Educational Information System
Many doubts among individuals involved in personal data protection in educational institutions arise regarding the necessity of registering personal data sets maintained under the educational information system.
Receive a package of free GDPR guides and micro-trainings
In light of the provisions of the Act on the Educational Information System, the only sets that may contain personal data are those concerning teachers, educators, and other pedagogical staff referred to in Article 3(4)(1) of the mentioned Act.
Considering that data controllers processing data related to employment are exempt from the obligation to register such a set with the Inspector General for Personal Data Protection, it should be acknowledged that schools and other educational institutions employing teachers are exempt from the registration obligation. However, the obligation to report the aforementioned sets for registration to the General Inspector for Personal Data Protection will apply to local government units (communes, counties), as they do not employ the individuals whose data is concerned.
Share Registers and Stock Registers
Two seemingly similar situations, yet with very different outcomes. The data of shareholders of a limited liability company is publicly available (disseminated). This results from Article 8 of the Act on the National Court Register, according to which the register is public, and everyone has the right to access the data contained therein through the Central Information of the National Court Register. This means that the data set of individuals who are shareholders of a limited liability company does not require registration with the General Inspector.
The situation regarding the registration of the share register is different. According to Article 341 § 7 of the Commercial Companies Code, the share register is public for every shareholder. Therefore, it is not generally accessible (provided by the data controller), and consequently, the exemption from the registration obligation is not justified under Article 43(1)(9) of the Personal Data Protection Act. The collection of personal data of the company's shareholders, as well as the collection of holders of bearer shares, is subject to the obligation of registration.
Publicly Available Data
The Polish DPA considers publicly available data to be those that can be accessed by an unlimited number of entities without requiring special effort and resources. The data controller is exempt from the registration obligation if all, and not just some, of the data contained in the collection is publicly available. It should be added that this refers to data that the controller processes, not data that is collected from publicly available data sets.
GDPR Compliance Diagnosis.
Do It Yourself
Therefore, in the case of providing all data processed in the collection to an unlimited number of entities (e.g., via the internet), the data controller is not obliged to report this collection for registration to the General Inspector for Personal Data Protection, in accordance with Article 43(1)(9) of the Personal Data Protection Act.
Paper Correspondence Register
It is commonly believed that a paper correspondence register is not a collection of personal data. Nothing could be further from the truth! Under the Personal Data Protection Act, it is a collection of data and may be subject to registration with the Polish DPA. This is because it meets the definition of a collection – it contains chronologically entered data in the form of: date of receipt, date of dispatch, and data identifying the sender or recipient of the correspondence.
Since the Personal Data Protection Act applies to the discussed dataset, such a dataset will also be subject to the registration obligation with the General Inspector of Personal Data Protection. None of the circumstances listed in Article 43(1) of the Personal Data Protection Act, which exempt the dataset from registration, are present.
Data Provided Under the Contract
Sometimes personal data is provided to the entrepreneur by the client for the purpose of executing the contract. The data controller is the party commissioning the work, and only they are entitled to register the dataset. The party receiving the commission does not register the dataset, as they process the data solely on behalf of the client.
Library Readers
How should the dataset of library readers be treated? The Polish DPA clearly explains the entire situation. If libraries run by schools or workplaces process only the data of individuals studying there, employed, or providing services to them based on civil law contracts, the datasets are exempt from the registration obligation. In cases where the datasets contain data of individuals other than those mentioned in Article 43(1)(4) of the Act, they will be subject to the obligation to report for registration to the General Inspector.
Read part one: Which datasets should be registered with the Polish DPA .1


