
The most controversial issues in the draft law published by the Ministry concern the provisions regarding the selection of the President and Vice Presidents of the Polish Data Protection Authority, certification, and the broadly understood simplification of proceedings before the Polish DPA. Of course, apart from these changes, we can observe many that are purely cosmetic in nature, such as the change of the name of the authority from the General Inspector of Personal Data Protection to the Polish Data Protection Authority, which will now be headed by a President, the changes from ABI to DPO, and the specification of the age threshold for individuals to whom services are provided electronically, set at the completion of the thirteenth year of life.
Threat of Politicization
A significant change concerning the structure of the Polish DPA is the method of selecting the Vice Presidents of this authority. They are to be appointed by the Prime Minister at the request of two ministers – of digitization and of internal affairs and administration. Undoubtedly, the authority that the Polish DPA will be should be highly independent in order to fulfill its tasks appropriately and in accordance with the law. Unfortunately, the proposed method of appointing the Vice Presidents may lead to a situation where the independence of the Authority is not maintained. According to the GIODO, such a solution would constitute a violation of the provisions of the EU regulation and Article 16 on the functioning of the European Union. It is possible that this method of appointing Vice Presidents was proposed by the Ministry due to the necessity of cooperation between the President and the two ministries. However, despite the above argument, it is not difficult to recognize that one of the standards for shaping an apolitical authority is the ability to select personnel by the person holding the position of the authority. It is also worth noting that the selection of the President himself, although compliant with the provisions of the regulation, represents a kind of "lowering of standards." The draft proposes that he be appointed by the Sejm at the request of the Prime Minister. Such a structure for the appointment of the President may raise serious doubts regarding the independence of this authority. Currently, the General Inspector of Personal Data Protection is appointed by the Sejm at the request of the Marshal or a group of 35 deputies. Such regulations concerning not only the appointment of the President of the Authority but also his Vice Presidents weaken its independence.
Important
It is worth remembering that the GDPR devotes a separate chapter describing the independence of the supervisory authority, aimed at ensuring that such an authority operates in a fully independent manner.
Certification in the Hands of the President of the Polish Data Protection Authority
The draft act on personal data protection stipulates that the only entity authorized to certify compliance with the provisions of the GDPR regarding personal data processing operations will be the President of the Polish Data Protection Authority.
Note
The plans of the Ministry of Digital Affairs include the President of the authority developing and providing the certification criteria.
This procedure may be initiated by a data controller, as well as by a data processor. The time frame within which the Authority considers applications has been set at 3 months from the date of submission. The procedure will be possible to conduct in electronic form. Following a positive review of the application, the period for which the certification is granted will be specified. Another novelty, apart from the certification itself, will be the possibility of conducting verification activities at the data controller or data processor during the validity of the certification by the Polish DPA. The verification activities may concern the assessment of the certified entity's compliance with the certification criteria. It is worth noting that if irregularities arise during the verification activities, the Authority may issue a decision to revoke the certification. This solution should be regarded as enhancing the real value of such certification, as the entity obtaining certification will be aware of the possibility of having its activities regarding personal data processing inspected. Although certification will strengthen the position of data controllers and data processors in the market, it is important to note that obtaining a certificate will not be free of charge. For conducting the aforementioned activities, the applicant will be required to pay a fee of approximately 12,000 zlotys, which is equivalent to three times the average monthly salary for work. In our opinion, entrusting the state entity with the certification process for compliance of data processing operations with the provisions of the GDPR is a solution deserving of full approval. Such a solution should ensure a high level of recognition of certification applications and seems to be a much better solution than outsourcing this process.
Simplification of the procedure, is it worth it at all costs?
The legislator's intention in the draft law on personal data protection is undoubtedly to expedite and simplify the proceedings before the Polish Data Protection Authority. It is worth noting that the proceedings concerning personal data protection remain under the jurisdiction of the Administrative Courts, thus continuing to be conducted under the provisions of the Code of Administrative Procedure (KPA) and the Code of Administrative Court Procedure (PPSA). This solution appears to be appropriate. Administrative Courts have extensive case law and experience in handling matters related to personal data protection. Another significant factor supporting the continued connection of data protection proceedings with the field of administrative law is the fact that Administrative Courts resolve cases more quickly than Common Courts. Of course, the issue of the speed of court proceedings in Poland is a contentious matter.
Important
A significant change, however, is to abandon the two-instance nature of the proceedings before the Polish Data Protection Authority.
According to the currently applicable regulations, the proceedings before the Polish Data Protection Authority (UODO) are two-instance proceedings. It is evident that abandoning the two-instance procedure before the authority will significantly expedite the process. Despite many voices of opposition, this solution is consistent with Article 15 of the Code of Administrative Procedure (KPA), which states that „Administrative proceedings are two-instance, unless a specific provision provides otherwise”. The above proposal has received approval from the Polish DPA; however, at this stage, it signals that it will not be possible for every proceeding to conclude within a month, as decisions issued by the authority are not based solely on a simple verification of formal prerequisites. The only form of appeal against the decisions of the Polish DPA under the draft law will therefore be the judicial-administrative route. Such a solution may significantly expedite the proceedings; however, it is worth noting that it may lead to a violation of one of the fundamental principles of the KPA contained in Article 24 – namely, the principle of hearing the parties. Regarding the acceleration of proceedings, it does not seem logical to reject the possibility of reaching a settlement. Undoubtedly, the institution of administrative settlement was introduced under the provisions of the KPA to expedite administrative proceedings. It is worth noting that in many European countries, most cases end in a settlement, which significantly speeds up the process. The Ministry argues for the exclusion of settlement from proceedings concerning personal data protection based on the fact that it may lead to abuses and attempts to circumvent the law. On the other hand, it is worth noting that the settlement in the KPA has existed since 1980, while its institution in administrative proceedings practically does not occur. It is often compared to a unicorn – everyone knows what it looks like, but no one has ever seen it. The issue concerning the settlement may therefore meet with both approval and opposition. On one hand, this institution is intended to expedite proceedings; however, experience indicates that it is not applied. Another issue raising doubts is the proposed requirement in the draft to grant immediate enforceability to decisions of the Polish DPA. The legislator explains that such a solution is again intended to contribute to increasing the speed of proceedings and will protect the authority from the necessity of separately granting this enforceability to all decisions each time. The justification for applying immediate enforceability is to indicate the right to personal data protection as a protected good. Additionally, the aforementioned single-instance nature of the proceedings is to be an argument. Since there will be no possibility of reconsidering the case by the Polish DPA in an appellate procedure, there will also be no institution of appeal that suspends the immediate enforceability, which seems to be an even less clear justification, as this enforceability can only be granted to decisions against which an appeal is available.
The above solution appears to be inconsistent with the general intention of the institution of immediate enforceability, which is applied under the Code of Administrative Procedure only in particularly justified cases.Note
According to Article 108 of the Code of Administrative Procedure, the rigor of immediate enforceability may be applied when it is "necessary for the protection of health or human life, or to secure the national economy against severe losses, or due to another social interest or an exceptionally important interest of a party." However, it becomes questionable to assert that every case related to personal data protection has such a lofty character.
However, this is not the last of the changes concerning the procedure. The issue of the appealability of decisions within the proceedings becomes problematic. Representatives of the Ministry of Digital Affairs explain that this measure has been implemented to achieve the goal of quick resolution of cases, and the possibility of appealing decisions will still be preserved, as the review of the justification for issuing a decision would be conducted during the examination of the complaint by the court. Although such a solution will expedite the proceedings, in practice, it virtually deprives the parties to the proceedings of the opportunity to present their arguments. This constitutes another manifestation of the violation of the principle of the Code of Administrative Procedure - the right to be heard.
Establishment of the Personal Data Protection Fund
The published draft also mentions the establishment of a targeted fund, which is to be the Personal Data Protection Fund. The administrator of this fund will be the President of the Polish Data Protection Authority. The revenues of this fund are to come from monetary penalties imposed by the authority and are to constitute 1% of those penalties. According to the provisions of the GDPR, this authority may impose fines of up to 20 million euros or 4% of the total annual global turnover of the entrepreneur who violated the provisions specified in the regulation.
Important
It is worth noting, however, that the fines for public administration for violating personal data protection regulations have been reduced to 100,000 PLN, which constitutes a significant disproportion.
Expenditures from the dedicated fund will be allocated to initiating and undertaking initiatives by the President of the Polish Data Protection Authority aimed at raising public awareness about the need for personal data protection, as well as the risks, regulations, safeguards, and rights associated with the processing of personal data, with particular attention given to actions directed at children. The second objective of the expenditures will be to initiate and undertake initiatives aimed at disseminating knowledge among data controllers and data processors regarding their obligations under personal data protection regulations. The proposed initiative to establish the Personal Data Protection Fund should be assessed very positively, as it will provide a specific resource enabling the implementation of valuable informational and educational campaigns. Although financial penalties arise directly from the regulation, it is worth considering whether, in conjunction with the new procedure for selecting the President of the Authority along with his deputies, it will not constitute a form of political pressure on "unruly" entrepreneurs.
Facilitating the restriction of personal data processing
The proposed regulations regarding the possibility for the President of the Polish Data Protection Authority to issue a decision obligating such an entrepreneur to restrict the processing of personal data may prove dangerous from the entrepreneur's perspective. Such a decision may be made without allowing the party to express their views on the evidence and materials collected by the Authority, as well as to submit their requests. In summary, such a decision could, in the worst-case scenario, lead to the collapse of the enterprise.
Regulations concerning criminal liability
The discussed provisions also regulate criminal liability. The draft law includes only two criminal provisions. In contrast, it is worth noting that the current law contains six such provisions. What is currently a crime, relating to obstructing or hindering the DPO's control activities, will become a misdemeanor in the new legal system and will be subject to a fine. Meanwhile, from the remaining five currently applicable crimes, the legislator intends to introduce only one crime. Its subject will be the processing of special category personal data (including personal data revealing political opinions, religious beliefs, membership in trade unions, processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, or data concerning health) without a legal basis. This will result in imprisonment for up to one year. It seems that this approach has been dictated by the high financial penalties introduced by the GDPR and the shift of the burden, ensuring the legal processing of data, onto financial aspects.
In summary, although the draft prepared by the Ministry of Digital Affairs presents comprehensive solutions regarding issues not regulated by the GDPR, it is worth noting that these solutions are not ideal. It is also important to examine the proposed amendments to over 133 laws included in the draft law introducing the Personal Data Protection Act, which will be the subject of the second part of this entry.

