On 14 November 2025 the Polish data protection authority fined a telecommunications operator EUR 4.5 million in relation to several compliance failures. The operator:
- failed to put in place SCCs and failed to inform data subjects about international data transfers
- processed excessive amounts of employee data contrary to advice given by their DPO
- failed to ensure the processor it used could provide appropriate guarantees that the processing would be compliant with data protection legislation
This is one in a line of recent enforcement actions relating to failure to properly vet processors. If you would like some assistance in ensuring you are meeting your obligations when it comes to engaging processors, feel free to get in touch by emailing hello@hellodpo.com