Publication of non-anonymised personal data in the Public Information Bulletin (BIP) led to a GDPR infringement
The President of the Personal Data Protection Office, Mirosław Wróblewski, conducted administrative proceedings concerning the disclosure of the personal data of individuals who had supported a petition that was subsequently published by the Myślenice Municipality in the Public Information Bulletin (BIP). The supervisory authority became aware of the matter following a complaint lodged by one of the individuals whose personal data had been disclosed. Following the proceedings, the President of the Personal Data Protection Office found that the data controller – the Mayor of the Myślenice Municipality – had infringed the GDPR and imposed an administrative fine of PLN 7700.
The petition, published without anonymising the personal data, contained the personal data of 749 individuals who had supported it, including their names, surnames, residential addresses and signatures. The Mayor requested that the proceedings concerning the failure to notify a personal data breach be discontinued, arguing that administrative proceedings had already been initiated following an individual complaint. The Mayor further submitted that the publication of personal data without anonymisation had resulted from an unintentional error and that the incorrect file containing personal data had subsequently been replaced with the correct version. During the proceedings, it was established that the incorrect file had remained publicly available on the Public Information Bulletin (BIP) website for several days. The controller explained, however, that it had found no evidence that any of its employees had acted intentionally or unlawfully.
The President of the Personal Data Protection Office decided to undertake investigative measures extending beyond the individual circumstances of the complaint, as the complaint indicated the possibility of deficiencies in the processing of personal data that went beyond the matters raised by the complainant. The incident that had been examined in the context of the complainant's individual rights prompted the President of the Personal Data Protection Office to examine the broader circumstances of the case that had come to the supervisory authority's attention. The unlawful conduct concerned not only an interference with the rights of the individuals concerned, but also required an assessment of the controller's compliance with its other obligations under the GDPR. Accordingly, the supervisory authority considered it justified to initiate administrative proceedings on its own initiative in order to examine the alleged infringement of the GDPR in connection with the publication in the Public Information Bulletin (BIP) of the Myślenice Municipality.
The notification of personal data breaches by controllers is an effective mechanism that contributes to improving the security of personal data processing in practice. It also enables the supervisory authority to assist in analysing the causes of an incident, identify measures to prevent similar incidents in the future, and help minimise their consequences. For this purpose, the President of the Personal Data Protection Office reviews the assessment carried out by the controller and may, where the controller has not notified the data subjects, require the controller to do so. The supervisory authority may also request the controller to provide the reasons for not notifying the personal data breach. The conclusions of the assessment should therefore be documented in the controller's internal personal data breach register, and the controller should act in accordance with the accountability principle laid down in the GDPR.
Upon becoming aware of a personal data breach, the controller is required to carry out, without undue delay, an assessment of the risk to the rights and freedoms of natural persons arising from the breach. That risk assessment should then form the basis for the controller's decision as to whether it is required to fulfil its obligations under the GDPR, including the obligation to notify the supervisory authority of the personal data breach.
Although the personal data breach in this case did not result in a high risk to the rights and freedoms of natural persons, the controller was nevertheless required to notify the President of the Personal Data Protection Office of the breach. Under the GDPR, a controller is exempt from the obligation to notify the supervisory authority only where the risk assessment demonstrates that the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. A low likelihood should be understood as a situation in which the controller, on the basis of its risk assessment, has sufficient grounds to conclude that no risk will materialise, that is, where it can genuinely be said that there is no risk. The European Data Protection Board takes the view that the exception provided for in the GDPR, under which a controller is not required to notify a personal data breach, must be interpreted narrowly. In other words, it applies only where it is clear that the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. This refers to situations in which there is no realistic possibility that such a risk will materialise or have adverse effects on the rights and freedoms of the data subjects.
In deciding to impose an administrative fine, the President of the Personal Data Protection Office took into account the fact that the controller, as a local government authority and a public body, should be expected to demonstrate a particularly high level of knowledge of the applicable legal framework. The infringement was serious, and the file containing personal data that had not been anonymised remained publicly accessible for several days.
Furthermore, the controller did not revise its position regarding its obligation to notify the personal data breach, despite being contacted by the supervisory authority in connection with the individual complaint and despite the initiation of administrative proceedings concerning the personal data breach. By the date on which the President of the Personal Data Protection Office adopted the decision, the controller had still not notified the supervisory authority of the personal data breach.
Decision in Polish: DKN.5131.17.2025