I received two letters from the Commissioner for Human Rights. A case that initially seemed to involve incomprehensible intricacies of GDPR, cookies, and data processing is changing before our eyes into an evident lack of oversight and likely mismanagement.
Table of Contents
Below, I publish the full text of my response addressed to the RPO (Rzecznik Praw Obywatelskich, which translates to the Polish Commissioner for Human Rights or Ombudsman—an independent constitutional authority safeguarding the rights and freedoms of citizens). It was prepared in relation to the initial intervention of the Commissioner and the official response from Deputy Mayor Tomasz Piotrowski, which the RPO sent to me for a reply. In it, I break down the claims of the officials and confront them with hard evidence from my audits. I am pasting the text in its entirety, redacting only the fragments regarding the technical details of an ongoing security audit and a classified attachment that I submitted directly to the Commissioner.
Additionally, I would like to inform you that all the files, documents, and materials I have collected over the past months will be made available in the Evidence tab. I will provide more information about this in a separate text tomorrow. I would also like to take this opportunity to sincerely thank the Łódź Cała Naprzód (ŁCN) association for sharing selected source materials.
Subject: letter dated September 11, 2026, ref. no. VII.501.122.2026.KK, forwarding the response of the Deputy Mayor of Lodz Tomasz Piotrowski dated September 9, 2026 (ref. no. DSiP-BPM-II.007.1.2026) to the Commissioner’s intervention of August 12, 2026.
Dear Mr. Head of Department,
Thank you for forwarding the response of the Deputy Mayor of the City of Lodz and for the opportunity to present my assessment. As a resident of Lodz, I have been investigating this matter for 2 years and comparing successive letters from the Lodz City Hall sent to various addressees regarding this issue, which in itself provides material for evaluation, regardless of the substantive layer.
The following assessment is based solely on documents that I possess in full: the public-private partnership agreement of October 28, 2020, the personal data processing entrustment agreement of August 17, 2021, along with Annex No. 1, Necessity Protocol No. 1/2023 of December 19, 2023, Annex No. 1 of January 2, 2024, the data protection impact assessments (DPIA) in draft and final versions and the Risk Analysis prepared for the Lodz Tourism Organization (ŁOT), the report on the personal data protection audit of the processor QB Sp. z o.o. prepared by DAGMA Sp. z o.o. on April 23, 2021, the privacy policy of the Lodz Resident Card program, the commercial offer of Łódź Media Group, three separate letters from the Lodz City Hall discussed below, and my own technical audit of the network traffic of the mops.uml.lodz.pl domain and 36 other municipal domains and services; the full documentation of this audit is publicly available at dowody.dadalo.pl/lodz-rodo-2025/. [REDACTED - CONCERNS SECURITY AUDIT AND CLASSIFIED ATTACHMENT]
Re. 1 — internal control and the consent mechanism - Google Consent Mode
The City admits that “due to a technical error in the operation of the script, a dataset for the Google Analytics tool ad_user_data with the flag set to ’not set’ was being transmitted to the Google analytics service,” adding that this flag “results in the lack of an explicit signal regarding granted consent, which results in Google blocking the ability to use this data.”
This response requires correction on a factual level, regardless of the outcome of any further technical analysis. According to the official Google Consent Mode documentation, in “Advanced Consent Mode,” the lack of user consent does not mean the absence of any data transmission to Google servers. Google tags load with a default consent denial status and, throughout the duration of this lack of consent, send so-called cookieless pings—signals containing, among others, a timestamp, browser type, and consent status, without saving cookies or persistent identifiers. Only in “Basic Consent Mode” is transmission completely blocked until consent is given.
The City’s response does not specify which of these two modes the system was operating in, and the statement that Google will “block the use of data” describes a restriction on how the data is used by Google, not a lack of transmission from the municipal infrastructure. These are two different issues under Article 4(2) of the GDPR—the act of transmission itself, regardless of further use by the recipient, is subject to assessment regarding a legal basis.
This is not a purely theoretical issue. I conducted my own technical audit using, in addition to Google Tag Assistant tools, the method of capturing network traffic in a sterile browser session (cookie storage empty prior to navigation, zero interaction with any consent mechanism). I document, among other things on the example of the mops.uml.lodz.pl domain, that within less than a second of starting navigation—and therefore before the document finished loading (DOMContentLoaded)—the browser sends a full “page_view” event to Google servers containing a persistent client identifier (cid=1271838583.1773049290), the exact URL and title of the visited page, a full technical fingerprint of the browser, and session markers—which means data going far beyond the scope of a “cookieless ping” proper for a correctly configured advanced mode. The exact same packet, with the exact same identifier and the same parameter gcd=13l3l3l2l1l1 that the City cites in its response, simultaneously hits the endpoint stats.g.doubleclick.net/g/collect—which belongs to Google’s advertising infrastructure, not solely the analytical one. Both transmissions ended with an HTTP 204 code, which confirms their technical acceptance by Google’s servers.
