Data Protection Officer (DPO)
The main concerns regarding the presented draft of the law revolved around the appointment of the Data Protection Officer (DPO). According to many individuals gathered in the room, limiting the form of appointing the DPO solely to an electronic application is too narrow and somewhat discriminates against individuals with disabilities who cannot use a computer.
The Ministry of Digital Affairs responded by stating that the electronic form would allow for better management of applications, especially since it can also be submitted using a free trusted profile. The Ministry of Digital Affairs also plans to introduce an additional system that would allow for the registration of the DPO. Furthermore, a provision is to be added to the law that will explicitly indicate the possibility of appointing a DPO through a proxy, which will be a significant facilitation for individuals with disabilities.
It is also worth mentioning that the provisions of the Code of Administrative Procedure do not apply to the notification, as no administrative decision is made in this process.
Matters Related to Proceedings Before the Polish Data Protection Authority (UODO)
Receive a package of free GDPR guides and micro-trainings
The amount of fines for public administration remains unchanged. According to the Ministry of Digital Affairs, in the public sector, the fine comes from public funds, thus changing its amount would be a superficial measure. However, it is worth mentioning that an obligation will be imposed on administrative bodies to report on the execution of the decisions of the President of the Polish DPA.
Article 76, which granted the President of the Polish DPA the authority to initiate disciplinary proceedings or any other legally prescribed proceedings against individuals guilty of breaches related to personal data protection, has been removed from the draft law. The legislator has also abandoned the possibility for the President of the Polish DPA to unilaterally decide whether a given piece of information obtained during the proceedings is a trade secret.
Conditions for a child's consent in the case of information society services
According to the assumptions of the draft, the age of a child in the context of offering them information society services, without the need for consent from their legal guardian, remains set at 13 years. The Ministry of Digital Affairs justifies this solution by the fact that the majority of EU member states have adopted a similar age classification. Additionally, this solution is supported by the need to ensure consistency with the provisions of the civil code.
It is worth noting that the issue of obtaining consent from the child's guardian becomes problematic in this case. During the conference, Dr. Maciej Kawecki proposed the following methods for obtaining such consent:
- a stipulation on the given website indicating that consent can only be given by an adult,
- authentication of the child's account using an adult's account, applying a linked accounts mechanism,
- authentication of the account through online transfers of symbolic amounts (e.g., in the amount of 1 grosz) from the child's guardian's account,
- contacting the parent, for example, via a phone call.
The above provision applies solely in cases where the basis for processing the child's personal data is consent. For example, registration on a gaming portal, purchasing a video game, or creating an account on a VOD service website occurs based on a contract, which is why these solutions do not apply here. The discussed provision primarily aims to address issues related to directing marketing content to the youngest, as they are the most receptive to it, and to regulate the processing of children's data by social media platforms.
Certification and accrediting body
The certifying body will no longer be solely the Polish DPA. The Ministry of Digital Affairs allows for the possibility of private sector entities being authorized to issue certificates as well. Consequently, an appropriate procedure will be established, with the Polish Centre for Accreditation serving as the accrediting body. The fee for certification by the authority remains unchanged, i.e., it will amount to three times the average salary – approximately 12,000 PLN. This fee will be collected upon submission of the application.
Limitation of Obligations for Sole Proprietors
During the conference dedicated to summarizing the Public Consultations regarding changes to personal data protection regulations, the Ministry of Digital Affairs preliminarily considered the remarks of the Ministry of Development concerning the limitation of certain obligations arising from, among others, Article 13 and Article 14 of the GDPR, specifically informational obligations for entrepreneurs employing up to 250 people, not processing special categories of data (sensitive data), and not transferring any personal data to third countries. Such a possibility is granted to member states by Article 23 of the GDPR, but with the limitation to the possibility of excluding individual elements of the informational obligation, rather than its complete non-application.
The discussed exemption from the informational obligation will rather pertain to those sole proprietorships that do not employ any workers, as their employment typically involves the processing of special categories of data (sensitive data) in areas such as sick leave. If the discussed provision is ultimately introduced into the law, a group of small entrepreneurs who do not employ workers (self-employed individuals, representatives of liberal professions) will still be able to benefit from it.
Summary
The above examples indicate that the Ministry of Digital Affairs is making significant efforts to incorporate amendments made during public consultations, which ensures a high level of transparency in the "new" personal data protection law, facilitating the interpretation of its provisions once it enters into legal circulation.
Watch: video report


