Recently, I was informed that Dom Development S.A., a major residential developer in Poland, suffered a cyberattack resulting in the unauthorized extraction of data from its IT systems. According to the official notification, my personal data may have been affected.
What is particularly concerning is the breadth and sensitivity of the data categories involved. Based on the communication sent to impacted individuals, the potentially exposed data appears to include not only standard identification and contact details, but also PESEL, identity document data, bank account numbers, transaction history, financial information related to crediting, civil status, and health-related data. This represents a combination of high-risk personal data and special categories under GDPR.
While the company states that it has complied with its obligations under Articles 33 and 34 of the GDPR, the timeline between the incident and direct communication to affected individuals highlights how critical incident detection, escalation, and transparent communication are as part of mature data governance. Timeliness in this context is not a formality, it is a core risk-mitigation control.
An additional concern is the sequence of communication. In my case, I became aware of the incident through media reports and public social media discussions before receiving a direct notification from the company. From a data protection and incident response perspective, learning about a potential breach affecting one’s own data via third-party channels undermines trust and reinforces the need for prompt, direct, and prioritized communication with affected data subjects.
From a risk management perspective, the response also raises questions about whether the remedial measures offered are proportionate to the potential impact of the breach. Beyond formal notifications and general guidance, there appears to be limited evidence of enhanced support, concrete remediation, or accountability measures that would meaningfully reduce downstream risk for data subjects. In incidents involving identifiers with long-term consequences, compliance alone may not be sufficient to restore trust.
I am sharing this not to sensationalize a single incident, but to underline a broader point: organizations that process large volumes of sensitive personal and financial data must treat cybersecurity and data protection as core operational risks, not auxiliary IT concerns. Incident response maturity, realistic threat modeling, and timely communication are essential components of that responsibility.
We should continue to expect high standards of accountability and transparency when it comes to the protection of personal data. Repeated exposure to such incidents erodes trust, even when formal compliance requirements are met.
It is my understanding this case has already been notified to Urząd Ochrony Danych Osobowych and the DPA as always will keep up their good work of oversight and control Mirosław Wróblewski
10