What actions are punishable under the DODO Act?
Receive a package of free GDPR guides and micro-trainings
Illegal processing or lack of authorization for data processing
The offense related to the processing of personal data in connection with preventing and combating crime is regulated in Article 54 of the DODO Act. It consists of processing personal data that is not permissible or for which we are not authorized to process. We can speak of the inadmissibility of processing personal data when the basis for this process is not a legal premise legitimizing that processing. According to the DODO Act, such a basis is the processing of personal data solely to the extent necessary to exercise a right or fulfill an obligation arising from a legal provision.
The lack of authorization for processing personal data, as mentioned in Article 54 of the DODO Act, refers to situations where, despite having a legal basis for processing data, the person performing the processing has not been authorized to do so within the framework of a given category of processing activities.
Furthermore, it should be noted that the processing of sensitive data – defined in Article 14 of the DODO Act as personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, membership in trade unions, as well as genetic data, biometric data processed for the purpose of uniquely identifying a natural person, data concerning health, data concerning sexuality and sexual orientation of a natural person – is permissible if:
- a legal provision allows such action or
- it is necessary for the protection of the life or health, or interests of the data subject, or another person, or
- such data has been made public by the person to whom it pertains.
Obstruction or significant hindrance to the conduct of compliance inspections
The offense concerning obstruction or significant hindrance to the conduct of compliance inspections under the DODO Act is defined in its Article 55. The obstruction or significant hindrance to the inspector's conduct of the inspection must relate to the inspection of compliance with personal data protection regulations processed in connection with the prevention and combating of crime. Criminal liability will be incurred by individuals who significantly contribute to disrupting the supervisory authority's inspection activities or completely prevent them, for example, by not allowing inspectors onto the data controller's premises or refusing them access to the data set subject to inspection and to other documents directly related to the subject of the inspection.
How is criminal liability shaped?
When the processing of personal data is not permissible or is carried out by a person who is not authorized to do so, the perpetrator is subject to a fine, restriction of liberty, or imprisonment for up to two years. If the subject of processing involves sensitive data, the upper limit of imprisonment increases to three years.
In terms of obstruction or significant hindrance to the inspector's conduct of the inspection, liability is sanctioned as a fine, restriction of liberty, or imprisonment for up to two years. It should be noted that such defined criminal liability will only apply to individuals who have committed the discussed actions intentionally, that is, with a specific intent (awareness and will).
Summary
Moreover, it should not be forgotten that the data controller is also liable under the provisions of the Polish DPA for civil damages to individuals who have suffered harm or injury as a result of actions violating the provisions of the Polish DPA. An important aspect of this liability is that entities applying the provisions of the Polish DPA will, to some extent, apply the provisions of the GDPR, and consequently may incur financial liability based on them.


