Poczta Polska
Incident posture
Linked entities
- Victim
- Poczta Polska
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Poland's data protection authority fined state-run postal administration 27 million PLN (approximately $7.4 million) for infringing the GDPR by processing personal data of all eligible voters provided to it by the country's Ministry of Digital Affairs ahead of the pandemic-era national elections conducted entirely by mail. The exposed information included voters' full names, home addresses, and national identification (PESEL) numbers, affecting the entire electorate. The postal service bore the larger penalty for the unlawful processing, while the ministry received a comparatively minor fine for unlawfully disclosing the data. The case highlighted significant gaps in how large-scale electoral data was handled between government entities, raising concerns about the safeguarding of sensitive personal identifiers of millions of Polish citizens.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In 2020, Poland held national elections conducted entirely by mail due to the COVID-19 pandemic, a decision that placed the country's state-run postal administration, Poczta Polska, at the center of a large-scale data processing operation. To facilitate the vote, the Ministry of Digital Affairs provided Poczta Polska with personally identifiable information covering all eligible voters in the country. The data set included full names, residential addresses, and national identification numbers known as PESEL numbers. The Ministry of Digital Affairs was fined 100,000 PLN for breaking the law by transferring this information to the postal service, while Poczta Polska was subsequently held responsible for how it processed the data once received. The Polish data protection authority, the UODO, ruled that by handling the voter dataset Poczta Polska had infringed the European Union's General Data Protection Regulation (GDPR), specifically in relation to the lawful basis and conditions under which the personal data was processed for the postal voting effort.
The UODO's investigation into the matter, which became associated in Polish media with the "envelope election" due to the postal ballot format, ultimately resulted in a 27 million PLN fine, equivalent to approximately $7.4 million, being imposed on Poczta Polska. The regulator determined that the postal administration had failed to comply with the GDPR in its handling of the personal data entrusted to it for the purposes of distributing and processing mail-in ballots. The fine placed the incident among the larger GDPR-related penalties issued in Poland during 2025, alongside other notable cases such as the fines levied against ING Bank Śląski and McDonald's Polska. The exposure of names, addresses, and PESEL numbers for the entire eligible voting population meant the potential scope of the breach was extensive, affecting virtually every adult citizen registered to vote in the 2020 elections.
The broader context of the case highlighted the legal and procedural difficulties of organizing a national election entirely by post during a public health emergency. By relying on Poczta Polska to handle the distribution and collection of ballots, the Polish government created a situation in which a single state-run entity was suddenly required to process a nationwide dataset of sensitive personal identifiers without the established legal framework that would normally govern such large-scale data handling. The Ministry of Digital Affairs' decision to provide the data to Poczta Polska was found to have been unlawful in itself, and the postal administration's subsequent processing of that information compounded the regulatory failure. The UODO's ruling made clear that both the originator of the data transfer and the recipient bore responsibility under data protection law, with the substantially larger fine directed at Poczta Polska reflecting the scale of its processing activities and the volume of data involved.
The incident drew attention to the particular risks associated with PESEL numbers, which serve as a universal identifier in Poland and are linked to a wide range of administrative, financial, and governmental services. The exposure of these numbers, alongside names and addresses, created conditions under which affected individuals could be exposed to identity theft, fraud, and other forms of misuse. Unlike isolated corporate breaches, the Poczta Polska case involved data that had been systematically collected and transferred by government bodies for a specific civic purpose, raising questions about the safeguards applied when state institutions share large datasets with other public entities. The UODO's penalty, while significant in Polish terms, was notably smaller than the record-breaking GDPR fines issued elsewhere in Europe during 2025, such as the €530 million penalty imposed on TikTok by the Irish Data Protection Commission for transfers of European user data to China. Nevertheless, the case underscored the willingness of national regulators to act against public bodies and state-owned enterprises when GDPR obligations were not met.
The response from the Polish authorities focused on regulatory enforcement rather than public disclosure of specific technical remediation steps taken by Poczta Polska. The UODO's published findings emphasized the legal violations rather than describing any particular security failures, such as unauthorized access, system compromise, or data exfiltration by external actors. The case was therefore distinct from many of the other major 2025 data protection enforcement actions, which frequently involved cyber-attacks, ransomware, or misconfigured servers, and instead centered on the lawful basis for processing personal data in connection with a national electoral process. The financial penalty served as the primary consequence for Poczta Polska, accompanied by the reputational impact of being publicly identified as a GDPR violator by Poland's data protection authority. The Ministry of Digital Affairs, for its role in providing the data, received a comparatively modest fine of 100,000 PLN, reflecting the UODO's assessment that the primary responsibility for the unlawful processing lay with the postal administration that subsequently handled the information.
Sources
Sources available to members: 1 source.