data breach. Therefore, since the essence of the violation of Article 34(1) of Regulation 2016/679 consists in the failure to notify an individual of a personal data breach, thus depriving them of knowledge of the incident, it cannot be argued that the data subjects could even potentially have suffered the negative psychological consequences indicated above – they were completely unaware that the incident had occurred. In determining the amount of the administrative fine imposed on the Center, the supervisory authority therefore took into account the fact that, although the violation of Article 34(1) of Regulation 2016/679 affected a significant number of individuals, it did not result in any damage to them, either material or non-material.
The President of the Personal Data Protection Office considers the long duration of the violation to be an aggravating circumstance in this case. It should be assumed that the violation of Article 34(1) of Regulation 2016/679 constitutes an aggravating circumstance. 1 of Regulation 2016/679 commenced no later than 8 July 2021 – for the reasons referred to in paragraphs 117–118 of the explanatory memorandum. Similarly, since the latest date at which the Personal Data Protection Office should have identified the personal data breach was 5 July 2021, the obligation on the Personal Data Protection Office to notify data subjects of the personal data breach without undue delay, pursuant to Article 34 paragraph 1 of Regulation 2016/679, also became effective from that date. The infringement continues to this day, as the Personal Data Protection Office has not provided evidence of having notified data subjects of the personal data breach.
Therefore, in the view of the President of the Personal Data Protection Office, the requirement of Article 83 paragraph 2 letter a) of Regulation 2016/679 supports the need to apply Article 34 paragraph 2 to the infringement. 1 of Regulation 2016/679, and also has an aggravating effect on its amount. Intentional nature of the infringement (Article 83 paragraph 2 letter b) of Regulation 2016/679)
In assessing this ground, the President of the Personal Data Protection Office (UODO) took into account that the Center failed to comply with the obligation provided for in Article 34 paragraph 1 of Regulation 2016/679 due to the finding that it did not act as a controller in relation to the personal data covered by the incident. However, in the supervisory authority's opinion, the Center should review this position after receiving the letter from the President of the Personal Data Protection Office dated July 1, 2021, in which the supervisory authority presented the findings regarding the incident (see paragraph 117 of the justification). However, since the Center was mistaken about its status as a data controller, and this mistake was the reason for the failure to notify data subjects of the personal data breach, the President of the Personal Data Protection Office (UODO) assumed that the breach was unintentional at that time. It should be noted, however, that on 9 August 2023, the supervisory authority sent a notice of initiation of the proceedings to the party, in which it expressly indicated that the Centre acts as a data controller and presented its obligations in this connection, which, in the light of the evidence collected, were violated, including the obligation provided for in Article 34 paragraph 1 of Regulation 2016/679. Therefore, it should be assumed that from that moment on, the failure to notify data subjects of the personal data breach was intentional, because despite being aware of the findings made by the authority, the Center did not take any action to fulfill its obligation.
Therefore, for the period from July 8, 2021 (i.e., the moment when, according to the findings, the obligation under Article 34(1) of Regulation 2016/679 was updated) to August 8, 2023 (i.e., the day preceding the delivery of the notification of August 9, 2023 initiating the proceedings), the infringement should be assumed to be unintentional due to the fact that during that period the Center was mistakenly declaring that it was not acting as a data controller, and therefore was unaware of its obligation under Article 34(1) of Regulation 2016/679. However, from August 9, 2023, i.e., the date of service of the notification of the initiation of these proceedings, the breach became intentional. At that point, the Center received clear information about the incorrect position regarding its failure to act as a data controller in the context of the incident and was aware of its obligation to notify data subjects of the personal data breach, which it has not done to date. Degree of cooperation with the supervisory authority to remedy the breach and mitigate its potential negative effects (Article 83 paragraph 2 letter f) of Regulation 2016/679)
During the investigation and administrative proceedings, the Center responded to the supervisory authority's requests. However, this circumstance cannot be treated by the President of the Personal Data Protection Office as a mitigating factor, but rather as a manifestation of compliance with the legal obligations incumbent on the controller.
The Data Protection Office, despite correspondence sent to it during the proceedings indicating the supervisory authority's position regarding its role as a data controller in the context of the identified data protection breach, failed to take the actions required under Article 34(1) of Regulation 2016/679, i.e., failed to notify data subjects of the personal data breach. Throughout the proceedings, the Data Protection Office consistently maintained its position that it could not be assigned the role of a controller in relation to the processing operations in which the breach occurred, challenging the position of the President of the Personal Data Protection Office. This means that the level of cooperation between the controller and the supervisory authority in order to remedy the breach of Article 34(1) of Regulation 2016/679 and mitigate its potential effects should be assessed as unsatisfactory, which constitutes an aggravating circumstance when determining the amount of the administrative fine.
The other circumstances referred to in Article 83(1) of Regulation 2016/679, indicated below, include: Article 83(2) of Regulation 2016/679, after assessing their impact on the infringement found in this case, were deemed neutral by the President of the Personal Data Protection Office (UODO), meaning they had neither an aggravating nor a mitigating effect on the amount of the imposed administrative fine. Actions taken by the controller to minimize the harm suffered by data subjects (Article 83(2)(c) of Regulation 2016/679)
Since it was not established that any harm was caused to data subjects as a result of the infringement consisting in the failure to notify data subjects, the controller was unable to take any actions to minimize such harm, which could be assessed by the supervisory authority as mitigating or aggravating circumstances. Therefore, the failure to take such actions by the Data Protection Office cannot in any way burden it. However, it cannot constitute a mitigating circumstance for it either, as it did not take any action that could be positively assessed by the supervisory authority. Any relevant prior infringements by the controller (Article 83(2)(e) of Regulation 2016/679)
With respect to the infringement in question, the assessment presented in paragraph 168 of the explanatory memorandum remains valid. The manner in which the supervisory authority became aware of the breach, in particular whether and to what extent the controller reported the breach (Article 83 paragraph 2 letter h) of Regulation 2016/679)
The President of the Personal Data Protection Office (UODO) found that the Center had violated Article 34 paragraph 1 of Regulation 2016/679 ex officio, as a result of proceedings conducted following a notification from a third party about a possible personal data breach (see point 17 of the explanatory memorandum). According to Guidelines 04/2022, "[w]here the supervisory authority became aware of the breach, for example, as a result of a complaint or in the course of proceedings, this element should, in principle, also be considered a neutral factor" (see point 99 of Guidelines 04/2022). Therefore, the ground of Article 83 paragraph 2 letter h) of Regulation 2016/679, as a neutral factor, did not affect the amount of the fine imposed on the Center. If the controller concerned has previously been subject to measures referred to in Article 58(2) in the same case, compliance with those measures (Article 83(2)(i) of Regulation 2016/679)
The assessment set out in paragraph 172 of the Explanatory Memorandum remains valid for the infringement under review. The use of approved codes of conduct under Article 40 or approved certification mechanisms under Article 42 (Article 83(2)(j) of Regulation 2016/679)
The assessment set out in paragraph 173 of the Explanatory Memorandum remains valid for the infringement under review. Any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial benefits gained directly or indirectly in connection with the infringement or losses avoided (Article 83(2)(k) of Regulation 2016/679)
The President of the Personal Data Protection Office, in his comprehensive review of the case, did not note any circumstances other than those described above that could have affected the assessment of the infringement and the amount of the administrative fine imposed. It was also not established that the controller gained any financial benefits or avoided such losses in connection with the infringement. Therefore, there is no basis to treat this circumstance as an aggravating factor.
