
On February 21, 2019, the Sejm adopted the Act amending certain acts in connection with ensuring the application of the Regulation of the European Parliament and of the Council (EU) 2016/679 of April 27, 2016, on the protection of natural persons in relation to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). It was published in the Journal of Laws in mid-April and came into force at the beginning of May.
Link to the Act: http://isap.sejm.gov.pl/isap.nsf/DocDetails.xsp?id=WDU20190000730
The purpose of the Act is to harmonize the provisions of individual legal acts with the GDPR. It amends as many as 162 laws (including, among others, the Code of Administrative Procedure, the Labor Code, the Banking Law) in order to regulate issues related to the processing of personal data arising from the GDPR. Such a large one-time amendment of sectoral regulations has not occurred in years.
Entities from both the public and private sectors must monitor changes and new obligations, as they will affect almost all of them.
Changes in the Labor Code
Receive a package of free GDPR guides and micro-trainings
Changes in the Company Social Benefits Fund
Another important change is the specification of the form for providing personal data of the employee and their family in the regulations concerning the company social benefits fund. The provision of personal data should occur through the submission of employee statements to the employer instead of delivering copies of documents containing a wide range of sensitive data. The new regulations also allow for the documentation of specific claims made by the employee by presenting an appropriate certificate confirming the factual state. Such action will strengthen the protection of personal data not only for the employee but also for their family, as employers should move away from the practice of copying documents that contain, for example, medical history.
Information Obligation Fulfilled by Micro-Entrepreneurs
A new element introduced by the Act of February 21, 2019, is the indication of how micro-entrepreneurs can fulfill their information obligation. The provisions of the Consumer Rights Act allow micro-entrepreneurs to meet the information obligation by displaying the necessary information in a visible place in their premises or by making it available on their website. It should be noted that the information obligation has not been excluded for such entrepreneurs; rather, a possible method of fulfilling it has been indicated. Regarding the information obligation, there is also the possibility of postponing its execution by public administration bodies (e.g., central government administration bodies, local government bodies). Such data controllers may fulfill the information obligation by providing the relevant information at the first action directed to the party to the proceedings, e.g., in the first letter or summons.
Changes in the Penal Code
For every entrepreneur, the amendment to the definition of unlawful threat is important. Its expanded catalog will also cover the threat of initiating proceedings in which an administrative monetary penalty may be imposed. This change will curb the actions of all fraudsters exploiting the confusion related to the GDPR, who have been sending advertising information in recent months indicating that failure to purchase an expensive audit or ready-made personal data protection policies will result in multi-million fines imposed by the Polish Data Protection Authority.
Other numerous changes in various laws aim, among other things, to directly indicate the entity that is the data controller (in many cases, identifying the controller was problematic), to establish retention periods for personal data by data controllers, and to regulate issues related to data protection concerning representatives of professional self-governments.


