The Supreme Administrative Court confirms the Polish authority's decision on the compliance of security measures from the GDPR's effective date

The Supreme Administrative Court of Poland confirms that the obligation to regularly test security measures has applied since the first day of the GDPR's application, and that notifying a data breach does not constitute a mitigating circumstance for calculating the fine.

Facts and context

The Supreme Administrative Court (Naczelny Sąd Administracyjny - NSA) of Poland confirmed, by a ruling dated May 7, 2026, a sanction decision by the Polish data protection authority (Prezes Urzędu Ochrony Danych Osobowych - UODO) against Virgin Mobile, including a fine of 1,599,395 PLN (approximately €370,000) for failures related to data security.

The case began in 2019 following the company's notification of a personal data breach that allowed an unauthorized person to access data of more than 114,000 prepaid service customers. The UODO then opened an ex officio investigation to determine whether appropriate technical and organizational measures had been implemented.

Reasons for the decision

The Court upheld the UODO's reasoning on the following failure:

  • Obligation to ensure the security of processing (Article 32 of the GDPR): The authority and the Court considered that the company was required, from May 25, 2018, the GDPR's effective date, to have solutions to regularly test, measure, and evaluate the effectiveness of security measures. The period of the infringement was correctly established as extending from May 25, 2018, until the company obtained certification on July 22, 2020. The absence of this regular testing process was considered a cause of the data breach.

The Court also confirmed that the UODO correctly assessed the criteria for setting the fine. Notably, the fact that the company notified the breach was judged as a neutral factor and not as a mitigating circumstance, the notification being a legal obligation.

Authority's decision

Consequently, the Supreme Administrative Court confirmed the fine of 1,599,395 PLN (approximately €370,000) imposed on Virgin Mobile.

Lessons learned

This decision confirms that:

  • The obligation to regularly test, measure, and evaluate the effectiveness of security measures is a fundamental requirement applying to any controller since May 25, 2018.
  • The duration of a failure related to the absence of security testing can run from the GDPR's effective date and continue until a demonstrable corrective measure is implemented.
  • Notifying a data breach to the supervisory authority, although mandatory, is considered a standard compliance action and does not in itself constitute a mitigating circumstance when determining the amount of a sanction.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire