The turn of August and September 2026 brought several important decisions and announcements regarding personal data protection. The Supreme Administrative Court's ruling on the disclosure of PESEL numbers, the UODO's position on the MyDr incident, and the fine for a lack of independence for a data protection officer demonstrate the types of errors that can expose an organization to liability. For entrepreneurs, medical facilities, and property managers, the common conclusion is practical: it's important to be able to demonstrate who assessed the breach, the basis for their decision, and whether they did so in a timely manner. In this edition of the Compliance series, we discuss selected events from August and September and the resulting recommendations.
What are the results of the Supreme Administrative Court's judgment regarding the disclosure of the PESEL number?
The controller should support the decision not to report a breach with a specific risk analysis. Simply recording the incident in the log is not sufficient to justify such a decision.
On August 26, 2026, the Supreme Administrative Court issued a judgment in case III OSK 251/24. According to the UODO's announcement of August 28, the SAC overturned the housing cooperative's favorable judgment of the Provincial Administrative Court and dismissed its appeal against the authority's decision. As a result, the nearly PLN 52,000 fine for failure to report a breach and failure to notify the data subject was upheld. The case involved the disclosure of a copy of a notification of a suspected crime, containing the data of a cooperative member. UODO announcement on the SAC's judgment.
In the circumstances described, the Supreme Administrative Court accepted the assessment that disclosing the first name, last name, address, and PESEL number posed a high risk of violating the rights or freedoms of that individual. It also confirmed the cooperative's status as an entrepreneur for the purposes of Article 83(4) of the GDPR. The judgment is a final and binding decision in a specific case, and its significance for other controllers lies primarily in its guidance on how to assess similar violations. Discussion of the decision by the Personal Data Protection Office.
In practice, combining a persistent identifier like the PESEL (Personal Identification Number) with data that allows for easy identification of identity and place of residence requires special attention. The assessment should consider, among other things, the scope of disclosure, data recipients, security measures employed, and possible consequences for individuals. The lack of information about data use does not necessarily mean a lack of risk. Risk is also assessed through the lens of possible future consequences.
Therefore, we recommend that the breach assessment form require the inclusion of facts supporting the assumed risk level. The "low risk" field should be justified, allowing for the assessment's reasoning to be reconstructed.
When should you report a breach and notify data subjects?
Reporting to the President of the Personal Data Protection Office (UODO) and notifying the individual are two separate obligations, triggered by different risk levels. The distinction is based on Articles 33 and 34 of the GDPR.
| Duty | When is it created? | Deadline |
| Documenting the violation | In every case of data protection breach, even if not reported to the authority | Ongoing – documentation should reflect the course of the event and the actions taken |
| Reporting to the President of the Personal Data Protection Office | It does not arise if the infringement is unlikely to result in a risk to the rights or freedoms of individuals | Without undue delay, and if possible no later than 72 hours after the infringement has been discovered |
| Notification of a person | When the breach is likely to result in a high risk, taking into account the exceptions in Article 34(3) GDPR | Without further delay |
Source: GDPR, in particular Articles 33–34.
The 72-hour deadline applies to reporting to the authority. It does not constitute a separate statutory deadline for notifying an individual or a basis for postponing action until the last hour. If complete information cannot be provided at once, Article 33(4) allows for it to be completed successively, without undue delay. Reports submitted after 72 hours require an explanation of the reasons for the delay.
The assessment should be developed on an ongoing basis and take into account information available at the time of the decision. The documentation should include the time the violation was discovered, the sources of the findings, missing information, the justification for the decision, and the persons involved in the assessment. New facts may require updated conclusions. This approach also allows for demonstrating why the controller deemed the report necessary at a given stage or why it was decided not to report.
What are the obligations of facilities using MyDr?
Entrusting data processing to a medical system provider does not release a facility from its obligations as a controller. In the FAQ of August 27, 2026, the Personal Data Protection Office (UODO) reminded that a facility that has received confirmation of its data being affected by a MyDr incident should assess the breach and its reporting obligations. In cases of high risk, patient notification is also required. This FAQ is informative and clarifies the application of existing regulations. The Personal Data Protection Office (UODO) FAQ regarding MyDr.
For a facility, the first step is to determine whether the incident affected its patients, what data was compromised, and what is known about the incident. Information from the vendor should inform the administrator's own assessment. It's important to retain all correspondence and subsequent versions of reports, as they can clarify when the facility gained specific knowledge.
However, waiting for a formal letter from the provider should not be considered an automatic postponement of the deadline. According to the European Data Protection Board (EDPB), establishing a breach requires obtaining reasonable certainty that the incident has compromised the security of personal data. If the institution already has credible evidence, it should act on it. EDPB Guidelines 9/2022, paragraphs 31-36.
Notification to the patient should clearly explain the nature of the breach, the possible consequences, the measures taken, and how to obtain further information. With health data, the risk of discrimination or infringement of personal rights must also be considered. General information about an "IT incident" may not allow the patient to understand the threat. The Personal Data Protection Office's position on data controllers' obligations.
Once the ongoing breach management is secured, it's worth reviewing the data protection agreement, the provider's obligations to cooperate, and the terms of the cybersecurity insurance. Assessing potential claims requires determining liability, damages, and causality. The mere fact that an incident occurred does not determine the validity of recourse or the payment of a policy benefit.
When can the bank and BIK process the entrepreneur's data after the loan has been repaid?
The protection provided for in Article 105a, paragraphs 2-3 of the Banking Law also applies to individuals conducting business activity. This is important when assessing whether the bank and the Credit Information Bureau (BIK) may continue to process data after the business loan obligation has expired.
In its judgment of September 2, 2026, III OSK 252/24, the Supreme Administrative Court confirmed that the above-mentioned provisions are not limited to consumers. According to the UODO's announcement of September 15, the court dismissed the cassation appeals filed by PKO BP and the Credit Information Bureau (BIK). The judgment is final. UODO announcement on entrepreneurs' data in banks and the Credit Information Bureau (BIK).
Repayment of a loan does not automatically trigger the obligation to delete all data. Further processing may be based on consent or on statutory grounds for processing without consent. When applying Article 105a, paragraph 3, the conditions for default or delay in repayment must be verified, as well as the effective notification of the individual's intention to continue processing their data. The corporate purpose of the loan does not exempt them from such an assessment.
In practice, we recommend that banks and financial institutions verify whether their post-contract data processing procedures also apply to sole proprietors. Businesses challenging a BIK entry should, however, establish the basis for further processing, their repayment history, and the content of any notifications received. This information will help assess the validity of a request to delete data in a specific case.
When does combining DPO functions lead to a conflict of interest?
A data protection officer should be able to independently assess how data is processed within an organization. The problem arises when they are also entrusted with making decisions that they are then tasked with overseeing.
In a press release dated August 31, 2026, the Personal Data Protection Office (UODO) described the case of a court bailiff who, for five years, served as both a personal data controller and a Data Protection Officer (DPO) in his own bailiff's office. The total fine was PLN 15,500, including PLN 12,000 for failing to ensure the inspector's independence and PLN 3,500 for failing to notify the authority of his appointment. Case number DKN.5131.24.2025. This is an administrative decision; the press release does not confirm the outcome of a potential court review. UODO press release on the independence of the DPO.
The origins of this case are also significant. Irregularities involving the Data Protection Supervisor (DPO) were revealed during the analysis of another breach report, which involved sending a letter to the wrong person. This demonstrates that handling a single incident can lead to the evaluation of broader organizational solutions. The UODO also noted that the faulty combination of functions was intended to generate savings for the controller. Description of the UODO's proceedings.
The GDPR allows DPOs to perform other tasks if they do not result in a conflict of interest. The previous CJEU judgment of 9 February 2023, C-453/21, clarifies that the assessment requires an examination of all relevant circumstances, including the organizational structure and actual involvement in determining the purposes and means of processing. CJEU judgment in X-FAB Dresden, paragraphs 44-46.
It's therefore worth considering combining the DPO function with management positions in IT, HR, compliance, or security. The position title alone doesn't replace a competency assessment. While advising on system implementation may be part of the DPO's role, independently establishing data processing rules that they later monitor can lead to conflicts of interest. Outsourcing a DPO also requires such an assessment.
You should also verify the publication of contact details and the timeliness of notifications to the Personal Data Protection Office (UODO). The 14-day deadline for notifying the appointment of a DPO is set out in Article 10(1) of the Polish Personal Data Protection Act. The UODO clarifies the notifications regarding DPOs.
What do the UODO statistics show for 2025?
Data for 2025 indicate an increase in the number of cases and the total value of fines imposed. The report presented on the UODO website on September 1, 2026, includes the following figures:
| Indicator | 2024. | 2025. |
| Complaints, excluding cases conducted in international cooperation | 8056 | 12 827 |
| Data breach reports | 14 842 | 22 435 |
| Inspections | 50 | 76 |
| Total amount of fines imposed | approx. PLN 13.91 million | approx. PLN 64.44 million |
Source: discussion of the report of the President of the Personal Data Protection Office for 2025.
The total value of fines imposed by the Personal Data Protection Office (UODO) increased by approximately 363% year-on-year. This indicator describes the sum of sanctions, so it does not allow us to assume that the risk of a specific company being penalized has increased by the same proportion. Similarly, an increase in reports does not in itself prove an identical increase in the number of all violations.
A list of recurring problems is useful for organizations: correspondence directed to the wrong recipients, faulty anonymization, monitoring, marketing, debt collection, and the processing of medical and employee data. These are the processes that make it worthwhile to begin reviewing. We discuss marketing issues in more detail in the article "UODO takes a closer look at marketing in 2026 – the end of fictitious consent?"
What is worth checking in the organization?
The most useful compliance review should test the performance of procedures using specific examples. A starting point might be a recent breach, a recently implemented system, or the current scope of a DPO's responsibilities.
We recommend verifying five issues:
1. Reporting incidents within the organization. Does the employee know who to report the information to and who will cover for that person during their absence?
2. Risk assessment. Does the justification address specific data, recipients, and personal impacts?
3. Deadlines and responsibility. Is it clear who makes the decision to report and prepares the notifications?
4. Cooperation with suppliers. Do contracts ensure prompt provision of information and assistance in handling breaches?
5. Independence of the DPO. Does the DPO have access to top management and can assess activities without overseeing their own management decisions?
A good supplement to this is a short exercise: an erroneously sent list contains employee PESEL numbers, and the recipient doesn't respond to a request to delete the message. Working through this hypothetical situation allows you to determine whether the organization can gather facts, assess risk, and make a decision in a timely manner.
If you need support with analysing a breach, assessing the independence of a DPO, or reviewing procedures, please review our personal data protection consultancy services and contact our law firm.
FAQ – frequently asked questions
Does every data protection breach need to be reported to the Personal Data Protection Office?
No. Notification is not required if the breach is unlikely to result in a risk to the rights and freedoms of individuals. However, each breach must be documented, and the decision not to report must be justified.
When does the 72-hour period for reporting a violation begin?
The deadline begins when the administrator identifies the violation. This point should not be considered the conclusion of the entire technical investigation or the approval of the report by management.
Does notification of the person also have to be made within 72 hours?
Article 34 of the GDPR requires notification without undue delay if the breach is likely to result in a high risk. It does not establish a separate 72-hour deadline, and the obligation must be assessed taking into account the exceptions provided for in that provision.
Can the system provider take over the facility's responsibility for reporting?
Merely entrusting data processing does not transfer the controller's obligations to the provider. The provider may assist in handling the breach, but the institution must ensure proper performance of its obligations.
Can a DPO work in the compliance or IT department at the same time?
Yes, provided other tasks do not create a conflict of interest. Actual competence must be verified, in particular whether the person in question determines the purposes and means of processing, which they are then expected to independently monitor.
Is the UODO fine the same as compensation for a patient or client?
No, these are separate types of liability. A claim under Article 82 of the GDPR requires proof of material or non-material damage caused by the infringement, and an administrative fine alone does not replace this assessment. Legal basis – Article 82 of the GDPR.
Basics and sources
Legal acts
1. GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, in particular: Article 5(1)(a), (e) and (f) and (2) and Article 6(1), Article 24, Article 28(3)(f), Article 32, Articles 33-34, Article 37(7), Article 38(3) and (6) and Article 39(1)(b), Articles 82-83. Text of the GDPR provided by the UODO.
2. Act of 29 August 1997 – Banking Law: Article 105a, sections 2–3 and 5. Consolidated text in ELI, pp. 193–194.
3. Act of 10 May 2018 on the Protection of Personal Data – Article 10, paragraphs 1 and 4, Article 11. Consolidated text in ELI, pp. 6–7.
Case law and source materials
4. Judgment of the Supreme Administrative Court of 26 August 2026, III OSK 251/24 – risk assessment after disclosure of data including the PESEL number and the administrator’s obligations, discussion based on the UODO announcement of 28 August 2026.
5. Judgment of the Supreme Administrative Court of 2 September 2026, III OSK 252/24 – application of Article 105a paragraphs 2–3 of the Banking Law to natural persons conducting business activities, discussion based on the announcement of the Personal Data Protection Office of 15 September 2026.
6. CJEU judgment of 9 February 2023, C-453/21, X-FAB Dresden, in particular paragraphs 44-46 – conflict of interest when combining the DPO function with other tasks. Full text of the judgment in EUR-Lex.
7. Decision of the President of the Personal Data Protection Office, DKN.5131.24.2025 – independence of the Personal Data Protection Officer and notification of his appointment, discussion based on the communication of the Personal Data Protection Office of August 31, 2026.
8. European Data Protection Board, Guidelines 9/2022 on personal data breach notification under the GDPR, version 2.0, adopted on 28 March 2023, in particular points 31-36 – the moment of ascertainment of a breach. The text of the guidelines is in English.
9. UODO, FAQ regarding the MyDr incident, August 27, 2026 – information for those affected by the breach and administrators. UODO FAQ.
10. UODO, "The controller must report a leak that occurred at the processor", announcement of August 12, 2026, updated on August 31, 2026 – obligations of institutions using MyDr. UODO position.
11. Report on the activities of the President of the Personal Data Protection Office in 2025, in particular pp. 17–18 – statistical data. The full report and overview of the Personal Data Protection Office published on 1 September 2026.
The UODO's announcements and EDPB guidelines serve to clarify the practice of applying the regulations; they do not constitute a standalone basis for the controller's obligations. The Supreme Administrative Court's judgments and the DPO decision indicate the announcements on which their discussion is based.
This article is for informational purposes only and does not constitute legal advice
Legal status as of September 16, 2026.
Author:
Series editor:
