08/27/2026 | Press release | Archived content
1. As a person whose data has been compromised, what can I do after receiving notification from the data controller about an incident involving my personal data?
Answer: In this situation, consider blocking your PESEL number. You can do this, for example, through the mObywatel app or by visiting any city or municipal office. Be cautious when providing personal information online or over the phone. Do not respond to suspicious messages. Carefully review any messages sent to you-such as text messages or emails-to avoid, for example, a phishing attack, which may aim to steal your information or gain access to online banking systems or other services you use.
2. Can I file a complaint against the data controller regarding the leak of my personal data from MyDr?
Answer: You do not need to file an individual complaint regarding this matter. The President of the Personal Data Protection Office will conduct an inspection of the technical and organisational measures implemented by the data processor (MyDr). However, you may exercise the rights granted to you under Chapter III of the GDPR by requesting that the controller of your personal data comply with them. Keep in mind, however, that the controller will not always be able to respond to you without undue delay. In any case, the controller should respond within one month of receiving the request. If necessary, this deadline may be extended by an additional two months due to the complexity of the request or the number of requests. Within one month of receiving the request, the controller must inform the data subject of such an extension, specifying the reasons for the delay. A complaint filed with the President of the Personal Data Protection Office (UODO) due to a lack of response within the aforementioned time limit is considered premature.
3. What steps should the data controller take in response to the incident at MyDr?
Answer: If you have received confirmation from MyDr that the incident also involved data for which you are the data controller, you should assess whether it is necessary to notify the President of the Personal Data Protection Office (UODO). This requires an analysis of the breach in terms of the risk of infringing the rights or freedoms of natural persons. Remember that, pursuant to Article 33(1) of the GDPR, you must report the breach to the President of the Personal Data Protection Office without undue delay; if possible, no later than 72 hours after the breach is detected. If you submit the report after this deadline, include an explanation of the reasons for the delay. If you determine that the risk to the rights or freedoms of natural persons is high, you must notify the data subject of such a breach without undue delay.
Information on data controllers' obligations related to data breaches is available in the UODO guide at the following link: https://uodo.gov.pl/pl/138/3561 (polish language).