The Importance of a Robust Data Protection Officer Relationship: Case Study
The Importance of a Robust Data Protection Officer Relationship: Case Study
Data Protection Officers (“DPOs”) are the backbone of General Data Protection Regulation (“GDPR”) compliance within a business. They are responsible for ensuring adherence to GDPR and preventing any breaches within the business. DPOs help to identify risks early on in a process to help a business avoid problems by advising on important compliance risks around new software, contracts or where personal data is stored.
A DPO is like a business’ “watchdog”, making sure that a business respects, protects and does not misuse personal data.
McDonald’s Poland Enforcement – 3.8 Million Euro Fine
Background:

McDonald’s Poland entrusted sensitive employee data, including names, PESEL numbers (Polish national ID), passport details, job roles and shift information, to 24/7 Communication, a third-party supplier responsible for managing an employee scheduling module.
What happened:
Due to misconfigured servers and a lack of basic security controls, this data was exposed on a publicly accessible server. The breach affected employees of both McDonald’s corporate-owned and franchise restaurants.
While both organisations had signed a data processing agreement (“DPA”), the agreement did not satisfy GDPR’s compliance requirements.
The €3.8 million penalty levied by the Polish Data Protection Authority (UODO), alongside additional sanctions against the data processor, represents one of Poland’s most significant GDPR enforcement actions. It also serves as a stark reminder for jurisdictions across Europe: do not be complacent when it comes to involving your DPO and staying on top of your obligations in relation to GDPR compliance.
Crucial Takeaways:
- DPOs should be heavily involved in the procurement and management process of technology, software and processors. Regulators will not take kindly if DPOs are left out of key decisions. A DPO’s job is to help protect your business and mitigate risks, whether this is from an existing business relationship or a new relationship. A DPO should be involved at the earliest opportunity.
- Appropriate due diligence processes should be undertaken to verify a processor’s, software or compliance tools with GDPR. DPOs will also help advise a business on the ‘right fit’ for their business needs. Due diligence should include evaluating why the business needs to procure the service, examining security practices, reviewing data protection policies such as privacy policies, terms and conditions and more.
- Data minimisation should be at the forefront of a business’ data protection practices, underpinned and upheld by the DPO. Any personal data retained should only be retained for a necessary, documented purpose. This helps to prevent retaining personal data for too long and breaching principles of GDPR.
- Breach notifications should be handled as soon as possible, and in the UK, the regulator (the UK Information Commissioner’s Office (“ICO”)) should be notified 72 hours at the latest when a business has knowledge of the breach. When this is not done, regulators may seek to impose more stringent enforcement consequences.