Criminal liability in the context of the DODO Act

06 January 2020

In the specified act DODO (Act of December 14, 2018 on the protection of personal data processed in connection with the prevention and combating of crime - Journal of Laws 2019, item 125), criminal norms regarding unlawful processing of personal data and obstructing or hindering the conduct of inspections have been introduced. The basis for formulating these regulations can be found in Recital 89 and Article 57 of Directive 2016/680, which speak of the adoption by member states of provisions defining sanctions for violations of national regulations adopted under Directive 2016/680. These sanctions are to be effective, proportionate, and deterrent. Similar, but not identical, criminal provisions can be found in the Act of May 10, 2018 on the protection of personal data (consolidated text: Journal of Laws 2019, item 1781).

What actions are punishable under the DODO Act?

GDPR Bulletin
Receive a package of free GDPR guides and micro-trainings
Join the ranks of our newsletter readers, receive a free package, and stay informed.
RECEIVE PACKAGE
The DODO Act regulates the processing of personal data for the purposes of identifying, preventing, detecting, and combating prohibited acts, including threats to security and public order, as well as executing temporary arrests, penalties, disciplinary measures, and coercive measures resulting in deprivation of liberty. The legislator introduced two offenses related to the processing of such personal data.

Illegal processing or lack of authorization for data processing

The offense related to the processing of personal data in connection with preventing and combating crime is regulated in Article 54 of the DODO Act. It consists of processing personal data that is not permissible or for which we are not authorized to process. We can speak of the inadmissibility of processing personal data when the basis for this process is not a legal premise legitimizing that processing. According to the DODO Act, such a basis is the processing of personal data solely to the extent necessary to exercise a right or fulfill an obligation arising from a legal provision.

The lack of authorization for processing personal data, as mentioned in Article 54 of the DODO Act, refers to situations where, despite having a legal basis for processing data, the person performing the processing has not been authorized to do so within the framework of a given category of processing activities.

Furthermore, it should be noted that the processing of sensitive data – defined in Article 14 of the DODO Act as personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, membership in trade unions, as well as genetic data, biometric data processed for the purpose of uniquely identifying a natural person, data concerning health, data concerning sexuality and sexual orientation of a natural person – is permissible if:

  • a legal provision allows such action or
  • it is necessary for the protection of the life or health, or interests of the data subject, or another person, or
  • such data has been made public by the person to whom it pertains.

DODO from the basics

Obstruction or significant hindrance to the conduct of compliance inspections

The offense concerning obstruction or significant hindrance to the conduct of compliance inspections under the DODO Act is defined in its Article 55. The obstruction or significant hindrance to the inspector's conduct of the inspection must relate to the inspection of compliance with personal data protection regulations processed in connection with the prevention and combating of crime. Criminal liability will be incurred by individuals who significantly contribute to disrupting the supervisory authority's inspection activities or completely prevent them, for example, by not allowing inspectors onto the data controller's premises or refusing them access to the data set subject to inspection and to other documents directly related to the subject of the inspection.

FREE

When GDPR, when DODO? Dilemmas of the Data Protection Officer

Watch the webinar

How is criminal liability shaped?

When the processing of personal data is not permissible or is carried out by a person who is not authorized to do so, the perpetrator is subject to a fine, restriction of liberty, or imprisonment for up to two years. If the subject of processing involves sensitive data, the upper limit of imprisonment increases to three years.

In terms of obstruction or significant hindrance to the inspector's conduct of the inspection, liability is sanctioned as a fine, restriction of liberty, or imprisonment for up to two years. It should be noted that such defined criminal liability will only apply to individuals who have committed the discussed actions intentionally, that is, with a specific intent (awareness and will).

Summary

Moreover, it should not be forgotten that the data controller is also liable under the provisions of the Polish DPA for civil damages to individuals who have suffered harm or injury as a result of actions violating the provisions of the Polish DPA. An important aspect of this liability is that entities applying the provisions of the Polish DPA will, to some extent, apply the provisions of the GDPR, and consequently may incur financial liability based on them.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.