Fortum Marketing and Sales Polska S.A. – €1,000,000 Fine (Poland, 2022)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Fortum Marketing and Sales Polska S.A. was fined EUR 1 million by the Polish DPA for a data breach. Unauthorized people accessed customer data due to poor security during an IT change. This highlights the importance of strong data protection measures when updating systems.
What happened
Unauthorized persons accessed and stole customer data from Fortum during an IT system change.
Who was affected
Customers whose data was stored in the Fortum database that lacked proper security measures.
What the authority found
The Polish DPA found that Fortum failed to implement adequate technical and organizational measures to protect personal data.
Why this matters
This case underscores the need for companies to ensure robust security during IT changes and to monitor service providers closely. It serves as a warning that inadequate data protection can lead to significant fines.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The Polish DPA has imposed a fine of EUR 1 million on Fortum Marketing and Sales Polska S.A.. The company had reported a data breach to the DPA in accordance with Art. 33 GDPR. During its investigation, the DPA found that unauthorized persons had managed to access and siphon off customer data. The data breach occurred at the time of the introduction of a change in the company's IT environment. The change was made by a processing agent. As part of the change, an additional Fortum customer database was created. However, the server on which the database was stored did not have sufficient security measures, which is why the unauthorized persons succeeded in accessing the data. The DPA also found that the processor failed to pseudonymize and encrypt the data. In addition, the processing agent had been using real customer data, rather than test data, to test the changes to the system. For this reason, the DPA concluded that the controller failed to take appropriate technical and organizational measures to ensure the protection of personal data. In addition, the DPA found that the controller would have been required to monitor the work of the processor to ensure that the protection of personal data is continuously guaranteed.
Related Enforcement Actions (1)
Other enforcement actions involving Fortum Marketing and Sales Polska S.A. in PL
Details
Fine Date
19 January 2022
Authority
Urząd Ochrony Danych Osobowych
Fine Amount
€1,000,000
Enforcement Tracker ID
ETid-1104
About this data
Cite as: Cookie Fines. Fortum Marketing and Sales Polska S.A. - Poland (2022). Retrieved from cookiefines.eu
Last updated: