Once upon a time… at KSSiP
Unauthorized access to the KSSiP database occurred on February 21 of this year. Nevertheless, the School only learned about it on April 7… from the Police, despite the fact that in certain online services (including foreign ones) the data had reportedly been present since April 2. Statements from judges and prosecutors appearing in the media indicate that they received emails notifying them of the breach from KSSiP on Holy Saturday in the evening hours (April 11).

Let us recall that under Article 34(1) of the GDPR, 1. if a breach is likely to result in a high risk to the rights or freedoms of natural persons, the data controller is obliged to notify those persons without undue delay, which occurred in this case. The data in question that appeared online included names and surnames, phone numbers, email addresses, residential addresses, places of work and their addresses, passwords, and various messaging app numbers. Furthermore, the Director of KSSiP does not rule out that the disclosure of PESEL numbers may also be involved, although this circumstance is still being verified. The cause of the incident is most likely an inadequately conducted migration of the training platform system. An external entity, with which the School collaborated in managing server resources, was responsible for this process.
Whether an appropriate data processing agreement was concluded between the parties involved is unknown. KSSiP's communications indicate that the organization does not feel responsible for the breach that occurred; on the contrary, it currently assesses its status as that of a victim. The Director of the unit – Judge Małgorzata Manowska – stated in one of the official communications that the School is an entity that always takes all actions with due care for the protection of personal data; however, the effectiveness of these actions does not solely depend on it. Can such a position be considered justified? Considering that the National School of Judiciary and Public Prosecution, being the data controller of the disclosed personal data under the GDPR, is responsible for the selection and verification of the entities to which it entrusts data, the answer to this question must be negative. The President of the Polish DPA may impose sanctions on the School as provided for data controllers by the Regulation.
Trusted data processor?
Setting aside the above, it is worth reflecting on the current functioning of the personal data protection system at KSSiP. At first glance, it may seem that the data controller has exercised due diligence, at least in terms of controlling and auditing the IT systems and information security. Last autumn, the School commissioned a security audit of these specific areas to the Wrocław-based company Test Army Group. The purpose of the audit was to identify potential threats and irregularities, as well as the security of data processing and compliance with currently applicable regulations. This was confirmed by the company itself, although it noted that the data migration process was not subject to its review.
Regarding the server hosting provider, Director Manowska indicates that it was selected through a public tender, adding that this company also underwent an audit and was appropriately vetted before gaining access to the School's systems.
What risk?
It is indisputable that unauthorized access and unjustified disclosure of personal data constitutes a violation that ranks among the highest in terms of potential consequences threatening individuals. However, it cannot be denied that the scale of a data leak involving users of a social media platform or an online store is different from that of judges and prosecutors, who – to put it mildly – do not enjoy sympathy among often dangerous criminals. Therefore, in addition to the typical threats associated with such incidents involving the misuse of personal data, including obtaining loans from non-bank institutions, gaining access to health data, entering into civil law contracts, or creating accounts on social media – the breach that has occurred may pose a real danger to the health and life not only of the mentioned lawyers but also of their loved ones.
Suspect detained
A man suspected of directly contributing to the data leak has been detained. He may face charges of providing data that enables unauthorized access to information stored in the IT system of the National School of Judiciary and Public Prosecution in Kraków, an act punishable by imprisonment for a term of 3 months to 5 years. The Prosecutor's Office does not rule out the detention of additional suspects.
IT Security Unduly Overlooked
The experiences of many consulting firms in the IT sector clearly indicate that in the process of implementing, maintaining, and developing IT systems, the topic of broadly understood IT security is still neglected or even completely overlooked. In times when increasingly newer and more stringent regulations regarding information protection are being introduced, can organizations afford to overlook information security? Information, which is an asset, one of the most important among all assets, and undoubtedly essential for conducting business. A data leak or the unavailability of a system providing critical services for business, regardless of the form, will always contribute to serious problems within the organization, and even to the bankruptcy of the company. Therefore, it is extremely important to ensure an appropriately high level of security, which will result from a risk analysis related to the system being built or developed and the likelihood of its realization.
How to Minimize the Risk of Data Loss?
Every risk can be quantified; it has a value that an organization prioritizing security should take into account in its operations. In practice, this means that the cost of risk management and potential losses in the event of its realization should be compared with the financial capabilities of the organization, and depending on the outcome, a dedicated strategy should be developed.
The factors that define secure systems are:
- availability,
- integrity,
- confidentiality,
- accountability and non-repudiation.
Free knowledge about GDPR.
Use it freely!
Let us assume that internal information security management systems will not give the organization certainty that the assets held will have a high level of security – they cannot predict the intentions of the provider delivering services, e.g., system migration, especially during a test migration. Analyzing the case of the recent migration in KSSIP, we would conclude that a properly maintained and continuously developed information security system would have significantly increased the chances of minimizing the risk of an undesirable and unplanned event occurring during this process. Here are a few actions to minimize the risk of leakage:
- data processed in the migrated application could be anonymized,
- the test migration would not take place using production data,
- the migration process would occur in an environment without Internet access,
- the migration process would be thoroughly analyzed in the change management system and then executed step by step under the supervision of a KSSIP employee.
Perhaps mere awareness of what data is processed in the migrated system would suffice to exclude it from the scope assigned to an external company. The fact that the provider "held the highest security certificates," as was the case with KSSIP, proves that transferring risk to another entity is not a correct action for improperly identified risks.
As long as the information security standards developed over the years remain standards only on paper and are not taken into account in the construction and development of IT systems, we will continue to witness increasingly spectacular data breaches, the consequences of which are difficult to predict.