The remaining circumstances listed in Article 83(2) of Regulation 2016/679 could not be taken into account by the President of the Personal Data Protection Office due to the nature of the infringement. These are: a) the degree of responsibility of the controller, taking into account the technical and organizational measures implemented by it pursuant to Article 83(2) of Regulation 2016/679. 25 and 32 (Article 83(2)(d) of Regulation 2016/679) – since the infringement, by its very nature, does not involve technical and organizational measures implemented by the controller to ensure the protection of personal data and the security of their processing, this premise cannot be considered in this case as a circumstance that may influence the assessment of the infringement and, consequently, the amount of the administrative fine imposed; b) the categories of personal data affected by the infringement (Article 83(2)(g) of Regulation 2016/679) – since the infringement ("isolated" from the processing of specific personal data) by its very nature cannot affect any personal data, and therefore no categories thereof. It consists in the failure to comply with a certain formal obligation of information towards the individuals affected by the personal data protection infringement. 4.5.2 Determining the amount of the administrative fine in accordance with Guidelines 04/2022
In determining the amount of the administrative fine imposed on the Center, the President of the Personal Data Protection Office (UODO) applied, in a limited manner, the methodology adopted by the EDPB in Guidelines 04/2022 (see point 175 of the justification). Considering the above, the President of the Personal Data Protection Office (UODO) carried out the calculation process for the fine imposed on the controller, as follows:
In accordance with Article 102, paragraph 1, item 1 of the Personal Data Protection Act, the President of the Personal Data Protection Office (UODO) has established the maximum legally defined fine that may be imposed on the Center as PLN 100,000. This amount applies regardless of the provision of Regulation 2016/679 that the infringement concerns.
The President of the Personal Data Protection Office (UODO) categorized the infringement of Regulation 2016/679 found in this case (see Chapter 4.1 of Guidelines 04/2022). The infringement of Article 34(1) of Regulation 2016/679 found in this case falls – in accordance with Article 83(4)(a) of Regulation 2016/679 – into the category of infringements punishable by the lower of the two penalties provided for in Regulation 2016/679, with a maximum penalty of EUR 10,000,000 or 2% of the company's total annual turnover in the previous financial year. Therefore, in abstracto (isolated from the individual circumstances of a specific case) it was considered by the EU legislature to be less serious than the infringements indicated in Article 83(5) and (6) of Regulation 2016/679.
The supervisory authority assessed the infringement found in this case as a medium-level infringement (see Chapter 4.2. of Guidelines 04/2022). This assessment took into account the factors listed in Article 83(2) of Regulation 2016/679 that relate to the subject of the infringement (constituting the "seriousness" of the infringement), namely: the nature, gravity, and duration of the infringement (Article 83(2)(a) of Regulation 2016/679) and the intentional nature of the infringement (Article 83(2)(b) of Regulation 2016/679). The categories of personal data concerned by the infringement (Article 83(2)(g) of Regulation 2016/679) were not taken into account due to the nature of the infringement ("isolated" from the processing of specific personal data, and therefore, by its very nature, not capable of infringing any personal data). A detailed assessment of these circumstances has been presented above (see paragraphs 212–217 and 227 of the justification). It should be noted at this point that considering their combined impact on the assessment of the violation found in this case, taken as a whole, leads to the conclusion that its level of seriousness (understood in accordance with Guidelines 04/2022) is medium. Consequently, the starting amount for calculating the penalty should be assumed to be between 10% and 20% of the maximum penalty that can be imposed on the Centre (see paragraph 60, third indent, of Guidelines 04/2022), i.e., considering the maximum amount of PLN 100,000 specified for public bodies and entities, between PLN 10,000 and PLN 20,000. The President of the Personal Data Protection Office (UODO) considered the starting amount of PLN 12,000 (12% of the legally defined maximum fine that could be imposed on the Center) to be an adequate, justified amount under the circumstances of this case.
