FineME
Run assessment
Back to Authorities
AggressivePL

UODO

Urząd Ochrony Danych Osobowych

Polish authority known for breach, telecom, and transparency enforcement.

Avg. Investigation

15months

Enforcement Intensity
Priority Sectors

Telecom, Finance, Public sector

Official Website

Enforcement Cases (10)

Orange Polska S.A.

technology
UODO2024

UODO fined Orange Polska after weaknesses in customer authentication and rights-handling processes exposed subscriber data, implicating GDPR Articles 12, 15 and 32.

€520,000.0

Polish Post

technology
UODO2023

UODO scrutinized processing of voter-related and citizen address data by Polish Post, emphasizing lawful basis, necessity, and accountability under GDPR Articles 5, 6 and 24.

€650,000.0

mBank S.A.

technology
UODO2022

UODO examined mBank's customer-data retention and internal access governance, identifying minimization and security shortcomings under GDPR Articles 5 and 32.

€410,000.0

P4 sp. z o.o. (Play)

technology
UODO2022

UODO sanctioned Play over inadequate customer verification and unauthorized SIM-related disclosures, citing GDPR Articles 25 and 32.

€560,000.0

Polish National School of Judiciary and Public Prosecution

technology
UODO2021

UODO imposed a fine after personal data was disclosed through an online recruitment process without adequate safeguards, contrary to GDPR Articles 5 and 32.

€23,000.0

ClickQuickNow sp. z o.o.

technology
UODO2021

UODO fined a lender for failing to notify a personal data breach promptly and for inadequate security measures, engaging GDPR Articles 33 and 34.

€470,000.0

Santander Bank Polska S.A.

technology
UODO2020

UODO reviewed Santander's retention and disclosure controls after customer data incidents and found shortcomings under GDPR Articles 5, 24 and 32.

€340,000.0

Virgin Mobile Polska

technology
UODO2020

UODO fined Virgin Mobile after inadequate authentication procedures enabled unauthorized access to customer data, implicating GDPR Articles 5 and 32.

€430,000.0

Morele.net

technology
UODO2019

UODO fined Morele.net after a major breach affecting millions of users, finding inadequate technical and organizational measures and weak authentication controls under GDPR Articles 5, 24 and 32.

€660,000.0

Bisnode Polska

technology
UODO2019

UODO sanctioned Bisnode for failing to inform millions of sole traders that their data had been obtained and processed, violating GDPR Articles 12, 13 and 14.

€220,000.0