Reprimands to the hospital for the lack of the processor’s verification
The President of the Personal Data Protection Office Mirosław Wróblewski issued a reprimand to a specialist hospital in Sosnowiec for failing to verify the processor to ensure sufficient security measures for the processing of personal data in accordance with the GDPR. The controller was also reminded that he did not carry out a proper risk assessment for the processing of personal data by e-mail. On the other hand, the processor was reprimanded by the President of the Personal Data Protection Office for the lack of proper implementation of appropriate measures to ensure the security of personal data processing.
The case started in 2021 when an unauthorised person gained access to a controller’s email box hosted on the servers of an external service provider, the processor. As a result of the hacking into the e-mail box, an unauthorized person downloaded all its content from it, including the personal data of 224 people.
After receiving the notification of a personal data breach, the President of the Personal Data Protection Office analysed the circumstances of the case, including the manner of fulfilling the controller's obligations, among others in terms of proper data security measures. On the basis of the explanations received, the supervisory authority initiated administrative proceedings to determine whether the controller and the processor breached their obligations under the provisions on the personal data protection.
According to its content, the processor declared that it applies security measures that meet the requirements of the GDPR and obtained the relevant ISO/IEC 27001 certification in the field of information security. Furthermore, he stated that his technical and organisational measures were adequate to the type of personal data entrusted to him.
Prior to the personal data breach, which was subsequently reported to the President of the Personal Data Protection Office, the controller carried out a risk assesment, including factors that: ‘can be materialised when processing data by e-mail’. However, it does not explicitly mention the postal service provider. Moreover, before determining the occurrence of personal data breach, the controller did not take measures to minimise the risk, including those specified in the risk assessment carried out.
The President of the Personal Data Protection Office stated that the controller had the organizational capacity to verify the guarantees declared by the processor—including, among other things, based on a policy governing cooperation with suppliers regarding information security and the requirement to conduct a risk assessment for public procurement contracts whose value does not exceed EUR 30 000. Nevertheless, the controller has not carried out a GDPR-compliant assessment of whether the processor actually provides sufficient guarantees to implement appropriate technical and organisational measures, so that the processing meets the requirements laid down by law and protects the rights of data subjects.
The controller did not follow its own risk assessment procedure when selecting the processor. On the other hand, the processor, as has been shown, did not carry out a risk assessment in order to ensure the security of the processing of the personal data entrusted. The incompatibility with the GDPR resulted from the inability to provide guarantees - to implement appropriate technical and organizational measures.
In accordance with Article 28(1) GDPR the controller is obliged to use only processors that provide sufficient guarantees to implement appropriate technical and organisational measures to ensure that the processing complies with the requirements of the GDPR and protects the rights of data subjects. This obligation applies both to the diligent selection of the processor by the controller and to the verification, at appropriate intervals, of the guarantees provided by the processor, e.g. by means of audits or inspections. The controller is also required to demonstrate (including having a tangible evidence) that the selection of the processor was made with due diligence, in an informed and lawful manner.
The President of the Personal Data Protection Office issued reprimands to the controller and the processor because the administrative procedure carried out showed that they had infringed the provisions on the protection of personal data. In the case of the controller, the identified non-compliances with the GDPR resulted in a violation of the principles of confidentiality and accountability. The processor has been reprimanded for failing to implement measures to ensure the security of the personal data processing and the protection of the rights of data subjects.
The President of the Personal Data Protection Office considered that, in the established circumstances of the present case, a reprimand to the controller was sufficient. This is supported in particular by the fact that, prior to the conclusion of the personal data processing agreement, the controller established a list of security measures aimed at ensuring the security of the entrusted personal data, and the breach found was not the result of a complete lack of action on the part of the controller in verifying the processor. In favour of the controller, it should be also included that circumstances indicate that he is aware of his negligence and has taken actions that give a guarantee that in the future there will be no violation in terms of the requirement to verify the processor. In addition, the President of the Personal Data Protection Office appreciated that the controller had taken a number of corrective actions to minimise the risk of recurrence of the infringement. The President of the Personal Data Protection Office also took into account the appropriate implementation in cases concerning the protection of personal data of the data protection officer, which was not indifferent to increasing the level of security of personal data processing. In turn, with regard to the processor, the President of the Personal Data Protection Office appreciated the actions taken by the controller to improve the level of security of personal data processing.