The City previously admitted the exact same thing in an even more literal form: in a letter dated June 30, 2026, to councilors Sebastian Bulak, Marcin Buchali, and Piotr Cieplucha (ref. no. DSiP-BPM-IV.0003.1.2026), Deputy Mayor Piotrowski explains the same mechanism with the words: “Google tags should behave in a traditional way, that is, the tags will indeed try to save and read cookies (e.g., _ga or _gcl_au) on the user’s device without hindrance, but a feature block may apply in the EU/EEA—even though the data physically hits Google servers.” This is a description of a mechanism operating fully, not limited to cookieless pings, confirmed by the City itself months before the response given to the Commissioner.
Therefore, the City’s response to question 1 is not corroborated by the recorded network traffic: the transmission documented above goes beyond the “cookieless ping” configuration designed for Google’s Advanced Consent Mode.
I also point out that the above analysis, much like the City’s response to questions 1 and 2, applies exclusively to Google mechanisms. My broader audit, published at dowody.dadalo.pl/lodz-rodo-2025/, also covers other tracking mechanisms, including Meta Pixel, on other domains of the same family. The City’s response, consistently limited to Google, therefore does not cover all third parties actually involved.
Re. 2 — scope of transfers to third parties, including the MOPS website
The City responds that “apart from those listed in the response to Q. 1, no other data was transmitted and to no other third party,” despite the fact that the Commissioner’s question 2 explicitly pointed to the website of the Municipal Social Welfare Center (MOPS) in Lodz as a subject of particular interest.
I have direct evidence that this response does not reflect the facts regarding this specific domain. The technical audit of mops.uml.lodz.pl, conducted in a sterile browser session (cookie storage empty prior to navigation, zero interaction with any consent mechanism), documents that:
- within 2.3 seconds of starting navigation, meaning before the document finished loading (DOMContentLoaded), the cookies _ga (GA1.1.1271838583.1773049290), _gid, _gat_gtag_UA_25825547_40, and _ga_30F084ZHSL are saved in the browser—all within the scope of the parent domain .uml.lodz.pl, and thus readable also on other subdomains of the City Hall, not only on mops.uml.lodz.pl;
- the site simultaneously loads the Universal Analytics library (property UA-25825547-40), the gtag.js script for GA4 property G-30F084ZHSL, the Facebook SDK (connect.facebook.net/pl_PL/sdk.js), and a script loading from an external ad server ads.biblioteka.lodz.pl/www/delivery/asyncjs.php;
- less than a second after starting navigation, the browser sends a full page_view event using the POST method simultaneously to region1.analytics.google.com/g/collect and to stats.g.doubleclick.net/g/collect—an endpoint belonging to advertising infrastructure, not analytical—containing the persistent identifier cid=1271838583.1773049290, the exact address (dl=https://mops.uml.lodz.pl/) and page title (dt=Miejski Ośrodek Pomocy Społecznej w Łodzi: MOPS), a full fingerprint of the browser and operating system, and the parameter gcd=13l3l3l2l1l1—exactly the value that the City cites in response to question 1 as proof that the data “was not used”;
- the consent mechanism on the City Hall’s domains (mops.uml.lodz.pl and, as evidenced by an analogous directory structure, mosir.lodz.pl) is served from the path …/Vendors/cookie-box/cookiebox.js. The source file header identifies it as “Cookie Box, a simple Cookies Law information” version 2.0, originating from the repository github.com/r4fx/cookie-box (currently the project has been deleted from GitHub), with a release date of March 16, 2014, and a last update on January 31, 2016—over two years before the GDPR entered into force (May 25, 2018) and with no recorded updates since then.
- in a letter dated June 30, 2026, to councilors, the City describes this same consent mechanism as a “proprietary cookie consent tool created for the needs of the Lodz City Hall”; the source code header of this mechanism points to the opposite—an off-the-shelf external library from before 2016, un-updated since then.
The above data comes from the domain pointed out explicitly by the Commissioner as an object of special concern due to the life situations of its users. Their scope—a persistent identifier, the address and title of a specific subpage, a full technical fingerprint of the device—allows a specific visit to the municipal social welfare center’s website to be linked to a user’s browser identifier, which is also readable on other City Hall websites.
The City’s response to question 2, in the part concerning the mops.uml.lodz.pl domain, is therefore not confirmed by the factual situation documented above. This is not the only domain within the municipal infrastructure that should be a matter of particular concern.
Re. 3 — access to public information on BIP websites
The City limits itself to stating that “there has been no restriction of application-free access to public information for users of the Public Information Bulletin (BIP) website of the Lodz City Hall,” without addressing the technical aspect of the Commissioner’s question—namely, whether the very process of loading the BIP website entails launching analytical-advertising mechanisms before any user interaction with the consent banner.
The technical availability of the content (the ability to read or print it) and the lack of behavioral data transmission in the background are two separate issues. A design in which access to public information entails—even exclusively on a technical level, without a formal restriction on access—the transmission of data to a third party’s commercial infrastructure prior to any user consent, raises doubts in light of Article 61 paragraph 1 of the Polish Constitution in conjunction with the data minimization principle of Article 5(1)(c) GDPR, regardless of whether access to the content itself remains unrestricted.
By way of supplementation, I point out that the domain mosir.lodz.pl is another example of a municipal website where – despite nearly a year having passed since my notification to the UODO – a sham consent mechanism based on outdated external code from 2014 is still actively operating.
Initial Observation: setting the narrative
Before I address the substantive content of the subsequent responses, I draw the Commissioner’s attention to the form in which the Lodz City Hall responds on this matter to various addressees.
The following paragraph appears, word for word, in three letters:
“The data controller of the personal data of the Lodz Resident Card program participants—comprising, among others, identification data, contact data, and documents confirming entitlements, processed both on the kartalodzianina.pl portal and in the mobile app provided to participants—is the Lodz Tourism Organization (ŁOT), which determines the purposes and means of processing within the meaning of Article 4(7) GDPR. […] The City of Lodz (Mayor of the City of Lodz) is the data controller exclusively of a narrow subset of data—contact data (first name, last name, phone number, email address) of those participants who have given their optional consent to receive informational and promotional communication from the City. The basis is the public-private partnership agreement of October 28, 2020, along with a separate data processing entrustment agreement (Article 28 GDPR), in which ŁOT processes this subset of data on behalf of the City as a processor.”
It appears identically in:
- a letter from Deputy Mayor Tomasz Piotrowski to the Commissioner for Human Rights dated September 9, 2026 (ref. no. DSiP-BPM-II.007.1.2026);
- a letter from acting director of the Promotion Bureau Aleksandra Hac dated September 4, 2026 (ref. no. DSiP-BPM-II.1431.12.2026), addressed to Ms. Justyna Wołkowska in response to a request for access to public information;
- a letter from acting deputy director of the Promotion Bureau Daria Głowacka (ref. no. DSiP-BPM-I.0530.1.2026), addressed to me in a separate, topically unrelated matter of a press inquiry about the use of solutions from the Łódź_Hack hackathon.
Three different signatories, three different addressees, three subject-matter distinct cases—an intervention by a constitutional organ protecting civil rights, a request for public information submitted by a civic organization, and a press inquiry concerning an unrelated event—and yet an identical, verbatim paragraph regarding the structure of data controllers. I leave it to the Commissioner to evaluate what this says about the way the Lodz City Hall prepares substantive responses on this matter in the context of source documents. I will try to clarify this issue below.
Re. 4 — structure of data controllers
The City’s response describes a structure in which the Lodz Tourism Organization is the sole controller of all data of program participants, and the City is the controller of only a narrow subset of contact data for individuals who gave optional marketing consent. This structure omits three circumstances documented by the program’s ecosystem itself.
First, point 8.1 of the public-private partnership agreement of October 28, 2020, stipulates that “any marketing activities of the Commercial Partners must be approved by the Public Entity.” Therefore, the City has retained from the very beginning the right to co-decide on marketing activities carried out within the System. This right was not purely theoretical: the minutes of a meeting from December 7, 2023, attached to Necessity Protocol No. 1/2023, document the direct participation of four representatives of the Promotion Bureau of the Lodz City Hall (Agata Riemer - acting deputy director of the Promotion and New Media Bureau of UMŁ, Monika Kudlicka - acting head of the Promotion and Tourism Branch, Kamila Szymczak - chief specialist in the Promotion and Tourism Branch, Karina Słówko - sub-inspector in the New Media Branch, and on the side of the concessionaire Tomasz Koralewski - President of the ŁOT Management Board, Adam Leszczyński - Manager of the Lodz Resident Card project) in determining the purpose, target groups, and messaging of the informational campaign accompanying the expansion of the Lodz Resident Card app.
Second, the privacy policy of the Lodz Resident Card program, maintained by ŁOT as the controller, states in the section on automated processing: “Automated decision making will serve to adjust the system’s functions to the user, as well as to generate a representative group for the purposes of social consultations on matters important from the point of view of the City of Lodz.” Thus, the controller itself indicates that the purpose of profiling users includes the interest of the City of Lodz, not solely the commercial interest of ŁOT. The Court of Justice of the European Union has recognized co-deciding on the purpose of processing for the benefit of another entity as sufficient to establish joint controllership in judgments C-210/16 (Wirtschaftsakademie Schleswig-Holstein) and C-40/17 (Fashion ID), regardless of whether this other entity has direct access to the data.
Third, the scale of the commercial use of the database deviates from the scope described in the City’s response. Łódź Media Group, the internal department of ŁOT responsible for monetizing the system, offers in its commercial offer campaigns directed at 100,000 active users of the Łódź.pl app, 174,000 email addresses, and 170,000 phone numbers, with “full targeting of the target group based on criteria such as: gender, age, interests, family structure, residence.” This scale significantly exceeds the narrow subset of people who have given separate, optional consent for the City’s promotional communication.
The allegation of joint controllership was one of the elements of my notification to the President of the UODO from November 2025, submitted at that time solely on the basis of publicly available information, without the source materials discussed in this letter. Today I have broader knowledge, the conclusions of which I present in this letter in a verifiable manner.
Re. 5 — data protection impact assessment and external audits
Deputy Mayor Piotrowski informs the Commissioner that ŁOT carried out DPIA assessments (initial and final) and of an external audit by DAGMA Sp. z o.o. from 2021. I have the contents of both DPIA assessments and the full DAGMA report, and I draw the Commissioner’s attention to their actual content.
First, both ŁOT DPIA assessments explicitly list in the table “Categories of data processed in the process”: identification data, address data, PESEL number, email address, phone number, guardian data, school name, scan of a school ID, scan of the first page of PIT (tax return), and scan of a certificate from the Labor Office about registration. In the “Minimum DPIA scope” section, the controller itself ticks “yes” next to “processing of personal data on a large scale, and in particular sensitive data including children’s data”. This juxtaposition is important for the City’s response to the Commissioner’s question 6: since the controller itself, in the document required by Article 35 GDPR, qualifies the processing as involving sensitive data on a large scale, including children’s data, reducing the discussion on the nature of the processed data exclusively to IP addresses and cookies omits a significant portion of the actually processed dataset.
Second, the attached Risk Analysis and Risk Treatment Plan have the character of a generic template based on typical information security threats (phishing, social engineering attacks, equipment theft, power outages). Nowhere does this document address the risks associated with analytical and advertising mechanisms, transferring data to third parties for marketing purposes, or behavioral profiling—that is, the category of risk that the Commissioner’s intervention concerns. Therefore, the City’s citing the completion of a DPIA as proof of due diligence does not apply to the alleged irregularity.
Third, the audit report by DAGMA Sp. z o.o. dated April 23, 2021, regarding the processor QB Sp. z o.o., states in point 35: QB Sp. z o.o. did not designate a data protection officer in accordance with Article 37 GDPR, and in its data protection policy designated as the Data Protection Officer Andrzej Rostkowski—a board member of the same company. The auditor stated explicitly: “By maintaining this provision, the Processor commits a violation of Articles 37 and 38 GDPR regarding the status of the DPO—independence from senior management (one cannot combine the function of DPO with a function in the senior management of the controller or the Processor).” I do not have information on whether the auditor’s recommendation was implemented; I request that the Commissioner examine the current status of this recommendation.
Fourth, according to the statute of ŁOT dated August 29, 2023 (§ 6 para. 2), the City of Lodz as an ordinary member of the Association has three representatives participating in its work, while other local government units of the Lodz agglomeration as well as natural and legal persons are entitled to one representative each. This same group of representatives, according to § 7 of the statute, participates with a casting vote in the General Assembly of Members—the highest authority of the Association, which elects the Council, which in turn appoints and dismisses the ŁOT Management Board (§ 13, § 15). The City thus occupies a structurally privileged position within the data controller’s structure relative to the other members, which further weakens the image of the City as an entity completely external to the decisions of the Lodz Tourism Organization.
Fifth, it is worth noting that the auditor Dagma sp. z o.o., conducted two audits for QB sp. z o.o. and ŁOT in the same week, and found in ŁOT real, named deficiencies—including “Lack of data (first and last name) of the data protection officer contrary to the provisions of the Personal Data Protection Act.” If we compare this with Sarnowska’s audit from four months prior (zero remarks on 63 pages, everything fulfilled), it is a very telling juxtaposition: the internal audit found nothing, the external audit four months later found concrete deficiencies, including in the exact same area (DPO) that the internal audit had assessed as fully compliant.
Additionally, I point out that none of the presented DPIA assessments covers the six modules added by Annex No. 1 of January 2, 2024 (news, ticketing, events, resident service, municipal waste, integration). The description of the process in both submitted assessments is limited to “handling of the Lodz Resident Card” in its original, discount-card form prior to this expansion. Expanding the System to include the sale of public transport tickets, waste collection schedules linked to a residential address, or broader communication with the resident constitutes, in my assessment, a significant change in the scope and nature of processing—which is, moreover, required by ŁOT’s own methodology, described in the attached Risk Analysis, which anticipates a re-analysis “after significant changes in data processing”. I do not possess a document attesting that such a reassessment was conducted.
[REDACTED - DETAILS OF THE AUDIT AND THE CLASSIFIED ATTACHMENT]
It is worth adding that the very content of the submitted DPIA assessments raises doubts about the reliability of the analysis conducted. The only process evaluated in them is the “handling of the Lodz Resident Card”—meaning accepting and processing applications and providing services related to the Card. Neither assessment covers separately the data processing process for direct marketing and advertising profiling purposes, indicated in the privacy policy as a distinct legal basis for processing (Article 6(1)(f) GDPR)—meaning the process from which the Lodz Tourism Organization derives commercial benefits via the Łódź Media Group. Since it is precisely this process, not just administering the card, that forms the basis for monetizing a database numbering nearly half a million accounts, omitting it in the data protection impact assessment is a significant substantive flaw, not a technical oversight. In both assessments, every criterion examined received a positive score, without a single reservation of partial compliance or non-compliance—which, given the lack of analysis of the riskiest, commercial processing operation, is difficult to consider a credible picture of the actual state of compliance.
This problem overlaps with the previously demonstrated lack of independence of supervisory functions on both sides of the controller-processor relationship: the Lodz Tourism Organization and QB Sp. z o.o. have separate data protection officer and compliance auditor functions, neither of which—as the above findings show—has been confirmed to be fully independent from the entity it concerns.
