UODO (Poland) - DKN.5131.4.2025

From GDPRhub
UODO - DKN.5131.4.2025
Authority: UODO (Poland)
Jurisdiction: Poland
Relevant Law: Article 38(3) GDPR
Article 38(6) GDPR
Type: Investigation
Outcome: Violation Found
Started: 24.02.2023
Decided: 02.01.2026
Published: 26.01.2026
Fine: 978128 PLN
Parties: Poczta Polska (Polish Post)
National Case Number/Name: DKN.5131.4.2025
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Polish
Polish
Original Source: UODO (in PL)
UODO (in PL)
Initial Contributor: aszo

The DPA fined the national postal operator €232,000 for appointing a DPO with a conflict of interest. The DPO concurrently served as a Security Director and representative of the controller, effectively monitoring their own decisions regarding the means of data processing.

English Summary

Facts

The case concerned Poczta Polska S.A., the Polish national postal operator (the controller). On 24 February 2023, the controller notified the Polish Data Protection Authority (UODO) of a personal data breach involving unauthorised access to a tax document .

While examining the breach notification, the DPA identified that the controller’s Data Protection Officer (DPO) simultaneously held several senior management roles within the organisation. In particular, the DPO served as:

i) Director of an organisational unit;

ii) Proxy for Classified Information Protection; and

iii) Proxy for the Information Security Management System.

Under the controller’s internal Organisational Regulation, the Director of unit “V.” was responsible for organising and improving the information protection system, including the protection of personal data. In that role, the DPO directly supervised the Information Protection Department, which was responsible for monitoring compliance, managing risks, conducting audits, and issuing opinions on contracts relating to data protection.

In addition, the DPO held a power of attorney granted by the Management Board to represent the controller before the DPA and administrative courts in data protection matters.

The controller acknowledged that it had not documented any formal assessment of potential conflicts of interest arising from the combination of these roles. It argued that no conflict existed because the DPO reported directly to the Management Board and was supported by a dedicated team. The controller also had not established any rules to prioritise the DPO’s tasks in the event of conflicting duties.

During the DPA’s investigation, in March 2025, the controller changed its organisational structure by dissolving unit “V.” and establishing an independent DPO function reporting directly to the Management Board.

Holding

The Polish DPA held that the controller infringed Article 38(6) GDPR by appointing a DPO who simultaneously held senior management positions involving responsibility for determining the means of processing personal data.

The DPA found that, as Director of unit “V.” and as proxy for information security, the DPO was responsible for designing, implementing, and supervising data protection and information security measures. As a result, the DPO was required to monitor compliance with decisions for which he was himself responsible, creating a structural conflict of interest.

The DPA rejected the controller’s argument that direct reporting to the Management Board and support from staff eliminated the conflict. It emphasised that the controller had neither documented an assessment of conflicts of interest nor established safeguards to prevent such conflicts.

The DPA imposed an administrative fine of €232,000. It noted that the controller’s later organisational changes removed the conflict but did not eliminate liability for the earlier infringement.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Polish original. Please refer to the Polish original for more details.

Decision
DKN.5131.4.2025
On the basis of Article 104 § 1 of the Act of 14 June 1960 - the Code of Administrative Procedure[1] (hereinafter referred to as the "KPA"), Article 7 paragraphs 1 and 2, Article 60, Article 101 and Article 103 of the Act of 10 May 2018 on the Protection of Personal Data[2] (hereinafter referred to as the "Personal Data Protection Act"), as well as Article 57 paragraph 1 letter a) and letter h), Article 58 paragraph 2 letter i), Article 83 paragraphs 1-3 and Article 83 paragraph 4 letter a) in conjunction with Article 38 paragraph 3 and paragraph 6 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter referred to as "Regulation 2016/679")[3],
after conducting ex officio administrative proceedings regarding the infringement of personal data protection provisions by T. (…) S.A. with its registered office in Z. at ul. (…) (hereinafter referred to as the "Company" or "Controller"), the President of the Personal Data Protection Office (hereinafter referred to as the "President of the Personal Data Protection Office" or "supervisory authority"):
finding that the Company has infringed the provisions of Article 38 paragraph 3 and Article 38 paragraph 4 6 of Regulation 2016/679, consisting in the Company's failure, as the controller, to ensure the independence of the Data Protection Officer's function and that the other tasks and duties performed by the Data Protection Officer do not result in a conflict of interest,
imposes an administrative fine on the Company in the amount of PLN 978,128 (in words: nine hundred seventy-eight thousand one hundred twenty-eight zlotys).

Justification
1.
On February 24, 2023, the Company submitted an initial notification to the President of the Personal Data Protection Office (UODO) of a personal data breach (supplemented by a notification submitted on March 6, 2023), consisting of an unauthorized person gaining access to personal data contained in the PIT-11 form.
2.
The aforementioned documentation indicated that the Data Protection Officer (hereinafter referred to as the "DPO") in the Company is held by Mr. H. S., who is also a Director within the Company. At the same time, Mr. H. S. – pursuant to the power of attorney granted to him by the Company's Management Board on February 16, 2021 – was authorized, among other things, to "(...) represent the Company in all proceedings pending before the President of the Personal Data Protection Office, as well as before the President of the Personal Data Protection Office, and to act on behalf of the Company before administrative courts in matters concerning proceedings before the President of the Personal Data Protection Office (...)."
3.
The personal data breach notification in question, registered under reference number DKN.5130.2004.2023, became an impulse for the supervisory authority to assess the Controller's compliance with its obligations under the provisions of Regulation 2016/679 regarding the appointment and status of a DPO.
4.
As a consequence of the review conducted pursuant to Article 58 paragraph 1 letter b) of the GDPR, On April 14, 2025, pursuant to Article 38(3) and (6) of Regulation 2016/679, the President of the Personal Data Protection Office (UODO) initiated ex officio administrative proceedings regarding the possible violation by the Company, as a data controller, of its obligation under Article 38(3) and (6) of Regulation 2016/679, due to the Company's failure to ensure that other tasks and duties performed by the DPO do not result in a conflict of interest (reference number DKN.5131.4.2025).

Facts

5.
By letters dated March 13, 2023, May 22, 2023, July 24, 2023, December 1, 2023, March 13, 2025, and April 7, 2025, the Supervisory Authority requested the Company to provide explanations regarding the performance of the DPO function by a person holding a managerial position in its organization (including, in particular, the presentation of documentation reflecting the Controller's analysis process to eliminate potential conflicts of interest related to the DPO's performance of other functions).
6.
The explanations provided by the Company in correspondence dated March 22, 2023, May 31, 2023, July 31, 2023, December 8, 2023, and April 10, 2025 indicate that:
1)
The Company is a controller within the meaning of Article 4(7) of Regulation 2016/679. 2)
Director (...) (hereinafter referred to as V.) served as the Company's Data Protection Officer, Representative for (...) and (...).
3)
In a letter dated March 22, 2023 (received on March 24, 2023), the Company indicated that the simultaneous performance of a managerial function by the Data Protection Officer "(...) was not deemed to constitute a conflict of interest, as Director V. does not determine the purposes and means of processing personal data at T. (...) S.A. (...)". In the Company's assessment, the performance of the DPO function by a person holding a managerial position took place taking into account the organizational, substantive and time criteria that were important from the point of view of ensuring the DPO's independence, i.e. "(...) the DPO reports to the highest management of the organizational unit, i.e. the President of the Management Board of T. (...) S.A.; the DPO does not receive orders from any persons in the Company; the location and functioning of the DPO in the organizational structure of the Company takes into account the number and complexity of processes, the organizational structure of the Company and its human resources." Furthermore, the Controller informed that "(...) the DPO and the Plenipotentiary for (...) are supported in particular by a team of full-time employees of the Department (...) (...)), the Head of which is also the permanent Deputy DPO and the Deputy Plenipotentiary for (...) (...)". Among the tasks of the said organizational unit, the Controller listed in particular: "(...) organizing, supervising and coordinating the security management system in the scope of information protection, including classified information, personal data, trade secrets and other legally protected secrets; supporting the Data Protection Officer in the implementation of tasks of informing and advising the controller, the processor and the Company's employees who process personal data on the obligations arising from the provisions of generally applicable law on personal data protection; monitoring the compliance of personal data processing at T. (...) S.A. and the processor with the provisions on personal data protection, as well as developing recommendations and instructions in this regard and supervising its implementation; implementing the standards required to maintain the System (...) compliant with the ISO 27001 standard; organizing and coordinating the service of external entities as part of inspections and audits carried out within the Company in the scope of information protection, legally protected secrets and personal data; providing opinions on draft agreements concluded by the Company in terms of ensuring the protection of information, legally protected secrets and personal data." Regardless of the above, the Company indicated that "(...) the DPO is, in particular: involved in all matters concerning personal data protection at T. (...) S.A., cooperates and consults with the relevant supervisory authority on matters related to personal data processing, is obligated to maintain confidentiality in the scope of the tasks performed, coordinates the implementation of the Personal Data Protection Policy at T. (...) S.A., ensures the publication of his/her contact details on the internal portal and on the pages of the Public Information Bulletin of T. (...) S.A.." The DPO is also obligated to present to the Company's Management Board the results of "(...) the annual review of the Data Protection Policy, which includes: compliance of the documentation with applicable law, compliance with the principles and obligations specified in the personal data processing documentation, and the possibility of improving this Policy." 4)
In a letter dated May 31, 2023 (presented by the Personal Data Protection Office: June 1, 2023), the Controller assured that "(...) it had analyzed for a potential conflict of interest in connection with the functions performed by Mr. H. S., but this was not documented." The Company also informed that "(...) under the Personal Data Protection Act of August 29, 1997, the controller function (...) was performed, along with other functions and tasks, by Director V., and this did not result in any conflict of interest." The Company refrained from specifying the division of working time allocated to the DPO function and other duties performed on its behalf, i.e., Director V., the Plenipotentiary for (...), and (...), perceiving such a solution as "(...) unjustified and highly impractical, and potentially preventing the proper performance of the function (...)." At the same time, the Controller argued that "(...) other tasks performed by the DPO (within the stipulated working time) may prevent the proper performance of the DPO's function, in particular as regards the timeliness of the activities undertaken."
5)
The Controller did not specify in any internal act the priority of the function performed (or duties performed) by the DPO in the event of a conflict between the DPO's tasks and duties and other tasks and duties performed for the Company or the inability to properly perform all the DPO's tasks due to the need to perform other tasks and duties for the Controller.
6)
By letter dated July 31, 2023 (date of receipt: August 3, 2023), the Company submitted the "Organizational Regulations (...)", constituting an annex to "Resolution No. (...) of the Management Board of T. (...) S.A. dated (...) regarding the Organizational Regulations (...)" (hereinafter referred to as the Regulations). § 2 of the document in question defines V.'s basic tasks, which – pursuant to point 3 – include "(...) organizing and improving the information protection system, including classified information, personal data, and other legally protected secrets (...)." In turn, § 6 point 7 states that the scope of activities of all organizational units and V.'s single-person position includes "(...) ensuring (...), including the protection of personal data in accordance with internal and external legal acts."
7)
By letter dated December 8, 2023 (date of receipt: December 13, 2023), the Company confirmed that the analysis of the functions performed by the DPO for a potential conflict of interest had not been documented, and referred to the opinion of the President of the Personal Data Protection Office regarding the possibility of the DPO simultaneously holding the position of proxy for (...)[4]. The Controller also reiterated the long-standing practice within its organization of Director V. combining the functions of the Data Protection Officer (formerly the Data Protection Officer) (along with other functions and responsibilities) with those of the Data Protection Officer (DPO). The Company reiterated the DPO's direct reporting to its top management and the fact that the DPO is supported in the performance of his duties by dedicated units of the Office he manages (divisions and departments). The Controller emphasized the importance of actions aimed at ensuring the continuity of the DPO's tasks by his permanent Deputy.
8)
By letter dated April 10, 2025 (date of receipt: April 11, 2025), the Company confirmed that the aforementioned Regulations constituted the exclusive internal regulation defining the tasks and competences of the units in which Director V. simultaneously performed the functions of the Data Protection Officer, the Representative for (...), and the Representative for the (...) System of T. (...) S.A. (in accordance with § 3 sec. 5 and 6 of the Regulations). Pursuant to the provisions of § 3 sec. 2 points 1, 4, 5 of the Regulations "(…) Director V. was responsible for the implementation of tasks and directly supervised the work of the following units: Department (...) (within which the Department (...) operated), Department (...), Department – (...). The tasks and competences of the above-mentioned units are defined in: - § 7 and § 11, i.e. Department (...) (including Department (...)) and Department – (...), whose employees, indicated by the Plenipotentiary for (...), constituted the department (...) within the meaning of the Act of 5 August 2010 on the protection of classified information; - § 10, i.e. Department (...), acting as the Team (...)." Regardless of the above, the Company announced: liquidation on (...) 2024 V., approval on March 24, 2025 by the Supervisory Board of the Company of amendments to its Organizational Regulations (Resolution of the Supervisory Board of T. (...) S.A. No. (...)), concerning, among other things, "(...) separating the function of the Data Protection Officer (DPO) within the data controller's structure, alongside other central units of the Company, which function reports directly to the Management Board of T. (...) S.A. (...) and confirming that the DPO performs only tasks arising from the provisions of the GDPR," and appointing a DPO in the Company by Resolution No. (...) of the Management Board of April 16, 2025.

In these circumstances, after reviewing all the evidence collected in the case, the President of the Personal Data Protection Office (UODO) considered the following:
General comments.
7.
Pursuant to Art. Pursuant to Article 34 of the Act of 10 May 2018, the Personal Data Protection Office (UODO), the President of the UODO is the competent data protection authority and the supervisory authority within the meaning of Regulation 2016/679. Pursuant to Article 57(1)(a) and (h) of Regulation 2016/679, without prejudice to other tasks specified under that Regulation, each supervisory authority on its territory shall monitor and enforce the application of this Regulation and conduct investigations into infringements of this Regulation, including on the basis of information received from another supervisory authority or other public authority.
8.
Pursuant to Article 4(7) of Regulation 2016/679, a controller is a natural or legal person, public authority, agency or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be laid down in Union or Member State law. 9.
Pursuant to Article 38(3) of Regulation 2016/679, the controller and processor shall ensure that the DPO does not receive instructions regarding the performance of these tasks. The DPO may not be dismissed or penalized by the controller/processor for fulfilling their tasks. The DPO is subject to the highest management level of the controller or processor.
10.
Pursuant to Article 38(6) of Regulation 2016/679, the DPO may perform other tasks and duties. However, the controller or processor shall ensure that such tasks and duties do not result in a conflict of interests.
11.
In light of the above, it should be noted that the EU legislator has introduced the possibility for the DPO to perform additional tasks and duties beyond those defined by the provisions of Article 38(4) and Article 39 of Regulation 2016/679. The above principle, however, does not exempt the controller (or processor) from the obligation to prevent potential conflicts of interest in the DPO's activities by entrusting them with additional duties and tasks. The CJEU made a particularly pertinent statement on this matter, stating in its judgment of February 9, 2023, that "(...) in accordance with the objective pursued by Article 38(6) of the GDPR, a DPO may not be entrusted with tasks or obligations that could jeopardize the performance of the functions they perform as DPO."[5] Consequently, the identification of a potential conflict of interest should be made in close relation to the DPO's tasks specified in the aforementioned provisions of Regulation 2016/679. This argument is strengthened by the fact that the primary purpose of the activities undertaken by DPOs remains to independently provide support to the aforementioned entities in the implementation of their obligations under personal data protection law[6]. 12.
The President of the Personal Data Protection Office has long held the position that, precisely because of the nature of the DPO's tasks, which focus on advising and monitoring the controller's (processor's) activities in terms of compliance of personal data processing operations with personal data protection regulations and the requirement to perform this function independently, the controller should not impose on the DPO tasks that, under Regulation 2016/679, belong to the controller (this refers to activities related to the performance of the controller's data processing tasks, including deciding on the purposes and means of data processing and ensuring the lawfulness of this process). Adopting a different assumption, where the DPO would be responsible for performing a specific task of the controller, e.g., reporting personal data breaches, and at the same time would be responsible for monitoring the compliance of this task with personal data protection regulations, as required by Article 39 paragraph 1 letter b) of the GDPR. b) of Regulation 2016/679 would lead to a situation in which the DPO would de facto supervise his or her own activities, thus leading to a conflict of interest. Of course, this conflict in the DPO's activities can also be considered in terms of time. It is obvious that if the DPO is entrusted with additional functions or tasks, they should have adequate time to properly perform them (taking into account, in particular, their complexity and number). Excessive concentration of responsibilities incumbent on the DPO may negatively impact the effectiveness of their activities, for example, in monitoring the compliance of personal data processing with personal data protection regulations and developing recommendations and guidelines in this regard, which is, after all, the quintessence of the DPO institution. 13.
Therefore, it is necessary to consider the amount of time required to perform individual duties (including cooperation with other inspection authorities), the complexity and importance of the tasks, the time available for unplanned tasks, the amount and type of personal data and the IT processes and systems used to process them, as well as the risks associated with these processes. Many other factors should also be considered, such as the structure, size, and human resources of the entity in question (including the obligation to conduct staff training)[7]. In this context, the Guidelines of the Article 29 Working Party are also relevant, as they recommend, as part of good practice, that the time allocated to the DPO's duties be determined depending on the nature of the processing activity, the activity, and the size of the organization[8].
14.
For a more comprehensive understanding of the concept of "conflict of interest," it is worth referring to the definition of "conflict" contained in the Dictionary of the Polish Language[9], which defines it as "a difference between values, attitudes, etc., which cannot be eliminated." It should therefore be noted that, under personal data protection regulations, a conflict of interest in the activities of a DPO always occurs when it is impossible to reconcile the proper performance of their tasks, assigned to them in the provisions of Article 38(4) and Article 39 of Regulation 2016/679, with the performance of other tasks and responsibilities, because there is a contradiction between these tasks and responsibilities, preventing their proper performance. In the case of a DPO, such a contradiction may result from them simultaneously fulfilling two roles or from taking actions or decisions that must then be subject to their assessment in accordance with Article 39(1)(b) of Regulation 2016/679.
15.
Regardless of the above, it should be clearly emphasized that a DPO, who is assigned a special role and particular importance in ensuring proper compliance with personal data protection regulations, must be guaranteed appropriate operating conditions for this purpose, i.e., conditions that allow them to effectively, independently, and properly perform their obligations under the law, as stipulated in Article 39(1)(b) of Regulation 2016/679. Article 38 paragraphs 2 and 3 of Regulation 2016/679. In this context, the view that imposing on the DPO tasks and responsibilities that lead to a conflict of interest not only calls into question the DPO's ability to effectively perform the tasks required by Article 39 of Regulation 2016/679, but also undermines the very foundations of the DPO institution, which is based primarily on its operational independence[10] should be considered correct.
16.
As indicated, the requirement to avoid a conflict of interest is – pursuant to Recital 97 of Regulation 2016/679 – closely linked to the controller's (processor's) obligation to ensure that the DPO performs its tasks independently (Article 38 paragraph 3 of Regulation 2016/679). Such an understanding of Article 38 paragraph 3 of Regulation 2016/679 is consistent with the principle of non-discrimination. Article 6 of Regulation 2016/679 is confirmed by the case law of the CJEU, which precisely states that "(...) this provision is essentially intended, like the other provisions referred to in paragraph 25 of this judgment, to preserve the functional independence of the DPO and thus to ensure the effectiveness of the provisions of the GDPR." The case law of the CJEU clearly states "(...) that the DPO cannot be entrusted with tasks or responsibilities that would lead to him determining the purposes and means of the processing of personal data by the controller or its processor. In accordance with EU law or the law of the Member States in the field of data protection, the monitoring of those purposes and means should be carried out independently by the DPO"[11].17.
The above-presented consensus of the supervisory authority and the jurisprudence on issues related to the concept of conflict of interest in the activities of a DPO is further confirmed by the opinion of the Article 29 Working Party contained in the Guidelines. It clearly states that "(...) The requirement not to create a conflict of interest is closely linked to the requirement to perform tasks independently. While DPOs [DPOs - added by the President of the Personal Data Protection Office] may have other tasks and responsibilities, these must not give rise to a conflict of interest. This means that a DPO cannot hold a position within an organization that involves determining the means and purposes of data processing. Due to the individual nature of each organization, this aspect should be analyzed separately for each entity." The Guidelines also present a sample set of management positions whose combination with the DPO function generally leads to a conflict of interest, i.e., CEO, COO, CFO, CMO, Marketing Manager, HR Manager, and IT Manager. Equally important, the Article 29 Working Party also considers lower-level positions to constitute a conflict of interest, provided that the individuals holding them participate in determining the purposes and means of personal data processing. At the same time, to prevent possible violations of Regulation 2016/679, the aforementioned Guidelines propose the implementation of specific measures. Best practices include, first and foremost, identifying positions incompatible with the DPO function by controllers or processors and developing internal rules to prevent the combination of positions that are subject to a conflict of interest.
18.
Considering the arguments cited above, it should be considered that any potential concentration of managerial and DPO functions, as well as situations involving entrusting the DPO with other tasks and duties within the controller's or processor's structure, should be preceded by an examination of the assigned duties for conflicts of interest. This argument, in which checking for the existence of a conflict of interest within the meaning of Article 38(1) of the GDPR, is considered inappropriate. Article 38(6) of Regulation 2016/679 should be assessed on a case-by-case basis, based on an assessment of all relevant circumstances (including, in particular, the organizational structure of the controller) and is consistent with the established case law of the CJEU[12]. Consequently, the failure of the entity appointing the DPO to conduct such an assessment exposes it to an allegation of failure to comply with the obligation referred to in Article 38(6), sentence 2 of Regulation 2016/679.
19.
Under these conditions, the entity entrusting the DPO with additional tasks and responsibilities should take into account at least three criteria: organizational (the DPO should report directly to the highest management level within the organization), substantive (other responsibilities should not negatively impact the independent performance of the DPO's tasks), and temporal (the DPO should have sufficient time to perform his or her duties, taking into account, among other things, the number of responsibilities and their complexity). As the doctrine rightly notes, the existence of a systemic conflict of interest undermines the independence of the DPO, while the occurrence of a time-based conflict reduces the DPO's effectiveness, while a substantive conflict negatively impacts their objectivity and independence[13]. At the same time, the risk of any of the aforementioned types of conflict arising should be constantly monitored, as the causes of such a conflict may also arise later, after the DPO has commenced performing his or her duties[14].
20.
Referring the above findings to the factual circumstances established during these proceedings, it should be noted that, in the Company's opinion, the performance of the DPO function by a person holding a managerial position takes into account organizational, substantive, and time-related criteria. However, the Controller did not substantiate the conduct of any analyses in this regard to prevent a conflict of interest, limiting itself to its own statement in this regard (see: point 3 of the factual findings). The organizational position of the DPO presented by the Company, making it, in accordance with the requirement of Article 38, sec. 3 of Regulation 2016/679 reporting to the highest management of the organizational unit, i.e. the President of the Management Board of T. (...) S.A., excludes – in the opinion of the President of the UODO – the existence of a conflict of interest of an organizational nature in the case at hand. Nevertheless, the content of the remaining explanations provided by the Company gives rise to a justified accusation against the Controller of a violation of Article 38 paragraph 6 of Regulation 2016/679 in terms of time and substance. This is primarily due to the fact that the Company did not document its analysis of a potential conflict of interest in connection with the DPO performing a managerial function within its structure, despite the fact that – in accordance with the legal requirements explained in the Guidelines and the above-mentioned case law of the CJEU – the Controller was obliged to do so taking into account an assessment of all relevant circumstances. Consequently, the Controller is unable to effectively demonstrate that it actually guaranteed the DPO appropriate operating conditions, enabling him not only to effectively but also independently perform the duties referred to in Article 39 of Regulation 2016/679 (especially since it is unable to provide sufficient evidence that any analyses were actually conducted within its organization).
Conflict of interest of a substantive nature.
21.
Although the company stated that Director V. (who also served as the Data Protection Officer) did not specify the purposes and methods of personal data processing, this is contradicted by the content of the Regulations disclosed by the company, which are in force at least until (...) 2024. The Regulations clearly state, among other things, in § 2 item 3, that the tasks of V. (headed by Director V.) included, among other things, "(...) organizing and improving the information protection system, including classified information, personal data, and other legally protected secrets (...)." It is therefore obvious that the person heading the unit substantively responsible for organizing and subsequently developing this system was, by definition, obligated to determine the purposes and means of personal data processing, not only within the framework of personal data processing processes carried out within the activities of the structure subordinated to it, but also within the personal data of its employees. Consequently, the person's decision-making regarding these purposes and means placed Director V. in the role of a data controller. This state of affairs unequivocally constituted a failure by the Company to comply with the obligation set forth in Article 38(6) of Regulation 2016/679, the ratio legis of which (as interpreted by the CJEU) aims to "(...) maintain the functional independence of the DPO, and thus ensure the effectiveness of the provisions of the GDPR" (see paragraph 42 of the cited CJEU judgment).
22.
The situation in which the designated DPO simultaneously held a managerial position in Director V., however, resulted in the exclusion of this independence. Director V. was responsible for the implementation of tasks and directly supervised the work of the organizational units subordinated to him (Department (...), within which the Department (...), Department (...), Department – (...)). Under these conditions, the DPO, who also held the above-mentioned position, was therefore unable to objectively perform the tasks assigned to him under Article 39 paragraph 1 of Regulation 2016/679. As a result of the operating conditions established by the Company, he remained responsible for determining the purposes and means of personal data processing, and at the same time, in accordance with Article 39 paragraph 1 letter b) of Regulation 2016/679, he was obliged to monitor the compliance of the processing processes he managed with the provisions on personal data protection. Consequently, the DPO de facto supervised his own activities within the Company, which undoubtedly constitutes an example of a substantive conflict of interest and demonstrates a gross violation by the Controller of the provision of Article 38 paragraph 6 sentence 2 of Regulation 2016/679. The DPO cannot be entrusted with tasks or responsibilities that would lead to the DPO determining the purposes and means of personal data processing at the controller or its processor, as monitoring of these purposes and means should be carried out independently by the DPO[15].
23.
There is also a noticeable contradiction between the functions of Director V., the Information Protection Officer, and (...) and the DPO regarding the performance by the DPO of the tasks specified in Article 38 paragraph 4 of Regulation 2016/679. The organizational solutions adopted by the Company resulted in the same person, on the one hand, acting in a position of authority, organizing the work of the organizational units subordinated to them, exercising supervision and control over the individuals employed within this structure, e.g., by evaluating the results of their work, and, on the other hand, acting as a contact point to facilitate contact between data subjects (employees) and the Controller. The wording contained in the cited provision of Regulation 2016/679 indicates that the DPO acts as a support point for data subjects, acting in their best interests (to the extent that they provide advice related to the processing of their data and the exercise of their rights under Regulation 2016/679).
24.
According to the legal doctrine, which the supervisory authority shares, this state of affairs could create conflict situations (which the Company cannot rule out, as it has not conducted any analyses in this regard). A scenario in which the DPO would act against the controller's interests, for example, by informing them of the possibility of filing a complaint with the supervisory authority, or against the interests of data subjects by refraining from providing them with such information, was realistic.[16]25.
The above state of affairs was not rebutted by the fact that "(...) under the Act of 29 August 1997 on the Protection of Personal Data, the function of the controller (...) [currently the Data Protection Officer – added by the owner] was performed, along with other functions and tasks, by Director V. (...)", which – in the Company's opinion – did not result in a conflict of interest. On the contrary: contrary to the Controller's intentions, this clearly confirms that – contrary to his claims – no conflict of interest analysis of the tasks performed by the Data Protection Officer in his organization actually took place, since the Controller a priori assumed that the long-term combination of the DPO function with other duties in his organization (including those related to making decisions regarding the purposes and methods of personal data processing) did not result in a conflict of interest. Furthermore, the Company's argument lacks logical justification also due to the issue raised therein of the long duration of the infringement of the provision of Article 38, paragraph 1. 6 of Regulation 2016/679, which – it seems – is intended to somewhat justify the violation of the law found in these proceedings. Instead, it clearly exemplifies the systemic nature of the violation of Article 38 paragraph 6 sentence 2 of Regulation 2016/679 attributed to the Controller.
26.
Regardless of the above, the President of the Personal Data Protection Office (UODO) also found a substantive conflict of interest within the Controller's organization, to the extent that the DPO was granted powers of attorney to act on behalf of the Company before the President of the Personal Data Protection Office or administrative courts in matters concerning personal data protection (including proceedings before a supervisory authority), as well as to represent the Company in matters concerning personal data within the Company, including providing information and responding to requests from data subjects (the content of these powers of attorney is included in the case files). Binding the DPO to the instructions of the Company, which acts as the principal in this relationship, naturally limits the representative's objectivity, consequently negatively impacting their independence, which should characterize the DPO. As established, the specific nature of the DPO's tasks should focus on advising and monitoring the controller's (processor's) activities in terms of compliance with personal data protection regulations, rather than achieving established procedural goals.[17] The practice of granting the DPO broad powers of attorney to represent the Controller, as demonstrated by the Company, therefore led to a violation of the prohibition on imposing on the DPO tasks that cause a conflict of interest (Article 38, paragraph 6 of Regulation 2016/679) and the prohibition on the DPO receiving instructions regarding the performance of tasks (Article 38, paragraph 3 of Regulation 2016/679) – especially considering the DPO's subordination to the highest management of the organizational unit, i.e., the President of the Management Board of T. (...) S.A.[18] Temporal conflict of interest.
27.
During the explanatory proceedings, the supervisory authority determined that the Company failed to determine the priority of the function performed (or duties performed) by the DPO in the event of a conflict between the DPO's tasks and duties and other tasks and duties performed for the Controller, or the inability to properly perform all of the DPO's tasks due to the need to perform other tasks and duties for the Company (see: point 5 of the factual findings). Meanwhile, as the doctrine rightly points out: "A conflict of interest may also result from an excess of duties entrusted to the data protection officer in a situation where the officer will have to choose which duties to perform and which they will not be able to perform due to a lack of time required for their performance"[19]. In this context, the President of the Personal Data Protection Office further reiterates his view that considering the time criterion should therefore include an analysis of whether the DPO, while simultaneously performing other functions, will be able to perform their duties properly, taking into account, in particular, the complexity and number of other tasks[20]. It is obvious that the DPO should have adequate time to properly perform all the tasks referred to in Article 39 of Regulation 2016/679. The Controller should, however, – in accordance with the requirements of Article 38 paragraph 2 of Regulation 2016/679 – support the DPO in fulfilling these tasks. By refraining from conducting such an analysis, the Company is therefore unable to effectively demonstrate that the DPO designated within its structure could effectively perform his or her duties, especially since he or she was also assigned tasks and responsibilities related to the position of Director (...), Representative for (...), and (...).
28.
Conducting such an analysis based on an assessment of all relevant circumstances, in particular the Controller's organizational structure, would therefore require the Company to carefully consider, among other things, the amount and type of classified information, as well as the time and capacity to perform all the tasks specified in Article 15 of the Act on the Protection of Classified Information, which include, among others, ensuring (...), including the use of physical security measures, ensuring the protection of IT systems in which classified information is processed, security risk management, in particular risk assessment, control (...), and compliance with regulations on the protection of such information[21]. However, the Company has not demonstrated that it ever conducted any analyses in this regard. The Controller's failure to reliably verify whether the DPO is able to perform his or her duties properly while simultaneously performing all the functions entrusted to him or her (as well as to clarify the division of working time allocated to the DPO function and other duties performed on its behalf, i.e., Director V., Plenipotentiary for (...) and (...)), clearly demonstrates his or her inconsistency, especially when he or she referred to the above-mentioned opinion of the President of the Personal Data Protection Office regarding the possibility of the DPO simultaneously performing the function of proxy for (...). 29.
However, the above does not invalidate the arguments presented so far, indicating that even if the Company had made such an assessment in this respect, this circumstance would not have eliminated the conflict of interest in the substantive activities of the DPO (see point II.B).
30.
Importantly, to achieve this objective, it is not necessary to strictly define the allocation of time that a person combining the DPO function with other functions is to devote to the performance of individual duties. In this sense, the supervisory authority does not deny the admissibility of departing from the solution consisting in clearly and rigidly defining the time frames for the performance of the DPO's duties and the duties related to the other functions or tasks performed by them. In principle, the Company is therefore correct in arguing that in some cases "(...) [such a solution should be assessed as unjustified and highly impractical, and could potentially prevent the proper performance of the function (...)" (see point 4 of the factual findings). Nevertheless, such an assessment should be based on realistic grounds, and therefore be the result of an analysis of the existence of a conflict of interest in the DPO's activities within the Controller's organization (a fact that the Company, however, is unable to demonstrate). Consequently, the Controller cannot, in order to demonstrate compliance with the provision of Article 38(6) of Regulation 2016/679, rely solely on its own declaration that imposing other tasks and responsibilities on the DPO does not negatively impact the effectiveness of those undertaken under Article 39 of Regulation 2016/679. This argument is strengthened when compared with the requirement to provide the DPO with conditions to actively perform their legally assigned duties. This approach is demonstrated, in particular, by the DPO submitting initiatives, e.g., regarding instructions addressed to the Controller regarding data processing activities, rather than merely reacting to events within the organization[22]. 31.
Therefore, in accordance with the risk-based approach to the DPO's activities (Article 39, paragraph 2 of Regulation 2016/679), which assumes a proactive stance, it becomes all the more necessary for the Controller to provide the DPO with the conditions (including time) necessary to perform their duties effectively. This requirement is clearly not met by the Company's failure to establish even a minimum framework of working time devoted exclusively to the DPO's duties assigned to them under Article 39 of Regulation 2016/679. At the same time, the Controller's claim that establishing rigid time frames for the performance of individual tasks may hinder the performance of the DPO's functions (see point 4 of the factual findings) remains unfounded, as the Company has not demonstrated that it ever conducted any analyses in this regard. Consequently, the Controller did not verify whether the DPO was able to perform his or her duties properly and effectively, based on the a priori assumption that "(...) other tasks performed by the DPO (within the designated working hours) may prevent the proper performance of the DPO's functions (...)."
32.
The President of the Personal Data Protection Office (UODO) took into account the Company's explanations, in which it referred to the support provided to the DPO appointed within its structure by a dedicated team of individuals (see point 3 of the factual findings). He also took into account the position cited in the Guidelines, according to which "Depending on the size and structure of the organization, it may be useful to appoint a team of data protection officers (DPO and their employees). If such a team is appointed, its structure, division, and scope of responsibilities should be clearly defined. Also, if a DPO is appointed from outside the organization, a team of employees from an external entity appointed to fulfill personal data protection obligations can effectively fulfill the DPO's duties if a person responsible for contact with the customer is appointed." The consequence of adopting this approach is that the DPO is not obliged to personally perform all the tasks and obligations incumbent on them under Article 39 of Regulation 2016/679. They can therefore, as a decision-maker, rely on the resources of their team.33.
This does not mean, however, that the Controller, by providing the DPO with a team of collaborators, could disregard the time criterion for the DPO to effectively fulfill its legally assigned duties (in particular, bearing in mind the need for a proactive approach demonstrated by the DPO's actions, in accordance with Article 39(2) of Regulation 2016/679). The fact that the DPO utilized the support of a team of "(...) full-time employees of the Department (...) ((...)), whose Head is both the permanent Deputy DPO and the Deputy Plenipotentiary for (...)" did not yet meet the above requirement. This is the case for two reasons. First, the Company's omission of the stage where it would have analyzed the time required for the DPO to effectively complete its tasks (this rational conclusion is drawn from the fact that the Controller failed to present any evidence sufficiently substantiating the fact that such an analysis was conducted) deprives the Company of a rational basis for believing that a DPO team is even necessary within its structure. Second, the appointment of such a specialized body without demonstrating such a thorough analysis undermines the Controller's position that the members of this team (who, as the Company explains, also perform other professional duties in parallel) will have sufficient time to effectively support the DPO in his duties. The Controller, unaware of the team's needs, also could not have been aware of the DPO's role within it, i.e., whether it should be more active and coordinating (as a risk-based approach would dictate), or responsive given the number of tasks the DPO and his subordinate group must perform. In other words, under these circumstances, despite appointing a DPO team, the Company was still unable to demonstrate that the DPO supported by this team was performing their function effectively, and therefore that the Controller had created appropriate operating conditions for them (enabling effective, independent, and proper performance of their obligations under the law).
34.
Regardless of the above, the supervisory authority also noted that the Deputy DPO simultaneously held the position of Head of Department (...) ((…)) within the Company, whose duties include, among others, "(…) organizing, supervising, and coordinating the security management system for the protection of information, including classified information, personal data, trade secrets, and other legally protected secrets (...)." It is therefore obvious that the Head of Department (...) determined the purposes and means of processing personal data (including those of individuals employed in the structure under his control). In this situation, all substantive comments regarding conflicts of interest made in Chapter II.B should be addressed to the Deputy DPO. The justification for this decision. Consequently, for this reason, the Controller cannot be said to have met the requirement set out in Article 38(6) of Regulation 2016/679.

Infringement of the provisions of Article 38(3) and Article 38(6) of Regulation 2016/679.
35.
As a result of its negligence, the Company failed to create conditions for the DPO (and his team) to perform their duties and tasks independently. By failing to meet the requirement of independence for the DPO, the Controller failed to meet its obligation to enable the DPO to perform these tasks in accordance with the objective of Regulation 2016/679, which – as stated in recital 10 thereof – aims to ensure a high level of protection of natural persons in the Union[23]. 36.
The Company's inability to demonstrate that it conducted an analysis to determine whether the DPO is capable of properly performing all of its duties simultaneously, as well as its failure to clarify the division of working time allocated to the DPO function and other duties performed on its behalf, i.e., Director V., Representative for (...), and (...), constitutes a violation of the Controller's obligation to prevent conflicts of interest of a time-based nature, which undermines the effectiveness of the DPO function.
37.
The DPO's role as the Company's proxy, by being bound by the Company's instructions, not only adversely affected his independence but also undermined his objectivity.
38.
As a consequence of the violations of Article 38 sec. 3 and sec. 4 of the Personal Data Protection Act, which were demonstrated to the Controller over a broad timeframe, 6 of Regulation 2016/679, he cannot therefore validly claim that he enabled the DPO to perform his duties properly, i.e., independently, objectively, and effectively.
39.
Until the first organizational changes in the Controller's structure, which took place in (...) 2024, when "(...) V. was liquidated," the Company's corporate governance included Director V. consolidating the functions of the DPO, the Representative for (...), and (...). Furthermore, this system operated within its structure even under the Personal Data Protection Act of 29 August 1997, when "(...) the function of the controller (...) was performed, along with other functions and tasks, by Director V (...)." This state of affairs, which continued uninterrupted until that date, never resulted in – in the Company's opinion – "(...) cases of conflict of interest." It also remained steadfast in its position, rejecting as "(...) unjustified and highly impractical, and potentially preventing the proper performance of the function (...)" the need to clarify the division of working time allocated to the DPO function and other duties performed on its behalf. The Controller even advanced the thesis that "(...) other tasks performed by the DPO (within the working time allocated to them) may prevent the proper performance of the DPO function, in particular as regards the timeliness of undertaken activities." Consequently, until the aforementioned organizational changes, the Controller did not specify in any internal act the priority of the function performed (or duties fulfilled) by the DPO in the event of a conflict between the DPO's tasks and duties and other tasks and duties performed on behalf of the Company, or the inability to properly perform all the DPO tasks due to the need to perform other tasks and duties on behalf of the Controller. Despite the Company's long-standing practice of systemic violation of the provision of Article 38, sec. 6 of Regulation 2016/679, it ultimately decided to implement changes to its Organizational Regulations, consisting of "(...) separating the function of the Data Protection Officer (DPO) within the structure of the data controller, alongside other central units of the Company, which function reports directly to the Management Board of T. (...) S.A. (...) and confirming that the DPO performs exclusively tasks arising from the provisions of the GDPR," which took place only on March 24, 2025. Therefore, in light of the solutions adopted by the Company, it can be concluded that, based on the implemented organizational changes, it has eliminated the "conflict of interest" in the activities of the DPO. The supervisory authority primarily took into account not only the fact that the Company separated the DPO function, but also the separation (within the new structure of the Company) of the division responsible for monitoring the Controller's compliance with personal data protection regulations from those departments responsible for implementing personal data protection solutions.
40.
It should be emphasized here that the Controller, in accordance with the principle of accountability expressed in Article 5, sec. 2 of Regulation 2016/679, is obliged to demonstrate that it meets the requirements of Regulation 2016/679 by proving that it has developed and applies measures to comply with personal data protection regulations, in this case, that it has adopted internal solutions aimed at effectively ensuring that the DPO does not perform tasks and responsibilities that create a conflict of interest. As mentioned above, the Article 29 Working Party recommends the development of such rules in its Guidelines. This change, beneficial from the perspective of the Controller's need to demonstrate compliance with the provisions of Regulation 2016/679, not only clearly undermines the credibility of the arguments it has presented so far. It also clearly confirms the Company's long-standing violations of the provisions of Article 38 paragraphs 3 and 6 of Regulation 2016/679, as the Controller has recognized the need to separate the DPO function and entrust him solely with the tasks arising from the provisions of that Regulation. The Company therefore implicitly recognized that the current positioning of the DPO within its organizational structure generated contradictions in its activities, which could not be avoided except by implementing the organizational measures referred to in point 6(8) of the description of the facts.
41.
In summarizing the assessment of the circumstances of the infringement of the provisions of Regulation 2026/679 in question, it should be emphasized that these provisions are aimed at protecting the fundamental rights and freedoms of natural persons, in particular their right to the protection of personal data (Article 1(2) of Regulation 2016/679), and that the protection of natural persons with regard to the processing of personal data is a fundamental right (first sentence of recital 1 of the preamble). The Data Protection Officer, who enjoys a special status in the personal data protection system (pursuant to Article 38 of Regulation 2016/679), remains the guarantor of these rights of natural persons within the scope of the tasks performed (defined in Article 39 of Regulation 2016/679). A necessary condition for maintaining this status is the functional independence of the DPO, which is ensured by the provisions of Article 38 paragraph 3 and Article 38 paragraph 6 of Regulation 2016/679[24].

Administrative fine.
42.
The administrative proceedings conducted by the President of the Personal Data Protection Office (UODO) are aimed at verifying the compliance of data processing with personal data protection regulations and are aimed at issuing an administrative decision to exercise the remedial powers specified in Article 58 paragraph 2 of Regulation 2016/679.
43.
Taking into account the above, as well as the violations of personal data protection provisions identified in these proceedings, the President of the Personal Data Protection Office – exercising the authority specified in Article 58 paragraph 2 letter i) of Regulation 2016/679, pursuant to which each supervisory authority has the power to apply, in addition to or instead of the measures referred to in Article 58 paragraph 2 letters a) to h) and letter j) of that Regulation, an administrative fine specified in Article 83 paragraph 4 letter a) – found that in the case at hand, the conditions justifying the imposition of an administrative fine on the Company had materialized.
44.
Pursuant to Article 83 paragraph 4 letter a) of Regulation 2016/679, a violation of the provisions concerning the obligations of the controller and processor referred to in Article 8, 11, 25-39, 42 and 43, shall be subject to an administrative fine of up to EUR 10,000,000, or in the case of an enterprise, up to 2% of its total annual worldwide turnover in the preceding financial year, whichever is higher.
Conduct subject to administrative fines and application of Article 83(3) of Regulation 2016/679.
45.
Pursuant to Article 83(3) of Regulation 2016/679, if the controller or processor intentionally or negligently, within the same or linked processing operations, infringes several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount of the fine for the most serious infringement. 46.
Having established that the Company had, in the circumstances under review, violated two provisions of Regulation 2016/679 (i.e., Article 38 paragraph 3 and Article 38 paragraph 6, each of which could constitute a separate basis for imposing an administrative fine), the President of the Personal Data Protection Office was obliged to take into account the regulation cited in the preceding paragraph in order to consider whether the circumstances of this case determine the supervisory authority's use of only one or several corrective measures provided for in Article 58 paragraph 2 of Regulation 2016/679 – or more precisely, whether the authority should impose only one administrative fine on the Company in response to both infringements committed by the Company, or separate and independent penalties for each of these infringements considered separately. 47.
When determining the specific sanctions for the infringements found in this case, the President of the Personal Data Protection Office (UODO) used the methodology for calculating administrative fines adopted by the European Data Protection Board (hereinafter referred to as the "EDPB"), according to which the first step for further calculations is to "assess the application of Article 83(3) [of Regulation 2016/679]"[25] by determining:
a)
whether the circumstances indicate a single conduct or multiple conducts subject to sanction,
b)
in the case of a single conduct, whether this conduct constitutes a single infringement or multiple infringements, and
c)
in the case of a single conduct that constitutes multiple infringements, whether the attribution of one infringement excludes the attribution of another infringement, or whether they should be attributed in parallel[26]. 48.
According to the interpretation adopted by the EDPB, "one conduct may consist of several parts that are carried out as a result of a single act of will and are so closely linked contextually (in particular with regard to the identity of the data subject, the purpose and nature of the processing), spatially and temporally that, from an objective point of view, they can be considered to constitute one coherent conduct."[27] 49.
Applying the above to the circumstances of the case at hand, the President of the Personal Data Protection Office found that the Company's omissions – consisting in failing to ensure that the Data Protection Officer did not receive instructions regarding the performance of his or her duties and that the other tasks and duties performed by him or her did not result in a conflict of interest – constituted "one coherent conduct" within the meaning presented by the EDPB. This interpretation is supported by the fact that the Company’s conduct (resulting in a breach of Article 38 paragraph 3 and Article 38 paragraph 6 of Regulation 2016/679), although not necessarily the result of a single act of will of the controller, is the result of a long-term, flawed approach of the controller to the role that the DPO should play in the Company’s structures and to the manner in which he should perform his tasks specified in Article 38 paragraph 4 and Article 39 of Regulation 2016/679. This resulted, on the one hand, in the Company failing to conduct an appropriate analysis to eliminate a potential conflict of interest related to the DPO's performance of other functions, and, on the other hand, in the Company's failure to implement appropriate organizational and procedural solutions that would ensure that the DPO would perform his or her tasks independently, free from instructions and commands from the controller, and without the risk of a conflict of interest – which was obvious in this case, given the DPO's simultaneous position as Director V., entrusted with determining the purposes and means of personal data processing in the Company (see Part II.B. of the justification for the decision). The failure to conduct appropriate analyses and adopt internal procedures, as a continuous and lengthy process, resulted in a violation of the provisions of Regulation 2016/679 regarding the status of the DPO, led to the Company being unable to demonstrate to the supervisory authority the compliance of its actions with the provisions of Regulation 2016/679. This situation was remedied only by the Company's decision to liquidate V. and separate the DPO position within its organizational structure, alongside other central units of the Company, reporting directly to the Management Board of T. (...) S.A.
50.
Although the violations alleged against the Company were not committed in connection with any of its processing operations – which is one of the conditions for the application of Article 83(3) of Regulation 2016/679 – but concerned irregularities in the proper definition of the status and powers of the Data Protection Officer, the supervisory authority believes that this provision should apply in this case. This is due to the fact that the identified violations could, during their duration, indirectly negatively impact the security of data processing at the Company and the proper protection of the rights, freedoms, and interests of data subjects (although this impact was not direct and automatic). Furthermore, the functional interpretation of Article 83(3) of Regulation 2016/679 Article 3 of Regulation 2016/679 supports the assumption that a controller committing several infringements resulting from a single act of conduct – as in the case at hand – should not be punished as severely as a controller committing multiple, separately motivated acts, separated in time and context, which nevertheless concern the same or related processing operations. This would be highly unfair. In the opinion of the President of the Personal Data Protection Office, all the above-mentioned circumstances require that the infringements attributed to the Company be considered together.
51.
Therefore, assuming that the Company's failure to ensure that the Data Protection Officer does not receive instructions regarding the performance of his or her duties and that the other tasks and duties performed by him or her do not result in a conflict of interest constitute a single, coherent act, and that this act violates several provisions of Regulation 2016/679 (Article 38, paragraph 3 and Article 38, paragraph 6), it should further be stated that none of these infringements excludes the possibility of attributing the second infringement to the Company. Each of the aforementioned provisions contains a different (separate) standard, specifying how a controller should ensure the DPO's decision-making freedom and independence within its organization. The consequence of the above is that the Company's liability in these proceedings should be "parallel" to all infringements committed, i.e., applying the provision of Article 83 paragraph 3 of Regulation 2016/679.
52.
In summary, in this case, an administrative fine was imposed on the Company for violating Article 38 paragraph 3 and Article 38 paragraph 6 of Regulation 2016/679. With respect to both of these infringements, the provision of Article 83 paragraph 3 of Regulation 2016/679 was applied, however – since both infringements are subject (in abstracto) to the same penalty under Article 83 paragraph 4 letter b) of Regulation 2016/679. 1(a) of Regulation 2016/679, in the amount of up to EUR 10,000,000 or up to 2% of the annual turnover – these infringements should be assigned the same gravity, being considered “most serious” within the meaning of Article 83(3) of Regulation 2016/679. Consequently, it is impossible to impose a fine for the above-mentioned infringements higher than the maximum fine for one of them, i.e., EUR 32,274,822.82 – due to the need to adopt the so-called “dynamic maximum fine” for the Company (see point 75 of the justification for the decision).

Justification for the imposition and determination of the amount of the administrative fine imposed on the Company.

Periods of the penalty – application of Article 83(2) of Regulation 2016/679.
53.
In deciding to impose an administrative fine on the Company, the President of the Personal Data Protection Office – pursuant to Article Pursuant to Article 83 paragraph 2 letters a) - k) of Regulation 2016/679, the Court took into account the following circumstances of the case, which constitute the necessity of applying this type of sanction in this case and have an aggravating effect on the amount of the administrative fine imposed.
54.
The nature, gravity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing in question, the number of data subjects affected, and the extent of the damage they suffered (Article 83 paragraph 2 letter a) of Regulation 2016/679). The nature of the infringement constitutes an aggravating circumstance for T. (…) S.A. As a professional entity, within the framework of its business activities, (…) and involves a relatively high risk of violating the rights and freedoms of data subjects. This circumstance supports the assumption that the Company should have exercised special diligence to ensure that the status of the DPO appointed by it, the tasks entrusted to him, and the manner of performing them comply with the requirements set out in the provisions of Regulation 2016/679. The EU legislator, in the text of Article Article 38 paragraphs 3 and 6 of Regulation 2016/679 therefore prohibited the controller from issuing instructions to the DPO regarding the performance of his or her tasks, and at the same time established the obligation to ensure that the performance of any other tasks and duties by the DPO does not result in a conflict of interest, as it considered that – due to the nature and importance of this function for data security – it is significant and requires full independence, both organizational and substantive. Meanwhile, by failing to meet the aforementioned requirements, the Company has clearly weakened the security of the processed data and betrayed the fundamental obligations of a controller established in the provisions of Regulation 2016/679. The violation of standards related to the status and proper positioning of the DPO within the Controller's structure is also significant due to: the wide scope of personal data processed by the Company (...), the manner of their processing (using ICT systems, (...)), and the large scale of processing. Ensuring the independence of the DPO in an institution such as T. (...) S.A. – considering the above processing circumstances, i.e., taking into account the nature, scope, and scale of data processing by the Company – impacts the security of this data and, consequently, the rights and freedoms of individuals whose data are processed, including the manner in which they are exercised. Considering the above, the nature and gravity of the identified violations should be considered a criterion significantly influencing the authority's decision to impose an administrative fine.55.
In this context, the fact that the violation of the provisions of Regulation 2016/679 regarding the status of the Data Protection Officer (DPO) was continuous and long-term should also be considered aggravating. As evidenced by the collected evidence, Director V.'s consolidation of the functions of the DPO (and previously: the controller (...)), the Representative for (...), and (...) took place under the provisions of the Personal Data Protection Act of 29 August 1997 and continued until (...) 2024, when the Company decided to liquidate V. A logical consequence of this decision was further changes in the Company's organizational structure and the separation of the DPO function on 24 March 2025, alongside other central units of the Company reporting directly to the Management Board of T. (...) S.A. Consequently, it should be stated that the Company took the first corrective actions to restore the Company's internal regulations to the currently applicable provisions regarding the position and independence of DPOs only more than six years after the provisions of Regulation 2016/679 entered into force (with full force). Such a long duration of the infringements could not have been without impact on the supervisory authority's decision, both to impose an administrative fine and its amount – resulting in a corresponding increase.
56.
The infringements of Article 38(3) and (6) of Regulation 2016/679 found in this decision are not affected – under the premise under consideration – by the number of data subjects affected and the extent of the damage they suffered, as no damage was found to have occurred on the part of the data subjects in this case. It should be noted, however, that the violations in question were not directly related to the Company's processing of personal data (although they may have indirectly affected its security). Therefore, damage to individuals in this case did not and could not have occurred due to the nature of these violations, which were formal in nature. Regardless of the above, the assessment of this premise, considered as a whole, requires that it be treated as an aggravating factor.
57.
Intentional nature of the Company's violation of the provisions of Regulation 2016/679 (Article 83 paragraph 2 letter b of Regulation 2016/679). The evidence collected during these administrative proceedings suggests that the Company committed the alleged violations intentionally. The intentionality of her actions is supported by the long-standing practice of combining the function of Director V. with the tasks and responsibilities of the DPO, who is also the Plenipotentiary for (...) and (...) despite knowledge – as directly indicated by the content of the Company's explanations of 8 December 2023 (see point 6, sub-point 7 of the justification for the decision) – of the position of the President of the Personal Data Protection Office regarding the possibility of the DPO simultaneously exercising the function of the plenipotentiary for (...)[30], which, by analogy, should also be applied to all other tasks and responsibilities entrusted to the DPO. The cited opinion of the President of the Personal Data Protection Office clearly indicates that the controller's decision to entrust the DPO with additional tasks and responsibilities should be preceded by a reliable assessment in terms of meeting all requirements guaranteeing the DPO's independent and proper performance of their tasks in conditions excluding the risk of a conflict of interest. Such an assessment, in accordance with the principle of accountability expressed in Article 5 paragraph 2 of Regulation 2016/679, should be duly recorded in internal documentation. In the absence of such evidence, the controller is unable to demonstrate to the supervisory authority that it actually undertook any analysis in the discussed scope. In this case, the Company, despite a request from the President of the Personal Data Protection Office, failed to provide any evidence indicating who, when (in what circumstances), to what extent, how, and on what basis conducted the analysis of the potential conflict of interest in the situation of entrusting the DPO with the duties of Director V., the Representative for (...) or (...). Such evidence certainly cannot be constituted by the Company's statement alone, the generality of which raises reasonable doubts as to its credibility.
58.
Additionally, it should be noted that the Company, as the controller, is obligated to be familiar with the provisions of Regulation 2016/679, including – if it has decided to appoint a DPO – the provisions regarding their position within the controller's structure and the performance of their duties independently and free from the risk of a conflict of interest. Any interpretation difficulties in this regard are generally resolved by the publicly available WP 243 Guidelines on Data Protection Officers, adopted on December 13, 2016. Given that the provisions of Regulation 2016/679, adopted on April 27, 2016, only became fully applicable on May 25, 2018, giving controllers time to adapt their existing procedures and implemented organizational measures related to personal data processing to the new legal environment, it should be stated that the Company had sufficient time to analyze its internal regulations related to the DPO status for compliance with Regulation 2016/679 and the aforementioned Guidelines. The Company could have communicated any doubts regarding the interpretation of the provisions of Regulation 2016/679 to the President of the Personal Data Protection Office, which it did not do. Given the above, it should be assumed that the Company consciously decided on the DPO's position within its structures (including binding him to instructions provided by the Controller) and entrusting him with additional tasks (including those of an authoritative nature), without analyzing the impact of these on the DPO's ability to properly perform his duties – particularly in terms of content and time. This circumstance not only supports the imposition of an administrative fine on the Company but also influences its amount, increasing it accordingly.
59.
Any relevant prior infringements by the Company (Article 83 paragraph 2 letter e of Regulation 2016/679). In deciding on the imposition and the amount of the administrative fine imposed on the Company, the President of the Personal Data Protection Office considered the Company's prior infringement of the provisions of Regulation 2016/679 as an aggravating circumstance. Due to the impact of complaints from natural persons about irregularities in the processing of their personal data by the Company, the supervisory authority issued the following decisions, by which it issued a warning to the Company or ordered it to adapt its personal data processing operations to the provisions of Regulation 2016/679:
–
Decision of September 22, 2020, reference number (...), finding an infringement of the provision of Article 12 paragraphs 3 and 4 in conjunction with Article 15 paragraph 1 letter b) of Regulation 2016/679,
–
Decision of January 11, 2021, reference number (...), finding an infringement of the provision of Article 15 paragraph 1 letter c), Article 15 paragraph 1 letter h), and Article 15 paragraph 3 of Regulation 2016/679,
–
Decision of July 1, 2021, reference number (...), finding an infringement of the provision of Article 6 paragraph 1 of Regulation 2016/679,
-
Decision of 7 March 2022, reference number (...), finding an infringement of the provision of Article 6 paragraph 1 of Regulation 2016/679,
-
Decision of 16 March 2022, reference number (...), finding an infringement of the provision of Article 6 paragraph 1 of Regulation 2016/679,
-
Decision of 20 September 2022, reference number (...), finding an infringement of the provision of Article 6 paragraph 1 of Regulation 2016/679,
-
Decision of 21 December 2022, reference number (...), finding an infringement of the provision of Article 6 paragraph 1, Article 9 paragraph 1 and Article 5 paragraph 1 letter a) of Regulation 2016/679,
-
Decision of 26 January 2023, reference number (...), finding an infringement of the provisions of Article 5 paragraph 1 letter c) and Article 6 paragraph 1 of Regulation 2016/679,
-
Decision of 2 February 2023, reference number (...), finding an infringement of the provisions of Article 6 paragraph 1 of Regulation 2016/679,
-
Decision of 2 February 2023, reference number (...), finding an infringement of the provisions of Article 6 paragraph 1 of Regulation 2016/679,
-
Decision of 29 June 2023, reference number (...), finding an infringement of the provisions of Article 6 paragraph 1 of Regulation 2016/679,
-
Decision of 28 December 2023, reference number (...), finding an infringement of the provision of Article 6 paragraph 1 in conjunction with Article 5 paragraph 1 letter a) of Regulation 2016/679,
-
Decision of March 25, 2024, reference number (...), finding an infringement of the provision of Article 6 paragraph 1 of Regulation 2016/679,
-
Decision of July 10, 2024, reference number (...), finding an infringement of the provision of Article 6 paragraph 1 of Regulation 2016/679,
-
Decision of September 12, 2024, reference number (...), finding an infringement of the provision of Article 6 paragraph 1 of Regulation 2016/679,
-
Decision of November 27, 2024, reference number (...), finding an infringement of the provision of Article 9 paragraph 1 in conjunction with Article 5 paragraph 1 letter b) of Regulation 2016/679 a) of Regulation 2016/679,
– decision of February 26, 2025, reference number (...), finding a violation of Article 6, paragraph 1 of Regulation 2016/679,
– decision of February 28, 2025, reference number (...), finding a violation of Article 6, paragraph 1 of Regulation 2016/679,
– decision of March 6, 2025, reference number (...), finding a violation of Article 6, paragraph 1 of Regulation 2016/679,
– decision of April 16, 2025, reference number (...), finding a violation of Article 6, paragraph 1 of Regulation 2016/679.
60.
The above-mentioned prior violations indicate the existence of significant problems within the Company's structures with the implementation of the obligations arising from the provisions of Regulation 2016/679. In the individual cases mentioned above, the Company was unable to demonstrate to the supervisory authority the lawfulness of the processing or the proper exercise of the rights of data subjects, which resulted in the application of appropriate corrective measures. However, it should be noted that the previously identified irregularities (concerning, among others, (...) or the unlawful processing of personal data of the Company's employees) arose largely as a result of human error and concerned the processing of personal data at the local level, and were therefore in no way related to the Company's activities assessed in these proceedings – which the supervisory authority assumed were centralized and systemic in nature. Above all, however, the President of the Personal Data Protection Office did not previously identify any other infringements that would be related to the positioning of the Data Protection Officer within the Company's organizational structure or the independence of the Officer, necessary for the performance of the tasks entrusted to him. In view of the above, the infringements previously attributed to the Company cannot be considered "relevant prior infringements" within the meaning of Article 83(2)(e) of Regulation 2016/679. However, taking into account the position of the EDPB, according to which "all previous violations may constitute information about the general approach of the controller or processor to complying with the provisions of the GDPR"[31], the President of the UODO considered the Company's previous attitude – indicating existing difficulties in respecting the provisions on personal data protection – to its detriment, assuming that the identified previous violations now justify the imposition of an administrative fine on the Company.
61.
An additional aggravating factor in the context of the premise under review is the fact that the President of the Personal Data Protection Office, by administrative decision of March 17, 2025, file reference (...), found that the Company had violated Article 5 paragraph 1 letter a) and Article 6 paragraph 1 of Regulation 2016/679, consisting in the unlawful processing of personal data (...). Although this decision is not final, and there is no direct material connection between the aforementioned violations and the Company's conduct analyzed in this case (Articles 5 and 6 of Regulation 2016/679 pursue completely different objectives from the norms expressed in Article 38 of the commented legal act), such a blatant violation of personal data protection regulations could not remain without an impact – albeit a limited one – on the amount of the subsequent administrative fine imposed on T. (...) S.A. 62.
When determining whether it was justified to impose an administrative fine on the Company, the President of the Personal Data Protection Office took into account in the Company's favor, as part of any other aggravating or mitigating factors applicable to the circumstances of the case (Article 83 paragraph 2 letter k of Regulation 2016/679), the fact that the infringements identified were remedied during the explanatory proceedings conducted by the supervisory authority, and even before the initiation of these administrative proceedings regarding the possible infringement by T. (…) S.A. of the obligations arising from Article 38 paragraphs 3 and 6 of Regulation 2016/679. This was manifested in the liquidation of V., and subsequently in the separation of the DPO position within the Company's organizational structure and the amendment of the Organizational Regulations of T. (…) S.A. (see point 6, subparagraph 8 of the justification for the decision). However, this circumstance – combined with other criteria indicated in Article 83 paragraph 2 of Regulation 2016/679, which the President of the Personal Data Protection Office (UODO) found to be detrimental to the Company (see paragraphs 54-61 of the justification for the decision) – could not independently decide not to impose an administrative fine, but it nevertheless allowed a significant reduction in its amount.
63.
The other circumstances indicated below, referred to in Article 83 paragraph 2 of Regulation 2016/679, after assessing their impact on the infringement found in this case, were deemed neutral by the President of the Personal Data Protection Office, that is, having neither an aggravating nor a mitigating effect on the amount of the administrative fine imposed.
64.
Actions taken to minimize the harm suffered by data subjects (Article 83 paragraph 2 letter c of Regulation 2016/679). In the present case, the President of the Personal Data Protection Office (UODO) assessed the Company's compliance with its obligations under Article 38 paragraphs 3 and 6 of Regulation 2016/679. The alleged violations of the aforementioned provisions are of a formal nature and, as such, are unrelated to the issue of material or immaterial damage that may have been suffered by data subjects. The fact that there were no circumstances in which the Company would have taken action to minimize the damage suffered by these data subjects means that this premise cannot be treated as an element of the assessment of the violations of Regulation 2016/679 identified in these proceedings.
65.
The degree of liability, taking into account the technical and organizational measures implemented by the President under Articles 25 and 32 of Regulation 2016/679 (Article 83 paragraph 2 letter d of Regulation 2016/679). Due to the nature of the violations of the provisions of Article In light of the violations of Article 38 paragraphs 3 and 6 of Regulation 2016/679 found in this case – which, in their essence, do not relate to the technical and organizational measures applied by the Company related to the processing of personal data within the Company – it should be assumed that the condition specified in Article 83 paragraph 2 letter d) of Regulation 2016/679 has neither an aggravating nor a mitigating effect on the amount of the administrative fine imposed.
66.
Degree of cooperation with the supervisory authority to remedy the violation and mitigate its potential negative effects (Article 83 paragraph 2 letter f of Regulation 2016/679). During the proceedings, the President of the Personal Data Protection Office (UODO) determined that the Company had made every effort to ensure that the DPO would perform his function independently, while simultaneously relieving him from other tasks and duties, which consequently led to the removal of the identified conflict of interest. However, this occurred on the Company's own initiative, prior to the initiation of these administrative proceedings. Therefore, it cannot be considered "cooperation with the authority," which could be treated as a mitigating circumstance under Article 83(2)(f) of Regulation 2016/679. However, the Company's action referred to above was treated by the President of the Personal Data Protection Office as an "other mitigating factor" referred to in Article 83(2)(k) of Regulation 2016/679 (see paragraph 62 of the justification for the decision).
67.
Categories of personal data affected by the infringement (Article 83(2)(g) of Regulation 2016/679). Due to the fact that the violations consisting in failing to ensure that the data protection officer does not receive instructions regarding the performance of his or her duties, and the performance of his or her other tasks and duties does not result in a conflict of interest, do not directly involve a breach of the protection of any personal data (or categories thereof), this premise cannot, by its nature, apply to the assessment of these violations.
68.
The manner in which the supervisory authority became aware of the breach, in particular whether and to what extent the controller or processor reported the breach (Article 83 paragraph 2 letter h of Regulation 2016/679).
The President of the Personal Data Protection Office became aware of the possible violation by the Company of Article 38 paragraphs 3 and 6 of Regulation 2016/679 during the investigation initiated following the notification to the supervisory authority of a personal data breach involving an unauthorized person gaining access to personal data contained in the PIT-11 document (see points 1-3 of the justification for the decision). At the same time, as the EDPB points out, "the manner in which the supervisory authority became aware of the breach may constitute a significant aggravating or mitigating circumstance. When assessing this aspect, particular weight may be given to whether the controller or processor notified the breach to the supervisory authority on its own initiative, and if so, to what extent, before the supervisory authority was informed of the breach by means of, for example, a complaint or proceedings. (...) Where the supervisory authority became aware of the breach, for example, as a result of a complaint or proceedings, this element should, in principle, also be considered a neutral circumstance. The supervisory authority may consider this to be a mitigating circumstance where the controller or processor notified the breach on its own initiative before the supervisory authority became aware of the matter"[33]. Due to the fact that unlawful conduct by the controller, somewhat unknowingly brought to the attention of the authority, does not constitute a "personal data breach" within the meaning of Article 10(1) of the GDPR. 4 point 12 of Regulation 2016/679 – i.e., a security breach leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed – the Company was not obliged to notify the supervisory authority in accordance with Article 33 of the aforementioned legal act. It should be noted that the provisions of Regulation 2016/679 do not impose a similar obligation on controllers in the event of a breach that does not result in a disruption of the security of the personal data being processed that may affect the confidentiality, integrity, or availability of such data. Therefore, the manner in which the authority learned of the breach – during the investigation initiated as a result of the Company's notification of a personal data breach – should be assessed as a neutral fact, irrelevant to the resolution of this decision.
69.
If the controller concerned had previously been subject to measures referred to in Article 58, paragraph 1 of the Personal Data Protection Regulation in the same case, the Company shall notify the supervisory authority in writing. 2 – compliance with these measures (Article 83 paragraph 2 letter i of Regulation 2016/679). Prior to the issuance of this decision, the President of the Personal Data Protection Office (UODO) did not apply any of the measures listed in Article 58 paragraph 2 of Regulation 2016/679 to the Company in the case at hand. Therefore, the Company was not obliged to take any actions related to their application, which, if assessed by the supervisory authority, could have an aggravating or mitigating effect on the assessment of the identified infringements.
70.
Application of approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42 (Article 83 paragraph 2 letter j of Regulation 2016/679). As of the date of this decision, the Company did not apply approved codes of conduct or approved certification mechanisms referred to in the provisions of Regulation 2016/679. However, as provided for in Regulation 2016/679, their adoption, implementation, and application are not mandatory for controllers, and therefore, their failure to apply them cannot be considered detrimental to the Company in this case. However, the adoption and application of such instruments could be considered to the Company's advantage as means of guaranteeing a higher than standard level of protection for personal data processing, but such a circumstance did not occur in the present case.
71.
Other aggravating or mitigating factors applicable to the circumstances of the case (Article 83 paragraph 2 letter k of Regulation 2016/679) – In a comprehensive review of the case, the President of the Personal Data Protection Office (UODO) did not note any circumstances other than those described above that could affect the assessment of the infringements and the amount of the administrative fine imposed.
Determining the amount of the fine in accordance with Guidelines 04/2022
72.In determining the amount of the administrative fine imposed on the Company in this case, the President of the Personal Data Protection Office (UODO) applied the methodology adopted by the EDPB in Guidelines 04/2022. In accordance with the guidelines set out in this document, the President of the UODO carried out the fine calculation process described below. 73.
As the basis for calculating the administrative fine, the President of the Personal Data Protection Office adopted the value of the Company's turnover for 2024 resulting from the financial statements for 2024, attached to the Company's letter dated August 7, 2025. According to this document, the Company's turnover in 2024 (i.e. in the "previous financial year", understood as the year preceding the issuance of the decision[34]) amounted to PLN (...), which – when converted into euro (at the average euro exchange rate of January 28, 2025, adopted for this and all other currency conversions below in accordance with Article 103 of the Personal Data Protection Office, according to which 1 euro = PLN 4.2092) – is the equivalent of the amount of EUR (...). Additionally, the Company's financial statements for 2023, attached to the Company's letter dated May 12, 2025, indicate that its turnover in that financial year amounted to PLN (...), and in 2022 – PLN (...).
74.
The President of the Personal Data Protection Office (UODO) categorized the infringements of Regulation 2016/679 found in this case (see Chapter 4.1 of Guidelines 04/2022). Infringements of Article 38 paragraphs 3 and 6 of Regulation 2016/679 fall – in accordance with Article 83 paragraph 4 letter a) of Regulation 2016/679 – into the category of infringements punishable by the lower of the two penalties provided for in Regulation 2016/679 (with a maximum amount of up to EUR 10,000,000 or up to 2% of the company's turnover in the previous financial year). They are therefore, in abstracto, less serious than the infringements provided for in Article 83(5) of Regulation 2016/679, which are punishable by a higher administrative fine – with an upper limit of EUR 20,000,000 or up to 4% of the company's turnover in the previous financial year.
75.
The President of the Personal Data Protection Office (UODO) also established a legally defined maximum fine that can be imposed on the Company in this case – see Chapter 6.1 of Guidelines 04/2022. The provision of Article 83(4)(a) of Regulation 2016/679 obliges the President of the Personal Data Protection Office to determine whether the so-called "static maximum amount" (EUR 10,000,000) or the "dynamic maximum amount" (2% of the turnover in the previous financial year) will apply in the case, and to adopt the higher amount as the maximum amount that the administrative fine imposed in the case cannot exceed. The value of 2% of the Company's turnover for the previous financial year is PLN (equivalent to EUR). Because this amount is higher than the static maximum amount (EUR 10,000,000), the President of the Personal Data Protection Office is obligated to adopt it as the maximum amount that cannot be exceeded when imposing an administrative fine on the Company.
76.
The President of the Personal Data Protection Office assessed the violations found in this case as a violation of medium severity (see Chapter 4.2 of Guidelines 04/2022). In this assessment, the following conditions were taken into account: those listed in Article 83, paragraph 1, of the Personal Data Protection Regulation. 2 of Regulation 2016/679, which concern the subject of the infringement (constitute the "seriousness" of the infringement), i.e.: the nature, gravity and duration of the infringement (Article 83 paragraph 2 letter a) of Regulation 2016/679) and the intentional or unintentional nature of the infringement (Article 83 paragraph 2 letter b) of Regulation 2016/679) – excluding the categories of personal data to which the infringement concerned (Article 83 paragraph 2 letter g) of Regulation 2016/679), as the identified infringements did not directly involve the processing of personal data. A detailed assessment of these circumstances has been presented above (see paragraphs 54-58 of the justification of the decision). Considering their combined impact on the assessment of the infringements attributed to the Company, taken together, leads to the conclusion that their level of seriousness is medium. As a consequence, the starting amount for calculating the fine will be a value ranging from 10% to 20% of the maximum fine that can be imposed on the Company.[35] Considering the dynamic maximum amount established for the Company (see point 75 of the justification), this will be an amount from PLN ((...) (EUR) to PLN ((...) (EUR). The President of the Personal Data Protection Office (UODO) deemed the starting amount to be PLN (...), equivalent to EUR (...) (10% of the legally defined maximum fine for the Company), to be adequate and justified under the circumstances of this case.
77.
In accordance with the EDPB guidelines regarding enterprises with an annual turnover exceeding EUR 500 million,[36] the President of the Personal Data Protection Office did not consider it justified to exercise the option of reducing the starting amount based on the assessment of the high seriousness of the infringement, which the guidelines (in Chapter 4.3) provide for enterprises of smaller size and economic power. The EDPB points out that in the case of large entities (and in this case, the Company undoubtedly is one such entity, as evidenced by its turnover), "the size of the enterprise is already reflected in the dynamic statutory maximum amount."[37] 78.
The President of the Personal Data Protection Office then assessed the impact on the established infringement of the remaining circumstances (apart from those considered above in the assessment of the seriousness of the infringement) indicated in Article 83(2) of Regulation 2016/679 (see Chapter 5 of Guidelines 04/2022). These circumstances, which may have an aggravating or mitigating effect on the assessment of the infringement, relate – as assumed in Guidelines 04/2022 – to the entity perpetrating the infringement, that is, to the entity itself, the perpetrator of the infringement, and its conduct before, during, and after the infringement, as well as to other circumstances relevant to the case. A detailed assessment and justification of the impact of each of these grounds on the assessment of the infringement have been presented above (see paragraphs 59-71 of the justification for the decision). It should be noted here that two of them affected the amount of the imposed penalty. The President of the UODO found that the aggravating circumstance against the Company was the relevant prior infringements of the provisions of Regulation 2016/679, as identified by the President of the UODO (Article 83 paragraph 2 letter e) of Regulation 2016/679). A significantly mitigating circumstance, however, is the fact that the Company remedied the infringement (Article 83 paragraph 2 letter k) of Regulation 2016/679). The remaining grounds in Article 83 paragraph 2 (letters c), d), f), h), i), and j)) of Regulation 2016/679 had neither a mitigating nor an aggravating effect on the assessment of the infringement and, consequently, on the amount of the penalty. Therefore, due to the existence of additional circumstances in this case affecting the assessment of the infringement, the President of the Personal Data Protection Office deemed it justified to further adjust the amount of the fine determined based on the assessment of the seriousness of the infringement (see point 76 of the justification). In the President's opinion, a further reduction of the fine by 40% – to PLN (…), equivalent to EUR (…) – is appropriate to the combined impact of both these factors on the assessment of the infringement. Such a significant reduction in the amount of the fine at this stage of its calculation is primarily the result of the President of the Personal Data Protection Office taking into account the fact that the Company had remedied the infringement before initiating these administrative proceedings. This action by the Company permitted the elimination of one of the purposes of the administrative fine – the need to restore compliance with the law.
79.
Although the amount of the fine determined in accordance with the above principles does not exceed the legally established maximum fine, the President of the Personal Data Protection Office determined that it requires an additional adjustment in accordance with the principle of proportionality set forth in Article 83, paragraph 1 of the Personal Data Protection Regulation. 1 of Regulation 2016/679, as one of the three penalty directives (see Chapter 7 of Guidelines 04/2022). Undoubtedly, a fine of PLN (...) would be an effective penalty that would achieve the punitive purpose of the sanction, which is to punish the controller for its unlawful conduct. A penalty of this amount would also be deterrent, i.e., effectively discouraging both the Company and other controllers from committing similar infringements of Regulation 2016/679 in the future. However, according to the President of the Personal Data Protection Office, a penalty of this amount would be disproportionate due to its excessive severity.
80.
According to Guidelines 04/2022, the principle of proportionality requires that the measures adopted do not go beyond what is appropriate and necessary to achieve the legitimate objectives pursued by the provisions in question. Where a choice is possible from a number of appropriate solutions, the least onerous solution should be applied[38]. In other words, as accepted in Polish legal doctrine, "[a] sanction is proportionate if it does not exceed the threshold of severity determined by taking into account the circumstances of a specific case."[39] 81.
It should be noted that the consideration of the minimal severity of the sanction applied in this case supports a reduction of the penalty imposed on the Company. Balancing the impact of the principle of proportionality on the penalty, as well as the need to maintain the effectiveness and deterrent nature of the penalty, i.e., all the requirements set out in Article 83(1) of Regulation 2016/679 – which are equivalent and equally important – the President of the Personal Data Protection Office took into account the Company's specific status, the context of its operations as (...), as well as its current financial situation, resulting in part from this context and the regulatory environment in which the Company operates. 82.
The financial statements for 2024 presented by the Company indicate that the Company's turnover (net income) during this period amounted to PLN (...), with a net loss of approximately PLN (...). For comparison, in 2023, the Company's turnover was PLN (...), with a net loss of approximately PLN (...). This represents a 3% increase in the Company's turnover compared to the previous year, while simultaneously reducing the generated loss by 69%. While these data undoubtedly indicate the continued difficult financial situation of T. (...) S.A., the visible increase in the aforementioned indicators implies its ongoing stabilization. In assessing the Company's financial condition, the President of the Personal Data Protection Office took into account the fact that the Company's results depend largely on the specific nature of its business activities. T. (...) S.A. is a sole proprietorship (...). The financial losses the Company has recorded in recent years are closely related to its obligation to provide (...), which are services not subject to free market conditions. As (...) – this affects both the Company's competitiveness and the increased costs it must incur in maintaining and developing its infrastructure, including (...). On the other hand, however, a consequence of the Company's special status is the support it receives (...). In a situation where (...).83.
Considering the above, it should be stated that the Company's negative financial result in 2023-2024 resulted from (...) by the Company in 2021-2022. This delay was caused, firstly, by the need to notify this cost (as state aid) to the European Commission, and secondly, by a delay in that body issuing a decision on the compliance of the refinancing with EU state aid rules. Ultimately, however, in June 2024, the Company received an initial payment towards financing the net cost of (...) in 2021-2022 (in the amount of approximately PLN (...)), and by decision of (...) 2024, the European Commission confirmed the compliance, with European Union law, of the state aid consisting in the financing of this cost by the Polish state in 2021-2025. As a result of the above, the President of the Office of Electronic Communications (hereinafter referred to as the "President of UKE") issued a decision of (...) specifying the amount of refinancing of the verified net cost for 2023 in the amount of approximately PLN (...). The Company recorded the inflow of the above-mentioned funds on March 13, 2025, which – given the amount of support – certainly helped stabilize its financial situation. Additionally, by the decision of the President of UKE announced (...) T. (...) S.A. was (...) In turn, by virtue of the Act (...), the limit of budgetary expenditures for the Company was increased in order to enable the payment of compensation to the Company for losses incurred in connection with (...). In accordance with the provisions of the Act – which entered into force on (...) – this limit was set at PLN (...) in 2026 (to cover the loss for 2024) and PLN (...) in 2027 (to cover the loss for 2025). Considering the above, it should be assumed that in the current situation, the Company's continued operation is not threatened, and its financial results (both in the current year and in subsequent years) should gradually improve. The Company itself seems to recognize this, indicating in the "(...)" section of the 2024 financial statements that "in the opinion of the Management Board of T. (...) S.A., there is no uncertainty that the Company will not be able to continue its operations within 12 months from the balance sheet date" (i.e., from (...) to (...)). 84.
When analyzing the Company's financial condition in the context of assessing the severity of the penalty and its effects on the continued operation of the fined entity, the President of the Personal Data Protection Office (UODO) also took into account the Company's independent attempts to improve its financial situation. In August 2024, the Company began implementing remedial measures, including: the adoption by the Company's Management Board of the so-called "Plan (...)" (assuming the Company's transformation into a "modern company (...)"[41]), termination of the Company (...) as of (...), and implementation of the (...) Program, lasting from (...) to (...). The President of the Personal Data Protection Office is aware that all of the above-mentioned remedial measures, necessary and justified by the Company's financial situation, may impact its ability to fulfill its public duties. In these circumstances, imposing an excessively severe penalty on the Company could entail the risk of reducing the quality of its services or disrupting the implementation process (...). At the same time, however, the supervisory authority notes that the Company's activities aimed at rebuilding its market position are yielding initial results. In particular, this activity allowed for a reduction in the Company's operating costs, including the reduction of employment costs ("optimization") – as undoubtedly evidenced by the Management Board's decision to terminate the workforce reduction process and to pay employees annual bonuses totaling PLN (...) in the second half of 2025.[44] According to the President of the Personal Data Protection Office (UODO), the ongoing transformation process at the Company allows for the assumption that its situation, although still complex, will improve in the near future. The reduction of the fine made at this stage, which the President of the Personal Data Protection Office deemed excessively onerous, also takes this circumstance into account. 85.
Considering that a fine of PLN (...) (taking into account the seriousness of the infringement, the size of the Company's business, and all the circumstances indicated in Article 83(2) of Regulation 2016/679, while undoubtedly being effective and deterrent) would be excessively onerous and therefore inconsistent with the principle of proportionality, the President of the Personal Data Protection Office further reduced its amount – by 88% compared to the amount obtained after taking into account additional circumstances that had aggravating and mitigating impact on the amount of the fine (see point 78 of the justification for the decision), i.e., to PLN 978,128 (the equivalent of EUR 232,378.72). According to the supervisory authority, this final amount of the imposed fine will not reduce its effectiveness or deterrent nature. This amount constitutes a threshold above which a further increase in the amount of the fine (and therefore its severity) will not increase its effectiveness or deterrent effect. On the other hand, reducing the fine to a greater extent than the one applied could lead to a situation in which this sanction would not achieve the objectives set out in Regulation 2016/679. Such action by the authority would be contrary to the requirement of consistent application and enforcement of Regulation 2016/679 by the European Supervisory Authorities and would be tantamount to a violation of the principle of equal treatment of entities within the EU and EEA internal market. According to the President of the Personal Data Protection Office, the Company's turnover allows it to pay the imposed administrative fine without undue detriment to its operations and the performance of tasks arising from its status (...). This fine represents only approximately (...)% of the Company's revenues in 2024. At the same time, its amount is only approximately (...)% of the legally defined maximum fine that the Company may face for its violations of Regulation 2016/679.
86.
The President of the Personal Data Protection Office stated that the amount of the administrative fine determined in the manner described above does not exceed – pursuant to Article 83 sec. 3 of Regulation 2016/679 – the legally defined maximum amount of the fine provided for the most serious infringement. The infringements of Article 38 sec. 3 and 6 of Regulation 2016/679 found in this case are punishable by the same fine of up to 2% of the Company's annual turnover in the previous financial year; these infringements should therefore be considered to be of the same seriousness within the meaning of Article 83 sec. 3 of Regulation 2016/679. As indicated above, the "dynamic maximum amount" applies in this case to the Company, i.e. the amount of (...) PLN (equivalent to (...) euro). The amount of the joint penalty imposed for infringements of both provisions of Regulation 2016/679, determined as presented in the above paragraphs – up to PLN 978,128 – clearly does not exceed the "dynamic maximum amount" specified for each of the infringements considered individually ("it shall not exceed the amount of the penalty for the most serious infringement", in accordance with the literal wording of Article 83 paragraph 3 of Regulation 2016/679).

Summary
87.
Taking into account the established factual circumstances and legal conditions, the President of the Personal Data Protection Office imposed an administrative fine of PLN 978,128 on T. (…) S.A. for the infringements of Article 38 paragraphs 3 and 6 of Regulation 2016/679, attributed in these proceedings to T. (…) S.A., constituting the equivalent of EUR 232,378.72. The penalty imposed on the Company was imposed on the basis of Article 83 paragraph 4 letter a) in conjunction with Article 83 paragraph 4 letter a) of the Personal Data Protection Regulation. 3 of Regulation 2016/679.
88.
In the opinion of the President of the Personal Data Protection Office, the aforementioned financial sanction fulfills the functions of a penalty specified in Article 83 paragraph 1 of Regulation 2016/679 and constitutes the most appropriate and, above all, fair response by the supervisory authority to the identified infringements of the provisions of Regulation 2016/679. The imposition of an administrative fine in the amount determined by the supervisory authority is necessary and justified by the nature, seriousness, and other circumstances of the case, which the supervisory authority deemed aggravating in the context of the infringements attributed to the Company. At the same time, the President of the Personal Data Protection Office notes that the application of any other corrective measure to the Company provided for in Article 58 paragraph 1 of Regulation 2016/679 is prohibited. 2 of Regulation 2016/679, in particular limiting the proceedings to a warning (Article 58 paragraph 2 letter b) of Regulation 2016/679), would not be proportionate to the irregularities identified and would not guarantee that the Company would not commit further negligence in the area of data protection in the future.

In this factual and legal situation, the President of the Personal Data Protection Office ruled as set out in the operative part.
[1] Journal of Laws of 2025, item 1691.
[2] Journal of Laws of 2019, item 1781.
[3] OJ EU L 119, p. 1, OJ EU L 127, 2018, p. 2, OJ EU L 74 of 2021, p. 35.
[4] Current version, available online: https://uodo.gov.pl/497/2371 .
[5] See judgment of the CJEU of 9 February 2023, C-453/21, X-Fab Dresden GmbH & Co. KG, paragraph 41.
[6] G. Sibiga, B. Żeromski, Consequences of the condition of avoiding a conflict of interests of the data protection officer for the permissible scope of his or her tasks in personal data protection, Monitor Prawniczy supplement to No. 11/2024, p. 85.
[7] See interpretation of the President of the Personal Data Protection Office regarding the concept of "conflict of interest", available online: https://uodo.gov.pl/pl/495/2371.
[8] See WP 243 Guidelines on Data Protection Officers, p. 18, point 3.2, and p. 28, point 9, hereinafter referred to as the "Guidelines", available online: https://ec.europa.eu/newsroom/just/document.cfm?doc_id=48137 .
[9] Available online: https://sjp.pwn.pl/slowniki/konflikt.html .
[10] See the National Report of the Polish Supervisory Authority, p. 2, available online: https://uodo.gov.pl/pl/138/2960 .
[11] See the judgment of the CJEU of 9 February 2023, C-453/21, X-Fab Dresden GmbH & Co. KG, paragraphs 42 and 44, respectively.
[12] See CJEU judgment of 9 February 2023, C-453/21, X-Fab Dresden GmbH & Co. KG, paragraph 45.
[13] See G. Sibiga, B. Żeromski, op. cit., p. 85.
[14] See the interpretation of the President of the Personal Data Protection Office regarding the concept of "conflict of interest", available online: https://uodo.gov.pl/pl/495/2398.
[15] See CJEU judgment of 9 February 2023, C-453/21, X-Fab Dresden GmbH & Co. KG, paragraph 44.
[16] See Commentary on Article 38 [in] E. Bielak-Jomaa (ed.), D. Lubasz (ed.), GDPR. General Data Protection Regulation. Commentary. Lex/el 2018.[17] See G. Sibiga, "Data Protection Inspector Regarding the Authoritative Actions of a Supervisory Authority in Individual Cases," Monitor Prawniczy supplement to No. 23/2020, p. 66.
[18] See judgment of the Provincial Administrative Court in Warsaw of September 18, 2025, file reference II SA/Wa 295/25.
[19] See P. Fajgielski, "General Data Protection Regulation. Personal Data Protection Act. Commentary," Lex/el 2022.
[20] See the interpretation of the President of the Personal Data Protection Office regarding the concept of a conflict of interest, available online: https://uodo.gov.pl/pl/495/2372.
[21] See the interpretation of the President of the Personal Data Protection Office regarding the concept of a "conflict of interest," available online: https://uodo.gov.pl/pl/495/2371. [22] See G. Sibiga, B. Żeromski, op. cit., p. 85.
[23] See CJEU judgment of 9 February 2023, C-453/21, X-Fab Dresden GmbH & Co. KG, paragraph 25.
[24] See CJEU judgment of 9 February 2023, C-453/21, X-Fab Dresden GmbH & Co. KG, paragraph 42.
[25] See Guidelines 04/2022 on the calculation of administrative fines under the GDPR. Version 2.1. Adopted on May 24, 2023, p. 9, point 17, available online: https://edpb.europa.eu/system/files/2024-01/edpb_guidelines_042022_calculationofadministrativefines_pl_0.pdf [accessed: September 1, 2025], hereinafter referred to as "Guidelines 04/2022".
[26] Ibid., p. 10, point 24.
[27] Ibid., p. 12, point 28.
[28] See the decision of the President of the Office of Electronic Communications (...).
[29] See information on the collection of personal data by the Company: https://(…) [accessed: September 1, 2025].
[30] See current version of the position of the President of the Personal Data Protection Office: https://uodo.gov.pl/497/2371 [accessed: 01.09.2025]
[31] See Guidelines 04/2022, p. 29, point 88.
[32] See: administrative decision of the President of the Personal Data Protection Office of 17 March 2025, reference number (...), available: https://uodo.gov.pl/decyzje/(…) [accessed: 01.09.2025]
[33] See Guidelines 04/2022, p. 31, points 98-99.
[34] See Guidelines 04/2022, p. 41, point 131.
[35] See Guidelines 04/2022, p. 22, point 60, second indent. [36] Ibid., p. 26, point 66, fourth indent.
[37] Ibid.
[38] See Guidelines 04/2022, p. 42, point 137.
[39] Commentary to Article 83 [in] P. Litwiński (ed.) General Data Protection Regulation. Personal Data Protection Act. Selected sectoral provisions. Commentary. Commentary to Article 83. Legalis.
[40] Journal of Laws of 2025, item 366.
[41] See the Company's announcement: (...).
[42] See the Company's announcement: (...).
[43] See the Company's announcement: (...).
[44] See the Company's announcement: (...).