The supervisory authority assessed the impact of the other circumstances (in addition to those considered above in assessing the seriousness of the infringement) indicated in Article 83(2) of Regulation 2016/679 on the established infringement (see Chapter 5 of the EDPB Guidelines 04/2022). These circumstances, which may have an aggravating or mitigating effect on the assessment of the infringement, relate to the entity perpetrating the infringement (i.e., the entity perpetrating the infringement and its conduct before, during, and after the infringement) and, where applicable, to other circumstances that may be relevant to its assessment. A detailed analysis and justification of the impact of each of these circumstances on the assessment of the infringement are presented above (see paragraphs 218–227 of the explanatory memorandum). The President of the Personal Data Protection Office (UODO) found that the aggravating circumstance in this case is the criterion set out in Article 83(2)(f) of Regulation 2016/679, i.e., the degree of cooperation with the supervisory authority in order to remedy the infringement and mitigate its potential negative effects (see paragraphs 218-219 of the justification). In conducting its analysis in this case, the supervisory authority did not take into account any mitigating circumstances that would reduce the amount of the sanction. Due to the existence of the aggravating circumstance indicated above, the President of the UODO, assessing its impact on the established infringement, deemed it justified to increase the amount of the fine by 10% (see paragraph 231 of the justification) – to PLN 13,200.
Pursuant to Article 83(1) of Regulation 2016/679, each supervisory authority shall ensure that administrative fines imposed for infringements of this Regulation are effective, proportionate, and dissuasive in each individual case. However, Guidelines 04/2022 indicate that the final step in calculating the fine in accordance with the methodology presented therein should be to analyze whether the final amount of the calculated fine meets these requirements and to increase or reduce the fine accordingly (see Chapter 7 of the Guidelines). In conducting such an analysis in this case, the President of the Personal Data Protection Office (UODO) found that the amount of the fine determined in accordance with the above principles does not require additional adjustment for effectiveness, proportionality, and deterrence (Article 83(1) of Regulation 2016/679).
In the context of the proportionality of the fine imposed for the infringement of Article 34(1) of Regulation 2016/679, the reasoning presented in paragraph 207 of the explanatory memorandum remains valid.
The President of the Personal Data Protection Office (UODO) determined that the administrative fine of PLN 13,200 imposed in these specific, individual circumstances will be effective because it will achieve its preventive objective, which is to prevent future violations – identical or similar to the one found in this case – committed by both the controller and other entities. Furthermore, the imposed fine, as a punitive measure, will effectively punish the Center for its long-standing unlawful conduct.
According to the supervisory authority, the imposed fine will also be proportionate to the identified violation of Regulation 2016/679, in particular its nature and gravity. The proportionality of the sanction imposed is also reflected in the fact that the amount of the fine determined by the supervisory authority will not constitute an excessive burden for the Center. In particular, its payment will not affect the controller's ability to fulfill its statutory obligations. According to the President of the Personal Data Protection Office, the Center should and is able to bear the consequences of its negligence in the area of personal data protection, therefore, imposing an administrative fine of PLN 13,200 on it is justified.
In the opinion of the President of the Personal Data Protection Office, the administrative fine of PLN 13,200 will also serve a preventive function in these specific circumstances, as it will indicate to both the Centre and other controllers (in particular, other public finance sector entities) that the supervisory authority – acting as guardian of personal data protection regulations – will vigorously enforce the liability of the aforementioned entities for any identified violations of Regulation 2016/679. Thus, the sanction applied in these proceedings will deter both the Centre and other similar controllers from committing the same or similar violations in the future. 4.6 Summary of Administrative Fines Imposed on the Centre
Taking into account the established factual circumstances and legal considerations, the President of the Personal Data Protection Office imposed three separate administrative fines on the Centre: a fine for violating Article 5 paragraph 1 letter f) and paragraph 2, Article 25 paragraph 1, and Article 32 paragraph 1. 1 and 2 of Regulation 2016/679 in the amount of PLN 15,000, a fine for violating Article 33, paragraph 1 of Regulation 2016/679 in the amount of PLN 5,500, and a fine for violating Article 34, paragraph 1 of Regulation 2016/679 in the amount of PLN 13,200. The total amount of the fines imposed on the Center was therefore PLN 33,700.