Additionally, the letter from the acting deputy director of the Promotion Bureau Daria Głowacka, discussed above regarding the City Hall’s response template, contains the sentence: “Once a year, ŁOT conducts a complete data protection impact assessment arising from the obligations of Article 35 GDPR for the entire project, and not for its individual elements”. This statement takes on additional significance in light of the chronology of audits and assessments presented by Deputy Mayor Piotrowski himself in response to question 5. He lists only: the initial and final assessments from before the System’s launch and the external audit by DAGMA Sp. z o.o. conducted in 2021—thus events from before or during the first year of the program’s operation, when the Lodz Resident Card was still a simple discount card. The only mention of subsequent activities is limited to a general statement about the “review and update of risk documentation over the course of the System’s operation,” without specifying any date or concrete document. Neither this sentence nor any other part of the City’s response indicates the existence of a DPIA assessment or audit conducted after the System was expanded by Annex No. 1 in January 2024.
The exact same gap is repeated in the response of the Lodz Tourism Organization dated September 16, 2026, to a request for public information, where once again only the same two documents from the pre-launch period of the System were indicated as the entirety of the provided DPIA documentation. Juxtaposed with Ms. Głowacka’s assurance about an annual, complete assessment “for the entire project”, two independent, official responses from the City Hall and ŁOT fail to confirm the existence of a single such annual assessment in the entire period from 2021 to the present. These responses leave little room for doubt: the City itself already admitted earlier—in the letter from the Promotion Bureau of September 4, 2026—that it did not summon the Private Partner to hand over DPIA documentation, nor did it conduct separate inspections or audits regarding personal data protection at their site. In this light, the assurance of an annual, complete assessment “for the entire project” is not corroborated by any document I possess, nor by the oversight practice that the City itself admits to. I request the disclosure of documentation confirming that such an assessment was conducted after January 2024, if such documentation exists.
It is worth noting the size of the system that this lack of independent oversight concerns. Throughout the entire duration of the concession—during which the simple discount card transformed into an app handling the sale of public transport tickets (Migawka), parking payments, and other municipal services, used by nearly half a million accounts—the City has not exercised its right to an annual comprehensive inspection or to order an external audit, which was reserved in points 10.5 and 10.6 of the PPP agreement. The City simultaneously declares in its letters that it “has no information about incidents or personal data breaches”. A system of such scale and such an operational period, maintaining a zero recorded breach rate for five years while simultaneously having a total lack of independent audits, would be a phenomenon worth noting in cybersecurity industry literature—not because it proves the absence of breaches, but because the declaration of a “lack of information about incidents” accompanied by the lack of any mechanism intended to provide this information, does not constitute an assurance of the system’s safety, but rather describes a structural inability to verify it.
This is not a lack of institutional capacity. In a response dated July 27, 2026, to an interpellation by councilor Sebastian Bulak regarding cybersecurity (ref. no. DOM-Inf-VII.0003.6.2026), the Secretary of the City of Lodz informs that the City Hall conducts an annual review of IT system security documentation, carries out audits “as needed”, and performed four penetration tests of its own systems in 2026 alone. The same level of diligence applied to the City Hall’s infrastructure has never been applied to a System processing the data of nearly half a million residents under a concession, despite the right to this type of inspection reserved in the PPP agreement.
This fact merits special attention particularly in the context of the operational scale of the system handling payments for public transport tickets as part of Migawka. According to press reports, the Office of Competition and Consumer Protection (UOKiK) confirmed receiving notifications regarding the restriction of distribution channels for MPK Lodz periodic tickets following the withdrawal of the possibility of their purchase in the external zBiletem app as of December 1, 2025, indicating that the provided information “constitutes valuable evidentiary material and will be used in the course of further analyses”, with the possibility of “adequate intervention measures” if a violation of competition law is confirmed (source: Wyborcza).
The financial scale of Migawka sales alone within the System grows from year to year: from PLN 2,519,135 of revenue in 2022 to PLN 20,175,214 in 2025. ŁOT’s annual reports separately list the amounts of settlements with MPK for these sales (PLN 8,841,368 in 2023, PLN 13,515,435 in 2024, PLN 18,501,392 in 2025)—the difference between the Migawka revenue and the settlement with MPK, remaining within the System, was thus PLN 872,902 in 2023, PLN 1,424,893 in 2024, and PLN 1,673,822 in 2025. At the same time, the separate item “QB subscription and QB commissions”, covering the entire remuneration of the technology provider for operating the System, increased from PLN 202,707 in 2021 to PLN 885,590 in 2025. Despite this, the financial result of the entire project remained negative in the years 2021–2024 and in 2025 reached a mere PLN 72,818—significantly below the threshold of PLN 1,250,000 of income, beyond which point 8.3 of the PPP agreement foresees profit sharing between the City and the Private Partner.
In this context, I draw the Commissioner’s attention to the independence of the audit and control functions overseeing the System’s compliance with the GDPR from the very beginning of its operation. The earliest such document known to me—the “Report from the internal audit of compliance with GDPR at the Lodz Tourism Organization Association” dated December 17, 2020, and thus from before the System’s launch—was prepared by Daria Sarnowska (contact: daria@lepsze.it) and was, according to its own content, a “first-party audit” within the meaning of the ISO 19011 standard, and therefore an internal, not independent, audit. This same person currently figures as the Data Protection Officer of the Lodz Tourism Organization in the program’s privacy policy.
The domain indicated in this report as the contact to the auditor (lepsze.it), at the time of writing this letter, redirects to the website of QB Sp. z o.o. (qb.com.pl)—the entity processing data within the System, whose compliance with GDPR the same person, as the current Data Protection Officer of the controller, should be able to assess independently from this entity. I do not possess documentation explaining the nature and history of this redirection, or connections of another sort—it may reflect a genuine organizational link, but could equally well result from a subsequent takeover of an expired domain by an entity unconnected to the original activity at this address. However, I flag this circumstance to the Commissioner as warranted for potential clarification, in conjunction with the above-described finding of DAGMA Sp. z o.o. from 2021 regarding an analogous problem of independence of the Data Protection Officer function on the side of QB Sp. z o.o.
Notwithstanding the above, decision no. 1/2026 of the Lodz Tourism Organization from September 16, 2026 (case ref.: 1/DIP/2026), refusing to provide access to the IT network security audit of the System, indicates—in accordance with the requirement of Article 16(2)(2) of the Act on Access to Public Information—that the position on this refusal was taken, alongside the ŁOT Management Board and the legal counsel, also by the “representative of the consortium member in the implementation of the Lodz Resident Card project - the company QB sp. z o.o. […] in the person of a board member – Andrzej Rostkowski”. This is the same person whom the DAGMA Sp. z o.o. report from 2021 identified as combining the function of a board member of QB Sp. z o.o. with the function of the Data Protection Officer of this company, in violation of Articles 37 and 38 GDPR. The representative of the processor thus formally co-decided on refusing to disclose a document concerning the security of the system, of which this same processor is a co-creator.
Furthermore, this same decision confirms the scope of the documentation provided in response to the analogous request for the DPIA and audits: despite the applicant explicitly requesting “any possible updates or reviews of the aforementioned assessments carried out during the operation of the system,” only the data protection impact assessment, risk analysis, and audits from 2020–2021, and annual reports for the years 2021–2025 regarding the execution of the contract were listed among the documents handed over. Not a single update or review of the DPIA or personal data security audit from the period after the System was expanded by Annex No. 1 was indicated as existing or made available.
Regardless of the substantive merit of the refusal to disclose this audit itself, the key issue is that the City—despite the right to its own inspection and audit reserved in points 10.5 and 10.6 of the PPP agreement, which it has never exercised—has no independent source of knowledge as to whether the vulnerabilities indicated in this audit have been eliminated, nor whether their removal was verified prior to the expansion of the System by Annex No. 1 with modules handling real payments for public transport tickets and other municipal services. I am not claiming that these vulnerabilities remain unpatched—I do not know that. I am stating that the City, taking into account the totality of the findings presented in this letter, possesses no mechanism that would allow it to ascertain this. I request an examination of whether the City has ever demanded from the Private Partner a confirmation of the remediation of the vulnerabilities indicated in this or any other security audit of the System.
Re. 6 — legal nature of the data and the obligation to report to the UODO
The City justifies the lack of internal explanatory proceedings and the lack of a report to the President of the UODO by stating that “neither cookies nor a computer’s IP constitute or have constituted personal data within the meaning of Article 4(1) GDPR,” citing a judgment of the Supreme Administrative Court (NSA) of October 16, 2025 (III OSK 2595/22) concerning the status of a dynamic IP address. The letter does not disclose who prepared this legal opinion.
This argumentation reduces the subject of assessment to two elements - the cookie file and the IP address - omitting the scope of data that my technical audit, described in Re. 1 and Re. 2, itself confirms. The data packet recorded on the mops.uml.lodz.pl domain includes not only the identifier in the cookie file, but a persistent client identifier (cid), the exact URL and title of the visited subpage, a full technical fingerprint of the browser and operating system, and session markers. The NSA judgment cited by the City concerns the narrowly defined issue of qualifying the IP address itself in isolation from other identifiers. The qualification of a combination of a persistent identifier, a URL, a page title, and a device’s technical fingerprint as enabling the indirect identification of a natural person is rooted in the established case-law of the Court of Justice of the European Union, in particular in the C-582/14 judgment (Breyer), regarding the combining of a dynamic IP address with other information. I am providing the Commissioner with additional material concerning a related issue in a classified attachment.
The decision not to initiate internal explanatory proceedings thus rests on a legal qualification that does not take into account the full scope of actually processed data, as demonstrated in Re. 1 and Re. 2 of this letter. The assessment that the processed data do not constitute personal data was formulated exclusively in relation to the IP address and the cookie file, omitting the persistent client identifier, URL, page title, and the device’s technical fingerprint, the transmission of which I document above.
It is worth noting that this response contradicts the City’s response to question 1, where the Deputy Mayor admits that a “dataset for the Google Analytics tool ad_user_data” was transmitted. The ad_user_data parameter in the Google Consent Mode v2 mechanism does not concern the IP address or the cookie file itself—according to official Google documentation, it controls whether user data can be sent to Google for advertising purposes, including to Google Ads, Google Shopping, and Google Play services. Therefore, the very name of the mechanism that the City refers to in its response to question 1 assumes the existence of a dataset of user data broader than a “cookie file and IP address”, to which dataset the City reduces the subject of evaluation in its response to question 6.
