The Voivodeship Administrative Court in Warsaw held that prior knowledge does not legalise disclosure

The full text of the judgment in the Judykatura database shows a dispute over the significance of the recipient’s prior knowledge of the data. The full text of the judgment in the Judykatura database also explains the limits of the effect of a final civil judgment on the assessment of the lawfulness of processing. The Voivodeship Administrative Court in Warsaw confirmed that these issues must be assessed separately.

This article is available free of charge in full. Subscribe to our newsletter to receive new case notes and a discount code for your first subscription.

Loading

⚖️ Key theses (click to expand)

Thesis 1 — Recipient’s prior knowledge

The mere fact that a person to whom the bank later disclosed the data had previously possessed the data subject’s personal data does not affect the lawfulness of the bank’s processing. The bank did not demonstrate that the processing was justified by any of the legal bases under Article 6(1) GDPR.

Thesis 2 — Separate safe-deposit agreements

The absence of a document confirming that the safe-deposit transfer procedure was tripartite does not permit the conclusion that the third party was entitled to obtain information about an agreement entered into by another person. The termination by the third party of a safe-deposit agreement and the conclusion, on the same day, of a separate agreement for the same safes by another person constitute two unrelated events.

Thesis 3 — Separate legal regimes

The assessment of the lawfulness of personal data processing under Article 6(1) GDPR belongs to public law and is distinct from the assessment of an infringement of personal rights based on a breach of banking secrecy, which belongs to private law. The dismissal of a civil claim concerning a breach of banking secrecy therefore does not determine the lawfulness of personal data processing.

Thesis 4 — Independence of the DPA

The President of the Personal Data Protection Office is a specialised and independent supervisory authority entitled to establish independently and autonomously the circumstances relevant to the lawfulness of personal data processing. The authority does not determine civil claims or assess the correctness of the application of law in matters falling within the jurisdiction of other courts and authorities.

Thesis 5 — Binding force of judgments

The binding force of a final judgment extends only to its operative part and not to the grounds that led to the ruling. Civil-law claims concerning infringements of personal rights and claims available under the GDPR are not identical and remain independent of one another.

The judgment of 8 April 2026 concerned a situation in which a bank issued a certificate to a third party containing a customer’s personal data and information that she had entered into safe-deposit agreements. The President of the Personal Data Protection Office issued the bank with a reprimand for an infringement of Article 6(1) GDPR, and the court dismissed the bank’s appeal against that corrective measure.

The case is of practical importance because the court clearly distinguished a recipient’s factual knowledge of information from the existence of a legal basis for its renewed disclosure. Confirmation of data by a controller is processing which itself requires the controller to demonstrate one of the legal bases under Article 6(1) GDPR.

What was the case about?

The bank provided the customer’s daughter with a certificate confirming that the customer had entered into agreements for the rental of specific safe-deposit boxes. The bank argued that the recipient already knew this information because she had previously been a party to agreements concerning those same safes. It also maintained that the customer’s later agreement formed part of the transfer of the use of the safes.

The court did not accept that argument. The bank did not provide a document showing that the procedure had been tripartite and carried out with the agreement of the customer, her daughter and the bank. The findings instead showed that the third party had terminated her own agreement and that the customer entered into a separate agreement for the same safes on the same day.

Is prior knowledge of the data sufficient?

No. The court upheld the President of the Personal Data Protection Office’s finding that the recipient’s prior possession of the information did not affect the lawfulness of the bank’s subsequent disclosure.

The court stated expressly that “the mere fact that the third party to whom the Bank subsequently disclosed the data had previously possessed the complainant’s personal data does not affect the lawfulness of the Bank’s processing of those data” (editorial translation).

This is an important clarification. A controller cannot equate the absence of novelty of information for the recipient with the absence of processing or with the existence of a legal basis for processing. Each disclosure of personal data requires an independent assessment of compliance with Article 6(1) GDPR.

The court found that the bank had demonstrated neither the customer’s consent, nor necessity for the performance of a contract, nor necessity for compliance with a legal obligation. Nor was it established that the recipient was entitled to obtain the information as a beneficiary of banking secrecy.

Does a civil judgment on banking secrecy bind the DPA?

The bank relied on the final dismissal of a civil claim concerning a breach of banking secrecy. The administrative court nevertheless held that this ruling did not determine the lawfulness of personal data processing.

The court stressed that “the examination of the lawfulness of personal data processing under Article 6(1) GDPR, which belongs to public law, must be distinguished from the assessment of an infringement of personal rights based on a breach of banking secrecy, which belongs to private law” (editorial translation).

These are two independent legal regimes. The dismissal of the civil claim meant only that the specified tort had not been established in the circumstances of that case. It did not remove the obligation to assess independently whether the bank had a legal basis for disclosure within the meaning of the GDPR.

The court also recalled that the binding force of a final judgment applies to its operative part, not to the grounds that led to the ruling. There was therefore no identity between the subject matter of the civil case and the proceedings conducted by the President of the Personal Data Protection Office.

Significance for controllers

The judgment confirms that a controller should document the legal basis for every disclosure of personal data, including where the recipient already knows particular information from earlier dealings with the data subject. The recipient’s knowledge of the data does not replace consent, necessity for the performance of a contract or a legal obligation.

The ruling also confirms the independence of the President of the Personal Data Protection Office in examining compliance of processing with the GDPR. An assessment made in civil litigation concerning banking secrecy or personal rights neither replaces that examination nor determines its outcome.

The judgment is not final.


This material was prepared partly with the use of a general-purpose AI model and, despite due care, may contain errors. The information provided does not constitute legal advice — it reflects solely the Author's view.

The rest of this analysis, all theses and the full text of the ruling are available with an AKTUALNOŚCI PLUS subscription.

Find out how EU supervisory authorities, administrative and civil courts and the CJEU reason their decisions — and keep your organisation aligned with current case law.

Join — see pricing   Have an account? Log in

Wersja polska / Polish version