Controls of the President of the Polish DPA – experiences and recommendations

17 May 2019

In the article "Welcoming Our Guests – Polish DPA Inspection," we explained the steps to take in the event of an inspection, while in the "Polish DPA Inspection Scheme," we answer questions regarding the rights and obligations of the data controller. Below, we present our experiences and recommendations that are worth utilizing right now.

Understanding the Work of Data Controllers

The key not only to preparing for an audit but also, in essence, to properly implementing and maintaining compliance with the GDPR is the ability to put oneself in the shoes of the auditors from the Polish Data Protection Authority (UODO) and to implement solutions that indicate the fullest possible compliance with data protection regulations.

In addition to knowledge of the regulations, which we explain in the articles mentioned above, it is important to be aware that auditors will want to perform their job well, primarily by:

  1. firstly – addressing all aspects of the audit – thus obtaining answers to every aspect of the authorization to conduct the audit,
  2. secondly – documenting all findings – thus obtaining the most comprehensive audit evidence – documents and prints of photographs from inspections,
  3. thirdly – preparing complete audit reports.

Awareness of what could potentially be the subject of an audit and what its scope may be is very important not only for direct preparation for the audit but, above all, for achieving and maintaining compliance with the GDPR. Through further reading, you will learn what to pay attention to in relation to each of the objectives that the auditor will want to achieve.

Addressing All Aspects of the Audit

GDPR Bulletin
Receive a package of free GDPR guides and micro-training sessions
Join the ranks of our newsletter readers, receive a free package, and stay up to date.
RECEIVE PACKAGE
Potential questions from auditors will depend on the content of the authorization for the audit. The authorization may revolve around the entire activity of the organization or – more likely – around a specific part of the organization's activity, most often related to the subject of a complaint or a report of a data protection breach that has been submitted to the Polish DPA.

During the inspection, all facts and circumstances that may be relevant for assessing compliance with personal data protection regulations will be examined. The assessment of compliance will be carried out by the President of the Polish DPA after the completion of the inspection activities – based on the collected information and materials. The inspectors will investigate facts pertinent to each aspect of the authorization for inspection, as this authorization will serve as the starting point for the structure of the inspection report.

Example: A typical authorization for inspection includes the determination of:

  1. the legal bases for processing personal data,
  2. the sources from which personal data is obtained,
  3. the categories of individuals whose data is concerned, as well as the categories of processed personal data,
  4. the purposes for which the data is processed,
  5. the recipients to whom the data is disclosed, as well as the details of sharing (legal basis, purpose, scope, and manner),
  6. the manner of fulfilling the information obligation,
  7. the manner of exercising the rights of individuals whose data is concerned,
  8. the principles of data processing delegation,
  9. authorizations for data processing,
  10. the implementation of data protection policies and procedures (including their formal validity and the awareness and training of staff members),
  11. whether a Data Protection Officer has been appointed,
  12. whether personal data is not stored for too long,
  13. whether technical and organizational measures have been implemented to ensure an appropriate level of data security,
  14. whether a records of processing activities and a record of all categories of processing activities are maintained,
  15. whether all data breaches are adequately documented.

Tip: Since the inspection involves personal interviews, evidence collection, and inspections, it is crucial to prepare responses in advance to potential questions from the inspectors. The most comprehensive answers are obtained by conducting an audit of the location to be inspected. As interviews may be conducted with any employee, it is advisable to ensure that they possess adequate knowledge of data processing principles.

DPO Function - it is well conveyed

Documentation of All Arrangements

Data controllers very rarely rely solely on verbal agreements. Almost all arrangements will need to be documented by attaching originals or certified copies of the requested documents to the protocol, as well as prints of photographs that the auditors may specifically request during inspections. Failure to present evidence of compliance with the GDPR may be considered a violation of the obligation to ensure accountability (Article 5(2) and Article 24(1) GDPR).

Example: When examining the issue of employee obligations, auditors may request not only the document granting authorization but also a document confirming employees' commitment to confidentiality and their awareness of the data protection principles they should adhere to (i.e., confirming familiarity with the data protection documentation).

Tip: It is crucial to gather the documents that auditors may request in advance. This will enable us to provide more accurate explanations and rectify any potential discrepancies. To avoid preparing documents just before the audit, the best approach is to take a comprehensive stance, i.e., to prepare and formally adopt policies, procedures, and records that cover those aspects of the GDPR that relate to a typical authorization for inspection (see the list above). Having such procedures, as well as proof that employees have familiarized themselves with them (and preferably that they have been trained on them), will indicate compliance with the GDPR. Since it is impossible to predict all materials that auditors will request, it is advisable to ensure continuous access to a color printer.

Preparation of Complete Audit Protocols

GDPR Tools
Working with Good GDPR Tools is not work!
Applications, calculators, GDPR snapshots - everything that can help you manage your personal data protection system.
SEE MORE
During the audit, partial reports will be prepared – including explanations from individual persons and observations (i.e., site visits). Based on these, a final report will be prepared. Each of the reports should be signed by both the auditors and the representatives of the audited entity. Each report should be read carefully – preferably by at least two people. Even if the final report reiterates the findings from the partial reports, it is advisable to read it calmly once again to ensure that none of the facts important to us have been omitted.

Example: It may happen that the auditors, who receive a lot of information and explanations from us, forget to include favorable findings in the report, such as the use of encryption or the implementation of a clean desk and screen policy. The auditors may also misunderstand our explanations, which we will only learn about from the content of the report.

Tip: If necessary, especially in the case of findings in the report with which we disagree, it is advisable to make use of Article 88(4) of the Personal Data Protection Act, which grants the audited party the right to submit written objections to the content of the report within 7 days from the date it is presented for signature.

Summary

Preparation for the audit can be seen as a last resort – this will be the case if we do not ensure compliance with the GDPR until the notification of its conduct. It is much better if preparation for the audit becomes a kind of philosophy for implementing and maintaining compliance with the GDPR. Since the audit is one of the final forms of verifying compliance with the GDPR, preparing the organization for it will also be the best way to ensure a smoothly functioning data protection system.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.