The next stage of the reform of personal data protection regulations.

10 May 2019

The reform of regulations related to personal data protection is ongoing. It should be noted that it consists not only of the provisions of the key legal act, which is the GDPR, but also of hundreds of regulations contained in Polish laws and executive regulations.

Summary 2018

On February 21, 2019, the Sejm adopted the Act amending certain acts in connection with ensuring the application of the Regulation of the European Parliament and of the Council (EU) 2016/679 of April 27, 2016, on the protection of natural persons in relation to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). It was published in the Journal of Laws in mid-April and came into force at the beginning of May.

Link to the Act: http://isap.sejm.gov.pl/isap.nsf/DocDetails.xsp?id=WDU20190000730

The purpose of the Act is to harmonize the provisions of individual legal acts with the GDPR. It amends as many as 162 laws (including, among others, the Code of Administrative Procedure, the Labor Code, the Banking Law) in order to regulate issues related to the processing of personal data arising from the GDPR. Such a large one-time amendment of sectoral regulations has not occurred in years.

Entities from both the public and private sectors must monitor changes and new obligations, as they will affect almost all of them.

Changes in the Labor Code

GDPR Bulletin
Receive a package of free GDPR guides and micro-trainings
Join the ranks of our newsletter readers, receive a free package, and stay up to date.
RECEIVE PACKAGE
Several changes are particularly significant, and therefore it is worth discussing them. These include a broad amendment to the Labor Code, which will present new challenges for employers already at the stage of recruiting employees. It is important to note the closed catalog of personal data that an employer may request from a candidate. This data includes: first name, last name, date of birth, and contact details provided by the job applicant. However, information regarding education, professional qualifications, or the history of previous employment may only be requested by the employer if it is necessary for the performance of the job. Additionally, employers are now required to provide written authorization to employees who have access to special category data (e.g., health-related data) to process such personal data.

Changes in the Company Social Benefits Fund

Another important change is the specification of the form for providing personal data of the employee and their family in the regulations concerning the company social benefits fund. The provision of personal data should occur through the submission of employee statements to the employer instead of delivering copies of documents containing a wide range of sensitive data. The new regulations also allow for the documentation of specific claims made by the employee by presenting an appropriate certificate confirming the factual state. Such action will strengthen the protection of personal data not only for the employee but also for their family, as employers should move away from the practice of copying documents that contain, for example, medical history.

GDPR. Support is useful!

Information Obligation Fulfilled by Micro-Entrepreneurs

A new element introduced by the Act of February 21, 2019, is the indication of how micro-entrepreneurs can fulfill their information obligation. The provisions of the Consumer Rights Act allow micro-entrepreneurs to meet the information obligation by displaying the necessary information in a visible place in their premises or by making it available on their website. It should be noted that the information obligation has not been excluded for such entrepreneurs; rather, a possible method of fulfilling it has been indicated. Regarding the information obligation, there is also the possibility of postponing its execution by public administration bodies (e.g., central government administration bodies, local government bodies). Such data controllers may fulfill the information obligation by providing the relevant information at the first action directed to the party to the proceedings, e.g., in the first letter or summons.

Changes in the Penal Code

For every entrepreneur, the amendment to the definition of unlawful threat is important. Its expanded catalog will also cover the threat of initiating proceedings in which an administrative monetary penalty may be imposed. This change will curb the actions of all fraudsters exploiting the confusion related to the GDPR, who have been sending advertising information in recent months indicating that failure to purchase an expensive audit or ready-made personal data protection policies will result in multi-million fines imposed by the Polish Data Protection Authority.

Other numerous changes in various laws aim, among other things, to directly indicate the entity that is the data controller (in many cases, identifying the controller was problematic), to establish retention periods for personal data by data controllers, and to regulate issues related to data protection concerning representatives of professional self-governments.

Authors:
Marcin Zadrożny, data protection expert.
Piotr Liwszic, data protection specialist.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.