ABI Exam - verification of "appropriate knowledge"

07 April 2016

The amendment to the Personal Data Protection Act of January 1, 2015, made the appointment of a Data Security Administrator an entitlement rather than an obligation for the data controller. By deciding to appoint a DSA, the data controller acquires for their organization an individual who, due to their expertise in the field of personal data protection, will be able to ensure not only the proper safeguarding of personal data but also the comprehensive compliance with personal data protection regulations within the data controller's organization.

By appointing a Data Protection Officer (DPO), the data controller must be aware that the DPO must meet the conditions explicitly specified in the Personal Data Protection Act (Article 36a, paragraph 5), namely:

GDPR Bulletin
Receive a package of free GDPR guides and micro-trainings
Join the ranks of our newsletter readers, receive a free package, and stay informed.
RECEIVE PACKAGE

  • have full legal capacity and enjoy full public rights,
  • not have been convicted of a deliberate crime,
  • possess appropriate knowledge in the field of personal data protection.

While verifying the fulfillment of the first two conditions does not pose excessive difficulties, as the amended provisions of the Personal Data Protection Act allow for requesting a certificate of no criminal record from the National Criminal Register from the candidate for DPO, there is a lack of tools to objectively confirm knowledge in the field of personal data protection.

According to the General Inspector of Personal Data Protection, the requirement for the DPO to possess appropriate knowledge in the field of personal data protection is assessed by the data controller themselves, who, acting in their own interest, should appoint a person capable of effectively carrying out the assigned tasks and ensuring the information security of their organization.

Equally importantly, when notifying the General Inspector of Personal Data Protection of the appointment of a DPO, the data controller simultaneously declares that the person they have chosen meets the statutory requirements for the indicated position, which is additionally confirmed by their signature and seal.

In order to meet the expectations of the community, we have prepared an exam to confirm the competencies of candidates or individuals performing the duties of a Data Protection Officer in the context of the practical application of the Personal Data Protection Act and industry regulations, as well as the design, construction, and supervision of the personal data protection system.

The exam prepared by us, drawing on experiences from, among others, the Slovak state exam for the position of Data Security Administrator, consists of 200 closed questions divided into three thematic blocks, grouping issues specified within the scope of the exam. The exam has been prepared by individuals who hold the position of Data Security Administrator or Deputy Data Security Administrator on a daily basis and aims to objectively and effectively verify the knowledge of personal data protection of the individuals taking the exam.  

We invite you to participate in the exam:

  • individuals serving as Data Security Administrators who wish to confirm their competencies,
  • CEOs, board members, and heads of organizational units who independently oversee the personal data protection system,
  • individuals designated for the position of Data Security Administrator,
  • individuals interested in the topic of personal data protection.

I also encourage you to familiarize yourself with
the systemic solution for building ABI competencies

The accredited course for DPO will confirm your high competencies

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.