Description

Upheld fine in investigation into the President of the District Court of Zgierz over alleged Dara Protection Breach

On 15 February 2022, the Voivodeship Administrative Court in Warsaw upheld the decision of the Polish Data Protection Authority (UODO) to impose an administrative fine of PLN 10'000 on the President of the District Court in Zgierz. The investigation was started based on a personal data breach involving the loss of an unencrypted pen drive containing the data of 400 individuals under probation supervision. The court agreed with the UODO that the controller (the President of the District Court) failed to implement appropriate organisational and technical measures to protect the confidentiality and integrity of personal data. Instead, the responsibility was improperly shifted onto the employees, who lacked the necessary knowledge and means to secure the data adequately. This failure led to unauthorised access to personal data, violating data protection regulations under the GDPR.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
cross-cutting
Implementation Level
national
Government Branch
judiciary
Government Body
court

Complete timeline of this policy change

Hide details
2021-07-13
in force

On 13 July 2021, the Polish Data Protection Authority (UODO) imposed an administrative fine of PLN …

2022-02-15
in force

On 15 February 2022, the Voivodeship Administrative Court in Warsaw upheld the decision of the Poli…

2024-09-30
in force

On 30 September 2024, the Supreme Administrative Court (NSA) dismissed the cassation appeal of the …