Cybersecurity Policy Report, Polish Bank Fined Over GDPR Violations, (Aug 26, 2025)
By Tony Foley
The Polish data protection authority, Urzad Ochrony Danych Osobowych (UODO), has fined ING Bank Śląski 18.4 million Polish zloty ($5.03 million) based on its copying of identity documents in violation of the European Union’s General Data Protection Regulation (GDPR).
In a news release today announcing the fine, UODO said that, from April 2019 through September 2020, ING Bank scanned the identity documents of clients and potential clients to comply with an anti-money laundering law. UODO’s investigation focused on ING Bank’s legal basis for the processing of the personal data, the scope and type of data processed, and the method and purpose of data collection and sharing.
UODO found that prior to the enactment of the anti-money laundering law, the bank had not been copying customer ID documents. After conducting analyses and implementing changes to its banking processes, however, the bank adopted practices that assumed that a scan of the customer’s or potential customer’s ID should be performed in each case. As a result of this analysis, UODO concluded that ING Bank failed to conduct an individual risk assessment of a given client and their actions. In addition, such documents were scanned by the bank in cases unrelated to the anti-money laundering law (e.g., during a complaint regarding an ATM).
UODO held that the bank’s task was to conduct an individual assessment of money laundering and terrorism financing risk and to design security measures appropriate to its findings. The bank only had the right to conduct processing of personal information in identity documents and to scan or copy them if it could demonstrate that the risk required the implementation of a security program. Accordingly, ING Bank, as a data controller, violated articles 5(1)(a)-(c) and 6(1) of the GDPR because it was not justified in processing or copying identity documents of customers and potential customers in situations unrelated to its obligations under the anti-money laundering law, UODO said.
News: InternationalLegislation LitigationEnforcement DataPrivacy GDPR