On September 14, 2016, a more than two-hour debate organized by the Polska Press publishing house took place under the title “European Data Protection Regulation. What awaits us, how to prepare?”, in which experts in personal data protection participated:
Receive a package of free GDPR guides and micro-trainings
- Piotr Drobek, Deputy Director of the Department of Social Education and International Cooperation at the GIODO Office,
- Magdalena Piech - Lewiatan Confederation,
- Joanna Karczewska - ISACA,
- Attorney Marcin Zadrożny - Knowledge is Safety Foundation,
- Monika Sobczyk - Medicover,
- Mariola Więckowska - Allegro Group,
- Attorney Emil Zubelewicz - Orange Polska,
- Attorney Kamila Niewęgłowska-Kennedy - Allianz,
- Maciej Kaczmarski - ODO 24.
The experts discussed the challenges that the new European regulations pose for entrepreneurs. “One must be aware that the entire system of personal data protection is changing,” noted a representative of the GIODO. Enterprises must be prepared by the date of the General Data Protection Regulation coming into effect, which is May 25, 2018. According to the experts participating in the debate, there is little time left for adaptation. Large organizations are already preparing for the implementation of the regulation, and those that have decided to implement the ISO/IEC 27001 standard are doing so significantly more efficiently. One such organization is Medicover, which is currently “consuming” the added value (in the area of personal data protection) resulting from the implementation of the ISO/IEC 27001 standard, which standardizes the information security management system.
Under the regulation, there will primarily be a change in the approach to the protection of personal data. It will be the data controller who must determine what solutions and tools will be used to protect personal data – the regulations will no longer specify how to create passwords or the frequency of their change. The regulation does not explicitly impose an obligation to maintain documentation regarding the protection of personal data, as the Personal Data Protection Act did; however, the data controller or the data processor will be required to demonstrate the implementation of appropriate policies and procedures. The regulation introduces the obligation to consider personal data protection already in the design phase and to set default personal data protection in products and services. Allegro began preparations for changes in the law two years ago, notes the Information Security Administrator at Allegro Group. Since then, it has been conducting a risk analysis and proactively approaching personal data protection in its services. A representative of the Polish Data Protection Authority emphasized that the new regulation is intentionally general so that the principles contained within it can be applied across various sectors, taking into account the specifics of their operations.
We present an animation illustrating the key changes and innovations brought about by the EU reform:
Experts debated the key changes that the regulation brings for businesses. Topics discussed included: the obligation to record processing activities, the reporting of personal data breaches within 72 hours, profiling, the obligation to assess the impact of planned processing operations on personal data protection, including mandatory consultations with the Polish DPA, high administrative fines for violations of the regulation, certification mechanisms, and an expanded information obligation. A representative of Orange Polska pointed out that the new regulations aim to protect data subjects; however, they will pose challenges for businesses that process data, for example, during a phone call with a consultant who will have to ask for multiple consents and read a lengthy privacy notice. She also mentioned that Orange Polska, as a large company, continues to identify areas where changes will need to be made due to the fact that the legal changes affect practically all business segments of the organization.
A representative of the Lewiatan Confederation emphasized that a significant challenge awaits the Polish legislator. Many laws, including sector-specific ones, require amendments – including the Banking Law, Telecommunications Law, Insurance Law, and the Act on Economic Information Offices. National legal acts must comply with the regulation.
The topic of outsourcing the functions of the Data Protection Officer (DPO) has sparked intensified discussions, and in the future, the role of the DPO. Engaging a specialized entity providing such services guarantees professional support in the field of personal data protection and the implementation of an efficient data protection system. Of course, a data protection system based on an "internal" DPO has its advantages, but when hiring a new person to perform such a role within the organization, it is difficult to verify their competencies and, later on, the reliability of their work. Practice shows that some organizations that opt for an "internal" DPO do not hire a new individual but appoint someone who is already an employee, thereby adding new responsibilities to their existing role. This often proves detrimental to the organization itself, as such a person may lack sufficient knowledge, experience, and simply enough time to perform their additional duties professionally.
In summary, entrepreneurs must primarily learn to actively utilize the knowledge of the DPO or specialized entities in order to adapt to the new legal requirements.


