DPO Conflict of Interest — Lessons from the PLN 978,000 Fine for Poczta Polska
Nearly a million złoty in fines — and not for a data leak, but for who held the DPO role in the company and how it was organised. The President of Poland’s Data Protection Authority (UODO) fined Poczta Polska (the Polish postal operator) PLN 978,128 (around EUR 232,000) for failing to ensure the independence of the DPO function and the resulting conflict of interest.
It is one of those decisions that should set off a warning light in many organisations — especially those where the DPO role was assigned “on the side” to someone from management. UODO sent a clear signal: simply appointing a DPO is not enough. The officer must be genuinely independent, their role must not clash with other duties, and the controller must be able to demonstrate this.
This article explains exactly what Poczta Polska was accused of, presents the three dimensions of a DPO conflict of interest on which the authority relied, and shows who in practice should not hold this role and how to guard against similar risk — including through outsourcing the officer function.
What Happened
The decision of the President of UODO (ref. DKN.5131.4.2025 of 2 January 2026, not final) followed proceedings opened on the authority’s own initiative in April 2025. The trigger was a data breach reported back in 2023: unauthorised access to data contained in a PIT-11 tax document. In examining the case, the authority looked not only at the incident itself but also at how the DPO function was organised.
And here a problem emerged. The DPO role was held by a person who was simultaneously the director of the unit responsible for organising and improving the information protection system — including personal data — and who additionally held a power of attorney to represent the company before UODO and the administrative courts in data protection matters. In practice, then, the officer was overseeing an area for which they were themselves responsible, and was acting on the controller’s behalf. UODO found this to breach Article 38(3) and Article 38(6) GDPR. Just as importantly, the company could not show that it had carried out a conflict-of-interest analysis before assigning the role.
It is worth noting straight away: the decision is not final, and Poczta Polska has announced it will appeal to the administrative court. Regardless of the final outcome, however, the case perfectly illustrates how the supervisory authority approaches DPO independence — and why it is a real financial risk.
The Legal Basis — Article 38 GDPR
The heart of the matter lies in Article 38 GDPR. The provision allows the officer to perform other tasks and duties too, but on one condition: the controller must ensure that they do not result in a conflict of interest (Article 38(6)). At the same time, in performing their tasks the officer receives no instructions, cannot be dismissed or penalised for them, and reports directly to the highest management level (Article 38(3)). In other words: the DPO is to monitor the compliance of processing with the GDPR (Article 39) — and it is hard to monitor objectively something you decide on yourself.
The requirement to avoid conflicts of interest also follows from Recital 97 and was confirmed by the Court of Justice of the EU in the X-FAB judgment (C-453/21): a DPO must not be entrusted with tasks that would lead them to determine the purposes and means of processing — because it is precisely the independent monitoring of those purposes and means that is the essence of the role.
The Three Dimensions of a DPO Conflict of Interest
The most interesting thing about this decision is that UODO broke the conflict of interest down into three dimensions. It is a practical lens for looking at your own organisation.
The organisational (structural) dimension. This concerns the DPO’s place in the structure — the officer should report directly to the highest management level. Interestingly, here UODO did not find a conflict: the DPO reported to the President of the Management Board. This is an important lesson — correct organisational reporting alone is not enough to establish independence.
The substantive dimension. This is where the core of the breach lay. As director of the unit responsible for organising the information protection system, the officer determined the purposes and means of processing — thus stepping into a role reserved for the controller. At the same time, under Article 39(1)(b) GDPR, they were to monitor the compliance of those same processes with the rules. The result: the DPO was in effect overseeing their own activity. In addition, the power of attorney to represent the company before UODO bound the officer by the principal’s instructions, directly undermining their independence and objectivity.
The temporal dimension. By combining the DPO role with director and attorney duties, the officer might simply lack the time to perform the Article 39 tasks properly. UODO stressed that the controller should analyse whether the DPO can carry out their duties adequately — and having a support team does not remove the need for that analysis (all the more so as the head of that team, who was also the deputy DPO, was affected by the same conflict).
The Real Sin: No Documented Analysis
Although the company argued that combining the roles caused no conflict, because the director “does not determine the purposes and means of processing”, it could not demonstrate this. Moreover, it admitted that the conflict-of-interest analysis had not been documented. That proved decisive.
Under the accountability principle (Article 5(2) GDPR), it is the controller who must prove it meets the GDPR’s requirements. A mere statement “we analysed it and there is no conflict” is not enough — a documented assessment of all relevant circumstances is needed, in particular the organisational structure. The absence of such documentation meant the company could not defend its position. This is the most important practical lesson from the case: the conflict-of-interest analysis must be carried out and written down — before the DPO is appointed.
Who in Practice Should Not Be a DPO
This logic yields a list of positions that, as a rule, should not be combined with the officer’s role — nor with that of the deputy. A conflict of interest arises especially where the DPO is at the same time:
- a management board member or owner who decides on the purposes and means of processing,
- an IT director or manager, or a person responsible for systems and information security,
- the head of HR, marketing, sales or customer service,
- the chief accountant or finance director,
- an attorney representing the controller in disputes and proceedings concerning personal data.
The common denominator: these are people who, in their area, decide how data is processed, or who act in the controller’s procedural interest. Adding the officer’s role makes oversight illusory — because they are supervising themselves. The same rule applies to the deputy DPO.
What Determined the Amount of the Fine
The amount of the fine (PLN 978,128) resulted from weighing aggravating and mitigating circumstances. On the aggravating side, UODO pointed among other things to:
- the intentional nature of the breach — a long-standing practice of combining the roles despite knowing the authority’s position on conflicts of interest,
- its continuous and long-lasting character — the model had operated even under the old 1997 data protection act, and the first remedial steps were taken only after more than six years of the GDPR being in force,
- earlier decisions against the company, indicating its general approach to GDPR compliance.
On the mitigating side, the decisive factor was that the company remedied the breach itself before the proceedings were opened — it dissolved the problematic unit, carved out the DPO function and entrusted the officer solely with GDPR tasks. This allowed a substantial reduction of the fine. It is worth noting that the breach was formal in nature and involved no demonstrated harm to individuals — and yet the fine reached almost a million złoty.
How to Do It Right — A Remediation Model
Paradoxically, the way Poczta Polska fixed the situation is a good model for other organisations. The key elements are:
- carving out the DPO function in the structure, alongside other units, reporting directly to the management board,
- entrusting the officer solely with GDPR tasks, without combining them with decision-making roles,
- separating the compliance-monitoring line (the DPO) from the departments implementing data protection solutions.
Add to this three constant elements of good practice: carrying out and documenting a conflict-of-interest analysis when appointing the DPO, ensuring genuine independence (no instructions, resources, time), and repeating that analysis periodically on organisational changes.
When Outsourcing the DPO Solves the Problem
An external data protection officer has one major advantage: by definition they do not determine the purposes and means of processing in the client’s organisation, nor do they hold a managerial position there, so the substantive conflict of interest disappears in practice. Outsourcing the DPO also delivers independence and objectivity (the officer is not entangled in internal dependencies or bound by a principal’s instructions), ongoing access to expert knowledge and current case law, and continuity of the function.
It is worth remembering that outsourcing is also governed by the rules from the guidance: a person responsible for contact must be designated, and the officer must be given the conditions and time to perform their tasks properly. A well-constructed DPO outsourcing agreement addresses these points expressly.
Checklist — Is Your DPO Genuinely Independent
- The DPO (and the deputy) is not a management board member or a person deciding on the purposes and means of processing.
- The DPO does not oversee an area for which they are operationally responsible.
- The DPO does not represent the controller as an attorney in data protection matters.
- A conflict-of-interest analysis has been carried out and documented (organisational, substantive and temporal dimensions).
- The DPO reports directly to the highest management level and receives no instructions on how to perform tasks.
- The DPO has adequate resources and time for the Article 39 tasks.
- The monitoring line (the DPO) is separated from the implementing departments.
- The DPO’s contact details have been notified to UODO and published.
- The independence analysis is repeated periodically and on organisational changes.
Need an Independent Data Protection Officer?
The Poczta Polska case shows that a DPO conflict of interest is a real financial risk — and that it is worth making sure in good time whether the officer in your organisation is genuinely independent and whether the conflict-of-interest analysis has been properly documented. At the Law Office of Dr Joanna Maniszewska-Ejsmont, we provide outsourcing of the data protection officer function and conflict-of-interest analysis for DPOs already appointed — ensuring independence, objectivity and expert support.

Check the details of our DPO outsourcing service and get in touch — we will help you organise the officer function in your company safely.