In the opinion of the President of the Personal Data Protection Office, the aforementioned financial sanctions fulfill the functions of a penalty specified in Article 83, paragraph 1 of Regulation 2016/679 and constitute an adequate and, above all, fair response by the supervisory authority to the identified infringements of the provisions of Regulation 2016/679. The application of any other corrective measure to the Center provided for in Article 58, paragraph 1 of Regulation 2016/679 shall be deemed inadmissible. 2 of Regulation 2016/679, in particular limiting the measure to a warning (Article 58 paragraph 2 letter b) of Regulation 2016/679), would not meet the requirement of proportionality, understood as the need for the supervisory authority to apply a measure that is appropriate, in particular, to the seriousness of the irregularities found. Refraining from imposing administrative fines would also not guarantee that the controller would not commit further personal data protection violations in the future. With the above in mind, the President of the Personal Data Protection Office ruled as follows: [1] Journal of Laws of 2025, item 1691. [2] Journal of Laws of 2019, item 1781, as amended. [3] OJ EU L 119, 4.05.2016, p. 1, as amended. [4] OJ Journal of Laws of 2025, item 1153, as amended. [5] Journal of Laws of 2025, item 1214, as amended. [6] Journal of Laws of 2025, item 1483, as amended. [7] “Personal data breach” – see Article 4, point 12 of Regulation 2016/679. [8] “Processing” – see Article 4, point 2 of Regulation 2016/679. [9] “Personal data” – see Article 4, point 1 of Regulation 2016/679. [10] “Controller” – see Article 4, point 7 of Regulation 2016/679. [11] See Article 2, points 11a and 12 and Article 34 of the Act of 5 December 2008 on the Prevention and Control of Infections and Infectious Diseases in Humans (Journal of Laws of 2024, item 924, as amended). [12] See (...) (accessed: 30/04/2026). [13] See (...) (accessed: 30/04/2026). [14] See Article 30, paragraph 1, of Regulation 2016/679. [15] "XLSX" – an open spreadsheet file format used by, among others, Microsoft Excel, for storing tabular data along with its structure and metadata. [16] "X." – a content management system (CMS) enabling the creation and management of websites and the publication of files and content within a server structure. [17] See C., Help Center, keyword "indexing", (...) (accessed: 30/04/2026). [18] See EDPB, Guidelines 07/2020 on the concepts of controller and processor, Version 2.0, Adopted on 7 July 2021, point 12, https://www.edpb.europa.eu/system/files/2023-10/edpb_guidelines_202007_controllerprocessor_final_pl.pdf (accessed: 30/04/2026). [19] See ibid., point 13. [20] See the Center's letters of 9 July 2021, 30 September 2022, and 10 August 2023. [21] See The Center's letters of July 9, 2021, September 30, 2022, and August 10, 2023. [22] See ibid. [23] See the Center's letter of July 9, 2021. [24] See the Center's letter of August 10, 2023. [25] See the Center's letter of July 9, 2021. [26] See ibid. [27] See the Volunteer Fire Department's letter of July 9, 2021. [28] See the order of the Voivode (...) of March 14, 2020, no. (...), (...) (accessed: April 30, 2026). [29] See Ministry of Family, Labor and Social Policy, What can persons under quarantine expect?, https://www.gov.pl/web/rodzina/pomoc-osobom-w-kwarantannie2 (accessed: April 30, 2026). [30] Journal of Laws of 2020, item 2261, as amended. [31] See the Statute of the Volunteer Fire Department in D., adopted (...), https://(…) (accessed: April 30, 2026). [32] See the Center's letter of