All news
Enforcement August 24, 2026 4 min

Poland quadrupled its fines in a year, and the three highest ever all date from 2025

Sixteen decisions, eighteen addressees, over sixty-four million zloty — against fourteen the year before. The record involves the postal operator, a bank and a restaurant chain

TL;DR for the DPO

Three cases, three mistakes you find everywhere: using data collected for a public purpose for a different one, copying identity documents without showing it was actually necessary, and leaving your own staff's data exposed. None of the three requires sophisticated technology to commit.

The numbers

In 2025 the President of the Personal Data Protection Office adopted sixteen fining decisions against eighteen entities, totalling more than sixty-four million zloty. The previous year the total was close to fourteen million. This is not a gradual rise: it is a change of scale, and the three largest fines ever imposed in Poland fall within those twelve months.

Postal operator: twenty-seven million for data used for another purpose

The largest fine concerns the national postal operator and the data of some thirty million citizens taken from the PESEL population register ahead of the 2020 postal elections, processed without an adequate basis. It is the textbook purpose-limitation case: data lawfully sitting in a public register does not thereby become usable for a different aim, not even when that aim is itself public.

Bank: eighteen point four million for copies of identity documents

A credit institution was fined for copying and scanning customers' identity documents without demonstrating that doing so was necessary to meet anti-money-laundering obligations. This is the point that touches the largest number of businesses: AML rules require identification, they do not automatically require photocopying. The necessity of that copy must be proven, not assumed, and almost nobody keeps the assessment that justifies it.

Restaurants: sixteen point nine million for the company's own staff data

The third decision hit a restaurant chain after an incident in which employee information became publicly accessible. It is worth noting whose data it was: not customers', but the workforce's — the category that risk analyses systematically treat as less exposed and that in fact produces the highest fines, because an employment relationship leaves the individual no alternative.

What to do now, if you have clients with a presence in Poland

1) Check whether anyone copies identity documents, and ask where it is written down why that is necessary; 2) make sure data received from public registers or bodies is not reused for purposes other than collection; 3) treat the HR archive with the same care as the customer one, because the authority does.

Official source:Urząd Ochrony Danych Osobowych — 2025 fining decisions

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement
26complaints, and no fine

You declare contract, then you reject the objections: Norway shows how the two mistakes travel together

SATS asked members for a photo kept in the membership system and used at the desk to check the identity of people coming in. Datatilsynet found the notice stated the wrong legal basis, failed to explain the right to object, and that objections were rejected without demonstrating compelling legitimate grounds. The deadline to fix it is 11 September 2026.

Aug 26, 2026New 6 min
Enforcement
825 mln €the second-largest fine ever

Eight hundred and twenty-five million for an algorithm that deactivated accounts with nobody looking

It is the second-largest fine ever imposed under the GDPR, behind only Meta's 1.2 billion. It is not about a data transfer or a security breach: it is about Article 22, the rule on automated decisions that almost nobody documents because it looks like a big-platform problem. It is in fact about anyone who lets software decide something that weighs on a person's life.

Aug 24, 2026New 5 min
Enforcement
80access requests refused

The client goes bankrupt, the vendor is left alone with the data — and becomes the controller

A retail chain goes bankrupt. Former employees need their own timesheets to document unpaid wages, but the only party holding them is the time-tracking software vendor, which replies that it may disclose nothing to anyone — "not even to the data subjects themselves" — because the contract with the controller has ended. The Norwegian authority decided the opposite: when you are the only one left deciding about the data, you are the controller.

Aug 21, 2026New 4 min