UODO – €83,681 Fine (Poland, 2021)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Bank Millennium in Poland lost customer data but didn't properly inform the affected customers or the authorities. This oversight led to a fine of over €83,000. Businesses must notify both customers and regulators promptly in case of data breaches.
What happened
Bank Millennium lost customer data and failed to adequately notify the affected customers and the Polish DPA.
Who was affected
Customers of Bank Millennium whose personal data was lost were affected.
What the authority found
The Polish DPA fined the bank for not notifying the data breach as required by GDPR.
Why this matters
This case highlights the importance of transparency and timely communication in data breach situations. Companies should ensure they have procedures in place to notify both customers and authorities when data is compromised.
GDPR Articles Cited
Entities Involved
The data subjects are customers at Bank Millennium S.A. (hereafter: controller). They provided the controller with their personal data in March 2019 to have a bank account set up. In May 2019, the controller notified them of the loss of their personal data. However, since the data subjects did not obtain additional information on the breach, in June 2019 they filed a complaint with the UODO (Polish DPA). During the DPA’s investigation, it turned out that, in April 2019, the controller sent a parcel to its Head Office, with several documents. These documents contained, in particular, the following data: name, surname, PESEL, registered address, bank account numbers, CIF number (identification number assigned to the controller's clients) of the Applicant and the Applicant's name, surname and PESEL. The controller considered the circumstances of the breach, i.e., what personal data had been lost, and assessed this breach in accordance with a methodology based on the European ENISA methodology (a risk management assessment tool by the European Union Agency for Cybersecurity). Based on this assessment, the controller considered that the breach is likely to (only) cause a medium risk of violation of the rights and freedoms of the data subjects. Hence, it did not notify the data subjects in accordance with Article 34(1) GDPR, only supplying very general information on the nature of the breach, and that the data subjects could use the controller’s free Alert service to minimise the negative effects. Moreover, the controller also did not notify the DPA in accordance with Article 33(1) GDPR. During the DPA’s investigation, the controller brought forward a number of arguments why it had not notified the data subjects and the DPA, i.e., that parcels are also categorized as ‘lost’ without leaving the supplier’s infrastructure, that the loss of PESEL numbers does not cause a high risk for the rights and freedoms of the data subject, and that the data subject’s personal data was
Related Enforcement Actions (0)
No other enforcement actions found for UODO in PL
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
14 October 2021
Authority
Urząd Ochrony Danych Osobowych
Fine Amount
€83,681
363,832 PLN
GDPRhub ID
gdprhub-4361About this data
Cite as: Cookie Fines. UODO - Poland (2021). Retrieved from cookiefines.eu
Last updated: