Formal Requirements for the DPO
To become a Data Protection Officer, the following criteria must be met:
- have full legal capacity and the ability to exercise public rights,
- not have been convicted of an intentional crime,
- possess appropriate knowledge in the field of personal data protection.
Receive a package of free GDPR guides and micro-trainings
With such a DPO, the data controller is exempt from the obligation to register ordinary data sets with the Polish DPA (sensitive data sets, except for those covered by Article 43 of the Personal Data Protection Act, still require registration). However, they must register their DPO with the Polish DPA!
Registration of the DPO with the Polish DPA
As of January 1, 2015, the data controller is required to report the appointment and dismissal of the Data Protection Officer to the Polish DPA each time. The deadline for such notification is 30 days from the appointment or dismissal. The notification of the appointment of the Data Protection Officer includes:
- identification of the data controller and the address of their registered office or place of residence, including the identification number from the National Business Registry, if assigned,
- data of the Data Protection Officer:
a) first name and surname,
b) PESEL number or, if this number has not been assigned, the name and number of the identity document,
c) correspondence address, if different from the address of the data controller, - date of appointment,
- the data controller's statement that the Data Protection Officer meets the necessary conditions to perform the specified function.
Changes to the information covered by the above notification must be updated within 14 days of their occurrence.
Notification Form for the appointment of the information security administrator is provided below. Its relatively small size is noteworthy, significantly smaller than the notification for the registration of a personal data set. Instead of eighteen, the data controller fills out two, relatively simple and intuitive pages of the form. This solution is decidedly more user-friendly for the notifier and additionally minimizes costs on the part of the data controller.
The above form allows the Polish Data Protection Authority to verify whether the data controller has indeed met the necessary conditions to be exempted from the obligation to register data sets. The information contained in the notification will serve as the basis for making the appropriate entries in the register of information security administrators and for their removal from this register.
The entry or removal of the information security administrator occurs through a material-technical action (the transfer of information by the data controller). The removal of the information security administrator from the register may also be carried out based on an administrative decision issued ex officio. This occurs in three cases:
- when the data controller does not notify the Polish Data Protection Authority of the dismissal of the information security administrator,
- when the information security administrator does not meet the statutory requirements,
- when the information security administrator does not perform their statutory duties.
In the case of information security administrators appointed before December 31, 2014, the data controller has until June 30 of this year to register them. Until that time, regardless of registration, the information security administrator performs their function in accordance with the new regulations.
Status and Duties of the Information Security Administrator
The amendment to the Personal Data Protection Act clarified the status of the information security administrator within the organization. The most important changes are:
- the specification of the hierarchical subordination of the information security administrator – they report directly to the data controller (the owner of the company, management, etc.),
- the possibility for the superior to assign the information security administrator other tasks than those specified in the law, provided that they do not hinder the proper performance of statutory duties,
- the possibility of appointing a deputy information security administrator who meets the same requirements as the information security administrator (this can be of great importance, especially in crisis situations when the information security administrator is temporarily unable to perform their duties).
The amendment also specified the duties of the information security administrator. They focus on two main issues: ensuring compliance with personal data protection regulations, including:
- verifying the compliance of personal data processing with personal data protection regulations and preparing a report for the data controller in this regard,
- overseeing the development and updating of personal data protection documentation (i.e., security policies and instructions for managing the IT system) and ensuring compliance with the principles set forth therein,
- ensuring that authorized persons involved in the processing of personal data are familiar with the regulations on personal data protection,
and maintaining a public register of ordinary personal data sets processed by the data controller.
ABI in the GIODO control model
According to the amendment, the GIODO may delegate information security administrators to verify the compliance of personal data processing in the enterprises they serve. This constitutes a significant relief for data controllers (including entrepreneurs), who previously were subject to direct control by the GIODO. It is worth noting that the control carried out by the ABI in no way infringes upon the competencies of the GIODO, which merely allows for simplified control at its discretion and is not limited in its ability to conduct its own subsequent inspections.
It should not be confused with the annual report prepared for the data controller. In the first case, the ABI, at the request of the GIODO, verifies the compliance of personal data processing with the regulations on personal data protection at the data controller that appointed it. The report from such verification is presented, through the data controller, to the GIODO. In the second case, the verification conducted by the ABI is of an internal audit nature, and thus the resulting report is an internal document of the data controller.