This same pattern can be seen in the City’s earlier letter of June 30, 2026, to the councilors, discussed in Re. 1: there, the Deputy Mayor describes this same mechanism as saving specific cookies («_ga or _gcl_au») on the user’s device, noting that «data physically hits Google servers». The City has thus, in two different letters, described the same mechanism in a more detailed and more accurate manner reflecting its real operation than in the answer given to the Commissioner to question 6, where this same mechanism was reduced to a statement that it does not process personal data.
Data retention and the illusory nature of the right to object
I would like to draw attention to a broader problem in the framework provisions of the agreement and the policies. The privacy policy of the Lodz Resident Card program provides that data processed on the basis of the controller’s legitimate interest, including for direct marketing purposes, is retained “until an effective objection is submitted pursuant to Article 21 GDPR”. This means that the user’s mere inactivity does not cause the processing to cease - their active action is required. In practice, this leads to a situation where a person who has stopped using the program remains in the marketing database indefinitely, until they themselves file an objection.
I have grounds to believe that this is not purely a theoretical risk. Personally, as a resident, I participated in the Lodz Resident Card program at the beginning of its operation and provided my phone number at that time. I have not used the Card for five years. Despite this, I still receive SMS messages about real estate development projects, which constitute the majority of promotional materials I have received - most recently on May 6, 2026, from a sender labeled “MediaLodz” [previously the sender name was KartaŁodzianina] (content: “Over 35 model homes live! Great Home Fair in Lodz, May 8-10 at Moto Arena. Buy a ticket: [link redacted]”). I am attaching a screenshot of this and other messages. The sender’s name is identical to the name of Łódź Media Group, the internal department of ŁOT responsible for monetizing the database, referred to in Re. 4.
In my opinion, this circumstance contradicts the annual report of ŁOT for 2024, which indicates that “user accounts of those who have not used the LRC in any way since 2021 have been anonymized”, which was supposed to cause a 13% drop in the number of accounts noted in the same report. My case—no activity since 2021 combined with simultaneously receiving marketing communication in 2026—is not consistent with the declared scope of this anonymization, unless it solely applied to the account in the Card system, omitting the phone number transferred for marketing purposes, which in turn would be difficult to reconcile with the purpose of the anonymization itself.
Regardless of the above, the findings of my audit regarding the consent mechanism described in Re. 2 point to the same pattern regardless of the specific implementation within the ecosystem created under the PPP agreement. The problem is therefore not limited solely to the narrow subset of contact data (phone, email, first and last name), but also encompasses other data processors operating within this ecosystem, including the mobile app Łódź.pl [REDACTED]. The register of given and withdrawn consents thus requires verification in relation to the entire data processing ecosystem of the program’s participants, not just the City’s marketing subset. Withdrawing consent in a mechanism lacking such a register has no effect on data already transferred—the right to object and the right to be forgotten (Articles 17 and 21 GDPR) become illusory in such a configuration.
I request that the Commissioner examine whether ŁOT actually carried out full anonymization of the contact data of individuals inactive since 2021, in accordance with the declaration contained in the 2024 annual report, and to examine whether the functioning consent mechanism practically enabled the effective exercise of the right to object and the right to be forgotten with regard to data already transferred to third parties, as well as to examine how, during the operation period of the consent mechanism based on a 2014 library, the System’s compliance with GDPR was documented in internal reviews and protocols, and whether this documentation reflected the actual technical state of this mechanism. It would also be justified to reach out to the PUODO in this specific context so that they can assess the principle of data minimization.
Context extending beyond the subject matter of data protection
I am signaling to the Commissioner a broader context that may be relevant to the assessment of the whole matter, although it exceeds the scope of the Commissioner’s constitutional competencies - I leave it for potential forwarding to the appropriate authorities. Via Annex No. 1 of January 2, 2024, concluded pursuant to point 16.2.5 of the PPP agreement (foreseeing a change to the agreement “in the event of significant changes in the scope of the project […] new modules”), the object of the concession was expanded by six new functional modules (news, ticketing, events, resident service, municipal waste, integration), transforming the Lodz Resident Card into a universal municipal app, Łódź.pl, without carrying out a new competitive procedure. The assessment of whether such a sweeping expansion of the concession’s object falls within the boundaries of permissible contract amendment under the Act on Concessions for Construction Works or Services is up to the appropriate control authorities; I request that this circumstance be noted as an element of the same pattern of the City’s conduct towards external oversight, as described in this letter.
Annex No. 1 to the PPP agreement significantly expanded the functionality of the application, which from a business point of view dramatically increased the value of the database monetized by Łódź Media Group. Expanding the object of the concession with new modules without simultaneously forcing new risk analyses (DPIA) and verifying the proportions of profit-sharing from this database is a classic example of failing to care for the proprietary interests of a public entity.
