Your cookie preferences

EDPB guidance · Art. 7 GDPR

We use technical cookies essential for the platform to work (login, security, sessions). We would also like to use analytics cookies to understand how to improve it.

You can accept all, reject all, or choose which categories to switch on.Your consent is valid for 6 months and you can withdraw it at any time from the footer.

You will find everything in our privacy notice.

All news
Enforcement May 25, 2026 6 min

Poland: a municipality fined not for publishing the data of 749 petition signatories, but for never reporting it

The wrong file stayed online for around ten days. The mistake that cost PLN 7,700 came afterwards: the mayor kept arguing that notification was not due

TL;DR for the DPO

The Art. 33 exemption applies where a breach is UNLIKELY to result in a risk. Citing the EDPB, the UODO recalls that this must be read narrowly: unlikely means the risk has no realistic possibility of materialising, not that it looks modest. When in doubt, notify - and write down why.

The facts

The municipality published a petition in its Public Information Bulletin without anonymising it. The document contained the names, surnames, home addresses and signature specimens of the 749 people who had signed it. The authority did not learn of it from a notification: it learned from a complaint by one of the people whose data had gone online.

The mayor explained that it had been an unintentional error and that the file had been replaced with the correct one. During the proceedings it emerged that the wrong file had remained accessible on the site for around ten days. He also asked for the failure-to-notify proceedings to be discontinued, arguing that proceedings on an individual complaint were already open on the same matter.

749
people whose name, address and signature were exposed

Why that defence fails

An individual complaint and own-motion proceedings look at different things: the first protects the rights of the complainant, the second checks whether the controller met its own obligations. The UODO says so expressly: the complaint was the occasion to notice irregularities of a different nature from those complained of, and justified opening separate proceedings. The fact that the data subject was protected does not cure the omission towards the authority.

The point that applies to everyone

The authority accepts that in this case there was NO high risk to rights and freedoms. And it fines anyway. High risk is the Art. 34 threshold, for communication to data subjects; notification to the authority under Art. 33 is due at a far lower threshold, and falls away only where a risk is unlikely. They are two separate assessments, and conflating them is the most common mistake in breach handling.

What weighed on the amount

  • The controller is a local authority, a public body from which the highest knowledge of the law is expected.
  • The file stayed online for around ten days, not for a few minutes.
  • The controller did not change position even after being prompted by the authority and after proceedings were opened.
  • By the date of the decision the notification had still not been made.

What to do now, in practice

1) In the breach register, for every event closed without notification, check that the reason is written down: not 'low risk', but the reasoning why the risk is unlikely. That reasoning is what gets examined. 2) If a client publishes documents on notice boards, bulletins or transparency sections, publication should be logged as a processing activity in the Art. 30 records, with a documented anonymisation step before going online. 3) A data subject complaint does not discharge obligations towards the authority: they run on separate tracks. 4) If you realise late that a notification was due, make it anyway and explain the delay: here the cost came from persisting, not from the original error.

Official source:UODO - Publication of un-anonymised personal data in the Public Information Bulletin as a cause of a GDPR breach (25 May 2026)Official source:Decision DKN.5131.17.2025 - UODO decisions portal

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement

The vendor's bug turned into a criminal conviction

On 7 September 2026, before the Dublin Metropolitan District Court, Brown Thomas Arnotts Limited pleaded guilty to five sample charges out of twenty-one for breaches of the Irish ePrivacy Regulations. Three concerned the absence of a valid opt-out address, two the sending of marketing without valid consent. The sum paid is two thousand euro. The sum is not the point: this was a criminal prosecution.

Sep 07, 2026New 5 min
Enforcement
403million euro, and six months to comply

Google, €403 million: half the findings live in your register

On 21 September 2026 the Irish Data Protection Commission closed the inquiry it opened into Google Ireland in February 2020. Its subject: location data in three features — Web & App Activity, Location History, Location Accuracy — between 25 May 2018 and 4 February 2020. Fines totalling €403 million and six months to come into compliance. The number makes the headlines; for practitioners, the interesting part is elsewhere.

Sep 23, 2026New 6 min
Enforcement
24.000euros for an access authorised by the medical management

«Not unlawful, the medical management authorised it»: the Italian DPA says no, EUR 24,000

The case is small and the lesson is not. A hospital is at once a place of care and the employer of the same person, and when the two capacities touch, the health record becomes the handiest and most wrong tool. The employer had put it in writing to the prosecutor: that access was not unlawful, it was «carried out on the instructions of the medical management» «for the performance of the work». That is precisely the sentence the authority takes apart.

Sep 22, 2026New 6 min