Sułkowice Cultural Center – €529 Fine (Poland, 2022)

€529Urząd Ochrony Danych Osobowych7 September 2022Poland
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Sułkowice Cultural Center was fined for not having a proper agreement with a company that handled personal data. This matters because it shows the importance of having clear contracts when sharing personal information. Small businesses should ensure they have written agreements in place to protect themselves and their users.

What happened

The Sułkowice Cultural Center failed to enter into a written data processing agreement with a company handling personal data.

Who was affected

Thirty individuals, including employees of the Sułkowice Cultural Center, were affected by the mishandling of their personal data.

What the authority found

The Polish data protection authority found that the Cultural Center did not have a valid legal basis for processing personal data, violating GDPR requirements.

Why this matters

This case highlights the necessity for companies to have proper contracts when outsourcing data processing. It sets a precedent that organizations can be held accountable for not ensuring their partners comply with data protection laws.

GDPR Articles Cited

Art. 28(1) GDPR
Art. 28(3) GDPR
Art. 28(9) GDPR
Full Legal Summary
Detailed

In May 2020, the Polish DPA received a notification of personal data breach caused by the Sułkowice Cultural Centre (the controller). The data breach affected 30 persons, including employees of the controller. The DPA initiated an investigation, in which it found that the controller entrusted the processing of personal data to an entity (the processor) without entering into a written data processing agreement. Moreover, they did not verify whether the processor provides sufficient guarantees of the implementation of appropriate technical and organisational measures in accordance with the GDPR. The processor was responsible for keeping accounting books and records as well as preparing reports. Therefore, they were entrusted with the processing of employee's and former employee's personal data, including names, dates of birth, bank account numbers, residence addresses, personal identification number (PESEL), email addresses, data on earnings and/or property, the mother's family names, series and numbers of ID cards, telephone numbers, and health data. Since the Polish DPA was not able to obtain information on any contract concluded between the controller and the processor with regards to the above-discussed processing operations, the DPA initiated ex officio administrative proceesings against the controller. First, the Polish DPA reiterated Article 28(1) GDPR, which prescribes that sufficient guarantees to implement appropriate technical and organisational measures must exist whenever the controller mandates data processing activities to be carried out on their behalf. Moreover, in line with Article 28(3) GDPR, a data processing agreement must be concluded between the controller and the processor, which stipulates the conditions of processing. Additionally, Article 28(9) GDPR requires the agreement to be in writing, including in electronic form. Second, the DPA clarified the roles of the entities involved in processing. As the employer and main administrator, the C

Related Enforcement Actions (0)

No other enforcement actions found for Sułkowice Cultural Center in PL

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

7 September 2022

Authority

Urząd Ochrony Danych Osobowych

Fine Amount

€529

Enforcement Tracker ID

ETid-1405

GDPRhub ID

gdprhub-5274

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Sułkowice Cultural Center - Poland (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: