Cybersecurity Policy Report, Poland’s Data Protection Authority Sees Potential Criminal Activity in Data Processing, (Oct 8, 2025)
The Polish data protection authority, Urzad Ochrony Danych Osobowych (UODO), has notified prosecutors about potential criminal activity linked to the publication of images on a website without the knowledge or consent of the data subjects.
The notification concerns two websites where users shared sexually explicit photos or videos of women that might have been taken without their consent, UODO said in a news release.
In some cases, “the materials reveal not only faces but also other characteristic features of the individuals, such as tattoos,” it said.
If the individuals visible in the recording or photos were unaware that their image would be used or that they were photographed or recorded in an intimate situation, the data may have been processed without the consent of the data subject and without any other legal basis relating to special categories of data in violation of the European Union’s General Data Protection Regulation (GDPR), it noted.
According to UODO, the described actions should be considered unlawful and, therefore, “it was necessary to submit a notification to the prosecutor’s office.”
News: InternationalLegislation DataPrivacy GDPR LitigationEnforcement