The President of the Polish Authority Imposes a Fine of 11,594 PLN on a Tax Firm for Insufficient Data Security
Facts and Context
The Polish data protection authority (UODO) today published a sanction decision against a tax advisory firm, including the imposition of a fine of 11,594 PLN (approximately €2,685), for breaches related to the security of personal data processing.
The case began with the notification of a data breach by the data controller itself, following unauthorized takeover of an email account of one of its employees which contained data of 111 individuals (clients, their employees, and children).
Grounds for the Decision
- Obligation to ensure security of processing (Article 32 of the GDPR): The authority found that the data controller had not implemented appropriate technical and organizational measures to ensure a level of security appropriate to the risk. Although the firm argued that there was no evidence of data exfiltration by the unauthorized person, the authority rejected this argument. It recalled that the definition of a "personal data breach" includes unauthorized access, regardless of proof of actual consultation or copying of the data. The firm's inability to determine the duration and extent of the unauthorized access, due to lack of connection logs, was considered a failure. Furthermore, it was established that before the incident, the firm had no internal policy specific to data protection, had not conducted a risk analysis for data processing via email, and did not regularly test the effectiveness of its security measures.
Authority's Decision
Consequently, the authority imposed a fine of 11,594 PLN (approximately €2,685) on the tax advisory firm.
Lessons Learned
This decision reminds that:
- A data breach is constituted as soon as unauthorized access to personal data is established, even in the absence of formal proof of exfiltration or consultation.
- The inability of a data controller to analyze a security incident, notably due to lack of event logs, constitutes in itself a breach of the security obligation.
- Security measures, such as risk analysis and policy implementation, must be proactive and implemented before any incident, not in reaction to a breach.
- The security obligation requires regularly testing, analyzing, and evaluating the effectiveness of the technical and organizational measures implemented.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire