The editorial team received a report from a driver who, at the beginning of July, received an SMS from a local vehicle inspection station. The message contained information about the approaching expiry of the vehicle’s technical inspection.

The man said that he had never given marketing consent, had not signed up for any notification system, and had not provided the station’s employees with his phone number.

The station admitted that the numbers are transferred to an external system

In correspondence with the customer (we have screenshots), a station representative indicated that customers’ phone numbers are entered into an external server, which then automatically sends SMS messages reminding them of the date of their next inspection.

When the Reader asked about the source from which the specific phone number had been obtained and the legal basis for its processing, the company representative reportedly gave a general answer that phone numbers are “provided by the customers themselves (...) if they wish”.

The driver decided to refer the matter to several supervisory and inspection authorities. The notifications were reportedly submitted, among other ways, via the ePUAP/e-Delivery platform.

The County Office confirmed receipt of the notification

The editorial team sent questions to the County Office in Bolesławiec, which exercises statutory oversight over vehicle inspection stations. The office confirmed that it had received a report concerning the matter. However, it does not plan to conduct an inspection in this regard:

(…) because this does not fall within the scope of supervision referred to in Article 83b of the Act of 20 June 1997, the Road Traffic Act (Journal of Laws of 2024, item 1251, consolidated text).

The Personal Data Protection Office also confirms: the complaint was received

The matter was also referred—among others—to the Personal Data Protection Office. The office confirmed that it had received a complaint concerning the entity in question.

As reported by the spokesperson for the Personal Data Protection Office, Karol Witowski:

(...) a complaint against the indicated (...) entity was submitted to the President of the Personal Data Protection Office. However, we provide details concerning complaints from individuals only to the parties to the proceedings or their representatives, if appointed.

The spokesperson stressed that the office cannot currently determine whether the regulations were breached: – At the same time, I would like to inform you that the President of the Personal Data Protection Office may take a position only in an administrative decision concluding the proceedings, after all the circumstances of the case have been examined.

The GDPR requires a legal basis for data processing

The Personal Data Protection Office recalled that processing personal data itself is not prohibited, but must take place in accordance with specific principles:

The GDPR does not prohibit the processing of personal data, but sets out the principles according to which it should be carried out. Therefore, a controller must have one of the legal grounds specified in Article 6 of the GDPR in order to process someone’s data.

The office pointed out that user consent is one possible legal basis for data processing, but the controller must be able to demonstrate that consent was obtained:

If data processing is based on the individual’s consent, then under Article 7 of the GDPR the controller must be able to demonstrate that the individual gave that consent (i.e. document it).

The Personal Data Protection Office also stressed that consent must be freely given, specific and informed:

Consent must also be freely given, meaning that, for example, the provision of a service cannot be made conditional on giving consent if processing data for the specified purpose and to the specified extent is not necessary to provide that service.

What happens next in the case?

At this stage, there is no ruling establishing that a specific station breached the regulations. Proceedings conducted by the competent authorities are intended to clarify, among other things, how the phone numbers were obtained, on what legal basis they were processed, and whether customers actually consented to receiving the messages.

The case nevertheless highlights a broader problem concerning the use of customers’ contact details by businesses. A phone number provided in connection with the provision of a service cannot always be automatically used for additional purposes, such as sending promotional messages or reminders, without meeting the requirements arising from personal data protection regulations.