UODO Responds to Massive Data Leak with Urgent Appeal to Poles
Following a massive cyberattack on medical database company MyDr exposing the data of nearly 19 million people, the Personal Data Protection Office has issued strict guidelines for administrators and...
Following a massive cyberattack on medical database company MyDr exposing the data of nearly 19 million people, the Personal Data Protection Office has issued strict guidelines for administrators and citizens.
Table Of Content
UODO Directives on Data Breach Notifications
Notifying individuals affected by the data leak rests on the administrators who used the services of MyDr. The Personal Data Protection Office stated that they should do this without delay, while also reminding that administrators must notify the President of UODO as well.
Deputy Prime Minister Gawkowski Details the Cyberattack
Deputy Prime Minister and Minister of Digital Affairs Krzysztof Gawkowski announced on Wednesday that data belonging to nearly 19 million Poles had leaked. Speaking after a meeting of the Joint Cyber Security Operations Center regarding the cyberattack on MyDr, one of Poland’s largest electronic medical records companies, the Deputy Prime Minister reported that the stolen database contains over 2 TB of data. Information about the stolen data will be available in the Secure Data base, and Gawkowski emphasized that blocking the PESEL number should be done first.
UODO Regulatory Deadlines and Reporting Procedures
The Personal Data Protection Office emphasized on Wednesday that under GDPR, in the event of a personal data breach, the administrator without undue delay and no later than 72 hours after becoming aware of it must report it to the supervisory authority. UODO wrote in a communication that any report submitted to the supervisory authority after 72 hours must be accompanied by an explanation of the reasons for the delay.
UODO explained that for individuals, notifications should describe the nature of the personal data breach, indicating categories and the approximate number of affected persons where possible, along with categories and the approximate number of data entries concerned. This information can be submitted to the Office using the personal data breach reporting form available on the official UODO website.
Preventative Measures Against Phishing and Identity Theft
The Personal Data Protection Office has provided a guide on its website detailing how to protect sensitive data and what steps to take in the event of a data leak. UODO pointed out that notifying affected individuals is the responsibility of administrators who used MyDr, and recommended blocking one’s PESEL number and exercising greater caution when providing data via the internet or phone to prevent identity theft.
Furthermore, individuals must carefully analyze incoming communications such as SMS and email messages to avoid phishing attacks aimed at extorting additional data or gaining access to online banking systems and other services.
General Guidelines on Data Processing and Document Disposal
If there is a suspicion that a company or institution is processing personal data without a legal basis or failing to disclose its source and purpose, individuals should first request explanations from that entity, with a subsequent step being a complaint filed with the President of UODO.
UODO drew attention to situations where administrators demand copies of identity cards, recommending that individuals ask them to indicate the legal obligation requiring such action. The Office also reminded that when obtaining loyalty cards, marketing consent for third-party partners should remain optional.
The Office stressed that before throwing documents such as invoices and receipts into the trash, they must be destroyed in a way that prevents the reconstruction of personal data. Before disposing of old hard drives, memory cards, or flash drives, users should restore the device’s factory settings to clear stored login credentials and passwords.