September 30, 2022. [33] See judgment of the CJEU of 5/12/2023, C-683/21, Nacionalinis visuomenės sveikatos centrums prie Sveikatos apsaugos ministerijos v Valstybinė duomenų apsaugos inspekcija, ECLI:EU:C:2023:949. [34] See coordinator's letter of May 19, 2021 [35] See letter from the Volunteer Guard of July 9, 2021. [36] See letter from the Center of August 10, 2023. [37] See EDPB, Guidelines 07/2020…, op. cit., point 35. [38] See ibid., point 19. [39] Journal Journal of Laws of 2022, item 679. [40] See P. Drobek [in:] GDPR. General Data Protection Regulation. Commentary, ed. E. Bielak-Jomaa, D. Lubasz, Warsaw 2018, art. 5, point 3. [41] See P. Barta, M. Kawecki, P. Litwiński [in:] P. Litwiński (ed.), Personal Data Protection Act. Commentary [in:] General Data Protection Regulation. Personal Data Protection Act. Selected sectoral provisions. Commentary, 2nd ed. 2025, art. 24. [42] See P. Fajgielski [in:] Commentary on Regulation No. 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) [in:] General Data Protection Regulation. Personal Data Protection Act. Commentary, 3rd edition, Warsaw 2025, Article 24. [43] See judgment of the CJEU of 14 December 2023, C-340/21, ECLI:EU:C:2023:986. [44] See judgment of the Regional Administrative Court in Warsaw of 17 March 2022, II SA/Wa 2516/21, https://orzeczenia.nsa.gov.pl/doc/E4A591D2AF (accessed: 30 April 2026). [45] Compare judgment of the Supreme Administrative Court in Warsaw of 5 July 2024, III OSK 2654/22; judgment of the Provincial Administrative Court in Warsaw of 26 August 2020, II SA/Wa 2826/19; judgment of the Provincial Administrative Court in Warsaw of 13 May 2023, II SA/Wa 2129/20; judgment of the Provincial Administrative Court in Warsaw of 5 October 2023, II SA/Wa 502/23; judgment of the Provincial Administrative Court in Warsaw of 27 February 2024, II SA/Wa 1404/23; judgment of the Provincial Administrative Court in Warsaw of 10 April 2025, II SA/Wa 1266/24; judgment of the Provincial Administrative Court in Warsaw of 17 April 2024, II SA/Wa 1342/23; Judgment of the Regional Administrative Court in Warsaw of May 22, 2025, II SA/Wa 45/25. [46] See also judgment of the Supreme Administrative Court of July 5, 2024, III OSK 2654/22. [47] See judgment of the Regional Administrative Court in Warsaw of June 21, 2023, II SA/Wa 150/23, https://orzeczenia.nsa.gov.pl/doc/8DFC7A2AF4 (accessed: April 30, 2026). See also judgment of the Regional Administrative Court in Warsaw of October 21, 2021, II SA/Wa 272/21; judgment of the Regional Administrative Court in Warsaw of June 6, 2023, II SA/Wa 1939/22; judgment of the Regional Administrative Court in Warsaw of February 27, 2024, II SA/Wa 1404/23; Judgment of the Regional Administrative Court in Warsaw of April 10, 2025, II SA/Wa 1266/24; judgment of the Regional Administrative Court in Warsaw of December 4, 2025, II SA/Wa 1026/25. [48] See the Center's letter of August 10, 2023. [49] See judgment of the Regional Administrative Court in Warsaw of October 5, 2023, II SA/Wa 502/23; judgment of the Regional Administrative Court in Warsaw of November 27, 2024, II SA/Wa 251/24; judgment of the Regional Administrative Court in Warsaw of April 10, 2025, II SA/Wa 1266/24. [50] See Judgment of the Supreme Administrative Court of February 9, 2023, III OSK 3945/21, https://orzeczenia.nsa.gov.pl/doc/55C45FFD79 (accessed: April 30, 2026). See also judgment of the Regional Administrative Court in Warsaw of November 27, 2024, II SA/Wa 251/24. [51] See judgment of the Supreme Administrative Court of February 9, 2023, III OSK 3945/21. See also judgment of the Supreme Administrative Court of June 12, 2025, II SA/Wa 1394/22. [52] See Judgment of the Supreme Administrative Court of June 12, 2025, III OSK 1394/22, https://orzeczenia.nsa.gov.pl/doc/5A82D60221 (accessed: April 30, 2026). See also judgment of the Supreme Administrative Court of February 7, 2025, III OSK 6801/21; judgment of the Regional Administrative Court in Warsaw of December 4, 2025, II SA/Wa 1026/25. EDPB, Guidelines 9/2022 on Personal Data Breach Notification under the GDPR, Version 2.0, Adopted on 28 March 2023, paragraphs 100-102, https://www.edpb.europa.eu/system/files/2024-10/edpb_guidelines_202209_personal_data_breach_notification_v2.0_pl_0.pdf (accessed: 30/04/2026). [54] See ibid., paragraph 7. [55] See ibid., paragraphs 24-25. [56] See ibid., paragraph 28. [57] See ibid., para. 15. [58] See judgment of the Supreme Administrative Court of 1 October 2025, III OSK 1830/22, https://orzeczenia.nsa.gov.pl/doc/3AABB6CADC (accessed: 30 April 2026). [59] See ibid., paras. 103-120. [60] "Data concerning health" – see Article 4(15) of Regulation 2016/679. [61] Charter of Fundamental Rights of the European Union (OJ EU C 1999, No. 303, p. 1, as amended). [62] See judgment of the Court of Justice of the European Union of 1 August 2022, C-184/20, ECLI:EU:C:2022:601. [63] See judgment of the Supreme Administrative Court of 1 October 2025, III OSK 1830/22. [64] See ibid. See also judgment of the Supreme Administrative Court of 20 March 2025, III OSK 210/22; judgment of the Regional Administrative Court in Warsaw of 22 September 2021, II SA/Wa 791/21; judgment of the Regional Administrative Court in Warsaw of 21 January 2022, II SA/Wa 1353/21; judgment of the Regional Administrative Court in Warsaw of 1 July 2022, II SA/Wa 4143/21; judgment of the Regional Administrative Court in Warsaw of 31 August 2022, II SA/Wa 2993/21; judgment of the Regional Administrative Court in Warsaw of 26 April 2023, II SA/Wa 1272/22; Judgment of the Regional Administrative Court in Warsaw of 4 December 2025, II SA/Wa 1026/25. [65] See judgment of the Supreme Administrative Court of 20 March 2025, III OSK 210/22, https://orzeczenia.nsa.gov.pl/doc/2A441D7EDE (accessed: 30 April 2026). [66] See EDPB, Guidelines 9/2022..., op. cit., item 31. [67] See ibid., item 40. [68] See judgment of the Supreme Administrative Court of 20 March 2025, III OSK 210/22. [69] Journal of Laws of 2025, item 1483, as amended. [70] See EDPB, Guidelines 04/2022 on the calculation of administrative fines under the GDPR (version 2.1), adopted on 24 May 2023, hereinafter referred to as "Guidelines 04/2022", https://www.edpb.europa.eu/system/files/2024-01/edpb_guidelines_042022_calculationofadministrativefines_pl_0.pdf (accessed: 30 April 2026). [71] See P. Fajgielski, op. cit., art. 33. [72] UODO, Obligations of controllers related to personal data breaches. Guide on the basis of the GDPR. Version 2.0, pp. 77 and 86. [73] See P. M. Przybysz [in:] Code of Administrative Procedure. Updated Commentary, LEX/el. 2024, Article 35. [74] See P. Fajgielski, op. cit., Article 5. [75] See Article 29 Data Protection Working Party, Guidelines on the application and setting of administrative fines for the purposes of Regulation (EC) No 2016/679, adopted on 3 October 2017, hereinafter referred to as "Guidelines WP 253", Chapter III, point a), https://ec.europa.eu/newsroom/article29/items/611237, (accessed: 30/04/2026). [76] See CJEU judgment of 14 December 2023, C-340/21, ECLI:EU:C:2023:986. [77] See P. Barta, M. Kawecki, P. Litwiński [in:] P. Litwiński (ed.), op. cit., article 83. [78] See UODO, op. cit., pp. 77 and 86.