You will need to report personal data breaches to the Polish Data Protection Authority.

01 February 2017

Under the currently applicable regulations, the data controller is not obligated to inform the Polish Data Protection Authority about incidents related to personal data protection that occur within the organization, with the exception that such an obligation applies only to telecommunications operators, as stipulated by the Telecommunications Law. However, this is set to change.

blog-121

Under the General Data Protection Regulation (GDPR), the obligation to notify a personal data breach will rest with each data controller.

In the event of a personal data breach within an organization, the data controller shall, without undue delay and within 72 hours of becoming aware of the breach, be obliged to report such a breach to the supervisory authority, i.e., the Polish Data Protection Authority, unless it is unlikely that the breach will result in a risk to the rights or freedoms of natural persons. The phrase "risk to the rights or freedoms of natural persons" is somewhat ambiguous; let us attempt to clarify it.

A breach of the rights or freedoms of natural persons, according to the recitals of the GDPR, will include, among other things, the occurrence of physical harm, material or non-material damages to natural persons, such as loss of control over their personal data or restriction of rights, discrimination, identity theft or fraud, financial loss, unauthorized reversal of pseudonymization, damage to reputation, breach of confidentiality of personal data protected by professional secrecy, or any other significant economic or social harm. Importantly, it will be the responsibility of the data controller to assess (the burden of proof will rest on them) whether it is unlikely that the breach will result in a risk to the rights or freedoms of natural persons.

Failure to notify the supervisory authority of a breach within 72 hours will result in an administrative fine of up to €10,000,000 or up to 2% of the total annual worldwide turnover of the undertaking from the previous financial year – the higher penalty will apply. In the case of a notification submitted to the supervisory authority after the 72-hour period, the data controller will be obliged to explain the reason for the delay.

Sample notification:

Informing ABI

It should also be emphasized that the obligation to report personal data breaches also applies to the data processor. The processor will be required to report any data breach directly to the data controller. Under the current legal framework, the law does not impose an obligation on the processor to inform the data controller of any incidents. Of course, such an obligation may already arise from the data processing agreement concluded between the data controller and the processor.

The GDPR introduces many changes and novelties compared to the currently applicable regulations. Do you want to know more? I encourage you to read the book „EU Reform of Personal Data Protection. Analysis of Changes.”

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.