The decisions issued by the president of the Office for individual Data Protection most frequently concern deficiencies which data controllers do in terms of compliance with the procedures, which sometimes comes to light after cyber attack**. In CyberDefence24, we described cases where penalties were imposed e.g. [because of the anti-virus exclusion](https://cyberdefence24.pl/cyberdefence24.pl/cyberdefence24.pl/cyberdefence24.pl/cyberdefence24.pl/cyberdefence24.pl/cyberdefence24.pl/cyberdefence24.pl/cyberdefence24.pl/cyberdefence24.pl/cyberdefence24.pl/politics-and-law/data protection-cara-za-wolok-w-w-in-in-in-in-in-infring). **The errors are besides committed by public authorities**, [such as the National Prosecutor's Office](https://cyberdefence24.pl/politics-i-law/national prosecution-republication-data-injured).