Support Centre

You have out of 5 free articles left for the month

Signup for a trial to access unlimited content.

Start Trial

Continue reading on DataGuidance with:

Free Member

Limited Articles

Create an account to continue accessing select articles, resources, and guidance notes.

Free Trial

Unlimited Access

Start your free trial to access unlimited articles, resources, guidance notes, and workspaces.

Poland: UODO fines Kancelaria Pionier PLN 45,697 for processing data without a legal basis

On April 12, 2024, the Polish data protection authority (UODO) announced that the Provincial Administrative Court in Warsaw upheld the UODO's decision in Case No. DKN.5112.5.2021, as issued on November 30, 2022, in which it imposed an administrative fine of PLN 45,697 (approx. $11,192) on Kancelaria Pionier Mazurek i Bal s.c. z for violations of the General Data Protection Regulation (GDPR), following an inspection. 

Background to the UODO decision

The UODO stated it had begun an investigation after receiving information that Kancelaria Pionier, a law firm, had committed data protection violations. According to the UODO, Kancelaria Pionier contacted potential clients using information obtained from various sources, including press releases, online publications, and social media. The UODO noted that Kancelaria Pionier claimed that after meeting the potential clients, a representative of Kancelaria Pionier received oral consent to the processing of personal data including the health data of the potential clients, pending a possible conclusion of a contract with the clients. 

Findings of the UODO

The UODO found that Kancelaria Pionier obtained only oral consent but did not record it in any way and there was no clear evidence that the persons had consented to the processing of their data. Further, the UODO held that the collection of data by Kancelaria Pionier was not necessary for the performance of a contract, because the people from whom the data was obtained were not yet clients of Kancelaria Pionier. Therefore, the UODO determined that Kancelaria Pionier processed personal data, including the health data of its potential customers without legal basis, in violation of Articles 6(1) and 9(1) of the GDPR. 

Outcomes

In light of the above, the Court upheld the UODO's decision to impose an administrative fine of PLN 45,697 (approx. $11,192) on Kancelaria Pionier for the abovementioned violations of the GDPR.

You can read the press release here and the decision here, both only available in Polish.

Feedback