Factual Background
The personal data breach identified by the supervisory authority involved the sending of a car insurance policy via email by an insurance agent, a data processor of WARTA S.A. Insurance and Reinsurance Company, to an unauthorized recipient, despite it being sent to the email address provided by the client.

The supervisory authority imposed a monetary fine (in the amount of PLN 85,588) on the company for violating two provisions: Article 33(1) of the General Data Protection Regulation of April 27, 2016 (2016/679) (hereinafter "GDPR") and Article 34(1) GDPR. According to the supervisory authority, WARTA, as the data controller, failed to fulfill its obligations related, on the one hand, to the notification of the personal data breach under the conditions and within the time frame specified in Article 33(1) GDPR, and on the other hand, neglected the obligation to inform the data subjects about the personal data breach.
What categories of data were subject to the breach?
As a result of the incident, the confidentiality of data belonging to two (sic!) individuals was breached, including their names, surnames, residential or correspondence addresses, PESEL numbers, phone numbers, email addresses, as well as information regarding the subject of insurance (passenger car), scope of insurance, payments, assignments, and additional provisions resulting from the agreement.
How did the Polish DPA obtain information about the breach?
The information about the incident reached the Authority from the unauthorized recipient, who came into possession of documents not intended for him containing the aforementioned personal data, namely the owner of the email inbox that was mistakenly provided by the client when concluding the insurance contract.
How did the Polish DPA react and what happened step by step?
- Upon receiving information about the incident, the Polish DPA requested the company to provide clarification on whether an analysis regarding the risk of infringement of the rights and freedoms of natural persons necessary to assess whether there was a data protection breach requiring notification of the President of the Polish DPA and the individuals affected by the breach had been conducted in connection with the sending of electronic correspondence to an unauthorized recipient.
-
In response, the company indicated that such an analysis had been conducted, and as a result, it was determined that there was no high probability of negative consequences for the individuals whose data were involved.
Provide employees
with valuable e-training - for freeDo you want to train your employees for free?SHOW MORE
It's simple - copy and send them the appropriate links.
TUiR Warta S.A. justified this by stating that
- firstly: the client provided an incorrect email address to which the insurance policy document was sent;
- secondly: the unauthorized recipient contacted the company himself, thus it can be inferred that he is aware of the regulations and the importance of the information he received.
The remedial action taken by the company was to send a request to the unauthorized recipient for the permanent deletion of the message along with a request for feedback confirming its deletion. - The President of the Polish DPA again summoned the Company to conduct an analysis regarding the risk of infringement of the rights and freedoms of natural persons.
- The Company reiterated that in its opinion, there was no high risk of infringement of the rights and freedoms of the individuals whose data were involved, as the data were disclosed only to an unauthorized recipient who himself contacted the Company with a notification of the incident; therefore, the probability of misuse of this information in an unauthorized manner or causing other harm is, in the Company's assessment, low.
- The Polish DPA initiated administrative proceedings.
- The Company reported the breach to the President of the Polish DPA and notified both individuals affected by the breach.
- The President of the Polish DPA imposed an administrative fine of 85,588 PLN on TUiR WARTA S.A.
According to the Polish DPA…
Below are a few “thoughts” from the Authority's justification for the decision in question that are worth noting.
- A breach occurs both when it is intentional and unintentional. The fact that the breach occurred due to a mistake by the client, who provided the agent with an incorrect email address, cannot influence the assessment of this event.
- The data controller allowing the use of email for communication with the client should be aware of the risks associated, for example, with the incorrect provision of the email address by the client and, in order to minimize them, must take appropriate organizational and technical measures, such as verifying the provided address or encrypting documents sent in this manner.
- The PESEL number along with names and surnames, residential addresses, phone numbers, and email addresses represents a high risk of infringement of the rights or freedoms of natural persons.
- On one hand: the fact of addressing a request to the wrong recipient for the permanent deletion of received correspondence or a statement regarding the destruction of received correspondence does not influence the assessment of the breach. There is no certainty that before these actions, that person did not make, for example, a photocopy or did not retain the personal data contained in the document in another way, such as by writing it down. Therefore, simply deleting the correspondence does not provide any guarantees that the intentions of such a person will not change now or in the future.
- But: [from the Guidelines of the Article 29 Working Party regarding reporting data breaches] what if personal data is accidentally sent to the wrong department of the organization or to a service provider organization that is commonly used? The data controller may request the recipient to return or securely destroy the received data. In both cases – given that the data controller maintains ongoing relationships with those entities and may be familiar with their procedures, history, and other relevant details – the recipient can be considered a “trusted” party. In other words, the data controller can trust the recipient enough to reasonably expect that this party will not read the mistakenly sent data or gain access to it and that it will comply with the instruction to return it.” However, in this case, there are no grounds to consider and treat the unauthorized recipient as a “trusted recipient.” Furthermore, the Article 29 Working Party clearly indicates in its guidelines that “in case of any doubts, the data controller should report the breach, even if such caution may seem excessive.”
- A breach of insurance confidentiality should be treated as an aggravating factor and justifying a stricter assessment.
Circumstances Affecting the Penalty
As aggravating circumstances, the Authority recognized:
- the significant weight and serious nature of the breach (risk of material or non-material harm to individuals and a high probability);
- the long duration of the breach (from May to October, during which the report was made);
- the intentional nature of the breach (the company made a conscious decision not to initially notify the President of the Polish DPA, as well as the individuals whose data were affected. In the past – in cases of breaches similar or analogous to the one discussed – the company reported them to the President of the Polish DPA, and thus should have been aware that this obligation also needed to be fulfilled this time;
- the fact that the identified breach was related to the failure to implement or improper implementation by the Company of organizational and technical measures ensuring data security, i.e., the verification of email addresses provided by clients or the encryption of files containing personal data that are sent in electronic messages;
- unsatisfactory cooperation on the part of the Company;
- the broad scope of data (generating high risk);
- the manner in which the supervisory authority became aware of the breach.
Mitigating Circumstances
- The number of affected individuals (two).
- Directing a request to the wrong recipient for the permanent deletion of received correspondence. Such action by the company, in the opinion of the Polish DPA, deserves recognition and acceptance; however, it does not in any way guarantee the actual deletion of personal data by an unauthorized person and does not exclude potential negative consequences of their use for data subjects.
Is the penalty justified or unjustified?
There have been many doubts and reservations regarding the findings of the President of the Polish DPA surrounding the decision. For example, some practitioners believe that such an event is difficult to assess from the perspective of a personal data breach, as the breach did not necessarily occur "with us" as the data controller – after all, it was the client who provided the incorrect email address, and thus the breach occurred outside our organization; however, this concept is rather difficult to defend. Furthermore, the decision can be criticized for not addressing the breach of Article 32 of the GDPR (which speaks of the necessity for the organization to implement appropriate measures and techniques), even though it seems that this article should be the basis for the entire decision. Since there was no breach of Article 32 of the GDPR, can we even speak of the updating of obligations under Articles 33 and 34 of the GDPR?
FREE
What the President of the Polish DPA imposes fines for – 10 most important decisions of the Polish DPA
Watch the webinarWhy did the supervisory authority ignore the issue of the principle of data accuracy, which could be attributed to WARTA? How should the email address verification process be organized in such a case? After all, merely sending a confirmation link to an email address does not guarantee that the link will be "clicked" by an authorized person (an unauthorized recipient of such an email could just as well click on that link). Is encrypting attachments the only solution?
The decision raises many questions and provides few answers; however, it seems that the aim of the Polish DPA was to "encourage" entrepreneurs to report even seemingly trivial breaches, and if – to make matters worse – the subject of the breach were a PESEL number, it should be reported to the President of the Polish DPA almost by default.
Is this a good direction?
It is hard to say, but it seems that we are all keeping our fingers crossed for WARTA in the proceedings before the administrative court, hoping that at the stage of the complaint proceedings, at least some issues will be resolved in such a way as to maintain guarantees for the security of personal data while not burdening entrepreneurs with impossible-to-meet standards that do not necessarily contribute to enhancing the protection of the rights and freedoms of data subjects.


