TL;DR for the DPO
Three cases, three mistakes you find everywhere: using data collected for a public purpose for a different one, copying identity documents without showing it was actually necessary, and leaving your own staff's data exposed. None of the three requires sophisticated technology to commit.
The numbers
In 2025 the President of the Personal Data Protection Office adopted sixteen fining decisions against eighteen entities, totalling more than sixty-four million zloty. The previous year the total was close to fourteen million. This is not a gradual rise: it is a change of scale, and the three largest fines ever imposed in Poland fall within those twelve months.
Postal operator: twenty-seven million for data used for another purpose
The largest fine concerns the national postal operator and the data of some thirty million citizens taken from the PESEL population register ahead of the 2020 postal elections, processed without an adequate basis. It is the textbook purpose-limitation case: data lawfully sitting in a public register does not thereby become usable for a different aim, not even when that aim is itself public.
Bank: eighteen point four million for copies of identity documents
A credit institution was fined for copying and scanning customers' identity documents without demonstrating that doing so was necessary to meet anti-money-laundering obligations. This is the point that touches the largest number of businesses: AML rules require identification, they do not automatically require photocopying. The necessity of that copy must be proven, not assumed, and almost nobody keeps the assessment that justifies it.
Restaurants: sixteen point nine million for the company's own staff data
The third decision hit a restaurant chain after an incident in which employee information became publicly accessible. It is worth noting whose data it was: not customers', but the workforce's — the category that risk analyses systematically treat as less exposed and that in fact produces the highest fines, because an employment relationship leaves the individual no alternative.
What to do now, if you have clients with a presence in Poland
1) Check whether anyone copies identity documents, and ask where it is written down why that is necessary; 2) make sure data received from public registers or bodies is not reused for purposes other than collection; 3) treat the HR archive with the same care as the customer one, because the authority does.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free