Table of Contents
Checklist - We Provide a Tool
To assist you in verifying whether remote work in your company has been organized in a secure manner, we have prepared an interactive survey that you can fill out and save (pdf). This will demonstrate that you are monitoring compliance with the GDPR.
Introduction
The necessity of organizing remote work in a way that maintains the continuity of key business processes arose from the realities of the pandemic and was solidified by the amendment to the Labor Code, which came into effect at the beginning of 2023. Many companies and institutions have enabled employees to work from their homes and use personal computers and smartphones, as well as commercial tools for communication (Slack, Zoom, Skype, Webex) or information gathering (Dropbox, Google Drive, OneDrive).
The above conveniences were often implemented hastily, without adhering to the appropriate security standards of the organization and without the necessary risk analysis. Meanwhile, the requirements regarding information security (including personal data), which pertain to maintaining their confidentiality, availability, and integrity during remote work, remain the same as under normal conditions (point 17.1.1 ISO/IEC 27002).
As a result, a problem has arisen regarding the compliance of the conducted activities with legal requirements, contractual obligations, and internal policies concerning the protection of personal data. This particularly pertains to the security of processed data, the principles of entrusting personal data for processing, and their transfer to third countries.
The Data Protection Officer (DPO), as an independent specialist, is obligated to oversee compliance with personal data protection regulations and to monitor these activities. The guidelines of the European Data Protection Board WP 243 indicate that in the context of monitoring compliance with regulations, the DPO should, among other things:
- collect information to identify processing activities,
- analyze and verify the compliance of such processing,
- inform the data controller, advise them, and recommend specific actions.
In our article, we indicate what procedures data controllers should implement to regulate the monitoring by the DPO of compliance with personal data protection regulations, supervision over remote processing of personal data by staff, and the authority regarding the documentation of adopted arrangements. We also present example topics that may be subject to supervision.
Would you like to discuss the issue of monitoring the security of remote work with our specialist? Cezary Lutyński – our data protection advisor will certainly assist you.
Basic Regulations Regarding Monitoring Compliance with GDPR
According to Article 39(1)(b) of the GDPR, the Data Protection Officer is responsible, among other things, for monitoring compliance with personal data protection regulations and internal policies established in this regard by the data controller or data processor. A document that undoubtedly falls into this category is the personal data protection procedure for remote work. The obligation to implement it arises from Article 67(26) § 1 of the Labor Code.
The GDPR does not specify formal requirements regarding internal mechanisms for maintaining a personal data protection system, leaving significant discretion to the data controller in shaping policies and procedures in this area. Consequently, the methods for implementing oversight of compliance with personal data protection regulations, the planning process for this oversight, conducting and documenting it, as well as the methods for distributing requests should be defined by the data controller and stem from a risk analysis of the resources defined by the data controller (managed or entrusted personal data) and threats (rights and freedoms of individuals whose data is processed), taking into account the existing processing conditions (nature, scope, context, and purposes of processing). The solutions adopted within the organization should ensure effective oversight of the personal data protection system within each identified location where processing operations take place (including in the context of remote work, if such a form of work is permitted by the data controller).
The President of the Polish Data Protection Authority (UODO), referring to Article 24(1) of the GDPR, also emphasizes the necessity of having procedures for monitoring compliance with personal data protection regulations. He underscores that the data controller should comprehensively demonstrate compliance with processing, including, among other things, ensuring control over the data processing process through monitoring by the Data Protection Officer (DPO) of adherence to regulations and adopted processing procedures.
Furthermore, the President of the UODO draws attention to the mechanisms for monitoring, reviewing, and improving the information security management system, as mentioned in the regulation of the Council of Ministers of April 12, 2012, on the National Interoperability Framework, minimum requirements for public registers and electronic information exchange, and minimum requirements for teleinformation systems. The President of the UODO refers to the requirements of § 20(2)(14) of the aforementioned regulation – the obligation to conduct a periodic internal audit regarding information security at least once a year.
It should be noted that the procedures and requirements adopted regarding the internal mechanisms established by the data controller for maintaining the personal data protection system must be adequate to the current state of technical knowledge – in accordance with Article 32(1) of the GDPR. According to the guidelines of the European Data Protection Board 4/2019 regarding Article 25 of the GDPR (data protection by default and data protection by design), this pertains both to technical knowledge about available security measures and knowledge about security management systems (standards regarding management, documentation of changes, configuration, and other elements that should be included in the processing documentation).

E-LEARNING
GDPR in Remote Work
after the amendment of the Labor Code
Through the training, employees will learn how to easily enhance the security of remote work.
In this regard, also considering the provisions of the ISO/IEC 27001 standard (point 9.2), the Data Protection Officer should conduct audits in the area of personal data protection to provide the data controller with information on whether the functioning system complies with personal data protection regulations and internal policies in this regard, as well as whether it is effectively implemented and maintained.
This requires the establishment of mechanisms for planning, establishing, implementing, and maintaining audit programs, including in the areas of:
- the frequency of audits, methods used, and reporting requirements,
- criteria and scope of each audit,
- presenting audit results to the highest management of the data controller,
- the retention period for audit reports.
In the audit program, the data controller and the Data Protection Officer should assign higher priority to those areas that are particularly significant for the given personal data protection system. Due to the increased risk, this includes the organization and execution of remote work. Therefore, this is a risk-based audit.
An audit is a systematic, independent, and documented process, with specific formal requirements regarding its initiation (the necessity of informing the data controller in a timely manner), execution, and documentation. Therefore, the data controller should consider employing flexible forms of compliance monitoring, such as ongoing verification of adherence to personal data processing policies.
It is important to emphasize that an audit conducted by the DPO as part of monitoring is not the same as the remote work control referred to in Article 6728 of the Labor Code, nor does it replace it. At first glance, it may seem that the subject matter of these two activities is – although partially – aligned. The control may encompass issues related to occupational health and safety as well as compliance with information security requirements – including data protection procedures. However, the difference lies in the fact that the audit aims to verify how well the entire organization has implemented data protection procedures, while the control merely verifies whether a specific employee complies with them.
Monitoring Methods
Considering the above findings, monitoring compliance with personal data processing conducted in the context of remote work can be carried out through:
- scheduled audits – in accordance with the adopted audit program,
- ad-hoc audits, when the Data Protection Officer becomes aware of a personal data breach or has reasonable suspicion of such a breach occurring,
- ongoing verification of adherence to personal data processing policies based on reports from individuals performing duties specified in the data processing documentation or reports from third parties or at the initiative of the Data Protection Officer.
During the audit (regardless of the method of its execution), the DPO should assess:
- the development and completeness of data processing documentation,
- the compliance of data processing documentation with applicable legal regulations,
- the factual state regarding personal data processing,
- the compliance of the technical and organizational measures for data protection specified in the data processing documentation with the factual state,
- the adherence of personnel to the principles and obligations specified in the data processing documentation.
Methods of Documenting Activities During Monitoring
The Data Protection Officer documents the activities undertaken as part of monitoring to the extent necessary to assess the compliance of personal data processing with the provisions on personal data protection and in a manner specified by the data controller in the personal data protection documentation.

TRAINING
GDPR in HR
after the amendment of the Labour Code
For individuals who want to understand what personal data protection entails in the context of personnel data and how to apply legal requirements in this area.
Documenting activities may involve:
- recording data from the information system used for processing personal data on an electronic data carrier or printing out this data,
- preparing a note from the activities, in particular from the collected explanations, conducted inspections, and activities related to access to devices, carriers, and information systems used for processing personal data,
- receiving explanations from the person whose activities are subject to verification,
- preparing a copy of the received document,
- preparing a copy of the image displayed on the screen of the device that is part of the information system used for processing personal data,
- preparing copies of the records of the information system used for processing personal data or records of the technical configurations of the security measures of that system.
Areas Subject to Verification
The criteria for monitoring conducted by the Data Protection Officer – in addition to being regulated by the provisions on personal data protection – are also defined in the detailed policy and procedure established by the respective data controller. Nevertheless, universal elements for the remote work model can be distinguished. These include:
- personal security,
- physical and environmental security,
- network security,
- computer hardware security,
- security of systems and applications.

