UODO (Poland) - DKN.5131.3.2025

From GDPRhub
UODO - DKN.5131.3.2025
Authority: UODO (Poland)
Jurisdiction: Poland
Relevant Law: Article 33 GDPR
Article 34 GDPR
Type: Investigation
Outcome: Violation Found
Started:
Decided:
Published: 27.10.2025
Fine: 40.000 PLN
Parties: Gyncentrum
National Case Number/Name: DKN.5131.3.2025
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Polish
Original Source: UODO (in PL)
Initial Contributor: xz

The DPA fined a medical center €9,000 for failing to report a personal data breach to the DPA and to notify the affected data subject without undue delay. The data breach involved the transmission of sensitive data to an incorrect recipient.

English Summary

Facts

Gyncentrum, the controller, is a medical center. One incident occurred when an employee accidentally sent a confirmation of a successful bank transfer to the wrong patient. The document, which was intended for a patient, the data subject, was instead sent to another patient who happened to have the same first name. The document contained several pieces of personal data, including the data subject’s full name, address, and bank account number, as well as the amount of the transfer. Importantly, the title of the transfer also included the name of a genetic test, indirectly revealing sensitive information about the data subject’s health status.

The data subject did not get informed about the incident from the controller, but they found out by themselves. Also the controller argued that the incident did not create a risk to the rights or freedoms of the data subjects. Based on this assessment, the controller decided not to report the data breach to the Polish DPA, the UODO, and did not notify the data subject.

Holding

The UODO held that the controller violated their obligations under Article 33 and 34 GDPR. Specifically, the controller failed to report a personal data breach to the supervisory authority and failed to notify the data subjects without undue delay.

According to the UODO, the incident was the result of human error, however, the data controller’s evaluation of the risk level was found to be incorrect. The incident involved the unauthorized disclosure of sensitive personal data concerning health, which is a special category of data under Article 9 of the GDPR. Such information is inherently sensitive and its disclosure creates a high risk to the rights and freedoms of data subjects, including the potential for discrimination and violation of personal rights.

As a result, UODO fined the controller PLN 40,000 (€9,000) for failing to report the breach and issued a warning for its failure to notify the data subjects in a timely manner. The decision emphasized that reporting data protection breaches is a key tool for improving personal data security.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Polish original. Please refer to the Polish original for more details.

The President of the Personal Data Protection Office imposed a fine of PLN 40,000 on Gyncentrum for failing to report a personal data breach. In the same case, the President of the Personal Data Protection Office issued a warning to the company for failing to notify data subjects without undue delay.

A medical center specializing in infertility treatment, among other things, sent a confirmation of a return transfer, the subject line of which indicated the name of a genetic test to another person, also a patient of the Center (with the same name). The document contained personal data: first name, last name, bank account number, and address. It also included the transfer amount and the name of the test performed, revealing that it was part of an extensive prenatal diagnostic program.

During the proceedings before the President of the Personal Data Protection Office, it was determined that the incident was the result of an employee's error. However, the data controller determined that the incident did not involve a potential violation of the rights or freedoms of natural persons, and therefore refrained from reporting the breach to the President of the Personal Data Protection Office. The patient herself learned about the incident from another patient at the Center.

In this case, it is crucial to assess whether the situation poses a potential risk of violating the rights or freedoms of natural persons. The GDPR requires the use of a three-level scale when assessing this risk.

A breach does not need to be reported to the President of the Personal Data Protection Office (UODO), but only documented if the likelihood of a violation of the rights or freedoms of natural persons has been ruled out. However, such a situation occurs when, although the incident occurred, there is no risk of its consequences (the English version of the GDPR uses the word "unlikely," which has a stronger meaning than the Polish word "odporny" and is used to describe something that is rather unlikely or almost impossible).

If the risk cannot be considered negligible (the materialization of specific threats is probable), the controller is obligated to report the data breach to the President of the Personal Data Protection Office (UODO) and to record it in the internal breach register.

In addition to recording a breach in the register of breaches, the controller must take appropriate action both with the supervisory authority (reporting a personal data breach) and with the data subjects (notifying them of the personal data breach).

In the case of the erroneously sent return transfer confirmation, the President of the Personal Data Protection Office (UODO) believes the Controller misjudged the situation. The incident constituted a breach of data confidentiality, which poses a high risk of violating the rights and freedoms of natural persons. The information contained in the transfer confirmation allows for conclusions to be drawn about the health of data subjects. This creates a risk of specific negative consequences – such as the possibility of infringement of their personal rights or discrimination.

Since the risk is high, it is necessary to notify the President of the Personal Data Protection Office and the data subjects.

In the decision, the President of the Personal Data Protection Office (UODO) indicates that reporting personal data breaches by controllers is an effective tool for improving the security of personal data processing. When reporting a breach, controllers inform the supervisory authority whether, in their opinion, there has been a high risk to the rights and freedoms of data subjects and, if such a risk has occurred, whether they have provided relevant information to the individuals affected by the breach. In certain cases, they may also indicate that notification is not required due to the special circumstances provided for in Article 34(3) of the GDPR. The controller's position in this regard is subject to review by the Personal Data Protection Office (PUODO). It is worth emphasizing that incident notification and the PUODO's review of the correct handling of the incident serve the interests of both the controller and the data subjects, contributing to the proper implementation of the controller's obligations and the protection of the rights and freedoms of data subjects. Video with a statement by Karol Witowski, spokesperson for the Personal Data Protection Office (UODO) - version with subtitles:

Video with a statement by Karol Witowski, spokesperson for the Personal Data Protection Office (UODO) - version without subtitles:

DKN.5131.3.2025