Company – €135,600 Fine (Poland, 2024)

€135,600Urząd Ochrony Danych Osobowych18 December 2024Poland
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Polish DPA fined a company in the banking sector EUR 135,600. The DPA inspected the fined company and found several violations of the GDPR. First, the company failed to ensure that the DPO could report directly to top management and that the DPO did not receive instructions on the performance of the tasks given to the DPO. Second, the company failed to include profiling in the list of data processing operations. Third, the company failed to conduct a privacy impact assessment regarding the use of profiling. The violation regarding the DPO resulted in a fine of EUR 61,600. The violation regarding the unlawful use of profiling resulted in a fine of EUR 74,000.

GDPR Articles Cited

AI-verified

Art. 30(1) GDPR
Art. 35(1) GDPR
Art. 35(7) GDPR
Art. 38(3) GDPR
View original scraped data
Art. 38(3) GDPR
Art. 30(1) GDPR
Art. 35(1) GDPR
(7) GDPR

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Art. 104 § 1 Kodeks postępowania administracyjnego
Art. 7 ust. 1 i 2 ustawy o ochronie danych osobowych
Art. 60 ustawy o ochronie danych osobowych
Art. 90 ustawy o ochronie danych osobowych
Art. 101 ustawy o ochronie danych osobowych
Art. 103 ustawy o ochronie danych osobowych
Source verified 6 March 2026
amount discrepancy
national law identified
Full Legal Summary

The Polish DPA fined a company in the banking sector EUR 135,600. The DPA inspected the fined company and found several violations of the GDPR. First, the company failed to ensure that the DPO could report directly to top management and that the DPO did not receive instructions on the performance of the tasks given to the DPO. Second, the company failed to include profiling in the list of data processing operations. Third, the company failed to conduct a privacy impact assessment regarding the use of profiling. The violation regarding the DPO resulted in a fine of EUR 61,600. The violation regarding the unlawful use of profiling resulted in a fine of EUR 74,000.

Related Enforcement Actions (8)

Other enforcement actions involving Company in PL

Current
Dec 2024

Fine

€136K

Details

Fine Date

18 December 2024

Authority

Urząd Ochrony Danych Osobowych

Fine Amount

€135,600

Enforcement Tracker ID

ETid-2591

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Company - Poland (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: