Polish National Personal Data Protection Office (UODO) · 14 October 2021
Bank Millennium S.A
Insufficient fulfilment of data breach notification obligations
Fine€78,000Fine issued
- Regulator
- Polish National Personal Data Protection Office (UODO)
- Decided
- 14 October 2021
- Country
- Poland
- Sector
- Finance, Insurance and Consulting
- Regulator’s reference
- Not recorded
- Fino case number
- 2021/PL/003
What happened
The Polish DPA fined a controller approximately €80,000 for violating Articles 33(1) and 34(1) GDPR by failing to notify the DPA after a data breach, and only providing very general information regarding the breach to data subjects.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 33Notification of a personal data breach to the supervisory authority33(1)Read →
- Art. 34Communication of a personal data breach to the data subject34(1)Read →
- Data breach
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/PL/003.