A few words about collections containing sensitive data in the register maintained by the data controller.

29 July 2015

In accordance with the provisions of the amended Personal Data Protection Act (hereinafter referred to as the "Act"), the designated and registered data security administrator (hereinafter referred to as the "ABI") in the register maintained by the Inspector General for Personal Data Protection (hereinafter referred to as the "GIODO") is obliged to maintain a register of personal data sets (Article 36a(2)(2) of the Act). According to the cited article, the ABI does not include in the register only those sets that are exempt from the registration obligation under Article 43(1) of the Act.

It should be noted that other collections not mentioned in Article 43(1) of the Act are subject to registration in the register maintained by the DPO, even if they contain sensitive data and, as a result, are also subject to mandatory registration in the register maintained by the Polish DPA (Article 43(1a) of the Act). This means that the mere fact that collections of personal data, including sensitive data, are required to be reported to the Polish DPA does not imply that this collection should not be included in the register maintained by the DPO.

GDPR Bulletin
Receive a package of free GDPR guides and micro-training sessions
Join the ranks of our newsletter readers, receive a free package, and stay informed.
RECEIVE PACKAGE

Therefore, if the collection of personal data containing sensitive data does not fall within the catalog of collections exempt from registration, it should be disclosed in the register maintained by the DPO and in the register maintained by the Polish DPA. An example of such a collection is a collection created for the purposes of conducting research by entities other than those providing medical services, for which sensitive personal data regarding health status will be used. Such a collection will be subject to registration both in the register of personal data collections maintained by the Polish DPA – as it does not fall within the catalog of collections exempt from this obligation and contains sensitive personal data – and in the register maintained by the DPO.

In summary, the necessity of registering a collection of data, within which sensitive data is processed in the Polish DPA register, does not exempt the DPO from the obligation to include the collection in its own register, provided that it does not fall within the catalog of collections for which the obligation to register is explicitly excluded (Article 43(1)).

However, it should be emphasized that all the above observations remain valid only if the DPO has been appointed and reported to the register maintained by the Polish DPA.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.