WhatsApp Instead of a Corporate System: Poland’s Data Protection Authority Fines Energa-Obrót Partner

LAWWhatsApp Instead of a Corporate System: Poland’s Data Protection Authority Fines Energa-Obrót Partner
- Advertisement -Translation agency in Poland – professional language servicesTranslation agency in Poland – professional language services

Sales representatives used WhatsApp to send documents belonging to Energa-Obrót customers. Scans and photographs of agreements were stored on private phones, while some communication may have taken place outside the European Economic Area. Poland’s Personal Data Protection Office, known as UODO, concluded that the company and its partners had failed to provide adequate safeguards. One entity was fined PLN 10,145.

An unauthorised messaging app, private phones and customer documents exchanged between sales representatives — this was the case investigated by the President of UODO after Energa-Obrót reported a personal data breach.

The proceedings resulted in formal warnings for the data controller and the processors involved. One of the company’s business partners was also fined PLN 10,145.

UODO found that, in the customer-service process, there had been insufficient effective control over how personal data was actually handled in practice.

Sales representatives used WhatsApp for work

The case concerned a door-to-door sales network acting on behalf of Energa-Obrót during the pandemic. Sales representatives visited customers at home and offered, among other things, amendments to existing contracts.

During the subsequent investigation, it emerged that people involved in sales had been using WhatsApp as a business communication tool. The problem was that the app had not been approved by the data controller for processing customer information.

Photographs and scans of documents concluded with Energa-Obrót customers were found on the private phone of a former sales representative. A screenshot provided to the company indicated that conversations had also taken place in group chats.

This meant that customer data could have reached individuals and systems over which the data controller did not have full control.

The case came to light through a payment dispute

The matter was uncovered by chance. A former sales representative contacted Energa-Obrót seeking help in recovering money owed to him by his former employer.

During the conversation, it emerged that he and other sales representatives had used WhatsApp to pass on work-related instructions and customer documents. The company launched an internal investigation and subsequently reported the breach to UODO.

Energa-Obrót established that the issue certainly involved the data of at least 15 people. However, the scale may have been greater because the messaging app had been used for many months.

A private phone is not a secure corporate system

The business partner that allowed the use of the messaging app argued that WhatsApp had merely been intended to streamline the work of sales representatives during the pandemic. Since representatives visited customers in person, they needed a fast way to communicate.

The entity also pointed out that staff had been authorised to process personal data and had signed confidentiality and non-compete commitments.

UODO concluded, however, that this was not enough. Signing documents alone is insufficient when a company does not control the tools employees actually use.

From a GDPR perspective, it matters not only who has access to data, but also where the data is stored, how it is transmitted and whether the organisation can supervise the process.

Some data may have been processed outside the EEA

The materials submitted to UODO included information suggesting that some communications carried out through the app may have taken place outside the European Economic Area.

This increased the risk further. Transfers of personal data outside the EEA require appropriate legal grounds and safeguards. A company should know where customer data is transferred, who may gain access to it and whether the service provider ensures the required level of protection.

In the case of widely used consumer messaging apps, companies often do not have full control over these elements.

UODO: Energa-Obrót did not verify its partner thoroughly enough

The President of UODO found that Energa-Obrót had failed to implement appropriate technical and organisational measures to ensure the security of personal data.

According to the authority, the company also did not verify sufficiently whether the partner processing the data was actually applying the required safeguards.

This is an important signal for companies using outsourcing. A data controller cannot stop at signing a data-processing agreement. It should also verify how its partner operates in practice.

This includes audits, procedures, training, and control over the devices and applications used by employees.

Fine imposed on the business partner

The entity that allowed sales representatives to use WhatsApp received a formal warning and an administrative fine of PLN 10,145.

UODO noted that discrepancies emerged during the proceedings between Energa-Obrót’s explanations and the partner’s position. The authority concluded that the processor had attempted to limit its own responsibility and shift it onto others.

The office stressed that a data processor is not merely an executor of the controller’s instructions. It has its own obligations under the GDPR and is responsible for ensuring that appropriate safeguards are applied.

Companies should be wary of “convenient” tools

The case shows that the biggest personal data protection problems do not always arise from sophisticated cyberattacks. Sometimes all it takes is a private phone, a group chat and a photograph of a customer’s document.

For an employee, this may seem like a quick and convenient solution. For the company, it may mean a GDPR breach, an obligation to report an incident, an investigation by the regulator and the risk of a fine.

Organisations using external sales networks, call centres, agents, marketing companies or customer-service subcontractors should be particularly careful. The more people involved in a process, the more difficult it becomes to retain control over data.

The conclusions are straightforward: companies should clearly specify which tools may be used, prevent private messaging apps from being used to exchange customer data, and regularly verify whether the rules are being followed.

Case reference: DKN.5131.7.2022

Check out our other content
Related Articles
The Latest Articles