The controller and processor are responsible for the protection of personal data
The President of the Personal Data Protection Office, Mirosław Wróblewski imposed administrative fines on the Starost of Lubartowski Poviat and on the Voivodeship Office for Geodesy and Management of Agricultural Lands in Lublin.
In 2023, the Starost of Lubartowski Poviat notified to the President of the Personal Data Protection Office personal data breach resulting from the theft of a company laptop of one of the employees of the Voivodeship Office for Geodesy. The notification indicated that the breach concerned the loss of confidentiality of personal data of approx. 700 persons, which included, among others, names, dates of birth, residence addresses, PESEL numbers (personal identification numbers), series and numbers of identity cards, and land register numbers.
The notification of the Starost of Poviat became an impulse for the supervisory authority to assess whether the controller and the processor have actually implemented adequate security measures to guarantee the security of the personal data processing.
The President of the Personal Data Protection Office stated that the controller’s breach of the GDPR consisted, among other things, in a failure to implement appropriate technical and organisational measures and a failure to verify that the processor had implemented measures to ensure lawful processing of personal data, as the controller assumed that the processor has in place all procedures to ensure the protection of personal data.
The reason for not considering a threat of computer equipment theft was that the employees of the controller, as well as the processor, did not process or were not allowed to process personal data outside of the premises of their organisations. In this case, however, a proper consideration in the risk assessment and selection of appropriate measures were necessary, given the specific nature of the tasks (land consolidation) carried out by the processor on behalf of the controller. Following the incident, security measures were implemented, including disk encryption, which – as can be assumed – introduced in advance could have prevented the access and loss of confidentiality of personal data from the stolen laptop.
The supervisory authority stressed that risk management is a cornerstone of the data protection system and is continuous. The risk assessment should be documented, specific and linked to the actual processing.
The President of the Personal Data Protection Office found that, whilst technical safeguards have been tested, the effectiveness of the organisational measures has not been assessed – for example the supervision of mobile devices, the rules governing the removal of the equipment from the personal data processing area, and the prohibition on leaving devices unattended.
The GDPR requires data to be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage. In accordance with the principle of accountability, the controller must be able to demonstrate compliance with the principles of personal data processing. The provisions of the GDPR explicitly refer to the obligation to implement appropriate technical and organisational measures to ensure that data processing is carried out in accordance with the applicable law.
Liability for a breach of the GDPR cannot be attributed solely to the controller. The processor is obliged to cooperate with the controller and assist them in fulfilling their obligations, including the implementation of appropriate security measures. In the present case, the processor not only failed to assist the controller, but through its negligence contributed to an infringement of the law.