Polish DPA - a larger budget, more control?

12 February 2016

Everything indicates that the budget of the General Inspector of Personal Data Protection will increase by as much as 23.5% in 2016 – to PLN 20.6 million. The GIODO also plans to increase its workforce by as many as 20 people compared to 2015. It seems that this will also be a year of increased inspections, including in law firms.

As evidenced by the significant increase in the budget, the legislator is paying more and more attention to the issues of personal data protection and compliance with the Personal Data Protection Act. This topic is not only currently in the spotlight in Poland. This year, the pan-European reform of the personal data protection system is expected to conclude – after four years of intensive work, the Regulation of the European Parliament and the Council on the protection of natural persons in relation to the processing of personal data and the free movement of such data will likely be adopted.

The Inspector General for Personal Data Protection (GIODO) recently published on its website (http://www.giodo.gov.pl/1520252/j/pl/) plans for sectoral inspections and categories of entities to which requests for checks under Article 19b of the Personal Data Protection Act will be directed in 2016.

GDPR Bulletin
Receive a package of free GDPR guides and micro-training sessions
Join the ranks of our newsletter readers, receive a free package, and stay up to date.
RECEIVE PACKAGE

Sectoral inspections will take place, among others, in:

  • authorities authorized to use the Customs Information System (SIC),
  • authorities processing personal data in the Schengen Information System and Visa Information System, including SIS/VIS security audits,
  • data processors in the Eurodac System,
  • county offices,
  • law firms.

During the inspections, as stated in the announcement, the security of clients' personal data and the processing of personal data based on entrustment or outsourcing will be particularly examined.

In 2016, the Chief Inspector also plans to request inspections to be conducted by information security administrators in banks, insurance companies, and municipalities. As noted in the announcement, requests for checks will also be directed on an ad hoc basis to other entities at the request of the directors of departments of the Office of the Chief Inspector for Personal Data Protection or public authorities.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.