As the most frequently reported and typical violations in 2021, the President of the Polish DPA indicated in his report:
- Incorrect addressing or packaging of correspondence (in traditional or electronic form) – as a consequence of these violations, personal data was disclosed to unauthorized persons. These violations most often occurred due to employee errors of the data controller. The source of the violation also included mistakes made at the stage of collecting address data, when intended recipients of the correspondence provided the controllers with incorrect addresses. The disclosure of personal data to improper recipients often occurred as a result of sending mass electronic correspondence without hiding the email addresses of other individuals (UDW).
- Incorrect anonymization of data or unintentional publication – in the public sector, such violations occurred, among others, in the Public Information Bulletin and official journals.
- Disclosure of data to the wrong person – such violations occurred, among other things, as a result of issuing documents (e.g., certificates and tax declarations) to individuals without the right to receive them or erroneous accounting of transfers.
- Loss of correspondence by the postal operator or opening of correspondence before returning it to the sender – during the global pandemic, such violations also occurred as a result of storing correspondence "in quarantine," which made it impossible to file a complaint with the postal operator in a timely manner and effectively determine at what stage of the correspondence flow the opening or destruction occurred.
- Unauthorized access to databases – these violations occurred due to software errors revealed after updates, lack of regular security tests to detect system vulnerabilities, and improper granting of permissions.
- Loss, theft, or leaving paper documentation in an unsecured location – such violations mostly occurred due to employee negligence and were generally characterized as one-time incidents. There were also cases of leaving documents in publicly accessible locations to mitigate epidemiological threats. This refers to the practice of placing makeshift, unsecured containers serving as drop boxes for submitting documents containing personal data.
- Loss or theft of data carriers – such breaches occurred as a result of the loss of data carriers such as laptops or USB drives, which often remained unencrypted at the time of the incident.
- Use of malicious software interfering with the confidentiality, integrity, or availability of personal data – such breaches occurred due to the exploitation of vulnerabilities and the bypassing of security measures. In many cases, system vulnerabilities were caused by the data controller's failure to update the software.
A handful of statistics:
In 2021, the Polish DPA received 12,946 reports of breaches, with the highest number of reports from entities in the private sector being:
- telecommunications – 1,890,
- insurance – 1,929,
- banks and financial entities – 1,113,
- and the private healthcare sector – 257.

