What to Do in Case of a Personal Data Breach According to the Polish Authority

The Polish Data Protection Authority (UODO) has communicated about a cybersecurity incident involving the company MyDr and reminded the steps to be taken by individuals affected by a data breach.

Following media reports about a possible cybersecurity incident and data leak in the systems of the company MyDr, the Ministry of Digitization was informed and the competent services are investigating the circumstances. The UODO specifies that the obligation to notify the individuals affected by this breach lies with the data controllers who used MyDr's services. The authority recommends potential victims to take measures to minimize the consequences, such as securing their national identification number (PESEL) and increased vigilance against phishing attempts.

The UODO also clarified its mission, reminding that data subjects must first contact the data controller to exercise their rights before filing a complaint. The authority emphasized that it does not have the same prerogatives as law enforcement to identify unspecified data controllers. Regarding sanctions, the President of the UODO indicated that administrative fines are not imposed on request but constitute a last resort measure, decided on a case-by-case basis after analyzing at least 11 factors, and that other corrective measures such as warnings or formal notices are preferred.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire