Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A. – €18,930 Fine (Poland, 2020)

€18,930Urząd Ochrony Danych Osobowych28 December 2020Poland
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

A Polish insurance company was fined EUR 18,930 for not reporting a data breach and failing to inform affected individuals. An insurance agent sent a policy to the wrong person, exposing personal data. This case shows the importance of promptly reporting breaches and notifying those affected.

What happened

An insurance company failed to report a data breach and did not inform the affected individuals after an agent sent a policy to the wrong person.

Who was affected

Individuals whose personal data was exposed when an insurance policy was sent to an unauthorized recipient.

What the authority found

The Polish Data Protection Authority found that the company violated GDPR by not reporting the data breach and failing to notify the affected individuals.

Why this matters

This case highlights the critical need for businesses to have procedures in place for quickly reporting data breaches and informing affected individuals. It emphasizes the importance of data security and breach notification under GDPR.

GDPR Articles Cited

Art. 33(1) GDPR
Art. 34(1) GDPR
Full Legal Summary
Detailed

The Polish DPA (UODO) fined Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A. EUR 18,930 for a breach of Art. 33 (1) GDPR and Art. 34 (1) GDPR. In May 2020, the DPA received a notification from a third party about a personal data breach involving an insurance agent acting as a processing agent for Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A. who sent an insurance policy to an unauthorized addressee by email. The document contained personal data concerning, among others, surnames, first names, residential addresses and information on the subject of the insurance policy. As a result, the supervisory authority asked the controller to clarify whether, regarding the sending of the electronic correspondence to an unauthorized addressee, a risk analysis on the data security of natural persons had been carried out, which is necessary to evaluate whether a data breach had occurred. Such a breach requires notification to the DPA and the individuals affected by the breach. In the letter, the supervisory authority advised the controller how to notify the breach and asked for explanations. Despite the letter requesting explanations, the controller did not report the data breach nor did it inform the data subjects about the incident. The DPA therefore initiated administrative proceedings. Only as a result of the initiation of the procedure did the controller report the personal data breach and inform two individuals affected by the breach.

Related Enforcement Actions (0)

No other enforcement actions found for Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A. in PL

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

28 December 2020

Authority

Urząd Ochrony Danych Osobowych

Fine Amount

€18,930

Enforcement Tracker ID

ETid-501

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A. - Poland (2020). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: