The Warsaw University of Life Sciences – €11,500 Fine (Poland, 2020)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
The Warsaw University of Life Sciences was fined €11,500 after a staff member's private computer, containing personal data of applicants, was stolen. This incident shows the risks of using personal devices for work purposes and the importance of proper data security measures. Organizations should ensure their data protection strategies are robust and involve their Data Protection Officers in key processes.
What happened
A university employee's private computer, used for processing applicant data, was stolen, compromising personal data.
Who was affected
Applicants to the Warsaw University of Life Sciences whose personal data was stored on the stolen device.
What the authority found
The UODO found that the university failed to implement adequate security measures to protect personal data, leading to a data breach.
Why this matters
This case highlights the importance of securing personal data, especially when using personal devices for work, and involving Data Protection Officers in data handling processes to prevent breaches.
GDPR Articles Cited
A university employee used their private computer for business purposes, including for processing the personal data of study candidates at SGGW. The employee's device was stolen, which led to the personal data of up to 100000 data subjects being compromised. Furthermore, the records included the data of candidates from the last 5 years, although the prescribed storage period at SGGW was 3 months from the completion of the recruitment process. Among others, the data included contact details, grades from diplomas, average grade from studies, and the field of study for which the candidate was applying. Had the SGGW, acting as data controller, implemented appropriate technical and organisational measures to ensure the security of the personal data? The UODO held that the SGGW had not taken sufficient technical and organisational measures to ensure a level of protection appropriate to the risks of the processing operation. In its reasoning, the DPA emphasised that such measures should include the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of the processing systems, as well as a process for regularly testing, assessing, and evaluating the effectiveness of the measures put in place. Furthermore, the UODO held that the Data Protection Officer (DPO) did not have due regard to the risks associated with the processing operations. The DPO was not involved by the SGGW in the recruitment process, including the functioning of the IT system used for this purpose. The DPA emphasised that an increased involvement of the DPO by the university could reduce the risks of inappropriate processing operations.
Related Enforcement Actions (0)
No other enforcement actions found for The Warsaw University of Life Sciences in PL
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
21 August 2020
Authority
Urząd Ochrony Danych Osobowych
Fine Amount
€11,500
50,000 PLN
GDPRhub ID
gdprhub-2716About this data
Cite as: Cookie Fines. The Warsaw University of Life Sciences - Poland (2020). Retrieved from cookiefines.eu
Last updated: