ID scans without a necessity review
- Author: Arno Schlösser, DP-Dock GmbH
- Last updated: August 2026
- Category: Enforcement, General Obligations
The Polish Data Protection Authority (UODO) imposed a fine of 18,416,400 PLN (approximately 4.3 million euros) on a bank. Between April 1, 2019, and September 23, 2020, the bank systematically scanned identification documents of both existing customers and prospective customers without verifying in each individual case whether this was actually necessary to comply with anti-money laundering obligations. The Polish Anti-Money Laundering Act grants such an entitlement. However, the authority made it clear that this authority may not be exercised across the board but requires an assessment of necessity on a case-by-case basis.
This case demonstrates that data controllers cannot simply invoke legal obligations as a blanket justification for extensive data processing. Even where legal obligations exist, the principles of lawfulness, purpose limitation, and data minimization under Article 5(1) of the GDPR must still be observed. Whether and to what extent an identification document must actually be copied or scanned must therefore be assessed on a case-by-case basis.