The Polish authority issues a warning to a specialized hospital for failures in personal data security

The Polish authority reminded a data controller and its processor for respectively failing to verify and implement sufficient safeguards regarding security, following unauthorized access to an email inbox.

Facts and context

The Polish data protection authority (UODO) today published a decision issuing a warning against a specialized hospital and its email service provider for failures related to verifying the processor's safeguards and the security of processing.

The case began in 2021 following a data breach notification by the hospital, after an unauthorized third party accessed the contents of an email inbox hosted by the provider and exfiltrated personal data of 224 individuals.

Grounds for the decision

The authority found several infringements against the data controller (the hospital) and its processor (the email provider):

  • Obligation to use processors providing sufficient guarantees (Article 28(1) of the GDPR): The authority found that the hospital, although having internal procedures to assess its providers, did not concretely verify whether its email provider offered sufficient guarantees to ensure processing compliant with the GDPR. The data controller did not follow its own policies and could not demonstrate having exercised due diligence in selecting and monitoring its processor, thus engaging its responsibility under the principles of confidentiality and accountability.
  • Obligation to ensure the security of processing (Article 32 of the GDPR): The hospital also failed its obligations by not conducting an adequate risk assessment regarding the use of email. Although an assessment was conducted, it did not specifically identify the provider and, above all, the hospital did not implement the risk mitigation measures it had itself identified before the incident.
  • Processor's obligation to ensure the security of processing (Article 28 of the GDPR and Article 32 of the GDPR): The processor was sanctioned for failing to implement appropriate technical and organizational measures guaranteeing the security of entrusted data. The authority noted that despite an ISO/IEC 27001 certification, the provider had not conducted a risk assessment specific to the hospital's data. It therefore could not demonstrate having implemented sufficient safeguards to protect individuals' rights, in violation of its obligations.

Authority's decision

Consequently, the authority imposed a warning on the hospital and its processor.

The authority justified the absence of a financial penalty by the fact that the infringements did not result from a total lack of action by the two entities. It also took into account corrective measures taken after the incident to improve security, awareness of the infringements, and the involvement of the data protection officer to raise the level of compliance.

Lessons learned

This decision confirms that:

  • The choice of a processor requires the data controller to actively verify and document that the processor provides sufficient technical and organizational guarantees, beyond mere declarations.
  • The existence of internal security or supplier management policies does not exempt the data controller from responsibility if it cannot prove that they were effectively applied.
  • A risk assessment is GDPR-compliant only if followed by the effective implementation of identified mitigation measures; a purely documentary exercise is insufficient.
  • A processor cannot rely solely on a general certification to prove compliance; it must conduct a risk assessment tailored to the specific processing it carries out on behalf of each data controller.
  • Taking rapid corrective measures after a breach and cooperating with the supervisory authority are decisive factors in the decision not to impose a financial penalty.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire