Obligations of the data controller of information systems

20 March 2017

At the outset, it should be noted that no legal regulations defining the management and security of personal data within an organization provide for the appointment of a person to the position of ASI. Both the European General Data Protection Regulation (GDPR) and the Personal Data Protection Act only define the role of the data controller, authorized persons, and optionally provide for the appointment of a Data Protection Officer (DPO). So where did the concept of ASI come from?

Who is the data systems administrator (ASI) and where did the concept originate?

This is a role that was developed and recognized as extremely important under the previous legal framework, which was in effect before May 25, 2018. As practice has shown, the person holding the DPO position in an organization often lacks sufficient knowledge regarding IT security and does not know which technical and organizational measures would be appropriate in a given case. Consequently, within the structure of the team responsible for the implementation or maintenance of the personal data protection system, the ASI role emerged. The person fulfilling this role should, to some extent, be a tool in the hands of the DPO and continuously collaborate with the Data Protection Officer, thereby ensuring the security of the processed data from an IT perspective. Can anyone become a data systems administrator in this context? What will be their responsibilities?

What requirements must a person designated for the ASI role meet?

The person serving as the data systems administrator can be an employee hired by the company under a civil law contract or an employment contract (an internal person) or someone from outside the organization (the so-called ASI outsourcing). It should be noted that this person should primarily possess appropriate IT knowledge but also stay updated on new threats and emerging solutions in the field of information security. To gain professional knowledge in this area, training and participation in conferences and other meetings on such topics are recommended. We should also not forget about the formalities related to fulfilling the role of data systems administrator. If it is an internal person, they should be granted authorization to process personal data. In the situation where we decide to outsource this function to an external entity, it will be essential to include appropriate provisions regarding the entrustment of personal data processing in the contract with the company providing such services (a draft of this contract can be found here). In both cases, it is also important to ensure that the contract or other regulations defining the type of cooperation include provisions regarding the confidentiality of data.

E-learning: cybersecurity

What does the data systems administrator do?

The primary task of the ASI is to cooperate with the Data Protection Officer (DPO) in overseeing compliance with personal data protection principles regarding IT security, including, among others:

  •  Collaboration in the preparation, implementation, and adherence by employees to personal data protection documentation, particularly the instructions for managing the IT system. The GDPR, unlike the previous legal framework, does not explicitly specify what scope of procedures within such documentation would be sufficient. However, the regulations emphasize the so-called accountability principle, according to which the data controller is obliged to implement appropriate technical and organizational measures and must be able to demonstrate this in the event of a potential audit. Furthermore, Recital 78 of the GDPR states that organizations should adopt appropriate policies. The scope of these policies remains unclear. In this regard, the President of the Polish Data Protection Authority has expressed that certain areas should be regulated through organizational safeguards in the form of formally adopted documentation by the organization, namely:
  • Collaboration in the preparation, implementation, and adherence by employees to personal data protection documentation, particularly the instructions for managing the IT system. The GDPR, unlike the previous legal framework, does not explicitly specify what scope of procedures within such documentation would be sufficient. However, the regulations emphasize the so-called accountability principle, according to which the data controller is obliged to implement appropriate technical and organizational measures and must be able to demonstrate this in the event of a potential audit. Furthermore, Recital 78 of the GDPR states that organizations should adopt appropriate policies. The scope of these policies remains unclear. In this regard, the President of the Polish Data Protection Authority has expressed that certain areas should be regulated through organizational safeguards in the form of formally adopted documentation by the organization, namely:
    •  asset management,
    • access control (registering and deregistering users, password management, use of privileged tools),
    • cryptographic protection measures (security policy implementation, key management),
    • physical and environmental security as well as operational security (change management, capacity management, business continuity assurance, event logging and monitoring),
    • communication security (network protection, separation),
    • acquisition, development, and maintenance of systems,
    • relationships with suppliers (contracts, including data processing agreements),
    • management of incidents related to information security,
    • business continuity management,
    • compliance with legal and contractual requirements.
  • Collaboration in conducting periodic checks, which is nothing more than monitoring compliance with the GDPR, including activities to raise awareness, training of personnel involved in processing operations, and related audits. In addition to the obligation to carry out the above activities by the DPO (Article 39(1)(b)), the regulations do not provide information on the frequency of such actions. However, the practice of applying personal data protection regulations from the previous legal framework has shown that due to the frequently encountered difficulties and time-consuming nature of implementing appropriate safeguards or modifying them, but above all due to the rapidly emerging new threats and the pace of technological development, such checks in information systems should be conducted at least once every 12 months.
  • Collaboration during the risk analysis process, the result of which should identify areas or resources that are not secured or where the applied safeguards are insufficient. This refers to resources that pose the highest likelihood of the identified threats materializing within the organization, and thus their use is associated with a high risk to personal data. The GDPR does not specify the frequency of conducting such a process, stating only that it is not a one-time activity but a continuous process. In this regard, the Guidelines of the Article 29 Working Party have indicated that the risk analysis process should be conducted no less frequently than every 3 years.
  • Ensuring the continuity of system operations, including securing data sets and programs used for processing personal data through systematic backup execution. In addition to the execution of the aforementioned process, the DPO should ensure that the created backups are stored in a location that protects them from unauthorized access, modification, damage, or destruction. In practice, encrypted external storage devices are most commonly used to preserve such important data within the organization, which are then stored in a location secured against access by unauthorized persons, in a different fire zone than the original data. An exception to this rule is the use of a safe/fireproof cabinet for this purpose. More information on performing and appropriately securing backups can be found in the article “Backup as a 21st Century Insurance Policy” and “Backup as a 21st Century Insurance Policy – Types of Backups and Their ApplicationsDPIA Service.
  • Providing an emergency power source and protection against disruptions in the power supply of information systems used for processing personal data, where a sudden interruption could lead to data loss or compromise their integrity. For this purpose, a UPS device is most commonly used, which supports the network and servers of at least critical systems until they can be safely shut down. It is advisable that, in addition to implementing a notification system for authorized persons about switching the infrastructure to an emergency power source, the system is configured in such a way that its safe shutdown occurs automatically in this case.
  • Supervision over the repair and disposal of computer devices. Devices, disks, or other electronic information carriers containing personal data, intended for disposal, repair, or transfer to an unauthorized entity for data processing, must have their data erased in a manner that prevents recovery.
  • Review and maintenance control of information systems used for processing personal data, including, among others, the use of only software that is supported by the manufacturer and systematic, automatic, or security bulletin-compliant updates. It is worth noting that this process should not only apply to all systems used on server devices and workstations but also to all types of routers and managed network switches.
  • Securing systems used for processing personal data against malicious software, which may aim to gain unauthorized access to data. This refers, of course, to the implementation of an antivirus system that utilizes an up-to-date virus database. When implementing this type of security, the DPO should consider all IT systems used in the organization, including those found on company smartphones or tablets.
  • Adjusting information systems used for processing personal data
    to the requirements of the GDPR, including, among others:
    • ensuring the ability to exercise the right to data portability,
    • ensuring the ability to exercise the right to restriction of processing,
    • ensuring the ability to exercise the right to be forgotten,
    • ensuring the ability to exercise the right to object to marketing activities, where, under the accountability principle, it is important to ensure the ability to verify the exact time and date when consent was given or withdrawn.
  • Securing premises, where personal data is processed, particularly archives, network shafts, or server rooms against unauthorized access
    or other random events, including, among others, security measures:
    • physical (doors, walls, ceilings, etc.),
    • technical (electronic security systems),
    • environmental (ensuring optimal working conditions for devices and fire protection),
    • personal (security personnel, aware company staff),
    • organizational (regulations, policies, etc. in force within the company),
    • for details on the security measures applied, please refer to the article „How to Secure a Server Room?”.
  • Protection against threats from the public network
    through the implementation of physical or logical safeguards protecting against unauthorized access, including but not limited to
    • firewalls,
    • anti-spam filters,
    • VLAN segmentation,
    • device filtering for devices that may access the production network,
    • the use of many other solutions considering available technologies and financial resources.

RODO Zone

Are these all the obligations of the data controller of IT systems?

In response to the question: unfortunately not… All the points mentioned above are only the basic tasks of the data controller of IT systems, who, in cooperation with the Data Protection Officer (DPO), should exercise overall supervision over organizational, physical, and technical security throughout the organization. It is worth noting that in most data processors, the scope of safeguards implemented and supervised by the IT system administrator often exceeds the provisions of personal data protection, and good practices are drawn from other regulations, such as the international standard PN-EN ISO/IEC 27002:2017, which contains many interesting insights on security.

You can discuss GDPR and the obligations of the data controller of IT systems with our experts – Cezary Lutyński is an experienced data protection advisor. If this topic resonates with you or raises any doubts, be sure to contact him. He will help you find the best solutions tailored to your organization.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.