UODO (Poland) · 25 May 2026
Not named in the source
About: Accountability, Data security, Processor obligations
FinePLN21,000≈ €4,960Violation found
- Regulator
- UODO (Poland)
- Decided
- 25 May 2026
- Country
- Poland
- Sector
- Not given
- Regulator’s reference
- DKN.5131.5.2025
- Fino case number
- 2026/PL/020
What happened
The DPA fined a controller PLN 21,000 (€4,900) and a processor PLN 12,500 (€2,900) following a data breach due to a failure to implement appropriate technical and organisational measures and insufficient processor oversight.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 24Responsibility of the controller24(1)Read →
- Art. 25Data protection by design and by default25(1)Read →
- Art. 28Processor28(1) · 28(3)Read →
- Art. 32Security of processing32(1) · 32(2)Read →
- Accountability
- Data security
- Processor obligations
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2026/PL/020.