Fortum Marketing and Sales Polska S.A. – €1,000,000 Fine (Poland, 2022)

€1,000,000Urząd Ochrony Danych Osobowych19 January 2022Poland
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Fortum Marketing and Sales Polska S.A. was fined EUR 1 million by the Polish DPA for a data breach. Unauthorized people accessed customer data due to poor security during an IT change. This highlights the importance of strong data protection measures when updating systems.

What happened

Unauthorized persons accessed and stole customer data from Fortum during an IT system change.

Who was affected

Customers whose data was stored in the Fortum database that lacked proper security measures.

What the authority found

The Polish DPA found that Fortum failed to implement adequate technical and organizational measures to protect personal data.

Why this matters

This case underscores the need for companies to ensure robust security during IT changes and to monitor service providers closely. It serves as a warning that inadequate data protection can lead to significant fines.

GDPR Articles Cited

AI-verified

Art. 5(1)(f) GDPR
Art. 24(1) GDPR
Art. 25(1) GDPR
Art. 28(1) GDPR
Art. 32(1) GDPR
View original scraped data
Art. 5(1)(f) GDPR
Art. 24(1) GDPR
Art. 25(1) GDPR
Art. 28(1) GDPR
Art. 32(1) GDPR
(2) GDPR

Original data from scraper before AI verification against source document.

Source verified 5 March 2026
amount discrepancy
entity split needed
Full Legal Summary
Detailed

The Polish DPA has imposed a fine of EUR 1 million on Fortum Marketing and Sales Polska S.A.. The company had reported a data breach to the DPA in accordance with Art. 33 GDPR. During its investigation, the DPA found that unauthorized persons had managed to access and siphon off customer data. The data breach occurred at the time of the introduction of a change in the company's IT environment. The change was made by a processing agent. As part of the change, an additional Fortum customer database was created. However, the server on which the database was stored did not have sufficient security measures, which is why the unauthorized persons succeeded in accessing the data. The DPA also found that the processor failed to pseudonymize and encrypt the data. In addition, the processing agent had been using real customer data, rather than test data, to test the changes to the system. For this reason, the DPA concluded that the controller failed to take appropriate technical and organizational measures to ensure the protection of personal data. In addition, the DPA found that the controller would have been required to monitor the work of the processor to ensure that the protection of personal data is continuously guaranteed.

Details

Fine Date

19 January 2022

Authority

Urząd Ochrony Danych Osobowych

Fine Amount

€1,000,000

Enforcement Tracker ID

ETid-1104

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Fortum Marketing and Sales Polska S.A. - Poland (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: