Poland's data protection authority fined a door-to-door sales partner of Energa-Obrot for letting reps trade customer contract scans over personal WhatsApp with no oversight.
Why It Matters
The decision, published 22 June 2026, targeted a business partner running field sales for the energy company: representatives used personal phones and WhatsApp to pass around scanned ID documents and signed contracts, with no approved tool, no device policy, and no data processing agreement covering the practice. The fine itself was modest, 10,145 zloty, but it confirms UODO will chase the unauthorized channel, not just the underlying breach.
What To Do About It
If field staff, sales reps or subcontractors handle client documents on personal phones, check what app they actually use to send them. Put an approved tool and a written data processing agreement in place with anyone outside the company who touches that data, before an audit finds the gap for you.
Related Signals
Germany's BSI set 31 July 2026 as a de facto NIS2 registration deadline, with only about 18,500 of an estimated 29,000 to 40,000 affected companies registered by late May.
28 Jul 2026
OpenAI reportedly lost 1.5 million subscribers in under 48 hours after agreeing to let the US Department of Defense use its AI models.
5 Mar 2026