Housing Association

€321

Insufficient fulfilment of data breach notification obligations

Date de décision

7 février 2023

Autorité

Polish National Personal Data Protection Office (UODO)

PL

Secteur

Real Estate

Pays

EE

Droit

GDPR

Statut

FINAL

Description

The Polish DPA has imposed a fine of EUR 321 on a housing association. The controller had suffered a data breach involving the theft of documents, including a copy of a notarial deed. During its investigation, the DPA found that the controller had both failed to report the data breach to the DPA in a timely manner and to notify the data subjects affected by the incident. Further, the DPA found that the controller had not adequately checked if the processor provided sufficient guarantees to implement appropriate technical and organisational measures to ensure data protection.

Citations légales

Art. 5 (1)Art. 28 (1)Art. 33 (1)Art. 34 (1)

Questions et violations

Insufficient fulfilment of data breach notification obligations

Restez informé sur l'application de la législation en matière de protection de la vie privée

Nous respectons votre vie privée. Un courriel par mois, pas de spam, désabonnement à tout moment.