Frequently Asked Questions from Data Subjects and Controllers Following the MyDr Security Incident

The Polish data protection authority (UODO) has issued recommendations for data subjects and controllers following a security incident involving the company MyDr.

UODO announced that it will conduct an inspection of the technical and organizational measures implemented by MyDr, identified as a processor, and specified that it is not necessary for individuals to file individual complaints on this matter. For those whose data has been affected, the authority recommends considering blocking their national identification number (PESEL), remaining cautious against phishing attempts, and exercising their rights under Chapter III of the GDPR directly with the controller. The controller has one month to respond, extendable by two months in case of complexity.

Controllers who have received confirmation from MyDr that the incident concerns the data they manage must assess the risk to the rights and freedoms of natural persons. If a risk is identified, they are required to notify the breach to UODO without undue delay and, if possible, within 72 hours of its discovery, in accordance with Article 33, paragraph 1 of the GDPR, justifying any delay. If the risk is deemed high, they must also inform the data subjects without undue delay.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire