Divulgare la privacy e la cybersecurity nelle aziende
con spiegazioni semplici e operative, AI assisted
Osservatorio a cura del dott. V. Spataro 



   data breach 2024-04-13 ·  NEW:   Appunta · Stampa · Cita: 'Doc 98445' · pdf

Rubato il pacco di un cliente di una banca: sanzione per omessa denuncia di data breach

abstract:



In Polonia cosi' l'Autorità.

Segue il comunicato tradotto automaticamente, unitamente alle due decisioni (Edge).

Omessa una sufficiente valutazione dei rischi.

Inutile il ritrovamento dopo poco tempo, secondo il Garante Polacco.

In analisi le traduzioni e le sintesi, AI gen.

Fonte: Uodo
Link: https://uodo.gov.pl/pl/138/3049




analisi:

L'analisi è riservata agli iscritti. Segui la newsletter dell'Osservatorio oppure il Podcast iscrizione gratuita 30 giorni

.'.' .... .. .....

.. ..... ... ..... ..... ........... ... ... .... ......., ... ....' .... ....., ..... ........... .........., .... ... .......... ....'.................. .. ... ............... ... .... .... .'........ ..... ......... .. ..... ..........

... ...... .. ....... ... .... ?

. ......... .... ..... ......... .... ...., ..... ...... .'.' ......... .. ......... .. . ......... .... ..... ..... .. ... .... . .. ... ..... ..... ....... ..... (..... .......... ..... .......).

.... .. ....... ... ......... .. .. ..... .. ...:

... ... ...... ......... .. ... ...... ........ .......:

  • . .... ...... ........ ......... ......... .... ...... .... .. ........ ...., ..... .... ......... .......... ........ .... .. .. .. ... ........... .... ..... ......... .. .. ......... ..... ..... ..... ...... ...... ....... .. . ....... ........

  • ... .... ... ... ........ .. ... .... ...... ..... ...... .... .... ... ...... .... .......... ......... (....) .......... ..... ....... ..... ... ........ .... ........ .....

  • ... .... ............ ... ..... .... ......... .... ...... .... ... ... ........ ... .... ...... .. ... ........... ......... ...... .. ....., .. ........ .. ....... .. .. ... ..... .... .... ... ... ...... ... ........... ..... .... ... ........, .. ........ .. ....... ...

  • ......... .... ........ ............ ... ... .. ... ... ... ... .... .. ...... .. ...... .. ... ...., ...... ....... .... ... ......... ..... ....... ..... ... ...... .. ...... .. .. .......... ....... ......., ... .... ......... .... .... ...........

  • .. . ...... .. ... ........, ... .... ....... .. .............. .... .. .,...,... ... .. ......... .... ... .......... .. ........ .. ... .. .. ... .....

  • ... .... ... .... ........ .. ...... ... ........... ........ .. ... .... ...... ...... . .... .. ....... ....... .. ............

  • ..... ... .... ... ..... ..... .. ....... .........., .... .. .......... ........ ......... ... ........ ............. ......... .... ........, .... .........

.. .. ......., ... .... ..... ......... .... ...... .. ........ ...... ... ....... .. ... .... .... ......, ......... .. .......... ......... ... .. ..... .. ...... ........... .. ...... ... .... ...-...........

---

.... ... ... ... ...... ....... .. ... ........ ... ... .... .... ........:

  • ... .... ........ . .... ...... .. ...... .... ...... ...., ..... ... ........ .... .. ... .......... (...., .... ....... ......, ......., ..... ......, .. .... ......) ... .......... .... .. ....... .... ........ .. ..... .....

  • ... .... ........ ... ........ ........ .......... ... ...... .. ...... ... .... .......... ......... (....) ...... .. ..... .. ........ .. .... .... ........ .... .... ... ..... ....., .. ......... .....

  • ... .... ...... .... .. ... ...., .... ........ ... .... .. ... ...... .. ... ..........'. ...... ... ........ .. .... .... .... .... ..... .... .. ....... .... .... ... ...... ..... ........, ... .... ..... ....... ........., ... ... ......... ..... .. ........ .... .........

  • ......., .... ...... .... ... .... ...... .... ........ .... .........., .. ... ........... ......... ..... ........ ...... ... .... ... ...... ... ..........'. ...... .... .......... ... ......... ........ .... .. .... ......... .....

  • .... .......... ..... .... ... .... ... ........ ... .......... ..... ....... ..(.) .. ... .... .. ...... ... .... .......... ......... ....... ..... ....., ... .. ..... .... .. ......

  • .. . ......, .... ....... .. .............. .... .. ..,...... ... .. ... .... ... ....... .. ........ ...... ... .... .......... ......... .. ... .... .......

.. .. ......., ... ... ...... .... ...... . .... ...... ............ .......... ... ... .......... .. . .... ... ... ....... ............ .. ... ...... .... .......... ..........

---

. .... ........ ... ....... .. ... ...... ........ ... .... ... ... ... .......:

  • ... ........ ......... .. ........ .. ...... ..... . ........'. ...... .......... ........ .... ......... ... ...... ...... ....... .. . ....... ........ ... ...... ... ..... ..... ......... .. . ........... .....

  • ... ......... ......... ......... ........ .... .. ... ....'. ......... .... ....., ........., .... ....... ......., .. ......., ....

  • ... .......'. .... .......... ......... (....) ....... . .... .. ... .... (......... .... ...... ....) ... ....... .. ...... .... ... ... ........ ........... ..... ... .... .......

  • ... .... ...... .... .... ... ... ........ .. . ...... ......... ............ ....... ... ...... ... ..... .. .. .......... .......... .... ....., .. ......... .... ......., ... ... ...... .... .. ........ .. ... ...... ... .... .... ... ... .... .........

  • ......., ... .... .......... ......... ... ... ...... ... ....'. .......... .... .... ... .... .......... .... .. .... ... ........... .. ... ........ ..........., ... ... ......... .. ... ...........

  • .... ...... ......... .. ... ......, ... ......... .... .. ... ......... ... .... ...... ... ...... ....... ... ...... ..... ...... ...... .... ......... . ...... .... ...........

  • .... ..... ... .... .... ....... ... ... ......... ........... .. ...... ... ......... ... ........ ........... ..... .... ........ .. ... ...

  • ... .... ... .... ....... .. ...... ... ... ........ ........... ..... ... ...... ...... . .....

.. .. ......., ... .... .......... ......... ... ... ...... ... ....'. ......... ... ... ......... ... ....... . ........... .... ... .......... .. ... .... ...... ............ .............

.. .......... .. ......... ... ......... ....... .. .... . ........ ..........:

  • .. ......... ..... .. .. ......... ........ .. ......., .... .. ..... .. .. ....... .......... ......... ....... ......... ........ ..... ...... ....... .. ......... .. .. ......... .. ..... ........ ..... ... ......... ........... .. ... .... .............
  • . ......... ........... .... ......... ......... ... ....... ..... ....., .... ...., ........., ...... .. ..... ........, ...... .. ..... .'..............., ....
  • .'............... ......... ... .. .......... ... .... (....) .. ....... ... ..... .... ..... (......... .... ...... ....) ... ... .... .......... .... ..... . .... ....... ........... .. .......... ... .....
  • .. ..... .. ......... .. ... ............ ... .......... .. .......... ............. .. ..... ........ ..... ....... .. ... ....... ............ .... ...., ... ....... ..... ......... . .. ....... .. .. ....... ............ .... ....... ....... .. ... .... ....... ......
  • ........, .'............... ... .. .......... ... .... ... .. ......... .. .............. ..... ...... .'............... .. ......... ... .. ........... ... ....... .... ........ ... ..... .. ..... ..... ....... ........... . ... ..... ......... ... ............ ... ............
  • ..... .. .. .... ........ ..... ......... . ... .... ......., .'............... .. ......... ... ... ........ ..... ...... ..... ....... .. ....... ..... ....... .. ........... .. ..... ... ..... ...... ....... ...... ... ........ ..'........ ........... ... ........
  • .'............... .. ........ .... ..... ... ..... .. .,.. ....... .. ..... ... .... ....... ... ........ .. ........ ...'............... . .... ....... ........... .. ..... ..... ........ .. . .. ... .....
  • .... ..... ........ ..... ....... ........ .. .......... .. .......... .... ... ....... ........... ..... . .......

......, .. .......

........ ... ......... (........ ........)




index:

Indice

  • .. .......
  • ......
  • ........... .... .........
  • ... ... .... ..........
  • .. ... ............ ... .......... .. ..
  • .... ..... ........ ..... ....... ......
  • The data controller explained that it ha
  • of the breach, which may cause serious
  • Personal Data Protection Office also fou
  • Notify the affected persons within three
  • Sending a person's data to an unauthoriz
  • Protection Office, imposing penalties o



testo:

2.04.2024

Concern for personal data more important than the interest of the controller

The President of the Personal Data Protection Office, Mirosław Wróblewski, imposed an administrative fine of PLN 1 million 440 thousand on Santander Bank Polska S.A. for failing to report a data breach. Similarly, Toyota Bank Polska S.A. was fined for failing to report a personal data breach.

The President of the Personal Data Protection Office learned about the personal data breach at Santander Bank Polska S.A. from the media. It consisted in making public bank documents contained in a parcel abandoned in one of the housing estates, after it had been stolen from a courier company. The parcel contained, m.in, such data as: names and surnames, dates of birth, bank account numbers, address and contact details, PESEL numbers, usernames and passwords to the bank, or data on earnings, series and numbers of ID cards, information about banking products. The data controller explained that it had not reported the breach because the parcel had been found by one identified person in a short period of time, after it had been lost by the courier. In addition, it was established that no documents were missing and that the person who found the documents took them directly to the police station and stated that he did not copy the documents found.

However, in his decision, the President of the Personal Data Protection Office indicated that in the event of a data breach, the risk of violation of the rights and freedoms of a natural person should be assessed through the prism of the person at risk, and not the interests of the controller. At the same time, the Court pointed out that the lack of notification of a personal data breach of persons affected by the breach, in the event of a high risk of violation of their rights or freedoms, deprives them not only of the possibility of an appropriate response to the breach, but also of the possibility of independent Assessment of the breach, which may cause serious consequences for them. On the other hand, failure to notify the President of the Personal Data Protection Office deprives the supervisory authority of the possibility of an appropriate response to the breach, i.e. of the Assessment of the risk of the breach to the rights and freedoms of a natural person, but also of the chance to verify whether the controller has taken appropriate measures to remedy the breach and minimise the negative consequences for data subjects. In such a case, the authority is not able to assess whether the controller has applied appropriate security measures to minimise the risk of a recurrence of the breach.

In the course of the proceedings, the President of the Personal Data Protection Office also found that it was also irrelevant that the data had been made available to only one identified person. What matters is that the parcel was found by that person. Also, the administrator is not sure how many people may have previously had access to the abandoned shipment. The very fact of theft of a parcel should affect the proper and adequate Assessment of this incident, including the Assessment in terms of the risk of violation of the rights and freedoms of natural persons.

When determining the amount of the penalty, the supervisory authority also indicated that this was another breach of personal data protection that had been found in the case of this controller. The President of the Personal Data Protection Office, by decision of 19 January 2022 (ref. no. DKN.5131.33.2021) imposed an administrative fine of PLN 545 thousand on Santander Bank Polska S.A. due to the breach under Article 34(1) of the GDPR, i.e. the obligation to notify data subjects of the breach.

In addition to the aforementioned penalty, the President of the Personal Data Protection Office ordered the controller to notify the affected persons within three days from the date of receipt of the decision.

In this case, the penalty amounted to PLN 78 thousand and was imposed for failing to notify the President of the Personal Data Protection Office of a personal data breach without undue delay, no later than within 72 hours after the breach was identified. The controller reported the data breach one and a half years after it occurred, at the time when it was contacted by the supervisory authority after receiving a complaint from the person affected by the breach.

The breach involved the bank sending a person's data to an unauthorized recipient. The scope of the data contained in the correspondence posed a high risk to the rights and freedoms of the person to whom the data was disclosed (e.g. the risk of identity theft). In the decision, the supervisory authority also noted that the controller is not sure whether the erroneous recipient did not make copies or record the personal data contained in the agreement in another way, e.g. by writing them down, before returning the correspondence.

The full text of both decisions of the President of the Personal Data Protection Office, imposing penalties on administrators in the described cases, can be found at the following links:

DKN.5131.59.2022

DKN.5131.28.2023

Seguono le traduzioni automatiche con edge:

Warsaw, on the 12th day March 2024

Decision

DKN.5131.59.2022

Pursuant to Article 104(1) of the Act of 14 June 1960 Code of Administrative Procedure (Journal of Laws of 2023, item 775, as amended), Article 7(1) and (2) and Article 60, Article 101 and Article 103 of the Personal Data Protection Act of 10 May 2018 (Journal of Laws of 2019, item 1781), as well as Article 57(1)(a) and (h), Article 58(2)(e) and (i), Article 83(1), (2) and (3), Article 83(4)(a) in conjunction with Article 33(1) and Article 34(1), (2) and (4) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). EU L 119, 04.05.2016, p. 1. EU L 127, 23.05.2018, p. 2 UE L 74, 4.03.2021, p. 35), hereinafter referred to as 'Regulation 2016/679', following ex officio administrative proceedings for infringement of personal data protection regulations by Santander Bank Polska S.A. with its registered office in Warsaw (Al. Jana Pawła II 17, 00-854 Warsaw), the President of the Personal Data Protection Office,1
finding that Santander Bank Polska S.A. with its registered office in Warsaw (Al. Jana Pawła II 17, 00-854 Warsaw) provisions:
a) Article 33(1) of Regulation 2016/679, consisting in failure to notify the President of the Personal Data Protection Office of a personal data breach without undue delay, no later than within 72 hours after the breach has been identified,b
Article 34(1) of Regulation 2016/679, consisting in failure to notify data subjects of a personal data breach without undue delay,

imposes an administrative fine of PLN 1,440,549 (in words: one million four hundred forty thousand five hundred and forty-nine zloty) on Santander Bank Polska S.A. with its registered office in Warsaw (Al. Jana Pawła II 17, 00-854 Warsaw),
2) orders Santander Bank Polska S.A. with its registered office in Warsaw (Al. Jana Pawła II 17, 00-854 Warsaw) to notify - within 3 days from the date of delivery of this decision - the persons whose data protection has been breached as a result of an event entered in the Register of Personal Data Violations of Santander Bank Polska S.A. under number (...), about the breach of the protection of their personal data in order to provide these persons with the information required in accordance with Article 34(2) of Regulation 2016/679, i.e.:
a) a description of the nature of the personal data breach;
(b) the name and contact details of the Data Protection Officer or other point of contact from whom more information may be obtained;
(c) a description of the possible consequences of the personal data breach;
(d) a description of the measures taken or proposed by the controller to remedy the breach, including measures to minimise its possible negative effects.

Justification

On 23 August 2022, the President of the Personal Data Protection Office, hereinafter also referred to as the "President of the Personal Data Protection Office" or the "supervisory authority", became aware of a breach of personal data protection of customers of Santander Bank Polska S.A. with its registered office in Warsaw, hereinafter referred to as the "Bank" or the "Controller", consisting in the publication of bank documents contained in a parcel abandoned in a housing estate in K., after it has been stolen in transit by a courier company. The article itself was published on (...) November 2018, while the incident took place (...) November 2018. Two days earlier, the website also reported about the incident (...).

Accordingly, by letter dated 25 August 2022 Pursuant to Article 58(1)(a) and (e) of Regulation 2016/679, the President of the Personal Data Protection Office requested the Bank to clarify whether, in connection with the incident, the Bank notified, pursuant to Article 33 of Regulation 2016/679, to the President of the Personal Data Protection Office a breach of personal data protection in the above scope, and if so, when and how it did so and whether the Bank complied with the obligation to notify persons data subjects of a personal data breach, in accordance with Article 34(1) and (2) of Regulation 2016/679. The President of the Personal Data Protection Office also asked for an indication of: when and how the Bank determined that the documents indicated in the letter had been made public, the number of persons affected by the personal data breach in question, the period from which the published documents originate, and an explanation of what actions were taken to minimise the risk of recurrence of such events in the future.

By letter dated 5 September 2022 The Bank asked the President of the Personal Data Protection Office to extend the deadline for responding until 16 September 2022, arguing that it was necessary to "make a reliable determination (with many people representing various units in the bank), namely: the Bank's investigation of the circumstances of the incident after its disclosure; the premises of the bank's Assessment of the event; conclusions and actions taken by the bank in connection with the occurrence of this event in order to comprehensively answer the questions of the President of the Office for Personal Data Protection".

According to the Bank's reply in the letter of 16 September 2022, the Bank established that the documents referred to in the supervisory authority's letter were found in the block in K. on (...) November 2018. This was done by a unit (...) by monitoring news appearing on the Internet. On the portal (...) she found an entry about finding the Bank's documents in a block of flats in K. Two days later, the portal also informed about the incident (...). A maximum of 158 people were affected by the personal data breach in question (this number was determined on the basis of the data contained in the pledge of the documentation sent, indicating the identification numbers of the customers whose documents were found). The published documents came from the period from (...) November 2018 to (...) November 2018 (the date of dispatch in (...) Branch of the Bank in K.). The personal data breach was not reported to the President of the Personal Data Protection Office. This decision was influenced by the following circumstances:

  • the parcel was found by one identified person within a short period of time, after it was lost by the courier;
  • verified that no documents are missing; the person who found the documents took them directly to the police station;
  • The person admitted that he had not copied the documents.

As a result, the data subjects were also not informed of the personal data breach.

The Bank also described what actions were taken to minimize the risk of recurrence of such events in the future, and therefore a working group was established to analyze the event and develop mechanisms to prevent similar situations from occurring in the future.
"(...) As a result of the work of this group:
1) a "Standard" has been developed for the process of sending paper documentation, including:
a. preparation of the shipment / method of packaging — use (...). The label (...) reads as follows: "(...)"
b. control of the "Standard" on three levels:
i) control on the part of the courier — (...),
ii) control carried out by (...),
iii) control on the part of G. - (...),
c. response to events (detected irregularities).
2) an alert check was carried out on the correctness of shipments with G. documentation. As a result of this inspection, the following post-inspection activities were determined:
- the Instructions for sending parcels for the Bank's Branches were prepared,
- e-mails were sent to each branch that sent a parcel incorrectly with information on how to correctly send a parcel with documentation to G.,
- involvement of direct control employees – during visits to the branches, they instruct the employees of the branches how to correctly send parcels with documentation,
3) talks were started with the courier regarding the communication process, including in particular:
i) the required times and methods of response to reported irregularities/identified events,ii
) communication tools,iii
) documenting explanations/statements".

In view of the clarifications provided so far in the case, by letter of 6 October 2022 The President of the Personal Data Protection Office additionally asked the Controller to:
1) indicate the exact scope of personal data contained in the bank documentation covered by the personal data breach;
2) clarification as to whether Santander Bank Polska S.A. is the sole controller of personal data in relation to the disclosed personal data of customers; alternatively, if personal data whose administrators are also other entities have been disclosed, the Bank has notified them of this personal data breach.

By letter dated 20 October 2022, The Bank requested an extension of the deadline for responding to the above letter until 27 October 2022.In
its response of 27 October 2022, the Administrator indicated that the documentation covered by the breach in question included the following categories of personal data: surnames and first names, dates of birth, bank account numbers, addresses of residence or residence, PESEL registration numbers, e-mail addresses, usernames and/or passwords, data on earnings and/or assets held, series and numbers of identity cards, telephone numbers, information about banking products, loans, bank accounts, i.e. names of contracts, dates of their conclusion, details of these products, information about property insurance policies, i.e. m.in. policy numbers, dates of their issuance, sums insured, insurance premiums, information about insured property. At the same time, the Bank pointed out that the bank records covered by the personal data breach in question did not contain data referred to in Article 9 or Article 10 of Regulation 2016/679. In addition, in the bank documentation covered by the personal data breach, there were two insurance policies issued for the property insurance contracts of the bank's customers. Within the scope of these insurance contracts, the data controller are insurance companies that have not been notified by the Bank of the personal data breach.

