Back to the insights archive
Legal updates

Personal data breach in the SGGW 

The Office for Personal Data Protection will carry out control activities concerning personal data breach by the School of the Village Farm in Warsaw.

The Office for Personal Data Protection will carry out control activities concerning personal data breach by the School of the Village Farm in Warsaw.

The SGGW in its Communication announces that the data were stolen by its employee, contrary to the law and contrary to the procedures in force at the university.

The Office for Personal Data Protection will carry out control activities concerning personal data breach by the School of the Village Farm in Warsaw. The SGGW in its Communication announces that the data were stolen by its employee, contrary to the law and contrary to the procedures in force at the university.

Personal data breach is related to the theft of a laptop used by one of SGGW’s staff. The disk featured personal data processed during recruitment procedures for studies at SGGW in recent years. These are names, names, peseles, residence addresses, data on the series and ID number, mobile phone number, or results obtained on the exam.

Importantly, even if personal data have not yet been used, persons whose data has been processed in breach of the rules may be compensated for exposure to identity theft and costs incurred to reduce the risk of adverse consequences.

Persons whose personal data have been breached are accused of the lack of adequate technical and organisational means to process personal data in accordance with the GDPR. Since the case is not eligible for collective action, one thousand persons are considering filing individual lawsuits against the SGGW.

Meanwhile, the SGGW in its website informs that the personal data of students and candidates for SGGW studies have been stolen because one He copied it to a portable computer. Today, a media report has appeared that the theft of suspects is third citizens of Georgia.

PUODO initiates control activities

The President of the Office for Personal Data Protection received a notification concerning the breach of the protection of personal data from the SGGW and took control activities. They aim to determine whether the processing of personal data in SGGW takes place in accordance with the GDPR.

On the basis of the control activities, the President of the Office for Personal Data Protection will assess whether the administrator correctly fulfilled, among others, the obligation to notify the data subjects of the breach (if there has actually been a situation in which the controller actually has a notification obligation). In the case of serious infringements (which we are probably dealing with in this case), it is very important to react.

Therefore, if it turns out, for example, that the administrator should notify not only the President of UODO, but also the persons concerned by the event, and did not do so, then it is possible to quickly indicate the necessity. It is very important that persons whose data has been disclosed, stolen or otherwise breached, can, after such notification, take action as soon as possible to protect them from further threats.

Consequence

Importantly, even if personal data have not yet been used, persons whose data have been processed in breach of the rules may be compensated for the exposure to identity theft and costs incurred to reduce the risk of adverse consequences (e.g. costs of exchanging identity cards).

Any person who considers that his personal data are processed unlawfully may lodge a complaint with the President of UODO. Regardless of the complaint to the President of UODO, such a person may assert his rights before a civil court. If such a person has suffered material or non-material damage, he shall also have the right to obtain compensation from the administrator.

Written by: Przemysław Lach, Councilor Application Russell Bedford

Continue exploring our insights.

View the full archive
Legal updates

Obligations of traders to provide non-cash payments

As part of the amendment package under the noisy name Polish Deal, which most of the solutions entered into force at the beginning of January 2022, to stimulate a new impetus for the gradually growing trend in the market for non-cash payments, and at the same time to counter and combat the gray...

Legal updates

Deduction – what is involved and when possible

Deduction is a legal institution regulated in Article 498-505 KC.

Legal updates

Business secrecy in the context of changes to the Public Finance Act - comment

From 1 July 2022 information on all contracts exceeding the value 500 PLN, which from the beginning of this year have been concluded by public authorities (including JST), will be public and will be entered in the register kept by the Minister of Finance.