Use of unauthorised data processing tools led to a personal data breach
Following administrative proceedings concerning an infringement of data protection legislation notified by Energa-Obrót S.A., the President of the Personal Data Protection Office, Mirosław Wróblewski, issued reprimands to the controller and the processors. In addition, the President of the Personal Data Protection Office imposed an administrative fine on one of the processors. The case concerned, among other things, the use of unauthorised communication tools by sales representatives acting on behalf of the company within its door-to-door sales network. The supervisory authority found, inter alia, that the company, in its capacity as controller, had failed to implement appropriate technical and organisational measures. Deficiencies were also identified on the part of the processors entrusted by the controller with the processing of personal data.
The case dates back to 2021, when, during the COVID-19 pandemic, sales representatives of Energa-Obrót's business partners visited customers in their homes and offered, among other things, amendments to their existing contracts. Media reports at the time raised concerns about the practices employed by those sales representatives. The lawfulness of the processing of personal data by the controller and the processors – the company and its business partners – subsequently became the subject of an assessment in the administrative proceedings initiated by the supervisory authority, the President of the Personal Data Protection Office. The proceedings were initiated following the supervisory authority's analysis of the personal data breach notification submitted by the controller.
Before submitting the personal data breach notification, employees of Energa-Obrót spoke with a former sales representative who sought the company's assistance in recovering outstanding remuneration from his former employer. During that conversation, it emerged that both the former sales representative and his colleagues had used the WhatsApp application for work-related communications. In addition to work instructions, his private mobile phone contained scanned copies and photographs of contracts concluded with the company's customers. A screenshot of the phone obtained by the controller indicated that the conversations had taken place in group chats.
The controller subsequently conducted an internal inquiry and, on the basis of its findings, assessed the incident and concluded that a personal data breach had occurred. On the same day, the controller notified the President of the Personal Data Protection Office of the personal data breach. According to the controller's findings, the breach concerned at least 15 data subjects whose personal data had been processed by employees in the course of the sales project.
The communication application, which had not been authorised by the controller, was used as a tool for the processing of personal data over a period of several months. During the controller's internal inquiry, conducted prior to submitting the personal data breach notification to the President of the Personal Data Protection Office, the controller obtained explanations from the business partner that had permitted the use of the application. According to those explanations, the application served as an auxiliary communication tool intended to facilitate communication between sales representatives during the COVID-19 pandemic, when they visited customers in person.
The business partner further explained that each employee had been authorised to process specific categories of personal data for the purpose of performing the contracts and had signed confidentiality and non-competition undertakings. In addition to the findings of its internal inquiry, the controller provided the supervisory authority with the results of a report containing an assessment of the severity of the personal data breach, indicating that communications exchanged through the application had, in part, taken place outside the European Economic Area.
The President of Personal Data Protection Office found that the controller had infringed the GDPR by failing to implement appropriate technical and organisational measures to ensure the security of the processing of personal data. The controller had also failed to verify adequately whether the processor provided sufficient guarantees to implement such measures, as required under the GDPR.
With regard to the processor that had permitted its employees to use the communication application, while failing to implement appropriate measures to ensure the security of the processing of personal data, the supervisory authority decided to issue a reprimand and impose an administrative fine of PLN 10 145. During the proceedings, the supervisory authority also identified inconsistencies between the explanations provided by the controller and those submitted by that processor, which sought to minimise its role in the processing of personal data and to shift responsibility for the identified deficiencies to other persons.
Decision in Polish: DKN.5131.7.2022