Polish National Personal Data Protection Office (UODO) · 20 May 2024
Company
Insufficient technical and organisational measures to ensure information security
- Regulator
- Polish National Personal Data Protection Office (UODO)
- Decided
- 20 May 2024
- Country
- Poland
- Sector
- Health Care
- Regulator’s reference
- Not recorded
- Fino case number
- 2024/PL/013
What happened
A controller was fined PLN 1,440,549 (€330,000) and ordered to bring its processing operations in line with the GDPR. The decision was made by the DPA after an ex officio investigation following a reported data breach by the controller. The breach was considered significant, and the controller had not implemented appropriate safeguards.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2024/PL/013.