In the absence of notification of the personal data breach to the President of the Personal Data Protection Office and the failure to notify the personal data breach of the persons affected by the breach, on 8 December 2022 the personal data breach was notified. The President of the Personal Data Protection Office initiated ex officio administrative proceedings against the Bank with regard to the possibility of the Bank's violation of Article 33(1) and Article 34(1) and (2) of Regulation 2016/679.

By initiating administrative proceedings, the President of the Personal Data Protection Office called on the Bank to indicate, m.in on what basis the controller concluded that the breach of personal data protection of Santander Bank Polska S.A.'s customers does not require notification to the supervisory authority and results in the lack of need to notify the persons affected by the breach. At the same time, the President of the Personal Data Protection Office requested that a risk analysis for this breach be submitted.

In response to the notice of initiation of the administrative procedure in the case at hand, by letter dated 19 December 2022 The Bank sent additional explanations in which it indicated that the breach of personal data protection of the Bank's customers, occurring as a result of the theft of a parcel containing the Bank's documentation during its transport in a courier company, and then abandonment of an open parcel in a gated community in K., was entered in the Register of Personal Data Violations of Santander Bank Polska S.A., under the number (...). The Assessment of the risk to the rights and freedoms of the data subject was set at a low level, and this Assessment was influenced by the following circumstances: the parcel was found by one identified person within a short period of time, after it was lost by the courier; The bank verified that no documents were missing; the person who found the documents took them directly to the police station; The person admitted that he had not copied the documents.

As a result of this assessment, the incident was not reported to the President of the Personal Data Protection Office. At the same time, the Bank also decided not to notify the persons affected by the breach.

After reviewing all the evidence gathered in the case, the President of the Personal Data Protection Office weighed the following:

As defined in Article 4(12) of Regulation 2016/679, a 'personal data breach' is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

Article 33(1) and (3) of Regulation 2016/679 provides that, in the event of a personal data breach, the controller shall, as far as possible, no later than 72 hours after becoming aware of the breach, report it to the supervisory authority competent in accordance with Article 33(1) of Regulation (EU) No Article 55, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. A notification submitted to the supervisory authority after 72 hours shall be accompanied by an explanation of the reasons for the delay. The notification referred to in paragraph 1 shall at least: (a) describe the nature of the personal data breach, including, where possible, the categories and approximate number of data subjects and the categories and approximate number of personal data alerts affected; (b) include the name and contact details of the Data Protection Officer or another point of contact from whom more information may be obtained; (c) describe the possible consequences of a personal data breach; (d) describe the measures taken or proposed by the controller to remedy the personal data breach, including, where applicable, measures to minimise its possible adverse effects.

On the other hand, pursuant to Article 34(1) of Regulation 2016/679, where there is a risk of a high risk to the rights and freedoms of natural persons, the controller is obliged to notify the data subject of the breach without undue delay. Article 34(2) of Regulation 2016/679 provides that a proper notification shall:
(1) describe in clear and plain language the nature of the personal data breach;
(2) contain at least the information and measures referred to in points (b), (c) and (d) of Article 33(3) of Regulation 2016/679, i.e.:
(a) the name and contact details of the Data Protection Officer or another point of contact from whom more information can be obtained;
(b) a description of the possible consequences of a personal data breach;
(c) a description of the measures taken or proposed by the controller to remedy the personal data breach, including, where applicable, measures to minimise its possible adverse effects.

Therefore, the analysis of the above-mentioned provisions shows that depending on the level of risk to the rights and freedoms of natural persons, the controller's obligations towards the supervisory authority and data subjects are different. If, as a result of the analysis, the controller finds that the likelihood of a risk of violation of the rights and freedoms of natural persons is low, it is not obliged to report the breach to the President of the Personal Data Protection Office. The infringement in question only has to be entered in the internal register of infringements. If a risk of violation of the rights and freedoms of natural persons is identified, the controller is obliged to report the data breach to the President of the Personal Data Protection Office, as well as to place an entry in the internal register of breaches. The occurrence of a high risk of violation of the rights and freedoms of natural persons, in addition to being entered in the register of breaches, requires the controller to take appropriate action, both against the supervisory authority (notification of a data breach), but also against the data subjects. Indeed, in the case of personal data breaches that may result in a high risk to the rights and freedoms of the data subject, Regulation 2016/679 introduces an additional obligation for the controller to notify the data subject without delay, unless the controller has taken preventive measures before the breach or remedial action after the breach has occurred (Article 34(3) of Regulation 2016/679).

As can be seen from the above, if the controller detects a personal data breach, it is first necessary to analyse the risk of violation of the rights and freedoms of natural persons. The controller is exempt from the obligation to notify the supervisory authority of a breach if the examination shows that there is at most a low probability of a risk of violation of the rights and freedoms of natural persons. However, it should be borne in mind that the supervisory authority will be able to ask the controller for justification for the decision not to report the breach, therefore the conclusions of the analysis should be recorded in the internal register of breaches. It is worth recalling that the Guidelines of the European Data Protection Board (EDPB) No 9/2022[1], adopted on 28 March 2023, contain recommendations on reporting personal data breaches to the supervisory authority.

It should be emphasised that the Assessment of the risk of violation of the rights and freedoms of a natural person should be made through the prism of the threatened person, and not the interests of the controller. This is particularly important because, based on a notification of a personal data breach, an individual can assess for themselves whether they believe that a security incident may cause negative consequences for them and take appropriate remedial action. Also on the basis of the information provided by the controller concerning the description of the nature of the breach and the measures taken or proposed to remedy the breach, the natural person may assess whether, after the personal data breach, the controller continues to warrant the proper processing of his or her personal data in a manner that ensures their security. Failure to notify a natural person of a personal data breach in the event of a high risk of violation of their rights or freedoms deprives them not only of the possibility of responding appropriately to the breach, but also of the possibility of independent Assessment of the breach, which, after all, concerns their personal data and may have serious consequences for them. On the other hand, failure to report a personal data breach deprives the supervisory authority of the possibility of responding appropriately to the breach, which consists not only in assessing the risk to the rights and freedoms of the natural person, but also, in particular, in verifying whether the controller has taken appropriate measures to remedy the breach and minimise the negative impact on data subjects, as well as whether it has taken appropriate security measures to minimise the risk of recurrence of the infringement.

Reporting personal data breaches by controllers is therefore an effective tool contributing to a real improvement in the security of personal data processing. When reporting a breach to the supervisory authority, controllers inform the President of the Personal Data Protection Office whether in their opinion there is a high risk to the rights and freedoms of data subjects and, if such a risk has occurred, whether they have provided relevant information to the natural persons affected by the breach. In justified cases, they may also provide information that, in their opinion, the notification is not necessary due to the fulfilment of the conditions set out in Article 34(3)(a) and (b) of Regulation 2016/679. The President of the Personal Data Protection Office verifies the Assessment made by the controller and may, if the controller has not notified the data subjects, request such notification from the controller. Notifications of personal data breaches allow the supervisory authority to react appropriately to limit the effects of such breaches, as the controller is obliged to take effective measures to ensure the protection of natural persons and their personal data, which on the one hand will allow for the control of the effectiveness of the existing solutions and, on the other hand, the Assessment of modifications and improvements aimed at preventing irregularities similar to those covered by the breach. On the other hand, notification of a breach to individuals provides an opportunity to provide them with information about the risks associated with the breach and to indicate the actions they can take to protect themselves from the potential negative effects of a personal data breach (this allows the individual to make his or her own Assessment of the breach in the context of the possibility of negative consequences materialising for such a person and to decide whether or not to apply the breach remedial action).

Santander Bank Polska S.A., due to the scale and subject matter of its operations, i.e. the provision of various types of financial services, processes the personal data of a very large number of customers with whom it concludes agreements for the provision of banking services. In the case under consideration, with the personal data of the Bank's Clients included in the bank documentation in the scope of: name and surname, date of birth, bank account number, address of residence or stay, PESEL registration number, e-mail address, username and/or password, data on earnings and/or assets, series and number of ID card, telephone number, information about banking products, loans, bank accounts, i.e. the names of the contracts, the date of their conclusion, the details of these products, as well as information about property insurance policies, i.e. m.in policy numbers, the date of their issuance, the sum insured, the insurance premium, information on the insured property, has been read by an unauthorized person. In addition, data related to the conclusion of contracts and their content were disclosed. It is also uncertain whether the documents in question were not read by other persons before the person who delivered the documents to the police station, as they were in a public place. There is therefore no doubt that, on the basis of the data disclosed, the data subjects can be easily identified.

Consequently, the very Assessment of the breach carried out by the controller in terms of the risk of infringement of the rights and freedoms of natural persons, which is necessary to determine whether there has been a data breach resulting in the need to notify the President of the Personal Data Protection Office (Article 33(1) and (3) of Regulation 2016/679) and the persons affected by the breach (Article 34(1) and (2) of Regulation 2016/679), should, as it should be emphasised once again, through the prism of the person affected by the infringement. Accidental disclosure of personal data to even a single identified person may lead to an increase in the scale of the breach and thus the risk of violation of the rights and freedoms of the data subject. At the same time, the Controller has not demonstrated, in accordance with the principle of Accountability referred to in Article 5(2) of Regulation 2016/679, that the person who found the parcel may be considered a so-called trusted recipient. According to the explanations provided by the Bank in its letter of 16 September 2022, it refrained from reporting the breach in question to the supervisory authority because "the parcel was found by one identified person in a short period of time, after it was lost by the courier". The risk Assessment was based on the belief that the person who came into possession of the parcel with the Bank's documents is the so-called "honest finder" because "it has been verified that no documents are missing", "the person who found the documents took them directly to the police station" and "the person admitted that he did not copy the documents". Taking the above into account, in the opinion of the Controller, "the Assessment of the risk of violation of the rights and freedoms of the data subject has been set at a low level".

To better illustrate cases of personal data breaches, as a result of which data has been accidentally disclosed to an unauthorized person, reference should be made to Guideline 9/2022, which indicates a case of a data breach involving the erroneous disclosure of personal data to a third party or other recipient in a situation where the data is accidentally sent to the wrong department of the organization or to a supplier organization. services used by the Administrator. In such a case, the controller has grounds to consider the unauthorised recipient to be trusted, because it has a stable relationship with such an entity, knows its procedures and can trust the recipient enough to be able to reasonably expect that the recipient will not read the data sent by mistake or gain access to it, as well as comply with the order to send it back. Even if the data has been accessed, the controller can still trust the recipient not to take any inappropriate action and to return the data to the controller immediately. As the EDPB further points out, in the case described above, the controller may take into account the fact that the recipient is a trusted person in the risk Assessment carried out following the breach. However, that is certainly not the case here. A third party who has accidentally found a parcel with bank documentation containing very detailed personal data of the Bank's Customers does not have any relations with the Bank that would allow it to be assumed that it is a trusted recipient, in accordance with the above position of the EDPB.

Referring to the above, it should be pointed out that it is also irrelevant that the data was made available to only one identified person, but rather the fact that the parcel was found by one identified person is important. As mentioned earlier, the Bank is not sure how many people could have had access to the abandoned parcel because, as it claims, it was stolen during transport in a courier company, which should have a sufficient impact on the proper and adequate Assessment of the security incident in question, including the Assessment of the risk of violation of the rights and freedoms of natural persons. Even if the wrong recipient is a person known to the Controller (e.g. his client who informs about the mistake), there is no guarantee that the intentions of this person will not change. The above Assessment is also not affected by the fact that the wrong recipient received a statement about maintaining the confidentiality of the Bank's Customers' data, or, as was the case in the present case, an admission that the person did not copy the documents. It is not certain whether, prior to submitting the statement, the person did not make copies or record the personal data contained in the content of the documentation in another way, e.g. by writing them down. Also, the Bank is not able to actually verify the assurance that the unauthorized recipient has not transferred the Bank's Customers' data to third parties or does not have a copy of this data. A similar opinion was expressed by the Provincial Administrative Court in Warsaw, which in its judgment of 21 January 2022, ref. no. II SA/Wa 1353/21, stated that "(...) There is no certainty that the person did not make a photocopy or record the personal data contained in the document in any other way, e.g. by writing them down, before these activities. The mere performance of the actions indicated in the statements made by the Third Party - the unauthorized recipient - does not guarantee that the intentions of such a person will not change now or in the future, and the possible consequences of the use of such categories of data may be significant for the persons whose data have been affected by the breach." It should be emphasised once again that a statement made by an unauthorised person does not mean that the breach is unlikely to result in a risk to the rights and freedoms of natural persons and does not preclude the assumption that there is a high risk to the rights and freedoms of data subjects.

As indicated in Guidelines 9/2022, a personal data breach has the potential to have a number of negative effects on the individuals whose data is the subject of the breach. Among the possible consequences of a breach, the EDPB mentions: physical, material or non-material damage. Examples of such damages include, m.in discrimination, identity theft or fraud, financial loss, damage to reputation, breach of the confidentiality of personal data, and significant economic or social harm. In the present case, there is no doubt that, due to the scope of data covered by the personal data breach in question, including PESEL registration numbers with names and surnames, there is a high probability of the above-mentioned damages occurring.

First of all, it should be emphasised that the personal data breach concerned the PESEL registration number, i.e. an eleven-digit numerical symbol that unambiguously identifies a natural person, containing, m.in, the date of birth and the gender designation, and thus closely related to the private sphere of the natural person and also subject, as a national identification number, to exceptional protection under Article 87 of Regulation 2016/679 – which is data with a special nature and such special protection in need. The PESEL number serves as a data identifying each person and is commonly used in contacts with various institutions and in legal transactions. The PESEL number, together with the name and surname, unambiguously identifies a natural person, in a way that allows to attribute the negative effects of the breach (e.g. identity theft, loan fraud) to that specific person. In addition, it should be taken into account that as a result of the personal data breach in question, these registration numbers were made available to at least one unauthorized person, together with the name and surname of the Bank's customers, which combination of data may be sufficient to "impersonate" the subject of these data and incur e.g. monetary liabilities on behalf of and to the detriment of such an entity (vide: https://www.bik.pl/poradnik-bik/wyludzenie-kredytu-tak-dzialaja-oszusci – where a case was described in which: "Only the name, surname and PESEL number were enough for fraudsters to extort a dozen or so loans for a total of tens of thousands of zlotys. Nothing else matched: neither the ID card number nor the address of residence."). It should also be noted that the 158 persons in question also affected a huge range of other data identifying them, such as contact details (which are commonly assumed to include the address of residence or residence, telephone number and e-mail address), date of birth, bank account numbers, series and numbers of identity cards, usernames and/or passwords. data on earnings and/or assets held, or the content of the agreements concerning banking products themselves (names of agreements, dates of their conclusion, details of these products) and a number of information related to property insurance policies (m.in. policy numbers, dates of their issuance, sums insured, insurance premiums, information on insured property). A key factor in the risk Assessment is the type and sensitivity of the personal data disclosed as a result of the breach. Guideline 9/2022 highlights that a set of different personal data is usually more sensitive than individual data.

At this point, it is worth quoting one of the examples found in the Guidelines of the European Data Protection Board 01/2021[2] (case no. 14, p. 31), referring to the situation of "sending highly confidential personal data by post by mistake". In the case described in the above-mentioned guidelines, a social security number was disclosed, which is the equivalent of the PESEL number used in Poland. In this case, the EDPB had no doubt that the disclosed data, including name, e-mail address, postal address, social security number, indicated a high risk of violation of the rights and freedoms of natural persons ("the involvement of their [the victims'] social security number, as well as other, more basic personal data, further increases the risk, which can be described as high"). The EDPB recognises the importance of national identification numbers (in this case, the PESEL number), while stressing that this type of personal data breach, i.e. covering data in the form of: name and surname, e-mail address, correspondence address and social security number, requires the implementation of actions, i.e. notification of the supervisory authority and notification of the breach of data subjects.

The European Data Protection Board has no doubt that an individually assigned number uniquely identifying a natural person should be subject to special protection, and its disclosure to unauthorised entities may entail a high risk of infringement of the rights and freedoms of natural persons.

The fact that data uniquely identifying a natural person may cause a high risk of violation of the rights and freedoms of the EDPB is also indicated by other examples provided in Guideline 01/2021. Points 65 and 66 of Guideline 01/2021 state: "(...) The compromised data allows for the unambiguous identification of data subjects and contains other information about them (including gender, date and place of birth), and can be used by an attacker to guess customer passwords or to launch a spear phishing campaign targeting the bank's customers. For these reasons, it was considered that a data breach is likely to result in a high risk to the rights and freedoms of all data subjects. As a result, material damage (e.g. financial loss) and non-material damage (e.g. identity theft or fraud) may occur."

The Provincial Administrative Court in Warsaw did not have similar doubts (that the disclosure of the PESEL number together with other personal data may result in a high risk of violation of the rights and freedoms of natural persons), which in its judgment of 22 September 2021, ref. no. II SA/Wa 791/21, stated that "There is no doubt that the examples of damage referred to in the guidelines may occur in the case of persons whose personal data – in some cases including the PESEL registration number or the series and number of the ID card – have been recorded on the recordings made available. Not without significance for such an Assessment is the possibility of using the disclosed data to identify the persons whose data have been affected by the breach." Further, the Court pointed out in the cited ruling that "the data were made available to unauthorized persons, which means that there was a security breach leading to unauthorized disclosure of personal data, and the scope of this data, including in some cases also the PESEL registration number or the series and number of the identity card, determines that there was a high risk of violation of the rights and freedoms of natural persons." When considering the above issues, it is also necessary to Recall the position of the Provincial Administrative Court in Warsaw expressed in the judgment of 1 July 2022 issued in the case ref. no. II SA/Wa 4143/21. In the justification of this judgment, the Court stated that: "It should be agreed with the President of the Personal Data Protection Office that the loss of confidentiality of the PESEL number in combination with personal data, such as: name and surname, registered address, bank account numbers and the identification number assigned to the Bank's customers - CIF number, is associated with a high risk of violation of the rights and freedoms of natural persons. In the event of a breach of data such as name, surname and PESEL number, it is possible to steal or falsify identity, resulting in negative consequences for data subjects. Therefore, in the present case, the Bank should have notified the data subjects of the personal data breach without undue delay, pursuant to Article 34(1) of the GDPR, so as to enable them to take the necessary preventive measures" (emphasis added). It is also worth mentioning the judgment of 31 August 2022, ref. no. II SA/Wa 2993/21, in which the Provincial Administrative Court in Warsaw emphasised that "(...) The authority correctly assumed that there was a high risk of violation of the rights and freedoms of the persons affected by the breach in question due to the possibility of easy identification of persons whose data were affected by the breach based on the disclosed data. This data includes the name and surname, correspondence address, telephone number, PESEL number of persons with Polish citizenship. In those circumstances, the controller was required to notify the data subjects of the breach without undue delay.' A similar opinion was expressed by the Provincial Administrative Court in Warsaw in its judgments of 15 November 2022, ref. no. act II SA/Wa 546/22, of 21 June 2023, ref. no. act II SA/Wa 150/23 and of 6 November 2023, ref. no. II SA/Wa 996/23.

In the light of the above, it is also worth recalling the judgment of the Supreme Administrative Court in Warsaw of 6 December 2023, ref. no. Act III OSK 2931/21, in which it was stated: "The President of the Personal Data Protection Office correctly determined that there was a disclosure of data m.in. in the scope of names and surnames, as well as PESEL numbers of natural persons, i.e. relatively permanent, unchangeable data, the disclosure of which may always give rise to the risk of negative consequences for the above-mentioned persons. Similarly, residential addresses are personal data the unauthorised disclosure of which creates a high risk of negative legal consequences, regardless of the fact that the disclosure of the addresses took place several years after they were updated.'

From the latest infoDOK report[3] (which is being prepared as part of the Social Information Campaign of the RESTRICTED DOCUMENTS System, organized by the Polish Bank Association and some banks, under the auspices of the Ministry of the Interior and Administration and in cooperation with, m.in, the Police and the Consumer Federation), shows that in the third quarter of 2023 alone, 2587 attempts to extort loans and advances for a total amount of PLN 104.1 million were recorded. On the other hand, in the whole of 2021, 8,096 attempts to extort loans for a total amount of PLN 336.6 million were recorded, while in the whole of 2022 there were 8,079 attempts to extort loans.

Moreover, according to court rulings, judgments in cases of loan fraud are not uncommon and have been issued by Polish courts in similar cases for a long time. By way of example, one can point to the judgment of the District Court in Łęczyca of 27 July 2016 (file reference number I C 566/15), in which fraudsters taking a loan using someone else's data used a PESEL number, a fictitious address and an incorrect ID number (invalid). In the justification of the above-mentioned judgment, the Court stated that:

"The evidentiary proceedings and the analysis of the documents attached by the plaintiff result in the fact that it can be clearly stated that in the present case the defendant was not a party to the loan agreement concluded on 5 May 2014. Although the PESEL number of the defendant J.R. was used when concluding the agreement, the indicated place of residence does not correspond to the defendant's place of residence. The defendant J.R. never lived in W. The amount of the loan was transferred to an account not held by the defendant. On the date of concluding the loan agreement, the ID card no. (...) expired on 15 March 2014. The mobile phone number indicated on the loan agreement and its appendices is also inconsistent with the actual telephone numbers used by the defendant."

In another case (I C 693/16), the District Court in Zgierz, in its judgment of 4 November 2016, ruled: "The personal data of the defendant in the form of his name and surname and PESEL number, which were consistent with the defendant's data, did not prove that the defendant made a declaration of intent to conclude a loan agreement on 17 December 2014. It cannot be ruled out that a person who has gained unauthorised access to the defendant's personal data may have entered into a loan agreement with (...) sp. z o.o. on the defendant's account. In the present case, the defendant proved that he had never lived at the address indicated in the loan agreement and that the telephone number and e-mail address used to register on the website and apply for the loan belonged to him."

There are still many cases related to loan fraud, where unknown persons usually only have their name and surname and the correct PESEL number (the rest of the data is false), which is confirmed by the judgments issued by the courts in these cases. Here are some examples:

  • Judgment of the District Court for Łódź-Widzew in Łódź of 13 August 2020 in the case ref. no. II C 1145/19, in which a third party unknown to the defendant illegally came into possession of his PESEL number and ID card number, and the remaining address data - indicated in the loan agreement - were false - "In the opinion of the Court, the evidence offered by the defendant - especially the documents from the files of the criminal case pending before the District Court in Tarnowskie Góry with file number VI K 383/16 - prove that the that the loan agreement of 8 November 2014 was concluded by a third party using some of Z.A.'s personal data. She gave a false address of residence where the defendant never resided, and the amount of the loan was transferred to a bank account that did not belong to Z.A. [...] and the ID number given in that agreement was an ID number which the defendant no longer used on the date of conclusion of the loan agreement, expired about 8 months earlier';
  • Judgment of the District Court in Pisz of 21 August 2020, ref. no. I C 260/20 — '... The court found that when concluding the agreement in question, the defendant's data was used in an unauthorized manner and entered as the borrower's data, and the defendant was not a party to the agreement. The defendant's position is confirmed by the complaint filed by him on the commission of the crime of fraud against him, as well as by the fact that the prosecutor's office is conducting proceedings in this case against a person indicated by the defendant. By the way, it should be noted that also in the context of the proceedings pending before the local court for the payment of ref. no. I C 1/19 and I C 482/19, where E.M. was also a defendant and where financial obligations were incurred in his name in the same circumstances as in the present proceedings, final judgments dismissing the action were also made. In the court's opinion, the circumstances of concluding the agreement with the plaintiff, where the first and last name of the borrower and his PESEL number are identical, and there is a discrepancy as to the other data resulting from the content of the defendant's identity card, i.e. the series and number of this document, the address of residence, taking into account the fact that a criminal trial was being conducted in relation to the person who was to impersonate the defendant, for the purpose of concluding contracts at a distance and incurring financial obligations in various institutions, clearly indicate that it was not the defendant who entered into a loan agreement No. (...) with the plaintiff's predecessor in title";
  • Judgment of the District Court in Puławy of 7 April 2022 in the case ref. no. I C 475/19, in which the Court of First Instance unequivocally acknowledged that '... The mere indication of the defendant's personal data: name, surname, PESEL number, as well as the series and number of the identity card in the content of the agreement is not evidence allowing for the verification of the defendant as a party to the agreement in question - in particular in a situation where the loan is concluded via an online platform, so obviously, the lender does not have the possibility of directly verifying the identity of the other party, and the contract itself is not confirmed by the borrower's signature."

It should also be borne in mind that the Controller's performance of its obligation under Article 34(1) of Regulation 2016/679 may not be made conditional on the occurrence of a breach of the rights and freedoms of natural persons whose data are affected by the personal data breach. The same applies to the obligation under Article 33(1) of Regulation 2016/679, as stated by the Provincial Administrative Court in Warsaw in its judgment of 22 September 2021 issued in the case ref. no. II SA/Wa 791/21: "It should be emphasized that the possible consequences of the event do not have to materialize. Article 33(1) of Regulation 2016/679 states that the mere occurrence of a personal data breach involving a risk to the rights and freedoms of natural persons implies an obligation to notify the breach to the competent supervisory authority, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. (the Court ruled in a similar way in the previously cited judgment of 1 July 2022 issued in case no. II SA/Wa 4143/21 and in the judgments of 31 August 2022, ref. no. II SA/Wa 2993/21, of 15 November 2022, ref. no. II SA/Wa 546/22 and of 26 April 2023, Ref. No. II SA/Wa 1272/22). The application of the provisions of Regulation 2016/679 should bear in mind the objective of that Regulation (as expressed in Article 1(2)), which is to protect the fundamental rights and freedoms of natural persons, in particular their right to the protection of personal data. On the other hand, the protection of individuals with regard to the processing of personal data is one of the fundamental rights (first sentence of recital 1). In the event of any doubts, e.g. as to the performance of duties by controllers – including in a situation where there has been a personal data breach – these values should be taken into account in the first place.

It is worth emphasizing that when assessing the risk of violation of the rights and freedoms of natural persons, on which the filing of a notification of a personal data breach depends, for m.in, the probability factor and the severity of the potential negative effects should be taken into account. A high level of any of these factors has an impact on the level of the overall Assessment on which the fulfilment of the m.in obligation set out in Article 33(1) of Regulation 2016/679 depends. Given that, given the scope of the personal data disclosed, there was a possibility of serious negative consequences for data subjects materialising in the present case, the significance of the potential impact on the rights and freedoms of natural persons should be considered high. At the same time, the likelihood of a high risk arising from the breach in question is not small and has not been eliminated. Thus, it must be stated that in connection with the breach in question, there was a high risk of violation of the rights and freedoms of data subjects, which consequently determines the obligation to notify the personal data breach to the supervisory authority.

In Guideline 9/2022, the EDPB, when indicating the factors to be taken into account in the risk assessment, refers to recitals 75 and 76 of Regulation 2016/679, which suggest that the controller should take into account both the likelihood of occurrence and the seriousness of the threat to the rights and freedoms of the data subject. In the event of a personal data breach, the controller should focus its attention on the risk of the breach affecting a natural person. Therefore, when assessing the risk to an individual arising from a personal data breach, the controller should take into account the specific circumstances of the breach, including the severity of the potential impact and the likelihood of its occurrence. Therefore, when assessing the risk, the EDPB recommends taking into account criteria such as the type of breach, the nature, sensitivity and volume of personal data, as well as the ease of identification, as these may have an impact on the level of risk for individuals. The risk of violating the rights and freedoms of an individual in accordance with Guideline 9/2022 will be greater when the consequences of the violation are more serious, as well as when the likelihood of their occurrence increases. The guidelines indicate that in case of any doubt, the administrator should report the violation, even if such caution could turn out to be excessive.

Summarizing the above considerations, it should be stated that in the present case there is a high risk of violation of the rights and freedoms of the persons affected by the breach in question, which in turn results in the Bank's obligation to report the personal data breach to the supervisory authority, in accordance with Article 33(1) of Regulation 2016/679, which must include the information specified in Article 33(3) of Regulation 2016/679 and to notify the persons of the breach, accordance with Article 34(1) of Regulation 2016/679, which must include the information set out in Article 34(2) of Regulation 2016/679. A bank which, due to the nature of its business, processes personal data on a massive scale, should be aware of the obligations arising from the provisions of law related to the determination of a personal data breach. Informing the Administrator about its obligations in the field of personal data protection, as well as advising the Administrator, is also one of the tasks of the Data Protection Officer appointed at the Bank. The Bank should also have knowledge in this respect due to the previously issued decision imposing an administrative fine against it for violating Article 34(1) of Regulation 2016/679, consisting in failing to notify the data subjects of a personal data breach without undue delay (decision of 19 January 2022, ref. no. (...)), all the more so as the Administrator's complaint against this decision was dismissed by the judgment of the Provincial Administrative Court in Warsaw of 15 November 2022 (ref. no. II SA/Wa 546/22).

Referring to the Controller's obligation set out in Article 34(2) of Regulation 2016/679, the President of the Personal Data Protection Office stated that the Controller (taking into account the nature of the breach and the categories of data that have been breached) should indicate to data subjects the most likely negative consequences of a breach of their personal data. Certainly, in the case of a breach of such data as names, surnames and PESEL registration numbers, it should be pointed out first of all to the possible theft or falsification of identity by third parties, to the detriment of the persons whose data has been breached, loans from non-bank institutions or extortion of insurance or insurance funds, which may result in negative consequences related to the attempt to assign to the person, responsible for the commission of such fraud. Indeed, the description of the possible consequences must reflect the risk to the rights and freedoms of that person in order to enable him or her to take the necessary preventive measures.

In a situation where, as a result of a personal data breach, there is a high risk of violation of the rights and freedoms of natural persons, the controller is obliged to implement all appropriate technical and organizational measures to immediately identify a personal data breach and promptly inform the supervisory authority as well as the data subjects. The Controller should comply with this obligation as soon as possible.

Recital 85 of the preamble to Regulation 2016/679 explains: "In the absence of an adequate and prompt response, a personal data breach may result in physical, material or non-material damage to individuals, such as loss of control over their personal data or restriction of rights, discrimination, theft or falsification of identity, financial loss, unauthorised reversal of pseudonymisation, damage to reputation, breach of data confidentiality protected by professional secrecy or any other significant economic or social damage. Therefore, as soon as a personal data breach is identified, the controller should report it to the supervisory authority without undue delay, if practicable, no later than 72 hours after the breach has been identified, unless the controller is able to demonstrate in accordance with the principle of Accountability that the breach is unlikely to give rise to a risk to the rights and freedoms of natural persons. If it is not possible to make a notification within 72 hours, the notification should be accompanied by an explanation of the reasons for the delay and the information may be communicated gradually without further undue delay.'

Recital 86 in the preamble to Regulation 2016/679 states: 'The controller shall inform the data subject without undue delay of a personal data breach where it is likely to give rise to a high risk to the rights and freedoms of that person in order to enable that person to take the necessary preventive measures. Such information should include a description of the nature of the personal data breach and recommendations to the individual on how to minimise the potential adverse effects. The information should be provided to data subjects as soon as reasonably practicable, in close cooperation with the supervisory authority, respecting the guidance provided by that authority or other relevant authorities, such as law enforcement authorities. For example, the need to minimise the imminent risk of harm will require data subjects to be informed without delay, while the implementation of appropriate measures against the same or similar data breaches may warrant subsequent notification."

By notifying the data subject without undue delay, the controller enables the person to take the necessary preventive measures to protect the rights or freedoms against the adverse effects of the breach. Article 34(1) and (2) of Regulation 2016/679 aims not only to ensure the most effective protection of the fundamental rights or freedoms of data subjects, but also to implement the principle of transparency, which stems from Article 5(1)(a) of Regulation 2016/679 (cf. Witold Chomiczewski [in:] GDPR. General Data Protection Regulation. Commentary. ed. E. Bielak – Jomaa, D. Lubasz, Warsaw 2018). The proper fulfilment of the obligation set out in Article 34 of Regulation 2016/679 is intended to ensure that data subjects are promptly and transparently informed of a personal data breach, together with a description of the possible consequences of a personal data breach and the measures they can take to minimise its possible negative effects. By acting in accordance with the law and by looking after the interests of data subjects, the controller should have ensured without undue delay that the data subjects could be protected in the best possible way. In order to achieve that objective, it is necessary at least to indicate the information listed in Article 34(2) of Regulation 2016/679, which the Bank has failed to comply with. Therefore, by making the decision not to notify the supervisory authority and the data subjects of the breach, the controller has in practice deprived the data subjects of reliable information about the breach of the protection of their personal data, provided without undue delay, and the possibility of counteracting potential damage.

Consequently, it must be concluded that the Controller did not notify the personal data breach to the supervisory authority in compliance with the obligation under Article 33(1) of Regulation 2016/679 and did not notify the data subjects of the breach of their data without undue delay, in accordance with Article 34(1) of Regulation 2016/679, which means that the Controller has infringed those provisions.

At this point, it should be noted that, in accordance with Article 34(4) of Regulation 2016/679, if the controller has not yet notified the data subject of a personal data breach, the supervisory authority, taking into account the likelihood that the personal data breach will result in a high risk, may request it to do so or may conclude that one of the conditions is met, referred to in paragraph 3. On the other hand, it is clear from the wording of Article 58(2)(e) of Regulation 2016/679 that each supervisory authority has a remedial power to order the controller to notify the data subject of a data breach.

In accordance with Article 58(2)(i) of Regulation 2016/679, each supervisory authority has the power to apply, in addition to or instead of the other remedies provided for in Article 58(2) of Regulation 2016/679, an administrative penalty payment under Article 83 of Regulation 2016/679, depending on the circumstances of the particular case. The President of the Personal Data Protection Office states that in the case under consideration there were grounds justifying the imposition of an administrative fine on the Bank on the basis of Article 83(4)(a) of Regulation 2016/679, which provides m.in that a breach of the controller's obligations referred to in Articles 33 and 34 of Regulation 2016/679 is subject to an administrative fine of up to EUR 10,000,000, and in the case of an enterprise – up to 2% of its total annual worldwide turnover from the previous year the higher amount applies.

Pursuant to Article 83(2) of Regulation 2016/679, administrative fines are to be imposed, depending on the circumstances of each individual case, in addition to or instead of the measures referred to in Article 58(2)(a) to (h) and (j) of Regulation 2016/679. When deciding to impose an administrative penalty on the Bank, the President of the Personal Data Protection Office – pursuant to Article 83(2)(a)-(k) of Regulation 2016/679 – took into account the following circumstances of the case, which make it necessary to apply such a sanction in the present case and have an aggravating impact on the amount of the administrative penalty imposed:

1. The nature, gravity and duration of the breach, taking into account the nature, scope or purpose of the processing in question, the number of data subjects affected and the extent of the damage suffered by them (Article 83(2)(a) of Regulation 2016/679).
In the present case, a violation of Article 33(1) of Regulation 2016/679 (consisting in failing to notify the President of the Personal Data Protection Office of a personal data breach without undue delay, no later than within 72 hours after the breach became known) and Article 34(1) of Regulation 2016/679 (consisting in failure to notify the persons responsible for the breach of personal data without undue delay data subjects). They are related to the disclosure of personal data of the Bank's customers in the scope of: names and surnames, date of birth, bank account numbers, addresses of residence or residence, PESEL registration numbers, e-mail addresses, username and/or password, data on earnings and/or assets, series and number of identity cards, telephone number, information about banking products, loans, bank accounts, i.e. the names of the contracts, the dates of their conclusion, the details of these products, information on property insurance policies, i.e. m.in. policy numbers, dates of their issuance, sums insured, insurance premiums, information on the insured property, as a result of theft of a parcel containing the Bank's documentation during its transport in a courier company, and then abandonment of the open parcel in a publicly accessible place, as a result of which the documentation was read by an unauthorised person (at least one). This event is of significant importance and serious in nature, as it can lead to material or non-material damage to the individuals whose data has been compromised, and the probability of its occurrence is high. In connection with the occurrence of a personal data breach, consisting in the loss of a parcel containing bank documentation, there was an unlawful disclosure of information covered by banking secrecy, which further increases the seriousness of the breach and indicates the possibility of negative consequences of the event for data subjects.

In addition, an aggravating circumstance is the fact that the breach, consisting in the failure to notify persons of the breach of the protection of their personal data, covered the personal data of many people, as it concerned 158 persons, and although in the present case there is no evidence that the persons to whose data was accessed by an unauthorised person suffered material damage, the breach of the confidentiality of their data itself constitutes non-material damage (harm) for them. At the very least, individuals whose data has been obtained in an unauthorised manner may be afraid of losing control over their personal data, identity theft or identity fraud, discrimination or financial loss. As indicated by the District Court in Warsaw in its judgment of 6 August 2020, ref. no. XXV C 2596/19, the fear, and thus the loss of security, constitutes real non-pecuniary damage entailing an obligation to remedy it. On the other hand, the Court of Justice of the EU in its judgment of 14 December 2023 in the case of Natsionalna agentsia za prihodite (C-340/21) emphasised that "Article 82(1) of the GDPR must be interpreted as meaning that the fear of possible misuse of personal data by third parties as a result of a breach of that regulation may in itself constitute 'non-pecuniary damage' within the meaning of that provision".

The President of the Personal Data Protection Office also considers the long duration of the Bank's breach of the provisions of Regulation 2016/679 as an aggravating circumstance, as it should be emphasised that the state of infringement on which the present proceedings are based is still ongoing and the breach itself is continuous. The Bank has still not reported the breach, which is justified by the low risk of infringement of the rights and freedoms of the natural persons affected; It also failed to notify individuals of the breach of their personal data. On the other hand, the Administrator received information about the personal data breach, i.e. finding abandoned documents of the Bank's customers, on 24 November 2018, so over the years the risk of violating the rights and freedoms of the persons affected by the breach could have materialized, and these persons could not prevent it due to the Bank's failure to comply with the obligation to report the personal data breach to the President of the Personal Data Protection Office and the obligation to notify persons about it, data subjects.

2. The intentional nature of the infringement (Article 83(2)(b) of Regulation 2016/679).
According to the Guidelines of the Article 29 Working Party on the application and determination of administrative pecuniary penalties for the purposes of Regulation 2016/679 WP253 (adopted on 3 October 2017, endorsed by the EDPB on 25 May 2018), intention 'includes both knowledge and deliberate act, in relation to the characteristics of the offence'. The Bank made a conscious decision not to notify the President of the Personal Data Protection Office or the data subjects about the breach. There is no doubt that the Bank, when processing personal data on a mass scale, must have knowledge in the field of personal data protection, including knowledge of the consequences of a personal data breach resulting in a high risk of violation of the rights and freedoms of natural persons (and this knowledge may be required not only from the controller, but also from the Data Protection Officer appointed by him). Undoubtedly, the decision of the President of the Personal Data Protection Office of 19 January 2022 (described below, in point 3), against which the Bank's complaint was dismissed by the judgment of the Provincial Administrative Court in Warsaw of 15 November 2022 (file reference number II SA/Wa 546/22), is also a source of knowledge for the Bank in the scope of obligations related to the personal data breach. The administrative penalty imposed by the above-mentioned decision, together with an extensive justification in which the President of the Personal Data Protection Office referred to the applicable regulations and guidelines, contains the necessary information about the Controller's obligations related to the identified personal data breach. Therefore, it can be concluded that the Controller, being aware of its liability, disregarded its obligations related to the data breach and failed to notify the personal data breach to the President of the Personal Data Protection Office and to notify the data subjects of the breach. Finally, the very fact that the President of the Personal Data Protection Office initiated the present proceedings concerning the obligation to notify the supervisory authority of a personal data breach and to notify the data subjects of the breach should at least raise doubts in the Controller's mind as to the correctness of its position.

3. Any relevant previous infringements by the controller or processor (Article 83(2)(e) of Regulation 2016/679).
When deciding on the imposition and amount of an administrative fine, the supervisory authority is obliged to pay attention to any previous violations of Regulation 2016/679. EDPB in Guidelines 04/2022
[4] on the calculation of administrative fines under the GDPR adopted on 24 May 2023 explicitly states: "The existence of previous infringements may be considered as an aggravating factor in the calculation of the amount of the fine. The significance given to this factor should be determined by taking into account the nature and frequency of previous infringements. However, the absence of previous infringements cannot be regarded as a mitigating circumstance, since compliance with the provisions of [Regulation 2016/679] is the norm' (point 94 of the Guidelines).

The President of the Personal Data Protection Office has already conducted administrative proceedings against the Bank (described further in this paragraph) regarding the breach of the obligation under Article 34(1) of Regulation 2016/679 due to the failure to notify the data subjects of the personal data breach without undue delay. By decision of 19 January 2022, ref. no. (...), the President of the Personal Data Protection Office imposed an administrative fine on the Bank in the amount of PLN 545,748 for violating this provision of Regulation 2016/679. The above decision, as mentioned in point 2, was upheld by the judgment of the Provincial Administrative Court in Warsaw of 15 November 2022, dismissing the Bank's complaint (due to the cassation appeal filed by the Bank, the case is currently awaiting a decision by the Supreme Administrative Court). Repeated violation of the provisions of Regulation 2016/679 by failing to notify the data subjects of a personal data breach without undue delay, as well as failing to notify the President of the Personal Data Protection Office about the identified personal data breach, proves the Bank's disregard for the obligations related to the processing of personal data, underestimating the incident and failing to see its effect on Data Subjects. The infringement of the provisions of Regulation 2016/679, which is the subject of the present proceedings, and which is not, as has been indicated, a one-off case, deserves a negative assessment, which is reflected in the imposition of an administrative penalty on the Bank.

According to EDPB Guideline 04/2022 "Although all previous breaches may inform the general approach of the controller or processor to compliance with the GDPR, more importance should be given to infringements relating to the same subject matter as they are closer to the infringement which is the subject of the current proceedings, in particular where the controller or processor has previously committed the same infringement (repeated infringements). infringement)' (point 88 of the Guidelines). 'First of all, account must be taken of the time at which the earlier infringement took place, given that the longer the time between that infringement and the infringement currently under investigation, the less relevant that earlier infringement is' (point 84 of the Guidelines). Given that the supervisory authority had already conducted proceedings against Santander Bank Polska S.A. for infringement of Article 34(1) of Regulation 2016/679, which resulted in the issuance of a decision imposing an administrative fine, this circumstance should undoubtedly be considered as having an aggravating effect on the amount of the administrative penalty imposed.

In addition, the supervisory authority found in other administrative decisions issued that the Administrator violated the provisions on the protection of personal data:
- in the decision of 17 December 2020 (ref. no. (...)) infringement of Article 6(1) and Article 21(3) in conjunction with Article 12(3) of Regulation 2016/679;
- In the decision of 22 April 2021 (ref. no. (...)) infringement of Article 6(1) in conjunction with Article 5(1)(f) of Regulation 2016/679;
- in the decision of 29 June 2022 (ref. no. (...)) Article 6(1) of Regulation 2016/679;
- in the decision of 30 June 2022 (ref. no. (...)) Article 6(1) of Regulation 2016/679;
- In its decision of 7 July 2022 (ref. no. (...)) Article 6(1) of Regulation 2016/679;
- in the decision of 19 August 2022 (ref. no. (...)) infringement of Article 15(1) in conjunction with Article 12(3) of Regulation 2016/679;
- in the decision of 30 August 2022 (ref. no. (...)) infringement of Article 15(1) in conjunction with Article 12(3) of Regulation 2016/679;
- in the decision of 28 September 2022 (ref. no. (...)) infringement of Article 6(1) of Regulation 2016/679;
- in the decision of 10 November 2022 (ref. no. (...)) infringement of Article 6(1) of Regulation 2016/679;
- in the decision of 18 November 2022 (ref. no. (...)) infringement of Article 12(3) in conjunction with Article 15(3) of Regulation 2016/679;
- In its decision of 9 January 2023 (ref. no. (...)) infringement of Article 6(1) of Regulation 2016/679;
- In its decision of 22 August 2023 (ref. no. (...)) infringement of Article 6(1) in conjunction with Article 21(2) and (3) of Regulation 2016/679;
- in its decision of 22 September 2023 (ref. no. (...)) infringement of Article 6(1) of Regulation 2016/679;
- In its decision of 8 December 2023 (ref. no. (...)) infringement of Article 6(1) of Regulation 2016/679;
- in the decision of 23 January 2024 (ref. no. (...)) infringement of Article 6(1) of Regulation 2016/679;
- in the decision of 30 January 2024 (ref. no. (...)) Article 6(1) of Regulation 2016/679.

Not without significance are the violations described above, which resulted in the supervisory authority applying corrective measures to the final amount of the penalty imposed on the Administrator. The supervisory authority recognises a link between the previously identified breaches and the breaches currently analysed, such as the Bank's similar modus operandi, consisting in the deliberate failure to provide the authorised entities with certain personal data and information, which was the case, for example, in the case of a breach of Article 15(1) and Article 34(1) of Regulation 2016/679, or even the frequency of breaches of personal data protection regulations by the Controller. As can be seen from the list of decisions issued by the President of the Personal Data Protection Office presented above, at the turn of the last 4 months, the supervisory authority has already issued 3 decisions in which it applied a remedial measure against Santander Bank Polska S.A.

Therefore, the issuance of numerous warnings and the subsequent imposition of a fine in the case ref. no. (...), justifies not only the imposition of a financial sanction in the present proceedings, but also its high level.

In view of the foregoing, in the present case, it must be concluded that there are grounds for treating the condition in Article 83(2)(e) of Regulation 2016/679 as aggravating.

4. Cooperationwith the supervisory authority to remedy the infringement and mitigate its possible negative effects (Article 83(2)(f) of Regulation 2016/679).
In the present case, the President of the Personal Data Protection Office found the Bank's cooperation with him unsatisfactory. This Assessment concerns the Controller's reaction to the letters of the President of the Personal Data Protection Office informing about the obligations incumbent on the Controller in connection with a data breach, or finally to the initiation of administrative proceedings concerning the obligation to report a personal data breach and to notify data subjects of a breach. In the opinion of the President of the Personal Data Protection Office, the correct actions (reporting the breach to the President of the Personal Data Protection Office and notifying the persons affected by the breach) were not taken by the Bank even after the President of the Personal Data Protection Office initiated administrative proceedings in the case.

5. Categories of personal data affected by the breach (Article 83(2)(g) of Regulation 2016/679).
The disclosed personal data do not belong to the special categories of personal data referred to in Article 9(1) of Regulation 2016/679 or the data referred to in Article 10 of Regulation 2016/679, however, the fact that the abandoned documentation contains a wide range of them in the form of: name and surname, date of birth, bank account number, address of residence or stay, PESEL registration number, e-mail address, username and/or password, data on earnings and/or assets held, series and number of identity card, telephone number, information about banking products, loans, bank accounts, i.e. the name of contracts, the date of their conclusion, details of these products, as well as information about property insurance policies, i.e. m.in. policy numbers, date of their issuance, sum insured, insurance premium, information on insured property, This entails a high risk to the rights and freedoms of natural persons. The PESEL number, i.e. an eleven-digit numerical symbol uniquely identifying a natural person, containing the date of birth, serial number, gender designation and control number, and thus closely related to the private sphere of a natural person and also subject to exceptional protection under Article 87 of Regulation 2016/679 as a national identification number, is data of a special nature and requires such special protection. There is no other data that would unambiguously identify a natural person. It is not without reason that the PESEL number serves as data that identifies each person and is commonly used in contacts with various institutions and in legal circulation. The PESEL number, together with the name and surname, unambiguously identifies a natural person in a way that allows for attributing the negative effects of the breach (e.g. identity theft, loan fraud) to that specific person.

In this context, it is worth recalling the EDPB Guideline 04/2022, which states: "With regard to the requirement to take into account the categories of personal data affected by the breach (Article 83(2)(g) of [Regulation 2016/679]), [Regulation 2016/679] clearly indicates the types of data that are subject to special protection and thus a stricter response when imposing fines. This applies at least to the types of data covered by Articles 9 and 10 of [Regulation 2016/679] and to data outside the scope of those articles, the dissemination of which immediately causes harm or discomfort to the data subject (e.g. location data, private communication data, national identification numbers or financial data such as transaction statements or credit card numbers). In general, the more such categories of data are affected by a breach or the more sensitive the data is, the more weight the supervisory authority may assign to such a factor. The amount of data on each data subject also matters, as the more data is shared with each data subject, so does the breach of the right to privacy and the protection of personal data."

It is worth pointing out once again the emerging case law in this area, where, for example, in the judgment of 15 November 2022 ref. no. II SA/Wa 546/22, the Provincial Administrative Court in Warsaw stated: "It was also obvious that the authority, when determining the amount of the penalty, had to take into account the fact that the infringement concerned highly sensitive data (m.in. PESEL, address, health data)". This view was also shared by the above-mentioned Court in its judgment of 21 June 2023 in the case ref. no. II SA/Wa 150/23, where the Provincial Administrative Court in Warsaw stated: "To sum up, the Court is of the opinion that the disclosure of the PESEL number indicates a high risk of violation of the rights and freedoms of natural persons".

When determining the amount of the administrative fine, the President of the Personal Data Protection Office found no grounds to take into account mitigating circumstances affecting the final amount of the penalty. In the opinion of the supervisory authority, all the conditions listed in Article 83(2)(a) to (j) of Regulation 2016/679 are either aggravating or merely neutral. Also applying the condition set out in Article 83(2)(k) of Regulation 2016/679 (requiring that any other aggravating or mitigating factors applicable to the circumstances of the case be taken into account), no mitigating circumstances were found.

The following other circumstances referred to in Article 83(2) of Regulation 2016/679, after assessing their impact on the infringement found in the present case, were considered by the President of the Personal Data Protection Office to be neutral in his opinion, i.e. having neither an aggravating nor mitigating effect on the amount of the administrative penalty imposed:

1. Measures taken by the controller to minimise the damage suffered by data subjects (Article 83(2)(c) of Regulation 2016/679).
On the basis of the evidence gathered in the case, it was not found that the Administrator had taken such actions.

2. Degree of responsibility of the controller, taking into account the technical and organisational measures implemented by the controller pursuant to Articles 25 and 32 (Article 83(2)(d) of Regulation 2016/679).
The infringement of the provisions of Regulation 2016/679 assessed in the present proceedings (failure to notify the President of the Personal Data Protection Office of a personal data breach and failure to notify data subjects of a personal data breach) is not related to the technical and organisational measures applied by the controller.

3. How the supervisory authority became aware of the breach (Article 83(2)(h) of Regulation 2016/679).
The President of the Personal Data Protection Office was not informed of the personal data breach which is the subject of the present case in accordance with the procedure provided for in such situations set out in Article 33 of Regulation 2016/679. The President of the Personal Data Protection Office received information about the occurrence of the breach in question related to the disclosure of personal data of the Bank's customers as a result of the theft of a parcel containing bank documentation concerning 158 people during its transport in a courier company, and then abandoning the open parcel in a publicly accessible place, as a result of which an unauthorised person became acquainted with the documentation, from a message on the portal (...), where the incident of "leaking the documents of the bank's customers" was described, which "were found in a cardboard box scattered in a gated community in K.". The failure to notify the supervisory authority of a personal data breach and to notify the data subjects of the personal data breach is the sole subject of the present proceedings and, in the circumstances of the facts under consideration, the supervisory authority assumed that it would not treat this condition as an aggravating circumstance.

4. Compliance with the measures referred to in Article 58(2) of Regulation 2016/679 previously taken in the same case (Article 83(2)(i) of Regulation 2016/679).
Prior to the issuance of this decision, the President of the Personal Data Protection Office did not apply any of the measures listed in Article 58(2) of Regulation 2016/679 to the Controller in the case under consideration, and therefore the Controller was not obliged to take any action related to their application, and which, if assessed by the President of the Personal Data Protection Office, could have an aggravating or mitigating impact on the Assessment of the infringement found.

5. Use of approved codes of conduct under Article 40 of Regulation 2016/679 or approved certification mechanisms under Article 42 of Regulation 2016/679 (Article 83(2)(j) of Regulation 2016/679).
The Controller shall not apply the instruments referred to in Articles 40 and 42 of Regulation 2016/679. However, their adoption, implementation and application are not, as provided for in Regulation 2016/679, mandatory for controllers and processors, so that the fact that they are not applied cannot be construed to the detriment of the controller in the present case. On the other hand, the Controller could benefit from the fact that such instruments are adopted and used as measures to guarantee a higher than standard level of protection of the personal data being processed.

6. Financial gains or losses avoided directly or indirectly as a result of the infringement (Article 83(2)(k) of Regulation 2016/679).
The President of the Personal Data Protection Office did not find that the Controller had gained any financial benefits or avoided such losses in connection with the breach. Therefore, there are no grounds to treat this circumstance as incriminating against the Controller. A finding of measurable financial benefits resulting from the infringement of Regulation 2016/679 should be assessed as decidedly negative. On the other hand, the failure of the Administrator to achieve such benefits, as a natural state, independent of the infringement and its consequences, is a circumstance which, by its very nature, cannot be mitigating for the Administrator. This is confirmed by the wording of Article 83(2)(k) of Regulation 2016/679, which requires the supervisory authority to pay due attention to the 'gains' from the infringer.

The President of the Personal Data Protection Office does not see any other aggravating or mitigating factors applicable to the circumstances of the present case.

In the opinion of the President of the Personal Data Protection Office, the administrative penalty applied in the circumstances of the present case fulfils the functions referred to in Article 83(1) of Regulation 2016/679, i.e. it is effective, proportionate and dissuasive in this individual case.

Taking into account the administrative fine imposed on the Bank by the previous decision of the President of the Personal Data Protection Office (file no. (...)), it should be assumed that its amount was not effective, therefore the President of the Personal Data Protection Office decided to increase the amount of the penalty imposed by this decision. The penalty will be effective if its imposition leads to the fact that the Bank, which processes personal data professionally and on a mass scale, in the future will fulfil its obligations in the field of personal data protection, in particular with regard to reporting personal data breaches to the President of the Personal Data Protection Office and notifying the affected persons about the personal data breach.

In the opinion of the President of the Personal Data Protection Office, the administrative penalty will have a punitive function, as it will be a response to the Bank's violation of the provisions of Regulation 2016/679. It will also have a preventive function; in the opinion of the President of the Personal Data Protection Office, it will point out to both the Bank and other data controllers the reprehensibility of disregarding the controllers' obligations related to the occurrence of a personal data breach, and aimed at preventing its negative and often severe consequences for the persons affected by the breach, as well as removing these effects or at least limiting them.

Pursuant to Article 103 of the Personal Data Protection Act of 10 May 2018 (Journal of Laws of 2019, item 1781), hereinafter referred to as the "Personal Data Protection Act", the equivalent of the amounts referred to in Article 83 of Regulation 2016/679 expressed in EUR shall be calculated in PLN according to the average EUR exchange rate announced by the National Bank of Polish in the exchange rate table as at 28 January each year, and if in a given year the National Bank of Polish does not announce the average exchange rate of the euro on 28 January – according to the average exchange rate of the euro announced in the table of exchange rates of the National Bank of Poland next to that date.

In view of the above, the President of the Personal Data Protection Office, pursuant to Article 83(4)(a) in conjunction with Article 103 of the Personal Data Protection Act, imposed an administrative fine of PLN 1,440,549 (equivalent to PLN 330,000) on the Bank for the infringement described in the operative part of this decision, using the average EUR exchange rate as at 29 January 2024 (EUR 1 = PLN 4.3653). EUR).

In the opinion of the President of the Personal Data Protection Office, the penalty imposed in the amount of PLN 1,440,549 (in words: one million four hundred and forty thousand five hundred and forty-nine zlotys) meets the conditions referred to in Article 83(1) of Regulation 2016/679 in the circumstances of the present case due to the seriousness of the infringement found in the context of the primary objective of Regulation 2016/679 – the protection of the fundamental rights and freedoms of natural persons, in particular the right to the protection of personal data. Referring to the amount of the administrative penalty imposed on the Bank, the President of the Personal Data Protection Office decided that it was proportionate to the financial situation of the Administrator and would not constitute an excessive burden for the Administrator.

According to the "Annual Report of Santander Bank Polska S.A. for 2022" presented by the Administrator, the Bank's total income (i.e. interest, commission and dividend income) in 2022 amounted to PLN 13,061,886,000, and therefore the amount of the administrative penalty imposed in the present case is approx. 0.01% of the above-mentioned amount of proceeds. At the same time, it is worth noting that the amount of the penalty imposed by PLN 1,440,549 is only 0.55% of the maximum penalty that the President of the Personal Data Protection Office could impose on the Bank for the infringements found in the present case, in accordance with Article 83(4) of Regulation 2016/679, of up to 2% of the total annual turnover of the previous financial year (i.e. PLN 261,237,720).

The amount of the penalty has been set at such a level that, on the one hand, it constitutes an adequate response of the supervisory authority to the degree of breach of the administrator's obligations, but on the other hand, it does not cause a situation in which the need to pay a financial penalty will entail negative consequences in the form of a significant reduction in employment or a significant decrease in the Bank's turnover. In the opinion of the President of the Personal Data Protection Office, the Bank should and is able to bear the consequences of its negligence in the area of data protection, as evidenced by the Bank's Annual Report sent to the President of the Personal Data Protection Office on 5 January 2024.

At the same time, pursuant to Article 83(3) of Regulation 2016/679, the President of the Personal Data Protection Office decided to impose a single penalty for two infringements attributed to the Administrator in the proceedings ref. no. DKN.5131.59.2022. The source of both breaches is the same event, i.e. the loss of a parcel with bank documents containing the data of the Bank's customers, and the subsequent decision of the Bank not to report this fact to the President of the Personal Data Protection Office and not to notify the data subjects of the personal data breach. These events are so contextually, spatially and temporally linked that, according to EDPB Guideline 4/2022 on the calculation of administrative fines under the GDPR, they should be treated as a single conduct of the controller, leading to the imposition of a single penalty payment (point 28 of the Guidelines).

Finally, it is necessary to point out that in determining the amount of the administrative penalty in the present case, the President of the Personal Data Protection Office applied the methodology adopted by the European Data Protection Board in Guidelines 04/2022 on the calculation of administrative fines under the GDPR adopted on 24 May 2023. According to the guidelines presented in this document:

1. The President of the Personal Data Protection Office categorised the infringements of Regulation 2016/679 found in the present case (vide Chapter 4.1 of Guideline 04/2022). The infringements of the two provisions of Regulation 2016/679 found in the present case (Articles 33(1) and 34(1)) are, in accordance with Article 83(4)(a) of Regulation 2016/679, in the category of infringements punishable by the lower of the two penalties provided for in Regulation 2016/679 (up to a maximum of EUR 10 000 000 or up to 2% of the total annual turnover of the undertaking in the preceding business year). They were therefore considered in abstracto (without reference to the individual circumstances of the individual case) by the EU legislature to be less serious than the infringements referred to in Article 83(5) of Regulation 2016/679).

2.The President of the Personal Data Protection Office assessed the infringements found in the present case as infringements of a low level of seriousness (vide Chapter 4.2 of Guideline 04/2022). That Assessment took into account the factors listed in Article 83(2) of Regulation 2016/679 that relate to the subject matter of the infringement (constituting the 'seriousness' of the infringement), namely: the nature, gravity and duration of the infringements (Article 83(2)(a) of Regulation 2016/679), the intentional or unintentional nature of the infringements (Article 83(2)(b) of Regulation 2016/679) and the categories of personal data, infringements (Article 83(2)(g) of Regulation 2016/679). A detailed Assessment of these circumstances is set out above. At this point, it should be pointed out that a consideration of their combined impact on the Assessment of the infringements found in the present case, taken as a whole, leads to the conclusion that the level of seriousness of the infringements is also low in concreto (on the scale of seriousness of infringements presented in point 60 of Guideline 04/2022). As a consequence, the starting point for calculating the penalty is the value between 0 and 10% of the maximum amount of the penalty that can be imposed on the Bank. Given that Article 83(4) of Regulation 2016/679 obliges the President of the Personal Data Protection Office to adopt as the maximum amount of the penalty for infringements referred to in that provision the amount of EUR 10,000,000 or, if that value is higher than EUR 10,000,000, an amount representing 2% of the Company's turnover from the previous financial year, the President of the Personal Data Protection Office held that the so-called dynamic maximum penalty amount – EUR 59,844,162 – resulting from the application of the 2% applied penalty rate applies in the present case. to the Bank's turnover for 2022, the value of which amounted to EUR 2,992,208,096 (equivalent to PLN 13,061,886,000). With a range from EUR 0 to EUR 59,844,162, the President of the Personal Data Protection Office adopted, as adequate and justified by the circumstances of the case, the starting amount for calculating the amount of the penalty amounting to EUR 2,393,766,000 (representing 4% of the dynamic maximum amount of the penalty).

3. In accordance with the guidance of the European Data Protection Board set out in point 66 of the Guidelines 04/2022 (for enterprises with an annual turnover of more than EUR 500 million), the President of the Personal Data Protection Office did not consider it justified to use the option to reduce the starting amount adopted on the basis of the Assessment of the seriousness of the breach, which the Guidelines (in Chapter 4.3) provide for enterprises of smaller size and economic power. Indeed, the EDPB states that in the case of large entities (which is undoubtedly the Bank in the present case, as evidenced by its turnover) "the size of the undertaking is already reflected in the dynamic statutory maximum amount" (point 66 of Guideline 04/2022).

4. The President of the Personal Data Protection Office assessed the impact on the identified infringement of the remaining circumstances (apart from those taken into account above in the Assessment of the seriousness of the breach) indicated in Article 83(2) of Regulation 2016/679 (vide Chapter 5 of Guideline 04/2022). These circumstances, which may have an aggravating or mitigating impact on the Assessment of the infringement, refer – as assumed in Guidelines 04/2022 – to the subjective side of the infringement, i.e. to the entity being the infringer itself and to its conduct before, during and after the infringement. A detailed Assessment and justification of the impact of each of these conditions on the Assessment of the infringement is set out above. The President of the Personal Data Protection Office found (as justified in the above-mentioned part of the justification for the decision) that the aggravating circumstances in the present case, and therefore further increasing the amount of the penalty imposed by this decision, are the relevant previous breaches on the part of the Bank (Article 83(2)(e) of Regulation 2016/679), as well as the degree of cooperation between the Bank and the President of the Personal Data Protection Office in order to remove the breach and mitigate its possible negative effects (Article 83(2)(f) of Regulation 2016/679). The other conditions (Article 83(2)(c), (d), (h), (i), (j) and (k) of Regulation 2016/679) did not, as stated above, have any mitigating or aggravating effect on the Assessment of the infringement and, consequently, on the level of the penalty. Therefore, due to the occurrence of additional aggravating circumstances in the case, related to the subjective side of the breaches (assessment of the Bank's conduct before and after the breaches), the President of the Personal Data Protection Office considered it justified to increase the amount of the penalty determined on the basis of the Assessment of the seriousness of the breaches (point 2 above). In the opinion of the President of the Personal Data Protection Office, the increase to EUR 2,600,000 is adequate to the impact of these premises on the Assessment of infringements.

5. The President of the Personal Data Protection Office stated that the amount of the administrative penalty determined in the manner described above does not exceed – pursuant to Article 83(3) of Regulation 2016/679 – the legally defined maximum amount of the penalty provided for the most serious infringement (vide Chapter 6 of Guideline 04/2022). In the case of both infringements of Regulation 2016/679 found in the present case, the legally defined maximum amount of the penalty (dynamic) is the same: it is, as stated in paragraph 2 above, EUR 59 844 162, i.e. 2% of the Bank's turnover achieved in 2022. The two infringements are therefore of the same gravity and the amount of the penalty of EUR 2 600 000 referred to above clearly does not exceed the maximum penalty imposed on each of them individually.

6. Despite the fact that the amount of the penalty determined in accordance with the above rules does not exceed the legally defined maximum penalty, the President of the Personal Data Protection Office decided that it required additional correction due to the principle of proportionality listed in Article 83(1) of Regulation 2016/679 as one of the three penalty directives (vide Chapter 7 of Guideline 04/2022). Undoubtedly, a fine of EUR 2 600 000 would be an effective penalty (due to its severity, it would achieve its repressive objective, which is to punish for unlawful conduct) and a dissuasive penalty (allowing it to effectively discourage both the Company and other controllers from committing future infringements of the provisions of Regulation 2016/679). However, in the opinion of the President of the Personal Data Protection Office, such a penalty would be disproportionate both in relation to the seriousness of the infringements found (which in abstracto and in concreto is low – vide points 1 and 2 above) and due to its excessive severity in relation to this seriousness. The principle of proportionality requires, m.in, that the measures adopted by the administrative authority do not go beyond what is appropriate and necessary to achieve legitimate objectives (vide paragraphs 137 and 139 of Guideline 04/2022). In other words: "A sanction is proportionate if it does not exceed the threshold of severity determined by taking into account the circumstances of the individual case" (P. Litwiński (ed.), Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 [...]; Commentary on Article 83 [in:] P. Litwiński (ed.) General Data Protection Regulation. Personal Data Protection Act. Selected sectoral legislation. Commentary). Therefore, taking into account the proportionality of the penalty, the President of the Personal Data Protection Office further reduced the amount of the penalty to EUR 330,000 (the equivalent of PLN 1,440,549). In his view, such determination of the final amount of the penalty imposed will not reduce its effectiveness and deterrent character. That amount is the threshold above which a further increase in the amount of the penalty will not result in an increase in its effectiveness and deterrent nature. On the other hand, a greater reduction in the amount of the penalty could come at the expense of its effectiveness and dissuasiveness, as well as the consistent understanding, application and enforcement of Regulation 2016/679 and the principle of equal treatment of operators in the EU and EEA internal markets with respect to other supervisory authorities and the EDPB.

In this factual and legal situation, the President of the Personal Data Protection Office ruled as in the operative part.


[1] These guidelines updated and supplemented the Article 29 Working Party Guidelines on the notification of personal data breaches under Regulation 2016/679 (Wp250 rev.01), adopted on 3 October 2017.

[2] European Data Protection Board Guideline 01/2021 on examples of personal data breach notification adopted on 14 December 2021, version 2.0 (hereinafter referred to as "Guideline 01/2021").

[3] https://www.zbp.pl/getmedia/2d3304db-34e6-4929-94cc-b9390456ff7a/infodok-2023-07-09-wydanie-55-sklad-231023-gk08

[4] Guideline 04/2022 on the calculation of administrative fines under the GDPR adopted on 24 May 2023, version 2.1, hereinafter referred to as "Guideline 04/2022" (published at: https://edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-042022-calculation-administrative-fines-under_pl).

Warsaw, on the 12th day March 2024

Decision

DKN.5131.28.2023

Pursuant to Article 104(1) of the Act of 14 June 1960 Code of Administrative Procedure (Journal of Laws of 2023, item 775, as amended), Article 7(1) and Article 60, Article 101 and Article 103 of the Personal Data Protection Act of 10 May 2018 (Journal of Laws of 2019, item 1781), as well as Article 57(1)(a) and (h), Article 58(2)(i), Article 83(1) and (2), Article 83(4)(a) in conjunction with Article 33(1) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). EU L 119, 04.05.2016, p. 1. EU L 127, 23.05.2018, p. 2 UE L 74, 4.03.2021, p. 35), hereinafter referred to as 'Regulation 2016/679', following ex officio administrative proceedings concerning infringement of personal data protection regulations by Toyota Bank Polska S.A. with its registered office in Warsaw (Postępu 18B, 02-676 Warsaw), the President of the Personal Data Protection Office,
finding that Toyota Bank Polska S.A. with its registered office in Warsaw (Postępu 18B, 02-676 Warsaw) of Article 33(1) of Regulation 2016/679, consisting in failure to notify the President of the Personal Data Protection Office of a personal data breach without undue delay, no later than within 72 hours after the breach has been identified, imposes an administrative fine of PLN 78,575.40 (in words: seventy-eight thousand five hundred seventy-five zlotys and forty groszy).

Justification

On 7 September 2022, Toyota Bank Polska S.A. with its registered office in Warsaw (Postępu 18B, 02-676 Warsaw), hereinafter also referred to as the "Bank" or the "Controller", notified the President of the Personal Data Protection Office, hereinafter also referred to as the "President of the Personal Data Protection Office" or the "supervisory authority", of a personal data breach involving the personal data of one natural person (hereinafter referred to as the "Data Subject" or "the Bank's Customer") in the scope of: name and surname, bank account number, address of residence, PESEL registration number, series and number of the identity card. The personal data breach consisted in sending – as a result of an error by a Bank employee – a bank parcel containing a loan agreement and repayment schedule to another customer of the Bank. The parcel was received and opened by this customer, and therefore the personal data of the Bank's Client was disclosed to an unauthorized person. After the Bank sent a courier to the person in possession of the erroneously sent parcel, the correspondence was returned to the Bank. According to the explanations provided, the Bank registered a security incident in connection with the situation, but did not report the personal data breach to the supervisory authority within 72 hours of its discovery.

In the personal data breach notification form, the Controller indicated 31 March 2021 as the date of finding the breach, and did not make the notification until 7 September 2022, justifying the reasons for the delay in notifying the supervisory authority of the personal data breach by saying that "the Bank assessed the risk of violation of the rights and freedoms of data subjects as low, however, after the PDPO occurred, it changed the rules for making the assessment". The statement referred to in the Bank's explanations concerns the proceedings conducted by the President of the Personal Data Protection Office regarding the complaint of the Bank's Client, in connection with the personal data breach, about irregularities in the processing of her personal data by Toyota Bank Polska S.A., consisting in making personal data available to a third party without a legal basis (file no. (...)).

In view of the notification of a personal data breach to the supervisory authority, after the lapse of the period of 72 hours from its discovery, i.e. almost 1.5 years from its discovery, the President of the Personal Data Protection Office initiated ex officio administrative proceedings against the Bank with respect to the violation of Article 33(1) of Regulation 2016/679.

In response to the notice of initiation of the administrative procedure in the case at hand, by letter dated 19 October 2023 The Bank sent additional explanations in which it indicated that "In assessing the seriousness of the breach in question, the Bank took into account the following circumstances: (i) the breach concerned only one person, (ii) the document containing the data was quickly recovered, (iii) there was no reason to assume bad faith on the part of the person who gained unauthorised access to the data as a result of the breach, in particular due to the fact that this person was a customer of the Bank, informed the Bank about the incident and cooperated with the Bank in order to return the incorrectly addressed parcel and (iv) the fact that the Bank knew the personal data of that person, which, in the Bank's opinion, was a circumstance reducing the risk of unauthorised use of the data to the detriment of the person affected by the breach. Moreover, at the time of the assessment, an important point of reference was ENISA's guidelines on the Assessment of the seriousness of the infringement, which stated that the abovementioned circumstances reduced the seriousness of the infringement and which suggested that infringements for which the risk of negative consequences for the rights and freedoms of natural persons were not subject to notification to the supervisory authority.'

According to the Bank, the reason for the failure to report a personal data breach to the President of the Personal Data Protection Office "[...] was to make a fair Assessment of the seriousness of the infringement, in the context of the interpretation of Article 33(1) of the GDPR, on the basis of market practice and on the basis of the available guidance from the agency with competence in the field of information security (ENISA)'. On the other hand, as soon as the Bank "became aware of the expectations of the President of the Personal Data Protection Office with regard to the application of Article 33(1) of the GDPR" - "immediately took steps to adapt its own practice in this respect to the expectations of the President of the Personal Data Protection Office. As a result of the change in the Bank's approach, the President of the Personal Data Protection Office was informed about the infringement that gave rise to the present proceedings."

In the further part of the explanations, the Bank points out that, regardless of the Assessment of the personal data breach in the context of Article 33(1) of Regulation 2016/679, it prudently informed the person affected by the breach of the breach, i.e. "although it did not report immediately after the breach occurred due to the risk Assessment applied, it nevertheless fulfilled the main task incumbent on the data controller, i.e. counteracted the effects of the breach by immediately informing the data subject of the breach by letter'.

In the Bank's opinion, the delay in reporting the breach in question to the President of the Personal Data Protection Office did not adversely affect the rights and freedoms of the data subject. The client had the opportunity to counteract the effects of the personal data breach immediately after it occurred, and she also received support from the Bank, which m.in covered the costs of purchasing the code (...).

On 23 January 2024, the Administrator's letter was received, which was a repetition of the Bank's explanations previously submitted, thus emphasizing the Bank's previous position in the present case.

After reviewing all the evidence gathered in the case, the President of the Personal Data Protection Office weighed the following:

According to Article 4(12) of Regulation 2016/679, a 'personal data breach' means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

Article 33(1) and (3) of Regulation 2016/679 provides that in the event of a personal data breach, the controller shall, without undue delay and, if possible, no later than 72 hours after becoming aware of the breach, report it to the supervisory authority competent in accordance with Article 33(1). Article 55, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. A notification submitted to the supervisory authority after 72 hours shall be accompanied by an explanation of the reasons for the delay. The notification referred to in paragraph 1 shall, at least: (a) describe the nature of the personal data breach, including, where possible, the categories and approximate number of data subjects and the categories and approximate number of personal data alerts affected; (b) include the name and contact details of the Data Protection Officer or another point of contact from whom more information may be obtained; (c) describe the possible consequences of a personal data breach; (d) describe the measures taken or proposed by the controller to remedy the personal data breach, including, where applicable, measures to minimise its possible adverse effects.

Therefore, the analysis of the above-mentioned provisions shows that depending on the level of risk to the rights and freedoms of natural persons, the controller's obligations towards the supervisory authority and data subjects are different. If, as a result of the analysis, the controller finds that the likelihood of a risk of violation of the rights and freedoms of natural persons is low, it is not obliged to report the breach to the President of the Personal Data Protection Office. The infringement in question only has to be entered in the internal register of infringements. If a risk of violation of the rights and freedoms of natural persons is identified, the controller is obliged to report the data breach to the President of the Personal Data Protection Office, as well as to place an entry in the internal register of breaches. The occurrence of a high risk of violation of the rights and freedoms of natural persons, in addition to being entered in the register of breaches, requires the controller to take appropriate action, both against the supervisory authority (notification of a data breach), but also against the data subjects. Indeed, in the case of personal data breaches that may result in a high risk to the rights and freedoms of the data subject, Regulation 2016/679 introduces an additional obligation for the controller to notify the data subject without delay, unless the controller has taken preventive measures before the breach or remedial action after the breach has occurred (Article 34(3) of Regulation 2016/679).

As can be seen from the above, if the controller detects a personal data breach, it is first necessary to analyse the risk of violation of the rights and freedoms of natural persons. The controller is exempt from the obligation to notify the supervisory authority of a breach if the examination shows that there is at most a low probability of a risk to the rights and freedoms of natural persons. However, it should be borne in mind that the supervisory authority will be able to ask the controller for justification of the decision not to report the breach, therefore the conclusions of the analysis should be recorded in the internal register of breaches.

It is worth recalling that the Guidelines of the European Data Protection Board (EDPB) No 9/2022[1] adopted on 28 March 2023, there are recommendations for reporting personal data breaches to the supervisory authority.

It should be emphasised that the risk of violation of the rights and freedoms of a natural person should be assessed through the prism of the data subject and not the interests of the controller. Failure to report a personal data breach deprives the supervisory authority of the possibility of an appropriate response to a personal data breach, which manifests itself not only in the Assessment of the risk of a breach to the rights and freedoms of a natural person, but also, in particular, in the verification of whether the controller has taken appropriate measures to remedy the breach and minimise the negative effects on data subjects, as well as whether it has taken appropriate security measures to minimise the risk of recurrence of the breach.

Reporting personal data breaches by controllers is therefore an effective tool contributing to a real improvement in the security of personal data processing. When reporting a breach to the supervisory authority, controllers shall inform the President of the Personal Data Protection Office whether in their opinion there is a high risk to the rights and freedoms of data subjects and, if such a risk has occurred, whether they have provided relevant information to the natural persons affected by the breach. The President of the Personal Data Protection Office verifies the Assessment made by the controller and may, if the controller has not notified the data subjects, request such notification from the controller. Notifications of personal data breaches allow the supervisory authority to react appropriately to limit the effects of such breaches, as the controller is obliged to take effective measures to ensure the protection of natural persons and their personal data, which on the one hand will allow for the control of the effectiveness of the existing solutions and, on the other hand, the Assessment of modifications and improvements aimed at preventing irregularities similar to those covered by the breach. On the other hand, notification of a breach to natural persons provides an opportunity to provide them with information about the risk associated with the breach and to indicate the actions they can take to protect themselves from the potential negative effects of the breach (this allows the individual to make an independent Assessment of the infringement in the context of the possibility of negative consequences materialising for such a person and decide whether or not to apply remedial action).

By letter dated 19 October 2023 The Administrator points out that "In the Bank's opinion, the delay in reporting the breach in question to the Personal Data Protection Office did not adversely affect the rights and freedoms of the data subject, because the client had the opportunity to counteract the effects of the breach immediately after its occurrence, moreover, she received support in this respect from the Bank, which m.in covered the costs of purchasing the code (...) (which is also now the Bank's standard)". In the opinion of the supervisory authority, the fact that the person affected by the personal data breach in question lodged a complaint with the President of the Personal Data Protection Office about irregularities in the processing of her personal data by the Bank, consisting in making her personal data available to a third party without a legal basis, proves that the Bank's reaction to this breach was not sufficient, and the Bank's Client herself had concerns about the security of the data processed by the Bank.

Toyota Bank Polska S.A., due to the scale and subject of its activity, i.e. the provision of various types of financial services, processes the personal data of a very large number of customers with whom it concludes, m.in, credit agreements. In the case under consideration, the personal data of the Bank's Client included in the agreement between the parties, i.e. PESEL number, name and surname, address of residence, bank account number and the series and number of the identity card, were read by an unauthorized person. Therefore, there is no doubt that the Data Subject can be easily identified on the basis of the disclosed data. In addition, data related to the conclusion of the agreement and its content were disclosed.

Consequently, the very Assessment of the breach carried out by the Controller in terms of the risk of infringement of the rights and freedoms of natural persons, which is necessary to determine whether there has been a data breach resulting in the need to notify the President of the Personal Data Protection Office (Article 33(1) and (3) of Regulation 2016/679) and the persons affected by the breach (Article 34(1) and (2) of Regulation 2016/679), should, as it should be emphasised once again, through the prism of the person affected by the infringement.

Although the Bank informed the data subject about the personal data breach by providing him with the content of the notification, due to the failure to properly notify the President of the Personal Data Protection Office within the time limit provided for by law (72 hours from the date of the breach), the Bank deprived the supervisory authority of the opportunity to take an appropriate response to the breach, and thus of the possibility of conducting an appropriate analysis of the content of the notification. addressed to that person, with a view to the fulfilment by the Controller of its obligations under Article 34(2) in conjunction with Article 33(3) of Regulation 2016/679 and to provide the Data Subject with complete information on the possible consequences of the breach, as well as the measures that the person may take to protect himself from the potential consequences of the breach.

Please note that the accidental disclosure of personal data to even a single identified person may lead to an increase in the scale of the breach and thus the risk of violation of the rights and freedoms of the data subject. At the same time, the Controller has not demonstrated, in accordance with the principle of Accountability referred to in Article 5(2) of Regulation 2016/679, that its client, to whose address the agreement with the Bank's Client's data was sent, may be considered a so-called trusted recipient. According to the explanations provided by the Bank in its letter of 19 October 2023, when assessing the seriousness of the breach in question, which resulted in the failure to report the breach in question to the supervisory authority, it "took into account the following circumstances: (i) the breach concerned only one person, (ii) the document containing the data was quickly recovered, (iii) there was no reason to assume bad faith on the part of the person who had gained unauthorised access to the data as a result of the breach, in particular, due to the fact that the person was a customer of the Bank, informed the Bank about the incident and cooperated with the Bank in order to return the wrongly addressed parcel and (iv) the fact that the Bank knew the personal data of that person, which, in the Bank's opinion, was a circumstance reducing the risk of unauthorised use of the data to the detriment of the person affected by the breach".

The risk Assessment was based on the belief that the person who came into possession of the agreement was characterized by the so-called "good faith" because "he informed the Bank about the incident and cooperated with the Bank in order to return the wrongly addressed parcel" and "the Bank knew the personal data of this person". Taking the above into account, the Bank assessed "that the above-mentioned circumstances reduce the seriousness of the infringement and which suggested that infringements for which the risk of negative consequences for the rights and freedoms of natural persons is low should not be notified to the supervisory authority".

In view of the above, in order to better illustrate cases of personal data breaches, as a result of which there has been an accidental disclosure of data to an unauthorized person, reference should be made to Guideline 9/2022, which indicates a case of a data breach involving the erroneous disclosure of personal data to a third party or other recipient in a situation where the data is accidentally sent to the wrong department of the organization or to a supplier organization, services used by the Administrator. In such a case, the controller has grounds to consider the unauthorised recipient to be trusted, because it has a stable relationship with such an entity, knows its procedures and can trust the recipient enough to be able to reasonably expect that the recipient will not read the data sent by mistake or gain access to it, as well as comply with the order to send it back. Even if the data has been accessed, the controller can still trust the recipient not to take any inappropriate action and to return the data to the controller immediately. As the EDPB further points out, in the case described above, the controller may take into account the fact that the recipient is a trusted person in the risk Assessment carried out following the breach. However, that is not the case here. Another client of the Bank, to whom correspondence with an agreement containing the personal data of the Data Subject was mistakenly addressed, does not have a relationship with the Bank that would allow for the assumption that he is a trusted recipient, in accordance with the above position of the EDPB.

Referring to the above, it should be pointed out that the position of the Bank is incomprehensible, as it explains the lack of notification of a personal data breach, m.in, by the fact that the Bank knew the personal data of the person to whom the parcel was erroneously sent, and on the basis of this belief, a risk Assessment was carried out, completely ignoring the fact that the personal data of the Bank's Client was disclosed to an unauthorized person. Otherwise, the Bank could treat such situations as not entailing a risk of violation of the rights and freedoms of natural persons by sending the data of its customers to the wrong addresses, and thus making them available to third parties – other customers. The fact that the data was made available to only one identified person is also irrelevant. In the event that erroneous correspondence is delivered to a person known to the Administrator, e.g. another customer who informed the Data Subject about the Bank's mistake, there is no guarantee that the intentions of this person will not change.

What is more, the Administrator is not sure whether, before returning the correspondence, the erroneous recipient did not make copies or did not record the personal data contained in the content of the agreement in another way, e.g. by writing them down. Also, the Bank is not able to actually verify that the unauthorized recipient has not transferred the Bank's Client's data to third parties or does not have a copy of this data. A similar opinion was expressed by the Provincial Administrative Court in Warsaw, which in its judgment of 21 January 2022, ref. no. II SA/Wa 1353/21, stated that "(...) There is no certainty that the person did not make a photocopy or record the personal data contained in the document in any other way, e.g. by writing them down, before these activities. The mere performance of the actions indicated in the statements made by the Third Party - the unauthorized recipient - does not guarantee that the intentions of such a person will not change now or in the future, and the possible consequences of the use of such categories of data may be significant for the persons whose data have been affected by the breach." It should be emphasised once again that the fact that, in the Bank's opinion, "there was no reason to assume bad faith on the part of the person who gained unauthorised access to the data as a result of the breach, in particular due to the fact that this person was a customer of the Bank, informed the Bank about the incident and cooperated with the Bank in order to return the incorrectly addressed parcel", does not preclude the fact that the breach is unlikely to result in a risk to the rights and freedoms of natural persons and does not preclude the assumption that there is a high risk to the rights and freedoms of the data subject. It should be pointed out once again that the personal data has been made available to an unauthorised recipient, which means that there has been a breach of security leading to an unauthorised disclosure of personal data, an unauthorised recipient cannot be considered a "trusted recipient", and the scope of the data determines that there is a high risk of infringement of the rights and freedoms of a natural person. On the other hand, the Bank's Client, who was the subject of the incident in question, filed a complaint with the President of the Personal Data Protection Office about irregularities in the processing of her personal data by the Bank, consisting in making her personal data available to a third party without a legal basis. The filing of the complaint by the Data Subject in the opinion of the President of the Personal Data Protection Office confirms that the risk Assessment presented in the Bank's explanations in the case in question does not take into account the perspective of the Bank's Client, who has suffered non-material damage as a result of a breach of the protection of her personal data, with a high probability.

As indicated in Guidelines 9/2022, a personal data breach has the potential to have a number of negative effects on the individuals whose data is the subject of the breach. Among the possible consequences of a breach, the EDPB mentions: physical, material or non-material damage. Examples of such damages include, m.in discrimination, identity theft or fraud, financial loss, damage to reputation, breach of the confidentiality of personal data, and significant economic or social harm. In the present case, there is no doubt that, due to the scope of data covered by the personal data breach in question, including the PESEL registration number and the name and surname, there is a high probability of the occurrence of the above-mentioned damages.

First of all, it should be emphasised that the personal data breach concerned the PESEL registration number, i.e. an eleven-digit numerical symbol that unambiguously identifies a natural person, containing, m.in, the date of birth and the gender designation, and thus closely related to the private sphere of the natural person and also subject, as a national identification number, to exceptional protection under Article 87 of Regulation 2016/679 – which is data with a special nature and such special protection in need. The PESEL number serves as a data identifying each person and is commonly used in contacts with various institutions and in legal transactions. The PESEL number, together with the name and surname, unambiguously identifies a natural person, in a way that allows to attribute the negative effects of the breach (e.g. identity theft, loan fraud) to that specific person. In addition, it should be taken into account that as a result of the personal data breach in question, the registration number was made available to an unauthorized person along with the name and surname of the Bank's Client, which combination of data may be sufficient to "impersonate" the subject of these data and incur e.g. monetary liabilities on behalf of and to the detriment of such an entity (vide: https://www.bik.pl/poradnik-bik/wyludzenie-kredytu-tak-dzialaja-oszusci – where the case is described, in which: "Only the name, surname and PESEL number were enough for the fraudsters to extort a dozen or so loans for a total of tens of thousands of zlotys. Nothing else matched: neither the ID card number nor the address of residence."). It is also impossible to ignore the fact that the analysed personal data breach also concerned the address of residence, bank account number and the series and number of the Bank's Customer's ID card. A key factor in the risk Assessment is the type and sensitivity of the personal data disclosed as a result of the breach. Guideline 9/2022 highlights that a set of different personal data is usually more sensitive than individual data.

Moreover, according to the case law, judgments in cases of loan fraud are not uncommon and have been issued by Polish courts in similar cases for a long time – for example, the judgment of the District Court in Łęczyca of 27 July 2016 (file reference number I C 566/15), in which fraudsters taking a loan using someone else's data used the PESEL number, a fictitious address and an incorrect ID number (invalid). In the justification of the above-mentioned judgment, the Court stated that: "The evidentiary proceedings and the analysis of the documents attached by the plaintiff result in the fact that it can be clearly stated that in the case under consideration the defendant was not a party to the loan agreement concluded on 5 May 2014. Although the PESEL number of the defendant J.R. was used when concluding the agreement, the indicated place of residence does not correspond to the place of residence of the defendant. The defendant J.R. never lived in W. The amount of the loan was transferred to an account not held by the defendant. On the date of concluding the loan agreement, the ID card no. (...) expired on 15 March 2014. The mobile phone number indicated on the loan agreement and its appendices is also inconsistent with the actual telephone numbers used by the defendant."

In another case (I C 693/16), the District Court in Zgierz, in its judgment of 4 November 2016, ruled: "The personal data of the defendant in the form of his name and surname and PESEL number, which were consistent with the defendant's data, did not prove that the defendant made a declaration of intent to conclude a loan agreement on 17 December 2014. It cannot be ruled out that a person who has gained unauthorised access to the defendant's personal data may have entered into a loan agreement with (...) sp. z o.o. on the defendant's account. In the present case, the defendant has shown that he has never lived at the address indicated in the loan agreement and that the telephone number and e-mail address used to register on the website and apply for the loan belong to him."

Similar rulings were made by courts in other cases of this type. An example of this is the rulings in which the Courts dismissed an action for payment of amounts for loans taken out by unknown persons using the personal data (name and surname and PESEL number) of the defendants:

  • Judgment of the District Court for Łódź-Widzew in Łódź of 13 August 2020 in the case ref. no. II C 1145/19, in which a third party unknown to the defendant illegally came into possession of his PESEL number and ID card number, and the remaining address data - indicated in the loan agreement - were false - "In the opinion of the Court, the evidence offered by the defendant - especially the documents from the files of the criminal case pending before the District Court in Tarnowskie Góry with file number VI K 383/16 - prove that the that the loan agreement of 8 November 2014 was concluded by a third party using some of Z.A.'s personal data. She gave a false address of residence where the defendant never resided, and the amount of the loan was transferred to a bank account that did not belong to Z.A. [...] and the ID number given in that agreement was an ID number which the defendant no longer used on the date of conclusion of the loan agreement, expired about 8 months earlier';
  • Judgment of the District Court in Pisz of 21 August 2020, ref. no. I C 260/20 — '... The court found that when concluding the agreement in question, the defendant's data was used in an unauthorized manner and entered as the borrower's data, and the defendant was not a party to the agreement. The defendant's position is confirmed by the complaint filed by him on the commission of the crime of fraud against him, as well as by the fact that the prosecutor's office is conducting proceedings in this case against a person indicated by the defendant. By the way, it should be noted that also in the context of the proceedings pending before the local court for the payment of ref. no. I C 1/19 and I C 482/19, where E.M. was also a defendant and where financial obligations were incurred in his name in the same circumstances as in the present proceedings, final judgments dismissing the action were also made. In the court's opinion, the circumstances of concluding the agreement with the plaintiff, where the first and last name of the borrower and his PESEL number are identical, and there is a discrepancy as to the other data resulting from the content of the defendant's identity card, i.e. the series and number of this document, the address of residence, taking into account the fact that a criminal trial was conducted in relation to the person who was to impersonate the defendant, for the purpose of concluding contracts at a distance and incurring financial obligations in various institutions, clearly indicate that it was not the defendant who entered into a loan agreement No. (...) with the plaintiff's predecessor in title";
  • Judgment of the District Court in Puławy of 7 April 2022 in the case ref. no. I C 475/19, in which the Court of First Instance unequivocally acknowledged that '... The mere indication of the defendant's personal data: name, surname, PESEL number, as well as the series and number of the identity card in the content of the agreement is not evidence allowing for the verification of the defendant as a party to the agreement in question - in particular in a situation where the loan is concluded via an online platform, so obviously, the lender does not have the possibility of directly verifying the identity of the other party, and the contract itself is not confirmed by the borrower's signature."

"It is also significant that, according to the delivery card with a debit card, the ID card No. (...) had an expiry date of 21 September 2019 and the original identity card belonging to Ł. B. (1) was valid until 2 June 2021 (k. 220), which confirms the defendant's testimony, also as to the fact that the probable source of the "leak" of his personal data was the car sale agreement concluded by him on 8 June 2017, in which, in addition to the seller's name and surname and his PESEL number, there is also an identity card number, however, the agreement does not contain data including the names of the parents - and in the bank account agreement these data are already entered incorrectly, as well as the date of validity of the identity card - this is also incorrectly entered in the delivery card of the bank account agreement, which clearly indicates that the person concluding the bank account agreement did not have Ł's data. B. (1) other than those contained in the contract for the sale of the car, as well as the original blank identity card - which, according to the defendant's testimony, is still in his possession and has not been made available to third parties."

At this point, it is worth quoting one of the examples found in the Guidelines of the European Data Protection Board 01/2021[2] (Case No. 14, p. 31), referring to a situation where 'highly confidential personal data is sent by post by mistake'. In the case described in the above-mentioned Guidelines, a social security number was disclosed, which is the equivalent of the PESEL number used in Poland. In this case, the EDPB had no doubt that the disclosed data in terms of: name, e-mail address, postal address, social security number, indicated a high risk of violation of the rights and freedoms of natural persons ("the involvement of their [the victims'] social security number, as well as other, more basic personal data, further increases the risk, which can be described as high"). The EDPB recognises the importance of national identification numbers (in this case, the PESEL number), while stressing that this type of personal data breach, i.e. covering data in the form of: name and surname, e-mail address, correspondence address and social security number, requires the implementation of actions, i.e. notification of the supervisory authority and notification of the breach of data subjects.

The European Data Protection Board has no doubt that an individually assigned number uniquely identifying a natural person should be subject to special protection, and its disclosure to unauthorised entities may entail a high risk of violation of the rights and freedoms of natural persons.

The fact that data uniquely identifying a natural person may cause a high risk of violation of the rights and freedoms of the EDPB is also indicated by other examples provided in Guideline 01/2021. Points 65 and 66 of Guideline 01/2021 state: "(...) The compromised data allows for the unambiguous identification of data subjects and contains other information about them (including gender, date and place of birth), and can be used by an attacker to guess customer passwords or to launch a spear phishing campaign targeting the bank's customers. For these reasons, it was considered that a data breach is likely to result in a high risk to the rights and freedoms of all data subjects. As a result, material damage (e.g. financial loss) and non-material damage (e.g. identity theft or fraud) may occur."

The Provincial Administrative Court in Warsaw did not have similar doubts (that the disclosure of the PESEL number together with other personal data may result in a high risk of violation of the rights and freedoms of natural persons), which in its judgment of 22 September 2021, ref. no. II SA/Wa 791/21, stated that "There is no doubt that the examples of damage referred to in the guidelines may occur in the case of persons whose personal data – in some cases including the PESEL registration number or the series and number of the ID card – have been recorded on the recordings made available. Not without significance for such an Assessment is the possibility of using the disclosed data to identify the persons whose data have been affected by the breach." Further, in the cited ruling, the Court pointed out that "the data were made available to unauthorized persons, which means that there was a security breach leading to unauthorized disclosure of personal data, and the scope of this data, including in some cases also the PESEL registration number or the series and number of the identity card, determines that there was a high risk of violation of the rights and freedoms of natural persons." When considering the above issues, it is also necessary to Recall the position of the Provincial Administrative Court in Warsaw expressed in the judgment of 1 July 2022 issued in the case ref. no. II SA/Wa 4143/21. In the justification of this judgment, the Court stated that: "It should be agreed with the President of the Personal Data Protection Office that the loss of confidentiality of the PESEL number in combination with personal data, such as: name and surname, registered address, bank account numbers and the identification number assigned to the Bank's customers - CIF number, is associated with a high risk of violation of the rights and freedoms of natural persons. In the event of a breach of data such as name, surname and PESEL number, it is possible to steal or falsify identity, resulting in negative consequences for data subjects. Therefore, in the present case, the Bank should have notified the data subjects of the personal data breach without undue delay, pursuant to Article 34(1) of the GDPR, so as to enable them to take the necessary preventive measures." It is also worth mentioning the judgment of 31 August 2022, ref. no. II SA/Wa 2993/21, in which the Provincial Administrative Court in Warsaw emphasised that "(...) The authority correctly assumed that there was a high risk of violation of the rights and freedoms of the persons affected by the breach in question due to the possibility of easy identification of persons whose data were affected by the breach based on the disclosed data. This data includes the name and surname, correspondence address, telephone number, PESEL number of persons with Polish citizenship. In those circumstances, the controller was required to notify the data subjects of the breach without undue delay.' A similar opinion was expressed by the Provincial Administrative Court in Warsaw in its judgments of 15 November 2022, ref. no. act II SA/Wa 546/22, 21 June 2023, ref. no. act II SA/Wa 150/23 and 6 November 2023, ref. no. II SA/Wa 996/23.

In the light of the above, it is also worth recalling the judgment of the Supreme Administrative Court in Warsaw of 6 December 2023, ref. no. Act III OSK 2931/21: "The President of the Personal Data Protection Office correctly determined that there was a disclosure of data m.in. in the field of names and surnames, as well as PESEL numbers of natural persons, i.e. relatively permanent, unchangeable data, the disclosure of which may always give rise to the risk of negative consequences for the above-mentioned persons. Similarly, residential addresses are personal data the unauthorised disclosure of which creates a high risk of negative legal consequences, regardless of the fact that the disclosure of the addresses took place several years after they were updated.'

It should also be borne in mind that the Controller's performance of its obligation under Article 33(1) of Regulation 2016/679 may not be made conditional on the occurrence of a breach of the rights and freedoms of natural persons whose data are affected by a personal data breach. As stated by the Provincial Administrative Court in Warsaw in its judgment of 22 September 2021 issued in the case ref. no. II SA/Wa 791/21: "It should be emphasized that the possible consequences of the event do not have to materialize. Article 33(1) of Regulation 2016/679 states that the mere occurrence of a personal data breach involving a risk to the rights and freedoms of natural persons implies an obligation to notify the breach to the competent supervisory authority, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. (the Court ruled in a similar way in the previously cited judgment of 1 July 2022 issued in case no. II SA/Wa 4143/21 and in the judgments of 31 August 2022, ref. no. II SA/Wa 2993/21, of 15 November 2022, ref. no. II SA/Wa 546/22 and of 26 April 2023, Ref. No. II SA/Wa 1272/22).

By letter dated 19 October 2023 The Administrator points out: "The Assessment made by the Bank, indicating that there was no obligation to notify the breach, also resulted from the lack of an unambiguous practice of the President of the Personal Data Protection Office regarding the reporting of personal data breaches at the time of the breach assessment, i.e. in April 2021. In 2021, the practice of applying Article 33(1) was still in its infancy, as evidenced by a number of publicly available and widely commented decisions of the President of the Personal Data Protection Office issued at the turn of 2021 and 2022, which ultimately shaped this practice (m.in. (...) of 14 October 2021-2022, (...) of 7 July 2022, (...) of 21 June 2021)".

It is impossible to agree with the Bank's argumentation quoted above, because the President of the Personal Data Protection Office, and previously the Inspector General for Personal Data Protection, has consistently been of the opinion for many years that the PESEL number is a unique identifier of a person, containing a lot of information, m.in about age and gender, and its disclosure to an unauthorized person may give rise to the risk of identity theft. The decisions issued in this regard only confirm the above. Special protection of personal data, including, above all, the PESEL registration number, is also required from institutions of public trust, which undoubtedly include a party to the proceedings in question.

Taking into account the previous activity of the President of the Personal Data Protection Office, who takes appropriate steps to protect the national identification number – PESEL, such as the disclosure of the PESEL number in the National Court Register or in a qualified electronic signature, it clearly indicates how – in the opinion of the supervisory authority – the procedure should be followed in the event of possible disclosure of the PESEL number. The President of the Personal Data Protection Office has repeatedly pointed out that the processing of a PESEL number without observing appropriate security rules poses a number of threats to the privacy of a natural person, and when disclosed in many places, it facilitates identity theft, as well as profiling of a person without their knowledge and consent.

Above all, however, in the period in which the breach occurred, similar cases of infringement were reported to the supervisory authority, which is confirmed by the Report on the activities of the President of the Personal Data Protection Office published this year on the website of the Personal Data Protection Office[3], and breaches involving the loss of correspondence by the postal operator or the opening of correspondence before returning it to the sender were among the most frequently reported breaches by data controllers protection of personal data.

Therefore, the Bank's explanations are incomprehensible, as it explains the lack of notification of a personal data breach by the ambiguous practice of the President of the Personal Data Protection Office in this respect, and at the same time did not use the materials and necessary guidelines available to it from the President of the Personal Data Protection Office. Importantly, by deciding not to report a personal data breach to the supervisory authority, the Controller deprived itself of the opportunity to verify the correctness of its own practice.

On the one hand, the Bank argues that "The statement of the President of the Personal Data Protection Office, from which it follows that the notification in accordance with the procedure provided for in Article 33(1) of the GDPR (...) any infringement including, m.in, is subject to the PESEL number is dated 1 July 2021, i.e. after the occurrence of the infringement to which the proceedings relate", and in the further part of the explanations it indicates that, quote: "From the moment the Bank became aware of the expectations of the President of the Personal Data Protection Office with regard to the application of Article 33(1) of the GDPR, the Bank immediately took steps to adapt its own practice in this respect to the expectations of the President of the Personal Data Protection Office. As a result of the change in the Bank's approach, the President of the Personal Data Protection Office was informed about the infringement that gave rise to the present proceedings."

With regard to the first statement, in cases analogous to the one at issue in the present proceedings, the President of the Personal Data Protection Office also informed the Bank about the relevant practice in letters from before 1 July 2021, such as in the case ref. no. (...), where the statement was sent on 26 March 2021, i.e. from the period when the infringement in question occurred. With regard to the second statement – the Bank did not report the personal data breach in the wake of the first reports on personal data breaches, where, in the opinion of the supervisory authority, no proper analysis of the risk of violation of the rights and freedoms of natural persons to whom the PESEL number relates was made, but only as a result of the request sent of 1 September 2022 to supplement the explanations on the complaint of the person, infringement (ref. no. (...)), in which the supervisory authority asked the Bank to indicate whether it had notified the personal data breach to the supervisory authority in accordance with Article 33 of Regulation 2016/679.

As an aside, it should only be pointed out that, for example, the notification of a personal data breach of 12 February 2021 ref. no. (...), which also involved sending correspondence to the wrong recipient, and in which the scope of personal data covered was almost identical to the infringement to which the present proceedings relate (the difference concerned only the series and number of the identity card – in the notification (...) the following data were disclosed: name and surname, PESEL registration number, bank account number, address of residence or stay, contract number), was reported by Toyota Bank Polska S.A. to the authority Supervisory.

In the case of a personal data breach, the failure to notify the supervisory authority within 72 hours of its discovery resulted in the initiation of the present proceedings, the Bank notified the data subject of the breach of the protection of his or her personal data, foreseeing that the breach may entail a high risk to the rights and freedoms of natural persons – therefore, it was all the more obliged to report the breach to the supervisory authority. As is apparent from Article 33(1) of Regulation 2016/679, in the event of a personal data breach, the controller shall, without undue delay, notify it to the supervisory authority, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.

In the context of the above-mentioned explanations, the Bank seems to forget that when applying the provisions of Regulation 2016/679, the purpose of this Regulation (expressed in Article 1(2)) should be taken into account, which is the protection of the fundamental rights and freedoms of natural persons, in particular their right to the protection of personal data. On the other hand, the protection of individuals with regard to the processing of personal data is one of the fundamental rights (first sentence of recital 1). In the event of any doubts, e.g. as to the performance of duties by controllers – including in a situation where there has been a personal data breach – these values should be taken into account in the first place.

If the supervisory authority obtains full information about a specific personal data breach, as required by Article 33(3) of Regulation 2016/679, it is able to properly assess such a breach and respond appropriately, e.g. by requesting the controller to notify the data subjects in a situation where it is necessary and the controller has not done so on its own initiative. Failure to adequately and promptly respond to personal data breaches increases the risk of the damage materializing.

It is worth emphasizing that when assessing the risk of violation of the rights and freedoms of natural persons, on which the filing of a notification of a personal data breach depends, for m.in, the probability factor and the severity of the potential negative effects should be taken into account. A high level of any of these factors has an impact on the level of the overall Assessment on which the fulfilment of the m.in obligation set out in Article 33(1) of Regulation 2016/679 depends. Given that, given the scope of the personal data disclosed, there was a possibility of serious negative consequences for the data subject materialising in the present case (as shown above), the significance of the potential impact on the rights and freedoms of the natural person should be considered high. At the same time, the likelihood of a high risk arising from the breach in question is not small and has not been eliminated. Thus, it should be stated that in connection with the breach in question, there was a high risk of violation of the rights and freedoms of the data subject, which consequently determines the obligation to notify the personal data breach to the supervisory authority.

In Guideline 9/2022, the EDPB, when indicating the factors to be taken into account in the risk assessment, refers to recitals 75 and 76 of Regulation 2016/679, which suggest that the controller should take into account both the likelihood of occurrence and the seriousness of the threat to the rights and freedoms of the data subject. In the event of a personal data breach, the controller should focus its attention on the risk of the breach affecting a natural person. Therefore, when assessing the risk to an individual arising from a personal data breach, the controller should take into account the specific circumstances of the breach, including the severity of the potential impact and the likelihood of its occurrence. Therefore, when assessing the risk, the EDPB recommends taking into account criteria such as the type of breach, the nature, sensitivity and volume of personal data, as well as the ease of identification, as these may have an impact on the level of risk for individuals. The risk of violating the rights and freedoms of an individual in accordance with Guideline 9/2022 will be greater when the consequences of the violation are more serious, as well as when the likelihood of their occurrence increases. The guidelines indicate that in case of any doubt, the administrator should report the violation, even if such caution could turn out to be excessive.

Summarizing the above, it should be stated that in the present case there is a high risk of violation of the rights and freedoms of the person affected by the breach in question, which in turn resulted in the Bank's obligation to report the personal data breach to the supervisory authority, in accordance with Article 33(1) of Regulation 2016/679, which must include the information specified in Article 33(3) of Regulation 2016/679, and, as has been done, the notification of the infringement to that person, in accordance with Article 34(1) of Regulation 2016/679, which must include the information referred to in Article 34(2) of Regulation 2016/679. It should also be stated that, in the present situation, there are no grounds to conclude that the Controller is exempt from the obligation to notify the personal data breach to the supervisory authority in accordance with Article 33(1) of Regulation 2016/679 and from the obligation to notify the data subject of the breach (in accordance with Article 34(1) of that regulation) for any reason. In the circumstances of the case under consideration, it cannot reasonably be argued that the breach is unlikely to result in a risk to the rights and freedoms of the Data Subject. This is because the breach concerned the following data: name and surname, PESEL registration number, address of residence, bank account number, series and number of the identity card of the above-mentioned person included in the agreement along with the loan repayment schedule, which was made available to an unauthorized person. Therefore, in the opinion of the supervisory authority, there is no justification for the Bank's failure to comply with the obligation under Article 33(1) of Regulation 2016/679, the breach of which is the subject of the present proceedings.

Recital 85 of the preamble to Regulation 2016/679 explains: "In the absence of an adequate and prompt response, a personal data breach may result in physical, material or non-material damage to individuals, such as loss of control over their personal data or restriction of rights, discrimination, theft or falsification of identity, financial loss, unauthorised reversal of pseudonymisation, damage to reputation, breach of data confidentiality protected by professional secrecy or any other significant economic or social damage. Therefore, as soon as a personal data breach is identified, the controller should report it to the supervisory authority without undue delay, if practicable, no later than 72 hours after the breach has been identified, unless the controller is able to demonstrate in accordance with the principle of Accountability that the breach is unlikely to give rise to a risk to the rights and freedoms of natural persons. If it is not possible to make a notification within 72 hours, the notification should be accompanied by an explanation of the reasons for the delay and the information may be communicated gradually without further undue delay.'

Summarizing the above arguments of the supervisory authority in their entirety, it should be stated that the Controller – despite updating its obligations in the circumstances of the analyzed case – did not notify the supervisory authority of the personal data breach within 72 hours of the breach being identified, which means that the Bank breached the obligation under Article 33(1) of Regulation 2016/679.

In accordance with Article 58(2)(i) of Regulation 2016/679, each supervisory authority has the power to apply, in addition to or instead of the other remedies provided for in Article 58(2) of Regulation 2016/679, an administrative penalty payment under Article 83 of Regulation 2016/679, depending on the circumstances of the particular case. The President of the Personal Data Protection Office states that in the case under consideration there were grounds justifying the imposition of an administrative fine on the Bank based on Article 83(4)(a) of Regulation 2016/679, which provides m.in that a breach of the controller's obligations referred to in Article 33 of Regulation 2016/679 is subject to an administrative fine of up to EUR 10,000,000, and in the case of an enterprise – up to 2% of its total annual worldwide turnover from the previous year the higher amount applies.

Pursuant to Article 83(2) of Regulation 2016/679, administrative fines are to be imposed, depending on the circumstances of each individual case, in addition to or instead of the measures referred to in Article 58(2)(a) to (h) and (j) of Regulation 2016/679. When deciding to impose an administrative penalty on the Bank, the President of the Personal Data Protection Office – pursuant to Article 83(2)(a)-(k) of Regulation 2016/679 – took into account the following circumstances of the case, which make it necessary to apply such a sanction in the present case and have an aggravating impact on the amount of the administrative penalty imposed:

1. The nature, gravity and duration of the breach, taking into account the nature, scope or purpose of the processing in question, the number of data subjects affected and the extent of the damage suffered by them (Article 83(2)(a) of Regulation 2016/679).
In the present case, a violation of Article 33(1) of Regulation 2016/679 was found (consisting in failure to notify the President of the Personal Data Protection Office of a personal data breach without undue delay, no later than within 72 hours after the breach became known). It is related to an event involving the disclosure of an unauthorized person with an agreement along with a loan repayment schedule containing personal data of one person in the form of: name, surname, PESEL registration number, address of residence, bank account number and series and number of an identity card, which makes it of significant importance and serious nature, because this event may lead to material or non-material damage to the person, where the data has been breached and the likelihood of it is high. In connection with the occurrence of a personal data breach, consisting in the disclosure of unauthorised bank records to a person, there was an unlawful disclosure of information covered by banking secrecy – which further increases the seriousness of the breach and indicates the possibility of negative consequences of the event for data subjects.

The President of the Personal Data Protection Office considers the long duration of the Bank's breach of Article 33(1) of Regulation 2016/679 to be an aggravating circumstance. It should be assumed that it lasted almost 18 months. The Controller became aware of the personal data breach on (...) March 2021, and did not report it until 7 September 2022, and only due to the parallel proceedings in connection with the filing of a complaint by the Data Subject against the disclosure of his or her personal data to a third party – one of the questions asked to the Controller in the pending proceedings concerned the indication that whether, and if so, when, the Bank reported the personal data breach to the supervisory authority. It should also be emphasized that in view of the above-mentioned complaint filed by the Bank's Client about irregularities in the processing of her personal data by Toyota Bank Polska S.A., consisting in making her personal data available to a third party without a legal basis, in the opinion of the President of the Personal Data Protection Office, this only confirms that the risk Assessment presented in the Bank's explanations in the case in question takes into account only the perspective of the Administrator, and this means that it does not take into account the perspective of the Bank's Client, who as a result of a breach of the protection of her personal data, with a high probability, suffered non-material damage.

In the present case, the personal data of only one person was breached at all. Such a number of persons affected by the breach, especially in view of the fact that the Bank – due to the scale and scope of its activity – processes the personal data of a very large number of customers, should be considered small, which undoubtedly speaks in favour of the Controller, but it did not change the overall assessment, i.e. the recognition of the condition under Article 83(2)(a) of Regulation 2016/679 as aggravating in the case at hand.

2. The intentional nature of the infringement (Article 83(2)(b) of Regulation 2016/679).
According to the Guidelines of the Article 29 Working Party on the application and determination of administrative pecuniary penalties for the purposes of Regulation 2016/679 WP253 (adopted on 3 October 2017, endorsed by the EDPB on 25 May 2018), intention 'includes both knowledge and deliberate act, in relation to the characteristics of the offence'. The Bank made a conscious decision not to notify the President of the Personal Data Protection Office about the breach of personal data protection within 72 hours of its discovery. There is no doubt that the Bank, when processing personal data on a mass scale, must have knowledge in the field of personal data protection, including knowledge of the consequences of a personal data breach resulting in a risk of violation of the rights and freedoms of natural persons (and this knowledge may be required not only from the Controller, but also from the Data Protection Officer appointed by the Controller). Being aware of this, the Controller decided not to report the personal data breach to the President of the Personal Data Protection Office within 72 hours of its discovery.

3. Relevant previous breaches of Regulation 2016/679 by the controller (Article 83(2)(e) of Regulation 2016/679).
When deciding on the imposition and amount of an administrative fine, the supervisory authority is obliged to pay attention to any previous violations of Regulation 2016/679. In Guideline 04/2022[4] on the calculation of administrative fines under the GDPR, adopted on 24 May 2023, the EDPB explicitly states: "The existence of previous infringements may be considered as an aggravating factor in the calculation of the amount of the fine. The significance given to this factor should be determined by taking into account the nature and frequency of previous infringements. However, the absence of previous infringements cannot be regarded as a mitigating circumstance, since compliance with the provisions of [Regulation 2016/679] is the norm.' Although, as the Guidelines indicate, 'infringements relating to the same subject-matter should be given greater importance, since they are closer to the infringement which is the subject of the present proceedings, in particular where the controller or processor has previously committed the same infringement (repeated infringements)' (point 88 of the Guidelines), 'all previous infringements may constitute information on the general approach of the controller or processor to the Regulation 2016/679'.

The supervisory authority has already found in its previous administrative decisions that the Controller has violated the provisions on the protection of personal data:
- in its decision of 29 September 2022 (ref. no. (...)) infringement of Article 6(1) of Regulation 2016/679;
- in the decision of 8 May 2023 (ref. no. (...)) infringement of Article 15(1)(c) of Regulation 2016/679;
- in its decision of 9 May 2023 (ref. no. (...)) infringement of Article 15(1)(a) of Regulation 2016/679;
- in the decision of 14 November 2022 (...), infringement of Article 15(1)(c) and Article 12(3) of Regulation 2016/679;
- in the decision of 1 February 2024 (ref. no. (...)) Article 6(1) of Regulation 2016/679.

The above-mentioned previous breaches indicate the Controller's generally dismissive approach to data protection issues, and the corrective measures previously applied to the Controller in the above-mentioned cases, including twice in May 2023 when the President of the Personal Data Protection Office ordered the Bank to adapt the personal data processing operations to the provisions of Regulation 2016/679 in view of the violation of Article 15(1)(c) of Regulation 2016/679 and Article 15(1)(a) of Regulation 2016/679, whether, in connection with decisions reprimanding the Controller for violating the provision of Article 6(1) of Regulation 2016/679, as was the case in cases ref. no. (...) and (...), fully justify the imposition of a financial penalty in the present proceedings, as well as the extent thereof. It is not without significance that the last decision for violating the provisions of Regulation 2016/679 in relation to Toyota Bank Polska S.A., in which the supervisory authority applied a corrective measure (warning) against the Administrator, was issued on 1 February 2024, which, in accordance with Guideline 04/2022 - "The moment when the previous infringement took place should be taken into account, taking into account the fact that that the longer the period between that infringement and the infringement currently under investigation, the less relevant that earlier infringement is. Consequently, the earlier the infringement occurred, the less importance the supervisory authorities should attach to it" (point 84 of the Guidelines) – should have an impact on the final decision of the supervisory authority and the amount of the administrative penalty imposed.

In view of the foregoing, in the present case, it must be concluded that there are grounds for treating the condition in Article 83(2)(e) of Regulation 2016/679 as aggravating.

4. Categories of personal data affected by the breach (Article 83(2)(g) of Regulation 2016/679).
Personal data made available to an unauthorised person do not belong to the special categories of personal data referred to in Article 9 of Regulation 2016/679 or to the data referred to in Article 10 of Regulation 2016/679, but the fact that the agreement made available between the parties contains a wide range of them (name and surname, address of residence, PESEL registration number, bank account number, series and number of the identity card), entails a high risk to the rights and freedoms of a natural person. The PESEL number, i.e. an eleven-digit numerical symbol uniquely identifying a natural person, containing the date of birth, serial number, gender designation and control number, and thus closely related to the private sphere of a natural person and also subject to exceptional protection under Article 87 of Regulation 2016/679 as a national identification number, is data of a special nature and requires such special protection. There is no other data that would unambiguously identify a natural person. It is not without reason that the PESEL number serves as data that identifies each person and is commonly used in contacts with various institutions and in legal circulation. The PESEL number, together with the name and surname, unambiguously identifies a natural person in a way that allows for attributing the negative effects of the breach (e.g. identity theft, loan fraud) to that specific person.

In this context, it is worth recalling the EDPB Guideline 04/2022, which states: "With regard to the requirement to take into account the categories of personal data affected by the breach (Article 83(2)(g) of [Regulation 2016/679]), [Regulation 2016/679] clearly indicates the types of data that are subject to special protection and thus a stricter response when imposing fines. This applies at least to the types of data covered by Articles 9 and 10 of [Regulation 2016/679] and to data not covered by those Articles, the dissemination of which immediately causes harm or discomfort to the data subject (e.g. location data, private communication data, national identification numbers or financial data such as transaction statements or credit card numbers). In general, the more such categories of data are affected by a breach or the more sensitive the data is, the more weight the supervisory authority may assign to such a factor. The amount of data on each data subject also matters, as the more data is shared with each data subject, so does the breach of the right to privacy and the protection of personal data."

It is worth pointing out once again the emerging case law in this area, where, for example, in the judgment of 15 November 2022 ref. no. II SA/Wa 546/22, the Provincial Administrative Court in Warsaw stated: "It was also obvious that the authority, when determining the amount of the penalty, had to take into account the fact that the infringement concerned highly sensitive data (m.in. PESEL, address, health data)". This view was also shared by the above-mentioned Court in its judgment of 21 June 2023 in the case ref. no. II SA/Wa 150/23, where the Provincial Administrative Court in Warsaw stated: "To sum up, the Court is of the opinion that the disclosure of the PESEL number indicates a high risk of violation of the rights and freedoms of natural persons".

When deciding to impose an administrative fine, the President of the Personal Data Protection Office took into account the following circumstances of the case, which necessitated the application of such a sanction in the present case and had a mitigating effect on the amount of the administrative penalty imposed:

1. The degree of cooperation with the supervisory authority to remedy the infringement and mitigate its possible negative effects (Article 83(2)(f) of Regulation 2016/679).
It should be noted that in addition to the proper fulfilment of the procedural obligations incumbent on the controller during the administrative proceedings which ended with the issuance of this decision, the Bank cooperated with the supervisory authority in the course of the administrative proceedings by providing relevant information related to the personal data breach (responding to the notice of initiation of the proceedings and the request to send documents necessary to determine the basis for the Assessment of the administrative penalty). The Controller also reported a breach of personal data protection as a result of initiating a complaint procedure and a summons issued in connection with these proceedings, and although this notification was a specific response to the supervisory authority's statement, it is a manifestation of an appropriate response to the letters addressed to the Bank, and therefore this circumstance should be classified as mitigating.

2. Any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial gains or losses avoided directly or indirectly as a result of the infringement (Article 83(2)(k) of Regulation 2016/679).
The Bank notified the data subject about the breach of the protection of his or her personal data and provided support to that person by purchasing a report from the Credit Information Bureau, which deserves to be noticed and accepted, therefore this action should be considered as a mitigating circumstance in the present case.

The following other circumstances referred to in Article 83(2) of Regulation 2016/679, after assessing their impact on the infringement found in the present case, were considered by the President of the Personal Data Protection Office to be neutral in his opinion, i.e. having neither an aggravating nor mitigating effect on the amount of the administrative penalty imposed:

1. Measures taken by the controller to minimise the damage suffered by data subjects (Article 83(2)(c) of Regulation 2016/679).
Despite the fact that the Controller notified the data subject of a breach of the protection of his or her personal data, resulting from Article 34(1) of Regulation 2016/679, in which the Controller indicated to that person the means to possibly prevent the possible negative consequences of the breach, due to the nature of the breach found in the present case (failure to notify the President of the Personal Data Protection Office without undue delay, no later than 72 hours after it has been discovered) - which in its essence does not directly entail a risk of damage to the person affected by the personal data breach - it must be assumed that the condition laid down in Article 83(2)(c) of Regulation 2016/679 has no aggravating or mitigating effect on the amount of the administrative penalty imposed in the present case. It is irrelevant in the Assessment of the Bank's infringement of Article 33(1) of Regulation 2016/679.

2. Degree of responsibility of the controller, taking into account the technical and organisational measures implemented by the controller pursuant to Articles 25 and 32 (Article 83(2)(d) of Regulation 2016/679).
In view of the nature of the infringement found in the present case (failure to notify the President of the Personal Data Protection Office of a personal data breach without undue delay, no later than within 72 hours after it has been identified) – which in its essence does not involve the technical and organisational measures taken by the controller – it must be assumed that the condition set out in Article 83(2)(d) of Regulation 2016/679 has no impact in the present case either on the aggravating or on the mitigating effect on the administrative penalty imposed. It is irrelevant in the Assessment of the Bank's infringement of Article 33(1) of Regulation 2016/679.

3. How the supervisory authority became aware of the breach (Article 83(2)(h) of Regulation 2016/679).
The President of the Personal Data Protection Office was informed of the occurrence of the breach of Article 33(1) of Regulation 2016/679 related to the event of the Controller making a document containing personal data available to an unauthorised recipient as a result of the notification of a personal data breach made by the Bank almost 18 months after it was discovered. On the other hand, the notification of the infringement itself after such a significant period of time was related to the parallel proceedings pending before the President of the Personal Data Protection Office on the complaint of the person affected by the infringement in question, and in which case the President of the Personal Data Protection Office asked Bank m.in. to report the infringement in question. As it was established, it was only the above request that was the basis for filing a notification of a personal data breach.

Failure to notify the supervisory authority of a personal data breach without undue delay, no later than within 72 hours after the breach has been identified, is the sole subject of the present proceedings and, in the circumstances of the facts under consideration, the supervisory authority assumed that it would not treat this condition as an aggravating circumstance.

4. Compliance with the measures referred to in Article 58(2) of Regulation 2016/679 previously taken in the same case (Article 83(2)(i) of Regulation 2016/679).
Prior to the issuance of this decision, the President of the Personal Data Protection Office did not apply any of the measures listed in Article 58(2) of Regulation 2016/679 to the Controller in the case under consideration, and therefore the Controller was not obliged to take any action related to their application, and which, if assessed by the President of the Personal Data Protection Office, could have an aggravating or mitigating impact on the Assessment of the infringement found.

5. Use of approved codes of conduct under Article 40 of Regulation 2016/679 or approved certification mechanisms under Article 42 of Regulation 2016/679 (Article 83(2)(j) of Regulation 2016/679).
The Controller shall not apply the instruments referred to in Articles 40 and 42 of Regulation 2016/679. However, their adoption, implementation and application are not, as provided for in Regulation 2016/679, mandatory for controllers and processors, and therefore the fact that they are not applied cannot be construed to the detriment of the controller in the present case. On the other hand, the Controller could benefit from the fact that such instruments are adopted and used as measures to guarantee a higher than standard level of protection of the personal data being processed.

6. Financial gains or losses avoided directly or indirectly as a result of the infringement (Article 83(2)(k) of Regulation 2016/679).
The President of the Personal Data Protection Office did not find that the Controller had gained any financial benefits or avoided such losses in connection with the breach. Therefore, there are no grounds to treat this circumstance as incriminating against the Controller. A finding of measurable financial benefits resulting from the infringement of Regulation 2016/679 should be assessed as decidedly negative. On the other hand, the failure of the Administrator to achieve such benefits, as a natural state, independent of the infringement and its consequences, is a circumstance which, by its very nature, cannot be mitigating for the Administrator. This is confirmed by the wording of Article 83(2)(k) of Regulation 2016/679, which requires the supervisory authority to pay due attention to the 'gains' from the infringer.

The President of the Personal Data Protection Office, while comprehensively considering the case in question, did not note any circumstances other than those described above, which could affect the Assessment of the infringement and the amount of the administrative fine imposed.

In the opinion of the President of the Personal Data Protection Office, the administrative penalty applied in the circumstances of the present case fulfils the functions referred to in Article 83(1) of Regulation 2016/679, i.e. it is effective, proportionate and dissuasive in this individual case.

It should be emphasised that the penalty will be effective if its imposition leads to the Bank, which professionally and on a mass scale processes personal data, in the future to fulfil its obligations in the field of personal data protection, in particular with regard to reporting personal data breaches to the President of the Personal Data Protection Office.

In the opinion of the President of the Personal Data Protection Office, the administrative penalty will have a punitive function, as it will be a response to the Bank's violation of the provisions of Regulation 2016/679. It will also have a preventive function; in the opinion of the President of the Personal Data Protection Office, it will point out to both the Bank and other data controllers the reprehensibility of disregarding the controllers' obligations related to the occurrence of a personal data breach, and aimed at preventing its negative and often severe consequences for the persons affected by the breach, as well as removing these effects or at least limiting them.

Pursuant to Article 103 of the Personal Data Protection Act of 10 May 2018 (Journal of Laws of 2019, item 1781), hereinafter referred to as the "Personal Data Protection Act", the equivalent of the amounts referred to in Article 83 of Regulation 2016/679 expressed in EUR shall be calculated in PLN according to the average EUR exchange rate announced by the National Bank of Polish in the exchange rate table as at 28 January each year, and if in a given year the National Bank Polish does not announce the average exchange rate of the euro on 28 January - according to the average exchange rate of the euro announced in the table of exchange rates of the National Bank of Poland next after that date.

In view of the above, the President of the Personal Data Protection Office, pursuant to Article 83(4)(a) in conjunction with Article 103 of the Personal Data Protection Act, imposed an administrative fine of PLN 78,575.40 (equivalent to EUR 18,000) on the Bank for the infringement described in the operative part of this decision, using the average EUR exchange rate of 29 January 2024 (EUR 1 = PLN 4.3653).

In the opinion of the President of the Personal Data Protection Office, the penalty in the amount of PLN 78,575.40 (in words: seventy-eight thousand five hundred seventy-five zlotys and forty groszy) meets the conditions referred to in Article 83(1) of Regulation 2016/679 in the circumstances of the present case due to the seriousness of the infringement found in the context of the primary objective of Regulation 2016/679 - the protection of the fundamental rights and freedoms of natural persons, in particular the right to the protection of personal data. Referring to the amount of the administrative penalty imposed on the Bank, the President of the Personal Data Protection Office stated that it was proportionate to the financial situation of the Administrator and would not constitute an excessive burden for the Administrator. The financial statements presented by the Administrator show that the Bank's total revenues for the financial year ended 31 March 2023 amounted to PLN 319,617,075, therefore the amount of the administrative penalty imposed in the present case is approx. 0.02% of the above-mentioned amount of revenues. At the same time, it is worth noting that the amount of the penalty imposed of PLN 78,575.40 is only approx. 0.18% of the maximum penalty that the President of the Personal Data Protection Office could impose on the Bank for the infringement found in the present case by applying the static maximum penalty (i.e. EUR 10,000,000) in accordance with Article 83(4) of Regulation 2016/679.

The amount of the penalty has been set at such a level that, on the one hand, it constitutes an adequate response of the supervisory authority to the degree of breach of the administrator's obligations, but on the other hand, it does not cause a situation in which the need to pay a financial penalty will entail negative consequences in the form of a significant reduction in employment or a significant decrease in the Bank's turnover. In the opinion of the President of the Personal Data Protection Office, the Bank should and is able to bear the consequences of its negligence in the area of data protection, as evidenced by the Bank's financial statements sent to the President of the Personal Data Protection Office on 15 December 2023.

Finally, it is necessary to point out that in determining the amount of the administrative penalty in the present case, the President of the Personal Data Protection Office applied the methodology adopted by the European Data Protection Board in Guidelines 04/2022 on the calculation of administrative fines under the GDPR adopted on 24 May 2023. According to the guidelines presented in this document:

  1. The President of the Personal Data Protection Office categorised the infringement of the provisions of Regulation 2016/679 found in the present case (vide Chapter 4.1 of Guideline 04/2022). The infringement of Article 33(1) of Regulation 2016/679 found in the present case falls within the category of infringements punishable by the lower of the two penalties provided for in Regulation 2016/679 (up to a maximum of EUR 10 000 000 or up to 2% of the total annual turnover of an undertaking in the preceding financial year). It was therefore considered in abstracto (without reference to the individual circumstances of the individual case) by the EU legislature to be less serious than the infringements referred to in Article 83(5) of Regulation 2016/679).
  2. The President of the Personal Data Protection Office assessed the infringement found in the present case as a breach of a low level of seriousness (vide Chapter 4.2 of Guidelines 04/2022). That Assessment took into account the factors listed in Article 83(2) of Regulation 2016/679 that relate to the party in question (they constitute the 'seriousness' of the infringement), namely: the nature, gravity and duration of the infringement (Article 83(2)(a) of Regulation 2016/679), the intentional or unintentional nature of the infringement (Article 83(2)(b) of Regulation 2016/679) and the categories of personal data, infringement (Article 83(2)(g) of Regulation 2016/679). A detailed Assessment of these circumstances is set out above. At this point, it should be pointed out that a consideration of their cumulative impact on the Assessment of the infringement found in the present case, taken in its entirety, leads to the conclusion that the level of seriousness of the infringement is also low in concreto (on the scale of seriousness of infringements presented in point 60 of Guideline 04/2022). As a consequence, the starting point for calculating the amount of the penalty is the value between 0 and 10% of the maximum amount of the penalty that can be imposed on the Bank. Given that Article 83(4) of Regulation 2016/679 obliges the President of the Personal Data Protection Office to adopt as the maximum amount of the penalty for infringement referred to in that provision the amount of EUR 10,000,000 or, if this value is higher than EUR 10,000,000, an amount representing 2% of the Bank's turnover from the previous financial year, the President of the Personal Data Protection Office states that the so-called static maximum penalty amount – EUR 10,000,000 – applies in the present case. Bank's turnover for the financial year ended 31 March 2023 (EUR 73,217,665, i.e. the equivalent of PLN 319,617,075 at the EUR mid-exchange rate for 29 January 2024) amounts to EUR 1,464,353 – lower than the static maximum penalty referred to in Article 83(4) of Regulation 2016/679. Thus, having at his disposal a range from EUR 0 to EUR 10,000,000, the President of the Personal Data Protection Office assumed, as adequate and justified by the circumstances of the case, the starting amount for calculating the amount of the penalty amounting to EUR 300,000 (representing 3% of the static maximum amount of the penalty).
  3. The President of the Personal Data Protection Office adjusted the starting amount corresponding to the low seriousness of the identified breach to the Bank's turnover as a measure of its size and economic strength (vide Chapter 4.3 of Guidelines 04/2022). According to Guideline 04/2022, for companies with an annual turnover between €50 million and €100 million, the supervisory authority may consider further calculating the amount of the penalty based on a value between 8% and 20% of the starting amount. Given that the Bank's turnover in the last reporting year (ending 31 March 2023) amounted to PLN 319,617,075, i.e. EUR 73,217,665 (based on the average EUR exchange rate for 29 January 2024), the President of the Personal Data Protection Office considered it appropriate to adjust the amount of the penalty to be calculated to the value corresponding to 12% of the initial amount, i.e. to EUR 36,000 (the equivalent of PLN 157,150.80).
  4. The President of the Personal Data Protection Office assessed the impact of the other circumstances (apart from those taken into account above in the Assessment of the seriousness of the breach) indicated in Article 83(2) of Regulation 2016/679 (vide Chapter 5 of Guideline 04/2022) on the identified breach. These circumstances, which may have an aggravating or mitigating impact on the Assessment of the infringement, refer – as assumed in Guidelines 04/2022 – to its subjective side, i.e. to the entity being the infringer itself and to its conduct before, during and after the infringement. A detailed Assessment and justification of the impact of each of these conditions on the Assessment of the infringement is set out above. The President of the Personal Data Protection Office held that the mitigating circumstances in the present case are: the degree of cooperation between the Bank and the supervisory authority in order to remove the breach and mitigate its negative effects (Article 83(2)(f) of Regulation 2016/679), as well as the actions taken by the Bank against the person whose data became the subject of a personal data breach ("other mitigating factors" referred to in Article 83(2)(f) of Regulation 2016/679). On the other hand, the amount of the penalty is affected by the relevant previous breaches of the Bank's personal data protection identified by the President of the Personal Data Protection Office (Article 83(2)(e) of Regulation 2016/679). The other conditions (Article 83(2)(c), (d), (h), (i) and (j) of Regulation 2016/679) did not, as stated above, have any mitigating or aggravating effect on the Assessment of the infringement and, consequently, on the level of the penalty. Due to the occurrence of the above mitigating and aggravating circumstances in the case, the President of the Personal Data Protection Office considered it justified to further reduce the amount of the penalty determined above, taking into account the Bank's turnover (point 3 above); In the opinion of the President of the Personal Data Protection Office, the reduction of the infringement to EUR 28,800 (the equivalent of PLN 125,720.64) is adequate to the assessed impact of the above-mentioned premises on the Assessment of the infringement.
  5. Finally, the President of the Personal Data Protection Office assessed the amount of the penalty determined in the above-mentioned manner in the context of the principles of effectiveness, proportionality and dissuasive nature of the administrative fine (vide Chapter 7 of Guideline 04/2022). As a result of this assessment, the President of the Personal Data Protection Office concluded that it required additional correction due to the proportionality directive indicated by the EU legislator as one of the three basic principles in Article 83(1) of Regulation 2016/679. In the opinion of the President of the Personal Data Protection Office, a fine of EUR 28,800 would undoubtedly be an effective penalty (due to its clear severity, it would allow it to achieve its repressive objective, which is to punish for unlawful conduct) and a dissuasive penalty (allowing it to effectively discourage both the Company and other controllers from committing future infringements of the provisions of Regulation 2016/679). However, in the opinion of the President of the Personal Data Protection Office, such a penalty would be disproportionately high in relation to the seriousness of the infringement found (which, both in abstracto and in concreto, is low – vide points 1 and 2 above) and in the context of the Assessment of the Bank's conduct after the infringement has been identified, which – as indicated above in the Assessment of the premises under Article 83(2)(f) and (k) of the 2016 Regulation – should, in principle, be assessed positively. The principle of proportionality requires, m.in, that the measures adopted by the administrative authority do not go beyond what is appropriate and necessary to achieve legitimate objectives (vide paragraphs 137 and 139 of Guideline 04/2022). In other words: "A sanction is proportionate if it does not exceed the threshold of severity determined by taking into account the circumstances of the individual case" (P. Litwiński (ed.), Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 [...]; Commentary on Article 83 [in:] P. Litwiński (ed.) General Data Protection Regulation. Personal Data Protection Act. Selected sectoral legislation. Commentary). Therefore, taking into account the proportionality of the penalty, the President of the Personal Data Protection Office further reduced it to EUR 18,000 (the equivalent of PLN 78,575.40). In his view, such determination of the final amount of the penalty imposed will not reduce its effectiveness and deterrent character. That amount is the threshold above which a further increase in the amount of the penalty will not result in an increase in its effectiveness and deterrent nature. On the other hand, a greater reduction in the amount of the penalty could come at the expense of its effectiveness and dissuasiveness, as well as a consistent understanding, application and enforcement of Regulation 2016/679 and the principle of equal treatment of operators in the EU and EEA internal market with respect to other supervisory authorities and the EDPB. It is also important to note that the effectiveness and dissuasiveness of the penalty imposed in the present case (even if it is far from its maximum limit) will be based on the fact that the fact that it has been imposed will have an impact, undoubtedly aggravating, on the Assessment of any subsequent breach of the provisions of Regulation 2016/679 committed by the Bank in the future.

In this factual and legal situation, the President of the Personal Data Protection Office ruled as in the operative part.


[1] European Data Protection Board Guidelines on Reporting Personal Data Breaches, version 2.0, hereinafter referred to as Guideline 9/2022. The above-mentioned guidelines updated and supplemented the Article 29 Working Party Guidelines on the notification of personal data breaches in accordance with Regulation 2016/679 (Wp250 rev.01), adopted on 3 October 2017.

[2] European Data Protection Board Guideline 01/2021 on examples for personal data breach notification adopted on 14 December 2021, version 2.0, hereinafter referred to as "Guideline 01/2021".

[3] Report on the activities of the President of the Personal Data Protection Office in 2021, p. 181.

[4] Guideline 04/2022 on the calculation of administrative fines under the GDPR adopted on 24 May 2023, version 2.1, hereinafter referred to as "Guideline 04/2022" (available in English at: https://edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-042022-calculation-administrative-fines-under_pl)


Link: https://uodo.gov.pl/pl/138/3049

Testo del 2024-04-13 Fonte: Uodo




Commenta



i commenti sono anonimi e inviati via mail e cancellati dopo aver migliorato la voce alla quale si riferiscono: non sono archiviati; comunque non lasciare dati particolari. Si applica la privacy policy.


Ricevi gli aggiornamenti su Rubato il pacco di un cliente di una banca: sanzione per omessa denuncia di data breach e gli altri post del sito:

Email: (gratis Info privacy)






Nota: il dizionario è aggiornato frequentemente con correzioni e giurisprudenza










Forum Banca 2026