Centrum Medyczne Ujastek Sp. z o.o. – €273,000 Fine (Poland, 2024)

€273,000Urząd Ochrony Danych Osobowych17 January 2024Poland
appealed
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Centrum Medyczne Ujastek was fined €273,000 for illegally recording patients without their knowledge. The medical facility installed surveillance cameras in neonatal rooms, violating privacy rules. This case serves as a reminder for healthcare providers to respect patient privacy and follow data protection laws.

What happened

Centrum Medyczne Ujastek installed surveillance cameras in neonatal rooms without informing patients or staff.

Who was affected

Newborns and their mothers, who were recorded during private moments, were affected.

What the authority found

The Polish Data Protection Authority imposed fines for unlawful surveillance and for losing unencrypted recordings of the footage.

Why this matters

This case highlights the critical need for healthcare facilities to prioritize patient privacy and implement proper security measures for sensitive data.

GDPR Articles Cited

AI-verified

Art. 5(1)(a) GDPR
Art. 5(2) GDPR
Art. 6(1) GDPR
Art. 9(1) GDPR
Art. 13(1) GDPR
Art. 25(1) GDPR
Art. 32(1) GDPR
View original scraped data
Art. 5(1)(a) GDPR
f) GDPR
Art. 5(2) GDPR
Art. 6(1) GDPR
Art. 9(1) GDPR
Art. 13(1) GDPR
(2) GDPR
Art. 25(1) GDPR
Art. 32(1) GDPR

Original data from scraper before AI verification against source document.

Source verified 6 March 2026
amount discrepancy
date discrepancy
national law identified
Full Legal Summary
Detailed

The Polish DPA has imposed two fines on the medical facility “Centrum Medyczne Ujastek” totaling approximately EUR 273,000. The first fine of approximately EUR 163,000 was imposed for the unlawful installation of surveillance equipment in two neonatal rooms. These devices recorded images of newborns and their mothers during intimate acts such as breastfeeding or care without informing patients or staff, which constitutes a violation of data protection regulations. The second fine, of around EUR 110,000, was imposed due to the loss or theft of memory cards on which these recordings were stored. The cards were not encrypted and the devices were not configured in accordance with the required security standards. It was also found that the risk analysis of the center did not take into account the dangers that led to this incident. ---UPDATE--- Following an appeal by the controller, the Provincial Administrative Court in Warsaw upheld the imposed fine.

Related Enforcement Actions (0)

No other enforcement actions found for Centrum Medyczne Ujastek Sp. z o.o. in PL

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

17 January 2024

Authority

Urząd Ochrony Danych Osobowych

Fine Amount

€273,000

Enforcement Tracker ID

ETid-2518

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Centrum Medyczne Ujastek Sp. z o.o. - Poland (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: