It has happened! A computer in the company is damaged, on which personal data is processed and information that may constitute a business secret is stored. Can the in-house IT specialist handle the repair? What should be done if the computer needs to be sent to an external service? How can unpleasant surprises be avoided?
Repairing equipment by a local IT specialist
Receive a package of free GDPR guides and micro-trainings
Repairing equipment by an IT specialist from an external company at the organization's premises
What should be done in a situation where the organization does not employ any IT personnel, and IT support is provided by an external company? According to the Polish DPA, in such a case, before any sharing of company equipment, we should ensure that the contract with the company providing such services includes appropriate provisions regarding the data processing agreement (a draft of such an agreement can be found here). However, the legislator allows us to bypass this requirement by introducing a relevant provision in the Regulation of the Minister of the Interior and Administration dated April 29, 2004. Part A of Chapter VI, point 2 states that “(...) devices, disks, or other electronic information carriers containing personal data intended for repair must have the data recorded on them removed in a manner that prevents their recovery, or they must be repaired under the supervision of an authorized person (...).” According to the quoted document, if the repair is carried out at our organization's premises and we do not have a signed data processing agreement with the external company, the technician cannot be left unsupervised by an authorized person.
Repair of equipment by an IT technician from an external company outside the organization's premises
However, if the computer cannot be repaired on-site and it becomes necessary to send it to a service center, it will be essential to conclude an appropriate agreement or completely erase the device's data in a manner that prevents their recovery. According to the opinion of the Article 29 Working Party on Data Protection, the process of securely deleting personal data requires that the carriers of the devices be destroyed or demagnetized, or that personal data be effectively removed by overwriting it multiple times (at least 3 times). Of course, if the situation allows, the most convenient solution is to send the device to an external entity with which we do not have a signed data processing agreement without the subject carrier. It is worth noting that the above steps can be waived provided that the disk of such a device is encrypted before being sent to the external service. In that case, we can be sure that no unauthorized person will gain access to it.
Exercising Particular Caution After Receiving Equipment from an External Service
We can never be certain who has repaired our device and what may have been installed on it. Therefore, after receiving equipment from an external service, it is important to take appropriate measures to minimize the risk of infecting the organization's network and leaking confidential information. After maintenance or repair, before restarting the computer on the production network, the device should be checked to verify that it has not been tampered with and is not performing any harmful functions. For this purpose, a full scan with antivirus software should be conducted on the compromised computer.

