Table of Contents
And what does the supervisory authority say?
In the administrative decisions issued, the President of the Polish Data Protection Authority, in situations where data controllers invoke the aforementioned basis for processing personal data and lack any other legal basis for such processing, has ordered data controllers to delete personal data processed for the purpose of establishing, pursuing, or defending claims.

According to the position of the President of the Polish Data Protection Authority, confirmed by the Provincial Administrative Court in Warsaw, among others, in the judgment of January 13, 2021 (case file II SA/Wa 607/20) and the judgment of March 11, 2021 (case file II SA/Wa 1340/20), the basis from Article 6(1)(f) of the GDPR should pertain to an already existing situation, where the purpose arising from the legitimate interests pursued by the data controller is the necessity to prove, the need to pursue, or defend against an existing claim, rather than a situation where data is processed to safeguard against a potential and uncertain claim.
In the opinion of the President of the Polish DPA, it is inadmissible to process personal data "just in case," assuming that they may be potentially useful in the future and referring to the provisions concerning the limitation period for civil claims.
Furthermore, in the judgments mentioned above, the Provincial Administrative Court found it unjustified for data controllers to invoke the necessity of having personal data for the purposes of a potential court dispute, as in the event of such a dispute arising, personal data will still be provided by the person initiating the proceedings, resulting in the data controller, as the defendant, having access to it.
Legal Bases Relating to the Retention of Personal Data
According to Article 17(1) of the GDPR, the data subject may request the deletion of their personal data if the personal data are no longer necessary for the purposes for which they were collected or otherwise processed. However, the right to be forgotten does not apply in cases where the processing of data is necessary for the establishment, exercise, or defense of legal claims. This is a consequence of the principle of data minimization, regulated in Article 5(1)(e) of the GDPR. According to this principle, personal data may be stored for no longer than is necessary for the purposes for which they are processed.
This principle is intended to protect the data subject from the processing of their personal data for an unlimited period. Therefore, it is the obligation of each data controller to designate the necessary period (the retention period for personal data) during which they will process the personal data they have collected. Of course, in some cases, this period is explicitly provided for by applicable legal regulations, such as in the case of the retention period for employee records or medical documentation.
In other situations, it is the responsibility of the data controllers to independently determine how long they will retain the personal data they have collected. Therefore, when determining the retention period for data, data controllers refer to the limitation periods for civil law claims, basing such actions on the legal basis for processing personal data specified in Article 6(1)(f) of the GDPR.
Is Personal Data Really Processed "Just in Case"?
In answering this question, it is essential to keep in mind that data controllers cannot predict when and what claims will be made by the data subjects. Limiting the legitimate interest pursued by the data controller solely to claims currently being pursued at the time of exercising the right to be forgotten places them in a less advantageous position than the rights holder exercising that right. The data subject may thus lead to the permanent deletion of their personal data and subsequently file a claim for which the data controller no longer has any evidence due to the deletion of all data.
The above leads to a situation in which data controllers are deprived of a real opportunity to defend themselves against claims (both in court and out of court), thereby disrupting the balance between individuals' rights to manage their rights and the legitimate interests of the data controller. It should be emphasized that the obligation to delete personal data is associated with the necessity to remove, among other things, the history of transactions made by the client and any correspondence conducted, which deprives the data controller of any evidentiary means.
The above is of great importance, especially in claims arising from Article 82 of the GDPR, according to which the data controller, in the event of potential proceedings, is obliged to prove that they are in no way at fault for the event that led to the damage (Article 82(3) of the GDPR).
Access to personal data as a result of a claim made by the data subject will not be sufficient, as the data controller will not have other information that would allow them to refute the allegations made against them.
Limitation of Claims and Personal Data
It should be noted that claims may be pursued within the time limits provided by the provisions of the Civil Code. The institution of limitation of claims is based on the assumption that the creditor (i.e., the person entitled to a claim against the debtor) can exercise their right against the debtor within a specified period, and after its expiration, the debtor – depending on their choice – may evade satisfying the creditor's claim. The limitation period is the time for pursuing the claim, without the need to take into account the debtor's evasion of satisfying it.
In connection with the above, since the legislator has provided a period during which claims may be pursued, it should be accepted that this period also justifies the retention of personal data for this purpose. Moreover, in Polish legislation, there is no institution of "notification of a claim." In the above case, there will therefore not be any processing of personal data for an unlimited period, as this period has been determined by the provisions regarding the limitation periods for claims, which also contributes to the realization of the principle of limited processing of personal data. The practice of data controllers invoking the retention of data for the period resulting from the limitation periods for claims ensures a uniform approach, thereby preventing the application of different data retention periods in analogous situations and the processing of data for a longer period.
Free knowledge about GDPR.
Use it freely!
The inability to process personal data after the termination of the contractual relationship (due to the necessity of deleting personal data) based on the legitimate interest of the data controller deprives the data controller of the ability to exercise their entitled rights.
Approach of Other Countries
An example of such an approach can be Bulgaria, where administrative courts have stated that a data controller may base the processing of special categories of personal data on the legitimate interest of the data controller, which is the establishment, pursuit, or defense of claims (Article 9(1)(f) GDPR) in order to safeguard against a claim that may arise in the future, and not solely against an already existing claim.
Moreover, the presented position indicates that the legal basis for processing personal data for the purpose of establishing, protecting, and pursuing claims should be considered superior to the interests and rights of the data subject. Consequently, the data controller is not required to conduct a legitimate interest assessment (LIA) to demonstrate a balance between the interests of the data controller and the interests, rights, and freedoms of the data subject, i.e., the individual to whom the processed data pertains.
Summary
When considering the issues of personal data processing for the period resulting from the provisions regarding the limitation of civil law claims, it should be remembered that the right to personal data protection should be viewed in the context of its social function and balanced against other fundamental rights in accordance with the principle of proportionality. The right to personal data protection should not restrict the rights of data controllers to effectively pursue or defend against claims. This is especially true since the data controller, prior to processing based on Article 6(1)(f) of the GDPR, should conduct a legitimate interest assessment (LIA) that indicates how the processing affects the freedoms and rights of the individuals whose data is being processed, and only based on the conducted assessment decides to rely on this basis for processing.
In this regard, processing personal data for the purpose of establishing, pursuing, or defending claims based on Article 6(1)(f) of the GDPR should be considered justified, provided that the processing is limited solely to storage and such data will not be used for other purposes.
We could talk about the GDPR for hours. If you are looking for support from the best experts in the market, schedule a consultation with Cezary Lutyński – he will introduce you to the world of regulations and guide you on the right path.


