Poczta Polska SA (Polish Post) – Fine (Poland, 2025)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Poczta Polska SA was fined €6.3 million for improperly sharing personal data of over 30 million citizens during the Covid-19 pandemic. The postal service received sensitive information from the government before the law allowing this was in effect. This ruling stresses the importance of legal compliance when sharing personal data.
What happened
Poczta Polska SA unlawfully disclosed personal data from the PESEL database to the postal service.
Who was affected
Over 30 million Polish citizens whose personal data was shared without proper legal backing.
What the authority found
The Polish data protection authority determined that Poczta Polska violated data protection regulations by disclosing personal data prematurely.
Why this matters
This case serves as a warning to companies about the consequences of sharing personal data without legal authorization. It underscores the need for strict adherence to data protection laws.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
Insufficient legal basis for data processing
Related Enforcement Actions (1)
Other enforcement actions involving Poczta Polska SA (Polish Post) in PL
Details
Fine Date
17 March 2025
Authority
Urząd Ochrony Danych Osobowych
Enforcement Tracker ID
2563
About this data
Cite as: Cookie Fines. Poczta Polska SA (Polish Post) - Poland (2025). Retrieved from cookiefines.eu
Last updated: