Unknown – €358,000 Fine (Poland, 2024)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
A Polish company was fined EUR 358,000 for accidentally publishing customer data while redesigning its website. This incident affected about 20,000 people and highlighted the importance of securing personal data during website updates. Companies must ensure they have proper oversight and security measures in place when handling customer information.
What happened
A company published customer data, including names and email addresses, during a website redesign.
Who was affected
Approximately 20,000 customers whose personal data was published online.
What the authority found
The Polish DPA found that the company failed to ensure the security of personal data, violating several GDPR requirements.
Why this matters
This case emphasizes the need for businesses to implement strict data security measures, especially during website changes. Companies must actively oversee subcontractors to prevent similar data breaches.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The Polish DPA has imposed a fine of EUR 358,000 on a company. The company had inadvertently published customer data (first name, last name, email address, home address, encrypted passwords) in the process of redesigning its website. The incident affected approximately 20,000 data subjects. The DPA found that the controller had not sufficiently ensured the security of personal data during the process, for example, by conducting regular tests and risk assessments. Instead, it relied on information provided by the hired subcontractor without proper oversight.
Related Enforcement Actions (13)
Other enforcement actions involving Unknown in PL
Fine
€358K
Details
Fine Date
20 November 2024
Authority
Urząd Ochrony Danych Osobowych
Fine Amount
€358,000
Enforcement Tracker ID
ETid-2491
About this data
Cite as: Cookie Fines. Unknown - Poland (2024). Retrieved from cookiefines.eu
Last updated: