Data security during the repair of company equipment

27 września 2017

It has happened! A computer in the company has been damaged, on which personal data is processed and information that may constitute a business secret is stored. Can the company's IT specialist handle the repair of the equipment? What should be done if the computer needs to be sent to an external service? How can unpleasant surprises be avoided?

It has happened! A computer in the company is damaged, on which personal data is processed and information that may constitute a business secret is stored. Can the in-house IT specialist handle the repair? What should be done if the computer needs to be sent to an external service? How can unpleasant surprises be avoided?

Repairing equipment by a local IT specialist

GDPR Bulletin
Receive a package of free GDPR guides and micro-trainings
Join the ranks of our newsletter readers, receive a free package, and stay informed.
RECEIVE PACKAGE
If a problem arises that we cannot resolve on our own, we simply call the in-house IT specialist, who will handle the device as part of their daily duties. According to the provisions of the Personal Data Protection Act of August 29, 1997, a necessary condition for the repair process to be carried out by such a person employed under an employment contract or a civil law contract is the prior granting of authorization to process personal data. It is also advisable to ensure that the relevant contract or other documents defining the type of cooperation include provisions regarding the confidentiality of data maintained by them.

Repairing equipment by an IT specialist from an external company at the organization's premises

What should be done in a situation where the organization does not employ any IT personnel, and IT support is provided by an external company? According to the Polish DPA, in such a case, before any sharing of company equipment, we should ensure that the contract with the company providing such services includes appropriate provisions regarding the data processing agreement (a draft of such an agreement can be found here). However, the legislator allows us to bypass this requirement by introducing a relevant provision in the Regulation of the Minister of the Interior and Administration dated April 29, 2004. Part A of Chapter VI, point 2 states that “(...) devices, disks, or other electronic information carriers containing personal data intended for repair must have the data recorded on them removed in a manner that prevents their recovery, or they must be repaired under the supervision of an authorized person (...).” According to the quoted document, if the repair is carried out at our organization's premises and we do not have a signed data processing agreement with the external company, the technician cannot be left unsupervised by an authorized person.

Repair of equipment by an IT technician from an external company outside the organization's premises

However, if the computer cannot be repaired on-site and it becomes necessary to send it to a service center, it will be essential to conclude an appropriate agreement or completely erase the device's data in a manner that prevents their recovery. According to the opinion of the Article 29 Working Party on Data Protection, the process of securely deleting personal data requires that the carriers of the devices be destroyed or demagnetized, or that personal data be effectively removed by overwriting it multiple times (at least 3 times). Of course, if the situation allows, the most convenient solution is to send the device to an external entity with which we do not have a signed data processing agreement without the subject carrier. It is worth noting that the above steps can be waived provided that the disk of such a device is encrypted before being sent to the external service. In that case, we can be sure that no unauthorized person will gain access to it.

Cybersecurity training

Exercising Particular Caution After Receiving Equipment from an External Service

We can never be certain who has repaired our device and what may have been installed on it. Therefore, after receiving equipment from an external service, it is important to take appropriate measures to minimize the risk of infecting the organization's network and leaking confidential information. After maintenance or repair, before restarting the computer on the production network, the device should be checked to verify that it has not been tampered with and is not performing any harmful functions. For this purpose, a full scan with antivirus software should be conducted on the compromised computer.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.