Duyurular
Polish DPA Imposes a Fine on Warsaw University of Technology for not Complying with its Obligation
The proceedings against the Warsaw University of Technology was initiated after the Polish Data Protection Authority (‘DPA’) received a data breach notification. As it was indicated, an unauthorized person downloaded from the controller's IT network resources a database containing personal data of students and lecturers (over 5 thousand people).
As it was established during the administrative proceedings, the establishment of the Warsaw University of Technology used an application created by the University’s employees to enrol for courses and allowed the user to have insight into the history of teaching, grades and calculations of fees. This application was modified depending on the controller’s needs. At the beginning of January 2020, an unauthorized person having credentials used the functionality of uploading files to the application. In turn, at the beginning of May 2020, an unauthorized download of personal data was made.
Warsaw University of Technology did not implement the appropriate technical and organizational measures to ensure the security of the personal data processed.
Taking into account the controller's failure to comply with its obligations and the high risk of adverse effects in the future for persons affected by the incident, the Polish Data Protection Authority found it reasonable and necessary to impose an administrative fine of PLN 45,000 (approximately EUR 9,900).
You can reach the further information here.
Kind regards,
Zumbul Attorneys at Law
Türkçe
English