Krajowa Szkoła Sądownictwa i Prokuratury – €22,200 Fine (Poland, 2021)

€22,200Urząd Ochrony Danych Osobowych11 February 2021Poland
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Poland's National School of Justice and Prosecution was fined EUR 22,200 for not securing personal data during a platform migration, which exposed information of over 50,000 people. This highlights the importance of having strong data security measures in place.

What happened

The National School of Justice and Prosecution exposed personal data of over 50,000 individuals during a website migration.

Who was affected

The affected individuals were users of the training platform whose personal data, including names and contact details, were exposed.

What the authority found

The Polish data protection authority found that the School failed to implement adequate security measures to protect personal data during the migration process.

Why this matters

This case highlights the critical need for organizations to ensure robust data security, especially during system changes or migrations. It serves as a caution for others to evaluate their data protection strategies.

GDPR Articles Cited

Art. 5(1)(f) GDPR
Art. 25(1) GDPR
Art. 28(3) GDPR
Art. 32(1) GDPR
Full Legal Summary
Detailed

The Polish DPA (UODO) fined Krajowa Szkoła Sądownictwa i Prokuratury (National School of Justice and Prosecution) EUR 22,200. UODO launched an investigation against the controller after it reported a data breach on its training platform website. During a test migration to the new platform, the data of more than 50,000 individuals had been exposed on the Internet. Among other things, this included the names, user names, postal and e-mail addresses, telephone numbers, units and departments of the data subjects. UODO found that the controller had not taken adequate technical and organizational measures to ensure the confidentiality of the data processed. In addition, the contract that the controller had concluded with the company entrusted with the processing of the data did not comply with the legal requirements. For example, the contract did not contain information about which categories of data would be processed.

Related Enforcement Actions (0)

No other enforcement actions found for Krajowa Szkoła Sądownictwa i Prokuratury in PL

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

11 February 2021

Authority

Urząd Ochrony Danych Osobowych

Fine Amount

€22,200

Enforcement Tracker ID

ETid-564

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Krajowa Szkoła Sądownictwa i Prokuratury - Poland (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: