Jurisdictional Intelligence · PL
Poland
High-visibility enforcement in telecoms, public registries, and cybersecurity incidents.
Total Fines Tracked
€4.3M
EUR equivalent
Average Fine
€428.3K
per enforcement action
Top Sector
telecoms
most-fined industry
Authorities
—
active regulators
Regulators
Authorities
No authority data yet.
Enforcement
Landmark Cases
Orange Polska S.A.
technologyUODO fined Orange Polska after weaknesses in customer authentication and rights-handling processes exposed subscriber data, implicating GDPR Articles 12, 15 and 32.
€520,000.0
Polish Post
technologyUODO scrutinized processing of voter-related and citizen address data by Polish Post, emphasizing lawful basis, necessity, and accountability under GDPR Articles 5, 6 and 24.
€650,000.0
mBank S.A.
technologyUODO examined mBank's customer-data retention and internal access governance, identifying minimization and security shortcomings under GDPR Articles 5 and 32.
€410,000.0
P4 sp. z o.o. (Play)
technologyUODO sanctioned Play over inadequate customer verification and unauthorized SIM-related disclosures, citing GDPR Articles 25 and 32.
€560,000.0
Polish National School of Judiciary and Public Prosecution
technologyUODO imposed a fine after personal data was disclosed through an online recruitment process without adequate safeguards, contrary to GDPR Articles 5 and 32.
€23,000.0
ClickQuickNow sp. z o.o.
technologyUODO fined a lender for failing to notify a personal data breach promptly and for inadequate security measures, engaging GDPR Articles 33 and 34.
€470,000.0
Santander Bank Polska S.A.
technologyUODO reviewed Santander's retention and disclosure controls after customer data incidents and found shortcomings under GDPR Articles 5, 24 and 32.
€340,000.0
Virgin Mobile Polska
technologyUODO fined Virgin Mobile after inadequate authentication procedures enabled unauthorized access to customer data, implicating GDPR Articles 5 and 32.
€430,000.0
Morele.net
technologyUODO fined Morele.net after a major breach affecting millions of users, finding inadequate technical and organizational measures and weak authentication controls under GDPR Articles 5, 24 and 32.
€660,000.0
Bisnode Polska
technologyUODO sanctioned Bisnode for failing to inform millions of sole traders that their data had been obtained and processed, violating GDPR Articles 12, 13 and 14.
€220,000.0
Legal Framework
Regulations by Domain
Marketplace