As the document consists of nearly 250 pages, we have gathered the most important and interesting information to provide a better understanding of the realities associated with overseeing the personal data protection system in the country.
To begin with, we present a brief numerical summary comparing data from 2018 and 2019, to better illustrate what occurred in the "GDPR year" and in the following year, when we had all become accustomed to applying the regulation.
It is worth noting the significant increase in both the number of complaints filed and the administrative decisions issued.
2018
|
2019
| |
|
|
235 |
246 |
Expenditures of the Polish DPA | 25,681,000 PLN | 31,390,000 PLN |
Complaints from data subjects | 5,565 | 9,304 |
Number of inspections conducted | 72 | 98 |
Issued administrative decisions | 527 | 1,369 |
Financial penalties | 0 | 8 |
Court complaints against decisions or rulings issued by the Polish DPA | 77 | 89 |
Reported breaches | 2,446 | 6,039 |
Complaints from data subjects
Although the complaints received in 2019 concerned various aspects of data processing, the supervisory authority points out the most frequently raised issues:

Acquisition, in connection with conducted activities, of personal data without a legal basis, or to a broader extent than provided for by law, including issues related to:
- the legality of processing personal data of debtors in databases of debtors who have not fulfilled their obligations to the bank, as in order for the processing of such a person's data to be possible based on the relevant provision of banking law, it is necessary to inform them of the intention to process their data without their consent, whereas banks usually do not have proof of delivery to the person concerned of the indicated information, presenting in proceedings before the Polish DPA prints from internal systems intended to indicate the circumstance of directing the aforementioned information to individuals, which evidence is not considered sufficient by the Polish DPA;
- the legality of processing by banks the personal data of prospective clients, also in the credit information system (in BIK), when following the submission of a credit application, no contract was concluded with the bank. Banks, despite receiving requests for the deletion of personal data, considered that there were no grounds for fulfilling the above, as entries were made with the consent of the clients. The President of the Polish DPA disagreed with this, ordering the deletion of personal data of prospective borrowers, as neither banks nor BIK have legal grounds for processing the above data in the context of credit inquiries and for processing them by BIK after verifying creditworthiness;
- acquiring an excessive scope of personal data, inadequate to needs, often in excess, including data concerning health in the case of insurers;
- processing personal data for the purpose of issuing motor third-party liability insurance policies, as a continuation after the expiration of the policy and the lack of its termination, and after the change of vehicle ownership.
Transferring data to debt collection companies and to BIK without a legal basis or in a manner that is not transparent to the individuals concerned.
- Debtors most frequently challenged the legitimacy of the claim, citing the lack of their consent to the processing of personal data by the creditor and expressing a request for the deletion of their data, which they believed was processed without a legal basis. Another important factor influencing the number of complaints in this group was the debtors' questioning of the legality of the assignment of receivables without their consent. Complaints also repeatedly questioned the legality of entrusting the personal data of debtors to third parties by securitization funds or other creditors for the purpose of pursuing claims. The decisions issued by the authority, in the vast majority of cases, amounted to a refusal to consider the complainants' requests due to the existence of a legal basis for data processing.
Data processing through monitoring installed in educational institutions, housing cooperatives, or by owners of single-family homes.
- Complainants mainly raised that their image was processed unlawfully, as the monitoring covered neighboring properties and public places, e.g., public roads, sidewalks, common areas of buildings, etc. Complainants did not consent to the installation of monitoring by the owners of neighboring properties, the information obligation was not fulfilled towards them, and their right to access the recordings was also not realized.
Disclosure or loss of personal data by, among others, Poczta Polska and courier companies, in the course of their activities.
- Complaints predominantly concern the issue of the disclosure of personal data contained in shipments by delivering them to unauthorized persons (including leaving them at the reception desk or with the security of the estate, or failing to deliver correspondence to the mailbox).
Use of data for marketing purposes.
- Complaints concerned overly broad consents for the processing of personal data;
- A serious problem was also that data controllers, using personal data databases provided by “information brokers,” did not provide complete information about contact details (such as name, address, and registered office) when calling individuals. Telemarketers did not give clear answers or did not respond to questions related to data processing processes, informational obligations, or even ended the phone call when these issues were raised. Often, data controllers did not record objections to the processing of personal data for marketing purposes, nor did they comply with requests for data deletion.
Sharing personal data with unauthorized persons and entities.
- Challenging the transfer of personal data of complainants between insurers and entities cooperating with them, particularly with healthcare institutions, entities involved in the assessment and settlement of claims, and intermediaries,
- In 2019, there was a strong trend of complaints regarding the sharing of personal data of children and their parents by healthcare entities conducting vaccinations for public health inspection authorities - the processing of personal data for the purpose of enforcing vaccination obligations is based on applicable regulations.
Failure to fulfill informational obligations under Articles 13 and 14 of the GDPR.
- Failure to meet informational obligations in telemarketing - particularly when the data was not obtained from the individual concerned, but from another source (the sources of personal data used for telemarketing purposes are often the aforementioned “information brokers,” who obtained personal data using available public sources);
Lack of response from the data controller to the request of the data subject - most often related to requests made under Articles 15 (right of access), 16 (right to rectification), 17 (right to erasure), or 21 (right to object) of the GDPR.
- It is worth noting that, for example, the right to be forgotten could not be respected in relation to entries made in state registers or collections maintained under legal provisions - from the assessment of complaints received by the Polish Data Protection Authority in 2019, it appears that in most cases, the requests of complainants boil down to questioning the applicable legal provisions;
- The most frequently cited purpose in requests for the provision of personal data (the failure to fulfill which resulted in complaints) was the necessity to obtain data about a person in order to file a lawsuit against an individual who violated the personal rights of the requester. The authority's task was to determine whether the data controller responded to the entire request of the party and whether they did not violate legal provisions. For the authority, the mere intention to file a lawsuit in a common court against the person to whom the data pertains was not sufficient;
- The Polish DPA also received complaints regarding employers' handling of employees' requests for the right to obtain copies of personal data contained in the personnel files maintained by employers;
- Complainants often confuse the request for the provision of copies of their data with the obligation to issue documents containing their personal data;
- Numerous requests were made for the provision of recordings from video surveillance conducted in entities such as stores and shopping centers, as well as requests for the provision of recordings from call centers in order to submit an effective complaint and prove circumstances related to, for example, the purchase of specific products with manufacturing defects, or improper execution of instructions given by the account holder over the phone by a bank employee regarding the client's bank account;
- There was significant interest in the "right to be forgotten" in the context of debt collection proceedings conducted via websites, as well as in relation to data published in the Google search engine.
Conducted Inspections
Most of the control activities focused on examining the ways in which data controllers ensure the confidentiality of data and whether they do not use the data for purposes other than those for which it was collected. The scope of the conducted inspections included, among others, the following issues:
- The legal basis for processing personal data; the source of obtaining personal data; the scope, purpose, and type of processed personal data;
- The manner of fulfilling the information obligations of the data controller;
- The manner of ensuring the realization of the rights of the individuals to whom the data pertains;
- the method of collecting and sharing personal data;
- whether appropriate technical and organizational measures have been implemented to ensure that the processing of personal data is carried out in accordance with the GDPR and taking into account the nature, scope, context, purposes of processing, and the risk of infringement of the rights and freedoms of natural persons, as well as whether these measures are reviewed and updated as necessary;
- whether data protection policies have been implemented;
- whether a Data Protection Officer (DPO) has been appointed;
- whether the data controller entrusts the processing of data to data processors, and if so, whether this entrustment has occurred under the conditions specified in Article 28 of the GDPR;
- whether actions have been taken to ensure that any natural person acting on behalf of the data controller who has access to personal data processes it on the instructions of the data controller;
- whether a Data Protection Impact Assessment (DPIA) has been conducted in connection with the introduction of a remote reading system for water meters;
- whether all personal data breaches are documented, including the circumstances of the personal data breach, its consequences, and the remedial actions taken;
- whether a records of processing activities is maintained, containing all the information specified in Article 30(1) of the GDPR;
- the control of IT systems used for processing personal data.
From the start of the application of the GDPR provisions, i.e., from May 25, 2018, to December 31, 2019, 31 inspections were conducted in private sector entities, of which in 2019 inspections took place in 20 entities. In the case of 4 entities, no violations of personal data protection regulations were found as a result of the inspections. In 14 cases, proceedings were ongoing, with decisions issued in the case of two entities, which were appealed to the court.
Issued administrative decisions, including financial penalties
The issued decisions can be reviewed at https://archiwum.uodo.gov.pl/pl/p/decyzje, which we highly encourage. The decisions are published in chronological order, and there is also the possibility of filtering them based on the issues addressed or the industry they pertain to.
In 2019, the Polish DPA decided to impose an administrative monetary penalty in 8 cases. The following entities were subject to penalties: a company conducting online sales, a company processing data from public registers, a housing community, a company engaged in property and personal protection, a sports association, a property management company, the mayor of a city, and a company conducting online marketing.
Notification of Suspected Criminal Offense
Receive a package of free GDPR guides and micro-trainings
In another case, the Polish DPA reported a suspicion of a crime involving one of the entities obstructing the Polish DPA's ability to conduct control activities. Another notification concerned the suspicion of a crime defined in Article 276 of the Penal Code, involving the destruction (damaging, rendering useless, concealing, or removing) of a document that the perpetrator has no right to dispose of exclusively (the liquidated company abandoned its documentation).
Complaints to the Court Against Decisions or Resolutions Issued by the Polish DPA
In 2019, 89 complaints were filed with the Provincial Administrative Court in Warsaw (the court competent due to the seat of the Polish DPA) against decisions or resolutions of the President of the Polish DPA, of which:
- 23 complaints concerned the private sector,
- 14 complaints concerned the public sector,
- 35 complaints concerned decisions issued against entities responsible for public safety and the prosecution of offenders,
- 3 complaints concerned decisions refusing to disclose public information,
- 14 complaints concerned the actions of the authority at the stage of preliminary assessment of complaints.
Reported Breaches
In 2019, the Authority analyzed 6039 reports of breaches, including an assessment of the occurrence of a high risk to the rights or freedoms of natural persons, of which 3894 were reported by entities in the private sector. In the private sector, the highest number of reports came from entities: telecommunications (1433), insurance (638), banks and financial entities (527), and healthcare (206).
Conclusions
The relatively small number of inspections conducted (and fines imposed) may have two causes: insufficient human resources of the Authority or – despite the submission of 9304 complaints and 6039 reported breaches – the low number of cases where the Authority actually saw grounds for initiating an inspection, which should give data controllers (as well as data processors) optimism.


