Administrative fine imposed on the Minister of Justice for disclosing judges' personal data
Following administrative proceedings concerning the case widely referred to in the media as the 2019 "hate campaign" scandal, the President of the Personal Data Protection Office, Mirosław Wróblewski, imposed an administrative fine of PLN 100 000 on the Minister of Justice. The personal data of judges were obtained by individuals who subsequently determined the purposes and means of the processing without, or beyond the scope of, the authorisation granted by the controller. The investigation established that the Minister of Justice had failed to implement appropriate technical and organisational measures to prevent the unlawful processing of personal data obtained from the Ministry's human resources records. The controller also failed to exercise appropriate oversight over the authorisations granted to employees, who used the personal data obtained unlawfully for political and private purposes.
The infringement of the rules governing the processing of personal data within the Ministry of Justice was first reported by online media outlets. In August 2019, three investigative articles were published on what subsequently became known as the "hate campaign" scandal. The articles described a scheme involving the acquisition of information about judges who had expressed criticism of the reforms being pursued within the justice system. As a result of the unlawful processing of personal data by the individuals involved, content insulting and discrediting those judges was disseminated to the public. Consequently, the judges became the targets of defamatory attacks.
The administrative proceedings were initiated by the supervisory authority in 2019, immediately after it became aware of the media reports. In response to the supervisory authority's request for explanations, the then Minister of Justice stated that the internal inquiry had not established the occurrence of an incident involving a personal data breach. The public prosecutor's office subsequently initiated criminal proceedings concerning allegations that public officials had exceeded their powers. For several years, the President of the Personal Data Protection Office unsuccessfully sought to obtain information on the specific findings of those proceedings. The investigation was conducted successively by the Public Prosecutor's Offices in Lublin and Świdnica, both of which informed the President of the Personal Data Protection Office that, in the interests of the criminal investigation, they were unable to disclose further information regarding their findings.
Findings of the Public Prosecutor's Office
It was not until December 2024 that the Regional Public Prosecutor's Office in Wrocław provided the President of the Personal Data Protection Office with the evidence gathered during the preparatory proceedings. The evidence proved sufficient for the supervisory authority to adopt an administrative decision. The information provided confirmed that the personal data of judges had been subject to unlawful processing by public officials.
The analysis of the evidence demonstrated that the infringement resulted primarily from the controller's failure to implement appropriate technical and organisational measures. In accordance with the GDPR, the supervisory authority was competent to assess the lawfulness of the processing of personal data only in respect of events occurring on or after 25 May 2018. However, prior to that date, the controller had already taken actions that subsequently gave rise to processing operations carried out after the GDPR became applicable.
The evidence provided by the Public Prosecutor's Office enabled the President of the Personal Data Protection Office to establish a detailed account of the irregularities that occurred in connection with the so-called "hate campaign" scandal. The unlawful conduct of the public officials included, among other things, using their authorised access to confidential personnel files of judges to obtain personal data, which they subsequently processed for personal and political purposes. The personal data of judges were also disclosed to unauthorised recipients, including other public officials and journalists. Sensitive information was further unlawfully disclosed online, on Twitter (now X), through an account created using an IP address from the range assigned to the Ministry of Justice.
Findings of the President of the Personal Data Protection Office
The President of the Personal Data Protection Office emphasised that the supervisory authority's decision does not preclude the legal liability of the individuals who unlawfully disclosed the personal data of judges to unauthorised recipients. Accordingly, the administrative proceedings conducted by the supervisory authority focused primarily on whether the controller – the Minister of Justice – had ensured an appropriate level of security for the processing of personal data.
Under the GDPR, the controller is required to implement appropriate technical and organisational measures and to ensure that the processing of personal data is carried out in accordance with the GDPR. In addition, both the controller and the processor are required to take measures to ensure that any person acting under their authority who has access to personal data processes those data only on instructions from the controller, unless required to do so by Union or Member State law. As established in the administrative proceedings, a number of deficiencies were identified in the present case.
The evidence gathered in the course of the proceedings established that personal data had been processed for the purpose of targeting judges who had expressed opposition to the judicial reforms introduced by the government at the time. It was established that the processing activities were unlawful, as the individuals responsible processed the personal data beyond the scope of the authorisation originally granted to them. However, this does not relieve the controller – the Minister of Justice – of responsibility. The controller remains responsible for the subsequent processing of personal data carried out by persons acting under its authority. The controller must exercise effective control over the processing of personal data in order to prevent personal data from being disclosed to unauthorised recipients (see the judgment of the Supreme Administrative Court of 4 April 2003, case no. II SA 2935/02). Furthermore, in its judgment of 5 December 2023 in Case C-683/21, the Court of Justice of the European Union held that the controller is responsible not only for any processing of personal data that it carries out itself, but also for processing carried out on its behalf.
The controller's failures resulted in a number of infringements of the GDPR. It should also be emphasised that the unlawful processing concerned special categories of personal data, including data relating to the judges' health, political opinions and membership of organisations.
Administrative Fine
The controller's infringements of the GDPR were of a serious nature, as they affected the fundamental principles governing the processing of personal data. Those principles are of fundamental importance within the data protection framework established by the GDPR. In the present case, the deficiencies in the processing of personal data consisted in the controller's failure to exercise appropriate oversight over the use of the authorisations granted, in order to ensure that personal data were processed only for the purposes and within the scope specified in those authorisations.
As an aggravating factor, the President of the Personal Data Protection Office took into account the fact that the infringements of the GDPR were committed by a constitutional authority of the Republic of Poland, namely the Minister of Justice. As a public authority, the Minister of Justice also performs the functions of the Prosecutor General and is responsible for a broad range of public affairs. The Minister of Justice should be expected not only to possess a particularly high level of legal expertise, but also to uphold the rule of law and to provide assurance that the rights and freedoms of individuals are respected. The seriousness of the conduct attributed to the Minister of Justice is further aggravated by the fact that, in view of the functions entrusted to that authority, it should act with due regard for, and in the interests of, members of the judiciary.
The controller did not cooperate to a significant extent in establishing the facts of the case. At an early stage of the preliminary inquiry in 2019, the Minister of Justice informed the supervisory authority that no personal data breach had occurred in relation to the personal data under its control. This statement was subsequently contradicted by the findings of the Public Prosecutor's Office. The controller's conduct at the initial stage of the proceedings hindered the President of the Personal Data Protection Office (UODO) in conducting a thorough and efficient investigation.
In the opinion of the President of the Personal Data Protection Office, the imposition of an administrative fine in the present case was unavoidable. The supervisory authority considered that only an administrative fine would ensure effective compliance with the GDPR.
Under the GDPR, an administrative fine may be imposed only on the controller, and not on persons acting under the authority of the controller who are authorised to process personal data, even where they have exceeded their authorisation or otherwise failed to comply with their obligations. The controller on whom the fine has been imposed may, however, seek to establish the legal liability of such persons under other applicable provisions of law, including, for example, labour law or civil law, and may pursue, where appropriate, disciplinary or compensatory (recourse) claims against them.
Decision in Polish: ZSPU.440.1111.2019