The Polish authority imposes fines for data security failures following the theft of a laptop
Facts and context
The Polish data protection authority (UODO) published on 27 July 2026 a sanction decision against the Staroste of the Lubartów district and the Regional Office of Geodesy and Agricultural Land Management of Lublin, for failures related to the security of personal data following the theft of a laptop.
The case originated from a data breach notification by the Staroste in 2023, following the theft of a laptop belonging to an employee of the Regional Office of Geodesy. The breach resulted in a loss of confidentiality of data of about 700 individuals, including their names, first names, dates of birth, addresses, national identification numbers (PESEL), identity card numbers, and land registry numbers.
Grounds for the decision
The authority's investigation revealed several failures by the controller (the Staroste) and its processor (the Regional Office of Geodesy):
- Obligation to ensure the security of processing (Article 32 of the GDPR): The authority found that neither the controller nor the processor had implemented appropriate technical and organizational measures. Notably, the absence of disk encryption was identified as a major failure that could have prevented access to data on the stolen laptop. The risk analysis was also deficient, as it did not consider the risk of theft of mobile equipment, although the nature of the tasks (land consolidation) involved work outside the premises.
- Obligation to use processors providing sufficient guarantees (Article 28 of the GDPR): The controller failed in its duty of care by not verifying that its processor had implemented the required security measures. It merely assumed that the processor had adequate procedures without conducting any effective verification, which constitutes a violation of its obligation to ensure that the processor provides sufficient guarantees.
- Obligation of assistance from the processor to the controller (Article 28 of the GDPR): The processor was also sanctioned for not cooperating with the controller nor providing the necessary assistance to ensure compliance. The authority considered that due to its unreliability and failure to implement security measures, the processor directly contributed to the breach.
- Obligation to respect the principles of processing and accountability (Article 5 of the GDPR): The authority recalled that the controller must be able to demonstrate compliance with the GDPR principles, notably integrity and confidentiality. In this case, the absence of documentation of a concrete risk analysis and the inability to prove the effectiveness of organizational measures (such as rules on the use of mobile devices) characterized a failure of the accountability principle.
Decision of the authority
Consequently, the authority imposed an administrative fine on the Staroste of the Lubartów district as well as on the Regional Office of Geodesy and Agricultural Land Management of Lublin.
Lessons learned
This decision reminds that:
- Risk analysis must be a continuous, documented, and concrete process that takes into account real working conditions, including employee mobility and associated risks such as equipment theft.
- The responsibility for choosing a processor is not limited to a simple declaration of compliance; the controller has an active obligation to verify that the processor has effectively implemented sufficient guarantees.
- A processor can be held directly responsible and sanctioned for its own security failures and for its failure to assist the controller.
- Disk encryption of mobile devices is a fundamental technical security measure whose absence is likely to be considered a violation of the security obligation.
- The accountability principle requires not only implementing measures but also regularly testing and demonstrating their effectiveness, both technically and organizationally.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire