Morele.net – Court Ruling (Poland, 2020)

Court Ruling
Urząd Ochrony Danych Osobowych3 September 2020Poland
final
Court Ruling

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

A Polish court upheld a fine against Morele.net for not securing customer data properly, leading to unauthorized access. This case underscores the importance of strong data protection measures for online businesses. Companies must ensure they have adequate security to protect customer information.

What happened

A Polish court upheld a fine against Morele.net for failing to secure customer data, leading to unauthorized access.

Who was affected

Customers of Morele.net whose personal data was accessed without authorization.

What the authority found

The court agreed with the data protection authority that Morele.net failed to implement adequate security measures, justifying the fine.

Why this matters

This case highlights the critical need for online businesses to implement robust security measures. It serves as a reminder that failing to protect customer data can lead to significant legal and financial consequences.

GDPR Articles Cited

Art. 5(1)(f) GDPR
Art. 83 GDPR
Art. 24(1) GDPR
Art. 25(1) GDPR
Art. 32(1)(b) GDPR
Art. 32(1)(d) GDPR
Art. 32(2) GDPR
Art. 58(2) GDPR
Decision AuthorityWSA Warsaw (Poland)
Reviewed AuthorityUODO (Poland)
Full Legal Summary
Detailed

In November 2018, the company reported to the supervisory authority two violations related to obtaining by an unauthorised person access to the database, and consequently - to personal data of customers of the company's online shops. After the inspection, the DPA concluded that the company had breached the rules on personal data protection. The deficiencies consisted in the violation by the company of the principle of data confidentiality, consisting in the failure to ensure the security and confidentiality of the processed personal data, which resulted in unauthorised persons gaining access to the personal data of the company's customers, and in the violation of the principle of legality, reliability and accountability by not showing that personal data from instalment applications collected before 25 May 2018 were processed by Morele.net Sp. z o.o. on the basis of the consent of the person to whom the data referred. In September 2019 UODO imposed a fine on the shop Morele.net in the amount of 2,830,410 PLN (660,000 EUR). The company appealed against this decision to the Provincial Administrative Court in Warsaw. Did the technical and organisational measures applied by the company comply with the standards of security measures in the business activity of entrepreneurs in the area of e-commerce of a scale and nature similar to the scale and nature of the company's activity in 2018? Were the technical and organisational measures applied by the company appropriate taking into account the state of technical knowledge, the cost of implementation and the nature, scope, context and objectives of the processing, as well as the risk of infringement of the rights or freedoms of natural persons of different probability and seriousness of the threat? The Provincial Administrative Court in Warsaw dismissed the appeal. The Court agreed with UODO and found that the fine imposed was justified.

Outcome

Court Ruling

A ruling by a national court on a data-protection matter.

Details

Ruling Date

3 September 2020

Authority

Urząd Ochrony Danych Osobowych

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Morele.net - Poland (2020). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: