The Supreme Administrative Court of Poland confirms a 52,000 PLN fine imposed on a housing cooperative for failure to report a data breach
The Supreme Administrative Court of Poland has confirmed the decision of the Polish data protection authority (UODO) sanctioning a housing cooperative for failing to notify a data breach. This final decision clarifies that the disclosure of identity and address data constitutes a high risk to the data subject and confirms that a housing cooperative is considered a "controller" for the calculation of fines under the GDPR.
Facts and context
The Polish data protection authority (UODO - Urząd Ochrony Danych Osobowych) published a decision of the Supreme Administrative Court confirming a sanction against a housing cooperative, including a fine of nearly 52,000 zlotys (approximately €12,000), for failures related to the management of a personal data breach.
The case stems from a data breach within the cooperative, which disclosed a copy of a suspicion report containing the personal data of one of its members, in the context of a dispute between them.
Reasons for the decision
After an initial annulment of the UODO decision by the Voivodeship Administrative Court, the Supreme Administrative Court ultimately sided with the supervisory authority on the following points:
- Obligation to notify a data breach to the supervisory authority (Article 33 of the GDPR): The cooperative did not notify the breach to the UODO within the 72-hour deadline, merely recording it in its internal register. The authority, whose reasoning was validated by the Court, found that the disclosure of data such as the national identification number (PESEL), name, first name, and residential address constituted a high risk to the rights and freedoms of the data subject. The controller having failed to present any documented risk analysis to justify its conclusion of a low risk, it could not rely on the exception to the notification obligation.
- Obligation to communicate a data breach to the data subject (Article 34 of the GDPR): As a direct consequence of the risk analysis, the Court confirmed that the breach was likely to result in a high risk to the rights and freedoms of the data subject. Therefore, the controller should have informed the data subject without delay, which it did not do.
- Principles for setting administrative fines (Article 83 of the GDPR): The Supreme Administrative Court overturned the first instance judgment which challenged the qualification of the housing cooperative as a "controller" within the meaning of the GDPR. It confirmed that the supervisory authority correctly calculated the amount of the fine based on the ceilings provided for in paragraph 4 of this provision, applicable to controllers.
Decision of the authority
Consequently, the fine of nearly 52,000 zlotys (approximately €12,000) imposed on the housing cooperative was confirmed.
Furthermore, the initial decision of the authority, also confirmed, ordered the cooperative to communicate the data breach to the data subject.
Lessons learned
This decision reminds that:
- The burden of proof of the absence of risk justifying non-notification lies with the controller, who must formalize its risk analysis focusing on threats to the data subject and not on its own interests.
- The unauthorized disclosure of basic identification data (name, address, national identification number) is likely to constitute a high risk to the data subject, justifying notification to the authority and the data subject.
- The notion of "controller" within the meaning of Article 83 of the GDPR for the calculation of fines may include entities such as housing cooperatives, regardless of their specific legal status under national law.
- Recording a breach in the internal register is a separate obligation and does not exempt from external notification obligations (authority and data subject) once the respective risk thresholds are met.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire