The first fine for a public entity for violating the GDPR

07 November 2019

The maximum administrative fines under the GDPR amount to up to €20 million, and in the case of an enterprise – up to 4% of the total annual worldwide turnover, with the higher amount applicable. Each member state could reduce administrative fines for the public sector, which the Polish legislator has taken advantage of.

According to Article 102 of the Personal Data Protection Act, the President of the Polish DPA may impose a fine of up to PLN 100,000 on entities in the public finance sector (as defined in Article 9 of the Public Finance Act), as well as research institutes and the National Bank of Poland.

GDPR Bulletin
Receive a package of free GDPR guides and micro-training sessions
Join the ranks of our newsletter readers, receive a free package, and stay informed.
RECEIVE PACKAGE
On October 18, 2019, the President of the Polish DPA issued an administrative decision following an administrative procedure regarding the processing of personal data by the Mayor of Aleksandrów Kujawski. The procedure was preceded by an audit of the compliance of personal data processing with the provisions of personal data protection law.

The scope of the audit included the manner of processing personal data by the Mayor of Aleksandrów Kujawski in the context of the correspondence mailing process and the operation of the Public Information Bulletin of the Municipal Office in Aleksandrów Kujawski (BIP), as well as the manner of maintaining records of processing activities and documenting personal data breaches.

Template of a data processing agreement compliant with GDPR
This will allow for the regulation of key issues within the relationship between the data controller and the data processor.
Download  

According to the above decision, the President of the Polish DPA imposed an administrative monetary penalty of PLN 40,000 on the Mayor of Aleksandrów Kujawski for violating the provisions of the GDPR. Considering the maximum penalty level for entities in the public finance sector – PLN 100,000 – this penalty should be regarded as high.

In the decision, the President of the Polish DPA stated that the Mayor of Aleksandrów Kujawski violated a number of provisions, namely:

  • Article 5(1)(a) and (f) in conjunction with Article 5(2) GDPR, i.e., the principles of lawfulness and confidentiality, as well as Article 28(3) GDPR by providing personal data without a legal basis to the entity on whose servers the resources of the Public Information Bulletin (BIP) were located, and to the entity that provided the software for creating the BIP and handled service maintenance in this regard, namely without prior conclusion of a data processing agreement with these entities, as referred to in Article 28(3) GDPR,
  • Article 5(1)(e) in conjunction with Article 5(2) GDPR, i.e., the principle of storage limitation, and Article 24 GDPR due to the lack of appropriate policies regarding the processing of personal data in the BIP concerning their relevance and purpose of publication, as well as defining the deadlines for the deletion of personal data,
  • Article 5(1)(f) in conjunction with Article 5(2) GDPR, i.e., the principles of integrity and confidentiality and the principle of accuracy, as well as Article 24 GDPR by failing to conduct a risk analysis related to the Mayor's use of the YouTube channel for broadcasting recordings of City Council meetings,

    Polish DPA Control - for us, it's routine!

  • Article 5(1)(f) in conjunction with Article 5(2) GDPR, i.e., the principles of integrity and confidentiality, and Article 32 GDPR by not implementing appropriate technical and organizational measures aimed at securing the personal data of individuals in connection with the storage of recordings of City Council sessions solely on YouTube servers, without creating and storing backup copies of these recordings in the resources of the Municipal Office,
  • Article 5(2) GDPR, i.e., the principle of accountability, as well as Article 30(1)(d) and (f) GDPR for failing to indicate in the records of processing activities the recipients of personal data for activities related to the publication of information on the BIP website, and for not specifying the planned date for the deletion of data for these processing activities in a manner that ensures data processing in accordance with the principle of storage limitation.
READ MORE: Data Processing Agreements

In the justification of the decision regarding the financial administrative penalty, the President of the Polish DPA stated that there are no circumstances that could mitigate the amount of the penalty, as the Mayor, i.e., the data controller, among other things, did not cooperate with the supervisory authority.

It should be noted that the public sector is obliged to comply with personal data protection regulations. Regulations concerning personal data protection include not only the GDPR but also sector-specific regulations. The public sector must also meet new standards for personal data protection. In these challenges, data controllers should be actively supported by Data Protection Officers (DPOs) – who are appointed mandatorily. Data controllers should also provide, among other things, the resources necessary to maintain the expertise of the DPO.

Personal data protection is also the protection of our privacy. Let us not forget that personal data is the gold of the 21st century.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.