McDonald’s Polska Sp. z o.o.

€3,955,000

Non-compliance with general data processing principles

결정 날짜

2025년 7월 21일

권한

Polish National Personal Data Protection Office (UODO)

PL

섹터

Employment

국가

PL

법률

GDPR

상태

FINAL

설명

The Polish DPA has imposed a fine of EUR 3,955,000 on McDonald’s Polska Sp. z o.o. The controller used a third party processor (see ETid: 2758) for the purpose of managing work scheduals. The controller failed to ensure, that the processor implemented sufficient technical and organisational measures to ensure data security, resulting in a data breach. Additionally the controller failed to ensure, that only necessary data had been processed and the controller also did not adequatly involve the DPO in all relevant activities.

법적 인용

Art. 5 (1)Art. 25 (1)Art. 28 (1)Art. 38 (1)

문제 및 위반 사항

Non-compliance with general data processing principles

개인정보 보호 정책 시행에 대한 최신 정보

당사는 사용자의 개인정보를 존중합니다. 한 달에 한 번, 스팸 없이, 언제든지 구독을 취소할 수 있습니다.