Receive a package of free GDPR guides and micro-trainings
In order to fill this gap, the EU legislator adopted Directive (EU) 2016/680 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons in relation to the processing of personal data by competent authorities for the purposes of preventing crime, conducting preliminary proceedings, detecting and prosecuting prohibited acts, and executing penalties, regarding the free flow of such data and repealing Framework Decision 2008/977/JHA (hereinafter: Directive 2016/680).
Regardless of the discussion regarding the effectiveness of this action, the directive was implemented into Polish law by the DODO Act, which came into force on February 6, 2019. This date is particularly significant, as from this moment, Poland has a second legal act alongside the GDPR that defines the principles and conditions for the processing and protection of personal data.
Important
February 6, 2019 – the date of entry into force of the DODO Act, and thus the commencement of the applicability of two equivalent legal acts in Polish law defining the principles and conditions for the processing of personal data, namely the GDPR and the DODO Act.
Relationship between GDPR and the DODO Act
Both the GDPR and the DODO Act establish independent legal bases for data processing, while simultaneously specifying the principles and conditions for such processing. However, this does not mean that the two acts do not intersect. For example, analogous definitions used within the framework of the GDPR and the DODO Act include personal data, personal data breaches, and processing of personal data. Additionally, both legal acts provide for a single supervisory authority in their application, namely the President of the Polish Data Protection Authority (in this regard, deviations from the general principle may be provided for by the provisions of specific laws, such as Article 175dd of the Act of July 27, 2001 on the Organization of Common Courts).
The fundamental difference between the GDPR and the DODO Act is that the latter applies only to certain entities that process data. The criteria for their designation are specified in Article 1 point 1 of the DODO Act, according to which the act defines the principles and conditions for the protection of personal data processed by competent authorities for the purpose of recognizing, preventing, detecting, and combating prohibited acts, including threats to security and public order, as well as executing temporary detention, penalties, disciplinary measures, and coercive measures resulting in deprivation of liberty.
Important
The DODO Act applies only to entities whose statutory obligations include: recognizing, preventing, detecting, and combating prohibited acts, including threats to security and public order, as well as executing temporary detention, penalties, disciplinary measures, and coercive measures resulting in deprivation of liberty.
Examples of entities applying the DODO Act:
Police, Border Guard, Municipal Guard, Military Gendarmerie, Prison Service, Road Inspection, Fisheries Guard, air carriers, entities responsible for the safety of mass events.
It is essential that entities responsible for the prosecution and combating of crime, processing data for the purposes specified in the cited Article 1 point 1 of the DODO Act, are also obliged to comply with the provisions of the GDPR in areas such as the processing of employee data. This means that there may be situations in which one entity will be required to simultaneously meet the requirements set forth by both the DODO Act and the GDPR. At this point, knowledge of the differences in the obligations imposed by both legal acts will be crucial.
Key differences under the DODO Act and GDPR regarding the obligations of data controllers:
1) Legal bases for data processing
The DODO Act does not provide data controllers with as wide a range of options as the GDPR does in Articles 6, 9, and 10. The processing of personal data under the DODO Act is only permissible when it is necessary for the realization of a right or the fulfillment of obligations arising from legal provisions (Article 13 of the DODO Act). Additionally, personal data of special categories may only be processed when permitted by law or when necessary to protect the life or health or interests of the data subject or another person, or when such data has been made public by the data subject (Article 14 of the DODO Act).
2) Data protection documentation under the DODO Act
According to Article 31 paragraph 4 of the DODO Act, the data controller is obliged to develop and implement a personal data protection policy, taking into account the manner of documenting the necessary technical and organizational measures applied by them, corresponding to the nature, scope, context, and purposes of processing as well as the risk of infringement of the rights or freedoms of natural persons of varying likelihood and severity of threat. Considering the above, the minimum scope of data protection documentation under the discussed Act should include the items listed in the table below.
