Toyota Bank Poland S.A. – €18,000 Fine (Poland, 2024)

€18,000Urząd Ochrony Danych Osobowych12 March 2024Poland
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Toyota Bank Poland accidentally sent a letter containing personal information about one of its clients to the wrong person. This mistake led to a fine because the bank took too long to report the incident to the data protection authority. Timely reporting is crucial for protecting customer privacy.

What happened

Toyota Bank Poland sent a letter with personal data to the wrong client and delayed notifying the data protection authority about the breach.

Who was affected

The person whose personal data was mistakenly sent to another client of Toyota Bank Poland.

What the authority found

The data protection authority found that Toyota Bank Poland failed to notify them promptly about the data breach, violating Article 33(1) of GDPR.

Why this matters

This case highlights the importance of quick reporting of data breaches. Companies must understand that even minor incidents can lead to penalties if not handled properly.

GDPR Articles Cited

AI-verified

Art. 33(1) GDPR
View original scraped data
Art. 33(1) GDPR

Original data from scraper before AI verification against source document.

Source verified 13 March 2026
verified correct
Full Legal Summary
Detailed

Toyota Bank Poland S.A. (controller) is a bank established under Polish law. On 31 March 2021 an employee of the controller, by mistake, sent a letter with personal data of the data subject to another client. The letter contained personal data from the loan agreement concluded between the data subject and the controller, specifically: name, surname, bank account number, address, national ID number (PESEL), ID number. The (incorrect) addressee picked-up and opened the letter. Eventually, the controller took the letter back by sending a courier. The controller registered the incident within the internal register and performed a risk assessment. During the risk assessment, the controller took into account European Union Agency for Cybersecurity (ENISA) data breach guideline https://www.enisa.europa.eu/publications/dbn-severity ENISA Recommendations for a methodology of the assessment of severity of personal data breaches. According to the controller, the breach affected only one person, the letter was swiftly retrieved and the (incorrect) addressee was the controller’s client and helped to solve the problem. Because of that, the controller assigned the breach a low-risk level. Hence, the controller did not notify the DPA. Nevertheless, the controller decided to inform the data subject about the breach by sending a letter. The data subject filed a complaint with the DPA, claiming the controller unlawfully disclosed their personal data. During the complaint proceedings, on 7 September 2022, the controller notified the DPA about the breach. The notification was done almost 18 months after the breach. The controller explained the late notification with the minor risk assigned to the breach. As a consequence of late data breach notification, the DPA initiated ex officio proceedings regarding the violation of Article 33(1) GDPR. According to DPA, the controller failed to adequately assess the risk of the data breach. The DPA emphasised that the data subject interests sho

Related Enforcement Actions (0)

No other enforcement actions found for Toyota Bank Poland S.A. in PL

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

12 March 2024

Authority

Urząd Ochrony Danych Osobowych

Fine Amount

€18,000

GDPRhub ID

gdprhub-8099

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Toyota Bank Poland S.A. - Poland (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: