background information date of final decision: 9 December 2021 National case Controller: Warsaw University of technology Legal Reference: Principles (Art. 5(1)(f), Art. 5(2)), Data protection by design and by nonpayment (Art. 25(1)), Security of processing (Art. 32(1), Art. 32(2)) Decision: misdemeanor of GDPR, mulct issued paint words: principles, processing, security, data protection Summary of the Decision extraction of the showcase The minutes against the Warsaw University of technology was initiated after the down Data protection Authority received a data breach notification. as it was indicated, an unauthorized person downloaded from the controller’s IT network resources a database containing personal data of students and lecturers (over 5 thousand people). key finding As it was established during the administrative proceedings, the establishment of the Warsaw University of technology used an application created by the Universitys employees to enrol for courses and allowed the user to have insight into the account of teaching, grades and calculations of fees. This application was modified depending on the controllers needs. at the rootage of january 2020, an unauthorized person having credentials used the functionality of uploading files to the application. in turn, at the start of May 2020, an unauthorized download of personal data was made. Warsaw University of Technology did not implement the appropriate technical and organizational measures to ensure the security of the personal data processed. Moreover, the University failed to regularly test, assess and evaluate the effectiveness of measures and did not have into consideration the risk related to the processing of data within the application. Decision taking into account the controller’s loser to comply with its obligations and the high risk of adverse effects in the future for persons affected by the incident, the smoothen data tribute Authority found it reasonable and necessary to impose an administrative mulct of PLN 45,000 (approximately EUR 9,900). For further info (decision in national language): https://www.uodo.gov.pl/decyzje/DKN.5130.2559.2020%20 The tidings published here does not constitute official EDPB communication, nor an EDPB endorsement. This news item was originally published by the national supervisory dominance and was published here at the bespeak of the sa for information purposes. Any questions regarding this tidings item should live directed to the supervisory authority concerned. Source: EDPB