In a recent decision issued by the President of the Personal Data Protection Office (UODO), a company was fined just over PLN 943,000 (EUR 220,058). What is more, it was ordered to fulfill its obligation to provide information on processing personal data to several million people.
The company in question processed data subjects’ information accessible from publicly available sources, including the Central Registry and Information on Business Activity (CEIDG), register of entrepreneurs of the National Court Register (KRS) and the REGON database of the Central Statistical Office. The company sold the data described as part of its business activity.
It failed to directly inform the data subjects for whom it did not have an email address about processing their personal data, citing the high operational cost of doing so. Instead it provided information on processing personal data on its website. Over 6 million individuals were not directly informed processing their personal data. Of the 90,000 who were informed, over 12,000 objected to processing their personal data.
The UODO held that the website notice was insufficient to meet the company’s GDPR obligations. In view of this decision, the following specific issues must be taken into consideration:
We absolutely recommend that organisations revise procedures for providing data subjects with information on processing personal data. It is vital for the data controller to be able to prove during an audit that the disclosure requirement has indeed been fulfilled.
We recommend utmost care in the case of large-scale data processing involving the creation of databases of job candidates towards whom information disclosure requirements have not been fulfilled.
Should you be contacted by the UODO, it is necessary not only to cooperate with the data protection authority by responding to inquiries immediately, but when the supervisory authority investigates an area where there is a risk of fines, remedial action must also be taken immediately to address all issues that were noted.