What to do if your data is leaked?

21 May 2021

It has happened – your personal data has been leaked. Regardless of where you obtained this information (media, message conveyed by the data controller), and regardless of how important this data was from your perspective (just a phone number, or perhaps information about your sexual orientation), you have certain rights in connection with the data breach. What should you do? First and foremost, take all actions that will protect you from the negative consequences of the leak or at least minimize those consequences. Subsequently, also consider legal steps.

Identity Card

In the event that your identity card number is leaked (you lose the document, it is stolen, or the data is leaked due to improper security measures by entities that process such data in accordance with the law):

  • in the case of theft – you should report the matter to the Police. However, is this equivalent to blocking the card? On the government website, we learn that it is. You no longer need to go to the municipal authority – the Police will pass on the information;
  • in the case of loss – you should report the loss to the nearest municipal authority or consular office (if you are abroad), the authority/office will block the card (this can also be done online using a trusted profile);
  • in the case of both theft and loss – regardless of the above, you should block the card at your bank or at one of the banks that accepts blocking requests from non-customers (details).

There are also tools created by private entities that allow for the blocking of data from the card, such as those prepared by Credit Information Bureau S.A. or CRIF Sp. z o.o.
It is also advisable to take advantage of the option to set up notifications/alerts in case of attempts to incur obligations using your data (e.g., BIK alerts).

Account Password

If for any reason you are concerned that your password used for logging into any website may have been compromised, you can check on the website haveibeenpwned.com whether this has occurred for a specific email or phone number used as a login.

Legal Step: Requesting Information from the Data Controller

Regardless of what data may have been leaked, every individual whose personal data was involved in the breach has the right to request information and explanations from the data controller, such as to whom your data was disclosed, whether the breach was reported to the President of the Polish Data Protection Authority (UODO), and what specific data was leaked. The information regarding the details of the breach will allow you to assess what steps you may be able to take to minimize threats to your interests, your reputation, or any other rights and freedoms.

What may also be important is to keep correspondence with the data controller, as well as any public statements issued in connection with the breach, for the purpose of filing a complaint with the UODO, reporting the matter to the Police, or pursuing claims through civil proceedings. In connection with the breach, you may also request the data controller to grant some form of compensation (e.g., a discount on services), although in this case, the decision rests with the data controller. An entity that cares about its reputation will certainly consider some form of redress, as was the case, for example, with H&M.

READ MORE:35 million euro fine for H&M

Nothing disappears on the internet?

 It is worth remembering that, for example, Google Search allows you to submit a request to remove your name from search results. The form for submitting such a request is available here.

FREE

What to do if your data is leaked?

Watch the webinar

Legal Step: Complaint to the UODO

Even if you have not suffered any specific material or non-material loss in connection with the data breach, you have the right to file a complaint with the Polish DPA. Important: the Polish DPA does not have the authority to issue a decision regarding financial compensation for you in connection with the breach. However, it can order the data controller to take specific actions related to data processing or prohibit such processing, as well as impose a monetary penalty. What will you gain in this case? Certainly, better protection of your data in the future. The data controller will be compelled, directly or indirectly, to implement solutions that eliminate the risk of breaches in the future. You will also gain the ordinary satisfaction that the irregularities in data processing did not go unnoticed and appropriate sanctions were applied.

Legal Step: Reporting the Case to the Police

If you believe that a specific person has committed a criminal act, you can report the suspicion of a crime to the Police. The Polish Personal Data Protection Act of 2018 contains criminal provisions stating that anyone who processes personal data, although such processing is not permissible or is not authorized to process it, is subject to a fine, restriction of liberty, or imprisonment for up to two years (Article 107 § 1). If the act specified in § 1 concerns data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, membership in trade unions, genetic data, biometric data processed for the purpose of uniquely identifying a natural person, data concerning health, sexuality, or sexual orientation, the offender is subject to a fine, restriction of liberty, or imprisonment for up to three years (Article 107 § 2). Remember that – as stated in Article 46 § 1 of the Penal Code – in the event of a conviction, the court may order the obligation to repair, in whole or in part, the damage caused by the crime or to provide compensation for the harm suffered.

GDPR. Support is useful!

Legal Step: Seeking Compensation or Redress in Court

In the GDPR itself, there is a clear legal basis for bringing claims against entities responsible for the improper processing of personal data. Any person who has suffered material or non-material damage as a result of a violation of the GDPR has the right to obtain compensation from the data controller or data processor for the damage incurred (Article 82(1)). For example, a German supervisory authority awarded compensation in a case concerning the sending of a newsletter in a case regarding the sending of a newsletter. Although the awarded amount of 50 euros is not staggering, this case demonstrates that the indicated mechanism works. In Poland, there has also been a ruling awarding compensation in the amount of 1,500 PLN, regardless of the fact that the personal data of the plaintiff (PESEL, phone number) were not made public or used unlawfully by an unauthorized person who came into possession of them. However, remember that civil proceedings involve costs (court fee, attorney's fees), unless you receive a waiver of court costs or assistance from a lawyer/legal advisor due to your financial situation. You can find a sample claim here

Better to Prevent than to Cure

It is clear that once you have entrusted your personal data to someone, you essentially have no influence over how it is processed and the security measures applied. However, you can often make a good choice before sharing your data. If you plan to use services, such as financial services or private medical care, it is worth taking a close look at the potential service provider's website for information on data processing. Check the privacy policy and information regarding data processing with cookies, as well as the contact form. Are the provided details clear and do they raise any doubts? Such simple research will at least allow you to gauge how seriously the entity treats personal data protection. A website that is well-prepared in terms of legal requirements provides a basis for assuming that you are dealing with a professional who cares about both creating and maintaining a compliant image with the GDPR.

Data breaches are not among the most pleasant situations. If you need specialized support, contact our Data Protection Advisor – Cezary Lutyński. He will advise you on what to do in your situation and indicate the best solutions.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.