It is also worth noting the scale and financial structure of the entire venture. The project’s revenues grew from PLN 169,278 in 2021 to PLN 22,767,852 in 2025, with costs reaching PLN 22,695,035 in 2025. The total limit of contractual penalties that the City can charge the Private Partner for any violations of the agreement, including data protection violations, amounts to PLN 250,000 gross (point 20.3 of the PPP agreement)—about 1% of the annual costs of the System’s functioning in 2025. The performance bond (PLN 100,000, point 14.1) is returned to the Private Partner in half already after the first year of the agreement’s validity (point 14.7), leaving a security deposit in the amount of PLN 50,000 for the entire subsequent, multi-year period of its duration. Furthermore, the PPP agreement itself contains a clause that it constitutes a «work within the meaning of the provisions of the act on copyright and related rights», and its further use by third parties requires the consent of its creators—a clause of this kind is sometimes found in concession contract templates; its practical impact on the accessibility of the content of this specific, signed contract under the Act on Access to Public Information remains unclear to me.
The City officially admits that it did not carry out data protection inspections or audits at the Private Partner. Tolerating a state where the contractor operates on the data of nearly half a million accounts without verification exposes the municipality to multi-million administrative penalties from the UODO and civil claims from citizens.
I further inform the Commissioner that in September 2026, I am being interrogated by the prosecutor’s office in cases related to this material. I am also preparing separate notifications regarding the possible attestation of untruth in official documents (Article 271 of the Penal Code) and, in connection with the aforementioned method of supervising and financing the concession, potential failure to fulfill duties by a public official (Article 231 PC) and mismanagement (Article 296 PC); I leave the final legal qualification of these events to the appropriate law enforcement agencies. I will inform the Commissioner of the further course of these proceedings in separate correspondence.
Technical verification of the remaining municipal domains, including BIP services (question 3), along with substantive commentary and evidence can be found at the address: https://dowody.dadalo.pl/lodz-rodo-2025/
I will gradually supplement the evidence repository with documentation from documents obtained from BIP, municipal websites, UDIP, and passed on from other entities under the press inquiry procedure.
Sincerely,
Maciej Lesiak
Attachments:
- Public-private partnership agreement of Oct 28, 2020 (excerpts: points 8.1, 16.2.5)
- Personal data processing entrustment agreement of Aug 17, 2021, together with Annex No. 1
- Necessity Protocol No. 1/2023 of Dec 19, 2023, along with the annex — minutes from the meeting of Dec 7, 2023.
- Annex No. 1 to the PPP agreement of Jan 2, 2024
- Data protection impact assessment (DPIA) — draft and final versions, ŁOT
- Two Reports from the personal data protection audit of the processor QB Sp. z o.o., DAGMA Sp. z o.o., April 23, 2021, and ŁOT March 21-23, 2021.
- Letter from Aleksandra Hac of Sept 4, 2026 (ref. no. DsiP-BPM-II.1431.12.2026)
- Letter from Daria Głowacka (ref. no. DSiP-BPM-I.0530.1.2026)
- Privacy policy of the Lodz Resident Card program (screenshot 2026-09-17 11:09) https://archiv.dadalo.pl/archive/1789643254.858585/readability/content.html
- Commercial offer of Łódź Media Group (screenshot 2026-02-25 15:08) https://archiv.dadalo.pl/archive/1772031559.533897/singlefile.html
- Screenshots of SMS messages
- Screenshot of the source code cookiebox.js with the header identifying the library and its origin (screenshot 2026-03-05 20:53 code still present on September 21, 2026) https://archiv.dadalo.pl/archive/1772740908.024709/mosir.lodz.pl/typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.js@1772639425
- Report from the internal audit of GDPR compliance at the Lodz Tourism Organization of Dec 17, 2020.
- Response to the interpellation - DSiP-BPM-IV.0003.1.2026DSiP-BPM-IV .0003.1.2026 of June 30, 2026.
- Refusal decision by ŁOT on the UDIP of Łódź Cała Naprzód no. 1/2026 ŁOT and the response of the City Secretary of July 27, 2026 (DOM-Inf-VII.0003.6.2026)
- Gazeta Wyborcza, MPK Łódź pod lupą UOKIK. Idzie o “komfort tysięcy pasażerów” (MPK Lodz under UOKiK’s magnifying glass. It’s about “the comfort of thousands of passengers”), Alicja Zboińska, 2026-03-25, URL: https://lodz.wyborcza.pl/lodz/7,35136,32682725,mpk-lodz-pod-lupa-uokik-uderza-w-komfort-tysiecy-pasazerow.html
- [CLASSIFIED ATTACHMENT - REDACTED]
Author’s Note: Disclaimer and conclusion
The above letter is a summary of my knowledge based exclusively on gathered, official source documents and conducted technical analyses. Every party – including the Lodz City Hall, the Lodz Tourism Organization, and external entities – naturally has the right to a substantive response and to present their own position. However, I point out that as a citizen I have exhausted the formal path: I inquired with the City Hall (which is a party to the concession) about the issues of interest to me, I received documentation, and it is precisely on this specific evidence that I base every thesis put forward. I will make these documents publicly available shortly.
The described case has long ceased to be just a technical dispute over cookies. It has become a story about a lack of basic oversight over a system in which the data of hundreds of thousands of Lodz residents circulate. If the city does not have the tools or documents to prove the independent verification of its own (by definition) app, is the Lodz Resident Card still a municipal service? I leave you with this question.


