VGS corporate lawyers

London
+442039665531

Milan
+39 02 873 482 02

  • Home
  • Who we are
  • Practice Areas
    • Company law
      • Setting up a company in Italy
      • Corporate governance
      • Bankruptcy
    • Debt Recovery & Credit Collection
    • Arbitration and Mediation
    • Contracts
      • Acquisition Finance
    • White collar crimes
    • Data protection and GDPR
    • Professional Negligence
      • Medical Malpractice
  • People
    • Avv. Flavia Di Pilla
    • Avv. Silvia Pellegrini
    • Avv. Giuseppe Ganci
    • Avv. Valentina Improta
    • Avv. Salvatore Fasciana
    • Dr. Yasine Ajlane
  • News & Blog
  • Discounted online consultation
Menu
  • Home
  • Who we are
  • Practice Areas
    • Company law
      • Setting up a company in Italy
      • Corporate governance
      • Bankruptcy
    • Debt Recovery & Credit Collection
    • Arbitration and Mediation
    • Contracts
      • Acquisition Finance
    • White collar crimes
    • Data protection and GDPR
    • Professional Negligence
      • Medical Malpractice
  • People
    • Avv. Flavia Di Pilla
    • Avv. Silvia Pellegrini
    • Avv. Giuseppe Ganci
    • Avv. Valentina Improta
    • Avv. Salvatore Fasciana
    • Dr. Yasine Ajlane
  • News & Blog
  • Discounted online consultation
Cerca
Chiudi questo box di ricerca.

General Data Protection Regulation Fines and Penalties – Poland

  • by VGS' Editorial Board
  • 3 Maggio 2019
  • Comments (2)

One year after GDPR entered into force, it is possible to observe first penalties and fines imposed by different Data Protection Authorities to several undertakings. This brief analysis is useful to provide insights and clarifications over possible misapplications of GDPR and related consequences. 

Country: Poland | Industry: Software | Company: Bisnode | Non-Compliance: Lack of communication with data subjects 

 A first and radical decision released by the Polish Data Protection Authority (“UODO”) involves the common practice of obtaining personal data not directly from the data subject. The €220.000 fine has been handed to a Sweden-headquartered digital marketing company that has an office in Poland after it failed to comply with Article 14 of the GDPR.

Art. 14 of GDPR states information to provide where personal data have not been obtained directly from the data subject. In that case, data controller shall provide data subjects with relevant information such as: identity of controllers and Data Protection Officer, categories of data processed, purpose of processing, recipients of personal, the period for which the personal data will be stored, the right to lodge a complaint with a supervisory authority et cetera. 

Polish Data Protection Authority requires also that Bisnode contact all data subjects in order to fulfil Article 14 obligations. However, the amount of data subjects involved is close to six million. This is a radical decision because of the interpretation of “disproportionate efforts” in relation to the obligation to provide information. In fact, Recital 62 clearly states that it would not be necessary to impose the obligation to provide information where it is not possible or would involve a disproportionate effort. 

However, as stated by the UODO, whoever involved personal data collection from public registers and other online sources it should be required to shape the business on such activities. Furthermore, UODO stated that Bisnode did not fulfil its obligations under art. 14 by publishing in its website a statement declaring it has complied the GDPR. In fact, fulfilling the communication obligation requires an active approach. A passive notification under a tab on a website, as Bisnode did, cannot be defined as an active approach. Moreover, active notification approach has been affirmed by Article 29 Working Party in its Transparency Guidelines adopted on 29 November 2017.

  • Data Protection
  • GDPR
  • Share:
Previous Article: Enforcement proceedings by distraint
Next Article Trademark registration in Italy

Practice Areas

  • Company law
    • Bankruptcy
  • Debt Recovery & Credit Collection
  • Arbitration and Mediation
  • Contracts
    • Acquisition Finance
  • White collar crimes
  • Data protection and GDPR
  • Professional Negligence
    • Medical Malpractice
Contact us now
VGS corporate lawyers

Get Started

  • Who we are
  • News & Blog
  • Privacy and cookie Policy
  • Contact us

Practice areas

  • Arbitration & Mediation
  • Company Law
  • Data protection & GDPR
  • Debt Recovery
  • Contracts
  • White Collar Crimes

Follow Us

  • Facebook
  • Twitter
  • Vgs Lawyers
  • Vgs Family Lawyers

Newsletter

© Copyright 2022 | VGS Lawyers | All right reserved. – Via Bagutta 13, 20121 Milano

Developed by Fabrizio Lo Pinto

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.