Considering the above as the minimum scope of data protection documentation under the discussed Act, the items listed below should be indicated:
- Documentation regarding the implementation of the following tasks (Article 31 paragraph 3):
- compliance with the general principles of processing (Article 31 paragraph 1),
- implementation of mechanisms for maintaining the substantive accuracy of data (Article 31 paragraph 2),
- ensuring that personal data is processed lawfully (Articles 13–14),
- application of the principles of automated processing of personal data, including profiling (Article 15),
- functioning of mechanisms for verifying personal data and the principles of handling such data after anonymization (Articles 16–18),
- application of the principles of distinguishing personal data (Articles 19–20),
- functioning of mechanisms for transferring or sharing personal data with other authorities, a third country, or an international organization (Article 21);
- Documentation indicating the factual or legal reasons for refusing to provide information or to share personal data with the data subject (Article 31(7)),
- Documentation indicating the factual or legal reasons for refusing or limiting access to data (Article 23(4)),
- Documentation regarding appropriate technical measures and necessary safeguards applied in the processing of personal data to implement the principles of data protection by default and data protection by design (Article 32(3)),
- Agreement between joint controllers (if the controller operates under a model of joint administration of personal data - Article 33),
- Data processing agreement (in the case of entrusting personal data for processing - Article 34),
- List of categories of processing activities (Article 35(1)),
- List of categories of processing activities carried out on behalf of the controller (if acting in the position of a data processor as referred to in Article 4(12), Article 35(3)),
- Procedure for conducting and the results of the assessment of the impact of planned processing operations on the protection of personal data, if a given type of processing may result in a high risk of infringement of the rights and freedoms of natural persons (Article 37(1)),
- Procedure and protocols for the destruction of data storage media used for processing personal data (Article 40),
- Request for granting access rights to personal data and a declaration from the person to whom the request pertains, committing to ensure the security of personal data (Article 41),
- Record of persons authorized to process personal data (Article 42),
- Declarations from persons authorized to process personal data regarding the provision of security for personal data and the confidentiality of shared personal data and the methods of their protection (Article 43 of the DODO Act),
- Procedure for handling personal data breaches and the register of personal data breaches (Article 44 of the DODO Act).
3) Rights of data subjects
The DODO Act, like the GDPR, imposes an obligation on the Data Controller to fulfill the rights of individuals whose data is being processed. The primary difference in this regard between the two acts concerns the catalog of rights granted to such individuals.
| DODO ACT (Chapter 4) | GDPR (Chapter 3) |
|
|
4) Information Obligation under the DODO Act vs. GDPR
There are no stupid GDPR questions.
There are free answers
Following the entry into force of the DODO Act, the fulfillment of the information obligation in the aforementioned cases will not exhaust the Data Controller's obligations in this regard. According to Article 22 of the DODO Act, the Data Controller will be required to fulfill the information obligation in the following situations:
- public dissemination of information by the Data Controller (Article 22(1) and (2) of the DODO Act),
- the provision of information by the data controller in specific cases, in order to enable the person whose data is being processed to exercise their rights (Article 22(3)).
Important
The content provided in privacy notices under the respective provisions of the DODO Act and the GDPR is not identical. Proper fulfillment of informational obligations requires verification of the factual state each time.
5) Appointment of a Data Protection Officer under the DODO Act and the GDPR
The Data Protection Officer is an institution known from the provisions of the GDPR, which also finds its function within the framework of personal data processing for the purpose of preventing and combating crime. However, the DODO Act introduces a significant difference regarding the grounds for appointing a DPO compared to the provisions of the GDPR. According to Article 46 of the DODO Act, every data processor engaged in the recognition, prevention, detection, and combating of prohibited acts, including threats to security and public order, as well as the execution of temporary detention, penalties, disciplinary measures, and coercive measures resulting in deprivation of liberty - thus fitting the definition of a data controller as defined in Article 4(1) of the DODO Act - is obliged to appoint a DPO. This means that the DODO Act does not provide any specific grounds in this regard compared to Article 37 of the GDPR. The provisions of the DODO Act thus clearly state the situation - you are obliged to comply with its provisions, and therefore you have a duty to appoint a DPO in your organization.
Important
Every entity obliged to comply with the provisions of the DODO Act is required to appoint a Data Protection Officer, regardless of the grounds arising from the provisions of the GDPR.
It should also be noted that in organizations obligated to comply with the DODO Act, there may be situations where these entities will be required to appoint a DPO under two regulations: Article 46 of the DODO Act and Article 37(1) of the GDPR. This is particularly important due to the fact that a large number of entities subject to the provisions of the DODO Act are public authorities within the meaning of Article 37(1)(1) of the GDPR (and thus required to appoint a DPO based on the provisions of the EU regulation). In such situations, it will be crucial for data controllers to make decisions regarding the following: whether to appoint two separate DPOs or to assign one person the responsibilities of the DPO arising from both the DODO Act and the GDPR.
Summary
The entry into force on February 6, 2019, of the DODO Act means that organizations that process data as part of their activities should verify whether they are doing so for the purposes specified in Article 1(1) of the aforementioned Act. A positive outcome of such an action will indicate the emergence of new, numerous obligations on the part of such entities. The most difficulties may arise from those obligations that must be fulfilled independently of the tasks imposed by the GDPR. This may be particularly challenging for individuals serving as data protection officers (without the assistance of a dedicated team or deputy). As practice shows, it is largely these individuals who bear the most responsibilities in terms of meeting the requirements set by personal data protection regulations – in this case, two independent legal acts. The above clearly demonstrates how critical the decisions of data controllers are regarding the proper implementation and application of the provisions of both the DODO Act and the GDPR.
If you wish to conduct training on the DODO Act in your company, please contact Marcin Kuźniak, our data protection advisor.


