Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations
    • DOGE Copied ‘Entire Country’s’ Social Security Data to ‘High-Risk’ Database, Whistleblower Says
    • D. Idaho: Health Insurance administrator prevails over its accidental data breach victims
    • EU Establishes Emergency Fund for Major Cyber Incidents
    • Polish Bank Fined Over GDPR Violations
    • U.K.’s ICO Seeks Input on Data Protection Complaint Procedures
    • Wash. App.: Privacy Act claim against Seattle Children's Hospital over website tracking dismissed
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations

    Cybersecurity Policy Report, Polish Bank Fined Over GDPR Violations, (Aug 26, 2025)

    By Tony Foley

    The Polish data protection authority, Urzad Ochrony Danych Osobowych (UODO), has fined ING Bank Śląski 18.4 million Polish zloty ($5.03 million) based on its copying of identity documents in violation of the European Union’s General Data Prote ...

    By Tony Foley

    The Polish data protection authority, Urzad Ochrony Danych Osobowych (UODO), has fined ING Bank Śląski 18.4 million Polish zloty ($5.03 million) based on its copying of identity documents in violation of the European Union’s General Data Protection Regulation (GDPR).

    In a news release today announcing the fine, UODO said that, from April 2019 through September 2020, ING Bank scanned the identity documents of clients and potential clients to comply with an anti-money laundering law. UODO’s investigation focused on ING Bank’s legal basis for the processing of the personal data, the scope and type of data processed, and the method and purpose of data collection and sharing.

    UODO found that prior to the enactment of the anti-money laundering law, the bank had not been copying customer ID documents. After conducting analyses and implementing changes to its banking processes, however, the bank adopted practices that assumed that a scan of the customer’s or potential customer’s ID should be performed in each case. As a result of this analysis, UODO concluded that ING Bank failed to conduct an individual risk assessment of a given client and their actions. In addition, such documents were scanned by the bank in cases unrelated to the anti-money laundering law (e.g., during a complaint regarding an ATM).

    UODO held that the bank’s task was to conduct an individual assessment of money laundering and terrorism financing risk and to design security measures appropriate to its findings. The bank only had the right to conduct processing of personal information in identity documents and to scan or copy them if it could demonstrate that the risk required the implementation of a security program. Accordingly, ING Bank, as a data controller, violated articles 5(1)(a)-(c) and 6(1) of the GDPR because it was not justified in processing or copying identity documents of customers and potential customers in situations unrelated to its obligations under the anti-money laundering law, UODO said.

    News: InternationalLegislation LitigationEnforcement DataPrivacy GDPR

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use