Poland: a bailiff who appoints himself as Data Protection Officer is in a conflict of interest situation

A bailiff who appoints himself as data protection officer for his own office creates a clear conflict of interest situation, as he cannot both make decisions as the controller and monitor the compliance of those same decisions as the data protection officer.

Facts and context

The Polish data protection authority (UODO) published on 31 August 2026 a sanction decision against a bailiff, including the imposition of a fine of 15,500 PLN (approximately €3,600), for breaches related to the independence of the data protection officer and the obligation to notify his appointment.

The case began following the notification of a data breach by the bailiff himself, during which the authority discovered that he had simultaneously exercised for five years the functions of controller and data protection officer within his office.

Reasons for the decision

  • Obligation to ensure the absence of conflict of interest for the data protection officer (Article 38, paragraph 6, of the GDPR): The authority ruled that the appointment of the bailiff, acting as controller, to the function of data protection officer was illegal. It recalled that although a data protection officer may perform other tasks, the controller must ensure that they do not result in a conflict of interest. In this case, the bailiff was in a situation where he had to monitor his own activities, notably regarding the monitoring mission provided for in Article 39, paragraph 1, point b), of the GDPR, which is fundamentally incompatible with the independence required for this function. The authority emphasized that appointing a person holding a management position (director, board member, etc.) is inadmissible as it would lead the data protection officer to self-assess.
  • Obligation to notify the appointment of the data protection officer to the supervisory authority (Article 37, paragraph 7, of the GDPR): The investigation revealed that the bailiff had never communicated his own appointment as data protection officer to the UODO. He thus failed in his notification obligation, which must occur within 14 days following the appointment. For this breach, a fine of 3,500 PLN was imposed.

Decision of the authority

Consequently, the authority imposed an administrative fine totaling 15,500 PLN (approximately €3,600) on the bailiff, including 12,000 PLN for the breach related to the conflict of interest. The authority considered that a simple warning would be disproportionate, notably because the bailiff's decision was deliberate and motivated by cost savings, not by error or negligence.

Lessons learned

This decision reminds that:

  • The function of data protection officer is incompatible with that of a manager or any person determining the purposes and means of processing, as this creates a conflict of interest situation where the data protection officer would be led to monitor his own decisions.
  • The independence of the data protection officer is a fundamental guarantee that cannot be compromised for economic reasons; a non-compliant appointment motivated by cost reduction constitutes an aggravating circumstance.
  • Professionals subject to specific ethical obligations, such as public officers, are held to a particularly high duty of care regarding GDPR compliance.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire