Unknown – €358,000 Fine (Poland, 2024)

€358,000Urząd Ochrony Danych Osobowych20 November 2024Poland
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

A Polish company was fined EUR 358,000 for accidentally publishing customer data while redesigning its website. This incident affected about 20,000 people and highlighted the importance of securing personal data during website updates. Companies must ensure they have proper oversight and security measures in place when handling customer information.

What happened

A company published customer data, including names and email addresses, during a website redesign.

Who was affected

Approximately 20,000 customers whose personal data was published online.

What the authority found

The Polish DPA found that the company failed to ensure the security of personal data, violating several GDPR requirements.

Why this matters

This case emphasizes the need for businesses to implement strict data security measures, especially during website changes. Companies must actively oversee subcontractors to prevent similar data breaches.

GDPR Articles Cited

AI-verified

Art. 5(1)(f) GDPR
Art. 5(2) GDPR
Art. 25(1) GDPR
Art. 28(1) GDPR
Art. 32(1) GDPR
View original scraped data
Art. 5(1)(f) GDPR
Art. 5(2) GDPR
Art. 25(1) GDPR
Art. 28(1) GDPR
Art. 32(1) GDPR
(2) GDPR

Original data from scraper before AI verification against source document.

Source verified 6 March 2026
amount discrepancy
entity split needed
national law identified
Full Legal Summary
Detailed

The Polish DPA has imposed a fine of EUR 358,000 on a company. The company had inadvertently published customer data (first name, last name, email address, home address, encrypted passwords) in the process of redesigning its website. The incident affected approximately 20,000 data subjects. The DPA found that the controller had not sufficiently ensured the security of personal data during the process, for example, by conducting regular tests and risk assessments. Instead, it relied on information provided by the hired subcontractor without proper oversight.

Related Enforcement Actions (13)

Other enforcement actions involving Unknown in PL

Current
Nov 2024

Fine

€358K

Details

Fine Date

20 November 2024

Authority

Urząd Ochrony Danych Osobowych

Fine Amount

€358,000

Enforcement Tracker ID

ETid-2491

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Unknown - Poland (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: