Leak of data from ZUS, including PESEL numbers.  “By e-mail to a private address”

Leak of data from ZUS, including PESEL numbers. “By e-mail to a private address”

Data of almost 300 payers were leaked from ZUS. It turned out that the data was sent by one of the plant’s employees by e-mail. The case has been reported to the Personal Data Protection Office, there is also a notice to the prosecutor’s office and a comment from ZUS itself.

The leaked data includes names and surnames, dates and places of birth, residential addresses, PESEL numbers, ID card numbers and bank account numbers. This concerns data from almost 300 payers, the website reports.

Data leak from ZUS. The case reported to the Personal Data Protection Office is a notification to the prosecutor’s office

“The leak is the responsibility of a ZUS employee who is a member of one of the trade unions operating at the plant, who sent it by e-mail to the private e-mail address of the vice-chairman of the trade union, who is no longer an employee of ZUS,” we read. The case was confirmed by a ZUS spokesman.

– The security system at the Social Insurance Institution detected an incident related to the breach of personal data by an employee. The case was reported, among others, to the President of the Personal Data Protection Office. ZUS also submitted notifications to the prosecutor’s office. In accordance with the regulations, the plant will inform the persons concerned about the incident. Official consequences were taken against the ZUS employee – Paweł Żebrowski explained to the website.

A ZUS employee disclosed payers’ data

Lawyers estimate that if the leak of data from ZUS occurred accidentally, we are still dealing with a serious violation of the law. – Even if the disclosure of data was intended to protect the individual interests of employees within the control rights of unions, the scope of such disclosure must be examined. Nevertheless, in the context of a violation, the reasons for disclosure may be relevant and influence both the assessment of whether there has been a violation of the provisions of the GDPR, and then the decision to impose an administrative fine, as well as the determination of its amount. The scope of data in this case is rather a circumstance that negatively affects the assessment – said Dr. Dominik Lubasz, legal adviser, partner at the Lubasz i Wspólnicy law firm, in an interview with praw.pl.

Source: Gazeta

You may also like

Immediate Access Pro