Your cookie preferences

EDPB guidance · Art. 7 GDPR

We use technical cookies essential for the platform to work (login, security, sessions). We would also like to use analytics cookies to understand how to improve it.

You can accept all, reject all, or choose which categories to switch on.Your consent is valid for 6 months and you can withdraw it at any time from the footer.

You will find everything in our privacy notice.

All news
Enforcement June 22, 2026 7 min

Poland: WhatsApp in the sales network brings a fine for the processor, and a reprimand for the controller that never vetted it

The UODO decision on Energa-Obrot is the textbook case for Art. 28(1): the controller answers for failing to verify its supplier's guarantees, the supplier for tolerating an unauthorised tool

TL;DR for the DPO

The controller was not sanctioned for the leak itself, but for two omissions: failing to implement appropriate technical and organisational measures, and failing to verify that the processor offered sufficient guarantees (Art. 28(1) GDPR). The processor that had tolerated the messaging app received both a reprimand and the fine. If the 'assessment of guarantees' column in your processor register is empty, this decision is about you.

How the breach came to light

The case dates back to 2021. During the pandemic, representatives of Energa-Obrot's business partners visited customers at home and offered, among other things, addenda to existing contracts. The breach was not discovered by an audit or a security alert: it emerged from a phone call. A former sales representative contacted the company for help recovering money owed by his former employer and, in the course of the conversation, it turned out that he and his colleagues used WhatsApp to communicate. On his private phone, alongside work instructions, were scans and photographs of contracts signed with the company's customers. The screenshot obtained by the controller showed the conversations were group chats.

The controller ran an internal investigation, classified the event as a breach and notified the UODO the same day. Its findings recorded that the breach certainly affected 15 people. The severity assessment report submitted to the authority also flagged that communication through the app had partly taken place outside the European Economic Area.

15
data subjects certainly affected

The partner's defence, and why it failed

The business partner that had allowed the messaging app explained to the controller that the application was an auxiliary tool, meant to smooth communication between salespeople under pandemic conditions, since customer visits were made in person. It added that it had issued each worker an authorisation to process specific data for the performance of contracts, and had taken non-compete and confidentiality declarations from them.

The conceptual mistake

Processing authorisations and confidentiality undertakings are organisational measures, and neither prevents data from ending up on an ungoverned channel. The authority found that the unauthorised application had been an actual processing tool for many months. A policy that bans a tool without providing the authorised alternative and without monitoring usage is not an appropriate measure: it is a statement of intent.

The two findings against the controller

  • Failure to implement technical and organisational measures appropriate to ensure the security of processing (Art. 32 GDPR). The sales network was operating outside company tools without anyone noticing.
  • Failure to properly verify that the processor offered sufficient guarantees to implement those measures. That is the Art. 28(1) obligation: the choice of supplier must be justified, not merely inherited.

Against the processor that had allowed the messaging app, the authority issued reprimands and an administrative fine of PLN 10,145. During the proceedings, inconsistencies emerged between the explanations given by the controller and by the processor, which attempted to downplay its role in the processing and to shift responsibility for the irregularities onto other parties. The amount is modest: the value of the decision lies not in the figure but in the structure of the reasoning.

What to do now, in practice

1) In your processor register, for every supplier whose people process data in the field, record which channel they use and who authorised it. 2) Ask the supplier for the list of tools actually in use, not the ones the contract foresees: they are different things. 3) Document the Art. 28(1) assessment of guarantees with evidence - certifications, completed questionnaires, audit outcomes - and date it. 4) Check whether sub-processors are authorised in writing: here the chain lengthened without the controller governing it. 5) If a client has external sales networks, the question to ask is not 'do you have a policy?' but 'show me the work chats from the last thirty days'.

Official source:UODO - Use of unauthorised data processing tools as the cause of a breach (22 June 2026)Official source:Decision DKN.5131.7.2022 - UODO decisions portal

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement

The vendor's bug turned into a criminal conviction

On 7 September 2026, before the Dublin Metropolitan District Court, Brown Thomas Arnotts Limited pleaded guilty to five sample charges out of twenty-one for breaches of the Irish ePrivacy Regulations. Three concerned the absence of a valid opt-out address, two the sending of marketing without valid consent. The sum paid is two thousand euro. The sum is not the point: this was a criminal prosecution.

Sep 07, 2026New 5 min
Enforcement
403million euro, and six months to comply

Google, €403 million: half the findings live in your register

On 21 September 2026 the Irish Data Protection Commission closed the inquiry it opened into Google Ireland in February 2020. Its subject: location data in three features — Web & App Activity, Location History, Location Accuracy — between 25 May 2018 and 4 February 2020. Fines totalling €403 million and six months to come into compliance. The number makes the headlines; for practitioners, the interesting part is elsewhere.

Sep 23, 2026New 6 min
Enforcement
24.000euros for an access authorised by the medical management

«Not unlawful, the medical management authorised it»: the Italian DPA says no, EUR 24,000

The case is small and the lesson is not. A hospital is at once a place of care and the employer of the same person, and when the two capacities touch, the health record becomes the handiest and most wrong tool. The employer had put it in writing to the prosecutor: that access was not unlawful, it was «carried out on the instructions of the medical management» «for the performance of the work». That is precisely the sentence the authority takes apart.

Sep 22, 2026New 6 min