Court case III C 904/23 – Court Ruling (Poland, 2026)

Court Ruling
DPA SOWarszawa16 February 2026Poland
final
Court Ruling

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

A Polish court ruled that the Financial Ombudsman improperly shared a customer's personal information with over 28,000 public institutions. This decision highlights the importance of protecting personal data and ensuring that companies take responsibility for data breaches. Small businesses should be aware that unauthorized data sharing can lead to legal consequences.

What happened

The Financial Ombudsman sent a letter containing a customer's personal information to 28,366 public institutions without proper authorization.

Who was affected

The customer whose personal data was disclosed without consent was affected by this incident.

What the authority found

The court found that the Financial Ombudsman was liable for the unauthorized disclosure of personal data, violating GDPR's requirement for data protection.

Why this matters

This ruling emphasizes that organizations must secure personal data and be accountable for breaches. Companies should ensure they have strong data protection measures in place.

GDPR Articles Cited

AI-verified

Art. 6(1) GDPR
Art. 82(GDPR)
View original scraped data
Art. 82(GDPR)

Original data from scraper before AI verification against source document.

Decision AuthorityRegional Court in Warsaw
Reviewed AuthoritySOWarszawa
Source verified 1 July 2026
articles corrected
authority corrected
Full Legal Summary
Detailed

The Financial Ombudsman’s office (the controller) sent a letter containing the name, the address, and the case reference number of a customer (the data subject) to 28,366 public institutions and entities registered on an official government platform in February 2021. The data subject demanded compensation for the unauthorised disclosure of his personal data from the controller in November 2021. The controller refused to accept liability for the incident. The supervisory authority issued the controller a reprimand in September 2022 for disclosure of personal data in violation of Article 6(1) GDPR. The data subject brought a lawsuit for damages under Article 82 GDPR before the Regional Court in Warsaw in August 2023. The data subject stated that they had experienced severe stress and lost the sense of security and control over their data as a result of the unauthorised disclosure of the letter. The controller argued it was not at fault for the incident as it was caused by a temporary IT system failure that the controller could not have foreseen. The Regional Court in Warsaw held that the controller was undoubtedly liable for the unauthorised disclosure of the data subject’s personal data pursuant to Article 82 GDPR: the controller was an administrator for the government platform and had not taken adequate measures to secure the data. Second, the court held that the data subject had suffered non-material damage in connection with the aforementioned incident. It took into account that the data had been disclosed to numerous entities. In addition, the deterioration of the data subject’s mental state was confirmed by a witness. The court awarded the data subject PLN 40,000 in damages. It considered the data subject’s claim of PLN 50,000 to be excessive in light of established case law.

Outcome

Court Ruling

A ruling by a national court on a data-protection matter.

Related Cases (0)

No other cases found for Court case III C 904/23 in PL

This is the only recorded case for this entity in this jurisdiction.

Details

Ruling Date

16 February 2026

Authority

DPA SOWarszawa

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Court case III C 904/23 - Poland (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: