Personal data breach must be notified without undue delay — fine for the housing community
Following an investigation, the President of the Personal Data Protection Office, Mirosław Wróblewski found a infringement of the GDPR and imposed an administrative fine of PLN 5000 on the housing community for failing to report the personal data breach without undue delay, no later than 72 hours after the breach was detected.
The personal data breach occurred through the disclosure of personal data —controller provided an unauthorized person with a “notice of settlement of fees for the use of residential premises.” It contained the following information:
• the name and surname of the community member,
• the address of the community member,
• the apartment number to which the fee settlement relates,
• the amounts related to the settlement of fees for the use of the apartment,
• meter numbers and meter readings,
• the bank account number for payments.
The improper disclosure of a housing community member’s personal data occurred in connection with the company’s performance of a property management agreement entered into with the housing community. Consequently, the President of the Personal Data Protection Office first summoned the company and requested an explanation to determine whether a risk assessment regarding the risk to the rights and freedoms of natural persons had been conducted. The company explained that, in its assessment, no personal data breach had occurred because both individuals listed “on the document are owners of the property comprising the community; thus, pursuant to the Polish Act on Ownership of Premises, they acquire the right to inspect all documents issued by the community.”
The President of the Personal Data Protection Office then requested an explanation from the data controller, the housing community. In response, the controller indicated that it had not notified the President of the Personal Data Protection Office of the breach because the improperly disclosed “notice of settlement of fees for the use of residential premises” contained “so-called ordinary data, and the breach concerned a single member of the community.”
Following an administrative proceeding, the President of the Personal Data Protection Office determined that, in this case, personal data had been disclosed without justification to an unauthorized person, thereby constituting a breach of personal data protection. The provisions of the Polish Act on Ownership of Premises do not in any way authorize the arbitrary disclosure of personal data of members of a housing community. This is all the more true when it is done against their will—as in the case in question—when they receive misdirected correspondence containing the personal data of another member of the community.
• Article 33(1) and (3) of the GDPR stipulates that in the event of a personal data breach, the data controller must notify the supervisory authority. The controller is also required to act without undue delay—where feasible, no later than 72 hours after the breach is detected—unless it is unlikely that the breach will result in a violation of the rights or freedoms of the data subjects.
• “Unlikely” should be understood as a situation where the circumstances indicate that violation of the rights or freedoms of data subjects will not occur at all. The Polish translation of the GDPR uses the phrase “mało prawdopodobne,” while the English version uses “unlikely.” This term carries a stronger meaning than its Polish equivalent and is used to describe something that is rather improbable, doubtful, or nearly impossible.
• It is worth emphasizing that the potential consequences of an event do not necessarily have to materialize. Article 33(1) of the GDPR states that the mere occurrence of a personal data breach involving a risk to the rights or freedoms of natural persons entails an obligation to notify the competent supervisory authority of the breach.
The reporting of personal data breaches by data controllers is an effective tool that contributes to improving the security of personal data processing. When reporting a breach, controllers inform the President of the Personal Data Protection Office whether, in their assessment, there was a high risk of a breach of the rights or freedoms of data subjects and—if such a risk existed—whether they have provided the relevant information to the individuals affected by the breach.
Reporting breaches allows the supervisory authority to respond appropriately to mitigate their effects, as the controller is obligated to take effective measures to ensure the protection of individuals and their personal data. On the one hand, this allows for monitoring the effectiveness of existing solutions, and on the other, for evaluating modifications and improvements aimed at preventing similar irregularities in the future.
In this case, the person to whom the personal data of another member of the housing community was disclosed did not request that the data be provided to them at all. The supervisory authority found that the disclosure was unrelated to the purposes specified in the Polish Act on Ownership of Premises.
It is unacceptable to disregard the obligation to conduct a thorough assessment of the risk to the rights and freedoms of natural persons simply because the breach concerned a single individual. The controller’s failure to comply with the obligation to report a personal data breach, as it is not supported by the GDPR and is contrary to the fundamental objectives of the GDPR, namely the protection of the fundamental rights and freedoms of natural persons, and in particular their right to the protection of personal data.
Decision in Polish: DKN.5131.16.2025