Adapting the Polish legal environment to the Regulation of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter: GDPR) requires, in addition to the enactment of a new personal data protection law, the amendment of numerous sectoral regulations.
The legislator, aiming to prepare as well as possible for the implementation of the GDPR, has prepared a draft law titled "Provisions introducing the Personal Data Protection Act." In this text, we present the most significant changes in sectoral regulations proposed by the legislator. The draft law consists of over 170 pages and includes amendments to 133 laws. Due to the volume of the discussed text, we have divided the amended laws into three groups.
- "Professional" laws – describing changes in the Labor Code and other laws related to professional groups.
- Laws significant for the state's infrastructure.
- Laws significant from the citizens' perspective.
I. "Professional" Laws
Revolution in the Labor Code
Receive a package of free GDPR guides and micro-trainings
- first name(s) and surname,
- date of birth,
- correspondence address,
- email address or phone number,
- education,
- employment history.
The wording of Article 221 § 2 is also changing. The employer will be able to request the following data from the employee, in addition to the above:
- residential address,
- PESEL number (and in the absence of this, the type and number of the identity document),
- other personal data of the employee, as well as personal data of the employee's children and other members of their immediate family, if providing such data is necessary due to the employee's use of specific rights provided for in labor law.
Important
The above data is to be provided in the form of a declaration; however, if the employer deems it necessary, they may request documentation to verify its authenticity.
The above data may be processed by the employer only for purposes necessary to fulfill the obligation to provide work. However, the legislator excludes from this catalog the correspondence address, phone number, or email; these data may only be processed by the employer after prior written consent in paper or electronic form has been given.
A revolutionary and long-awaited provision is Article 222 § 2, which pertains to biometric data.
Note
According to the legislator's proposal, the employer will have the right to process the employee's biometric data if the employee consents to it.
This consent cannot be implied; it must be given in written form – either paper or electronic.
The legislator has absolutely prohibited the employer from processing sensitive data of employees concerning:
- addictions,
- health information,
- sexual life,
- sexual orientation.
The employer cannot process this data even after prior consent has been given by the employee. However, it is puzzling why other sensitive data, such as religious beliefs or political opinions, were not included in this category. From the above provision, it follows that the employer, with the employee's prior consent, may process their data regarding political party affiliation, but cannot process data concerning their sexual orientation.
It is commendable that there is an attempt to legally regulate video surveillance in the workplace. According to Article 224 § 1, the employer may use camera surveillance to ensure:
- the safety of employees,
- the protection of property,
- the confidentiality of information whose disclosure could expose the employer to harm.
It is worth noting that it cannot be used as a "means of controlling employees' work performance." The legislator has clearly designated areas where monitoring cannot be applied, including: smoking rooms, sanitary facilities, cafeterias, and other rooms not intended for work purposes.
Note
Employees must be informed about the monitoring no later than 14 days before its implementation. Newly hired employees must simply be informed about it at the time they are allowed to work.
Changes in other "professional" laws. In addition to the Labor Code, the following will also be amended:
1) Teacher's Charter
The legislator has clearly defined the catalog of personal data that may be processed in:
- matters concerning the professional advancement of teachers,
- matters of supervision over teachers' advancement,
- disciplinary matters and disciplinary committees.
Another change is the limitation of the information obligation and the right of access to data for individuals in the above matters to free access once every six months. In other cases, the data controller has the right to charge a fee corresponding to the costs of preparing the response or copy of the data.
An interesting measure employed by the legislator is the construction of the institution that exempts the data controller from the obligation to notify the data subject of a personal data breach (Article 34 GDPR) when they publish a breach notification on their website in the Public Information Bulletin or on their own website within 72 hours of discovering the breach.
2) Law on Advocacy. Law on Legal Advisors. Law on Notaries. Law on Court Bailiffs and Enforcement
Essentially, very similar legal regulations have been introduced in all the mentioned laws, which is why they have been discussed collectively. The new solutions and exclusions are practically identical for all four professional groups and include:
- the establishment of data controllers, both in the context of the internal organization of the above professions and individuals whose data are processed by representatives of these professional groups,
- exemptions in certain cases from the application of some provisions of the GDPR.
For example, in the law on advocacy, we will recognize:
- The Minister of Justice (in matters concerning control and supervision as well as the activities of the team preparing questions for the preliminary examination for candidates for legal trainees),
- The Supreme Bar Council (in matters of proceedings, including complaints and applications, administrative and disciplinary matters; implementation of public tasks arising from the law),
- The District Bar Councils (in matters conducted by them and the implementation of public tasks)
- Examination Committees for Trainees under the Minister of Justice (in matters related to admission and appeals against the examinations conducted by them)
- Lawyers (in the case of personal data processed in the course of performing their profession).
The provision stating that lawyers and legal advisors are data controllers is problematic. It is worth noting that legal advisors and lawyers often perform their profession not only in individual law firms but also, for example, under a civil contract or (in the case of legal advisors) an employment contract. In the above cases, it seems incorrect to consider legal advisors or lawyers as data controllers – as the purposes and means of processing are determined by the entity for which they provide work or services.
Important
With respect to the data processed by the above-mentioned data controllers, the provisions of the GDPR regarding the information obligation, partially the right of access to personal data, the right to restrict processing, the obligation to inform about the deletion of data, and the right to object do not apply.
The provisions of Article 58(1)(e) and (f) of the GDPR are also excluded – which grant the supervisory authority the rights to obtain access from the data controller and the data processor to all personal data and all information, as well as to gain access to all premises, including equipment and means used for data processing in the scope of data obtained as a result of the obligation to maintain professional secrecy.
3) Law on the Freedom of Economic Activity
The amendments proposed by the legislator, although they seem minor, may lead to many changes concerning sole proprietorships.
Important
First of all, after 10 years from the date of the entrepreneur's removal from the CEIDG, data entered into the CEIDG before the date of this removal are also to be deleted.
Secondly, Article 39b, concerning the exclusion of the application of the Personal Data Protection Act to data of natural persons conducting business activity disclosed in the CEIDG, is also to be repealed.
Although these provisions seem largely logical, when confronted with reality, the situation regarding the protection of personal data of individuals conducting sole proprietorships appears to be somewhat unjust, as it may expose businesses collaborating with sole proprietors to significant costs (e.g., related to the implementation of appropriate safeguards and fulfilling the information obligation).
4) Act on Forensic Doctors
The legislator in the proposed amendment defined the data controllers of forensic doctors and candidates for forensic doctors in terms of acquiring and losing their right to practice this profession.
5) Act on the License of Restructuring Advisors and Sworn Translators
The proposed provisions closely resemble those applied in the laws: the Law on Advocacy, the Law on Legal Advisors, the Law on Notaries, the Law on Court Bailiffs and Enforcement. Both in the Act on the License of Restructuring Advisors and in the Act on Sworn Translators, data controllers are defined. The same articles of the GDPR have also been excluded as in the previously described laws concerning "legal professions" (Articles 13-15(1) and (3), 18, 19, and 21). The only difference is the determination of the data retention period. It is to be established by the data controllers in accordance with "separate regulations concerning deadlines."
6) Act on the Profession of Physiotherapist
Only the content of Article 12(9) is being amended, where the provision regarding the Personal Data Protection Act is removed and replaced with the broadly understood provision of "compliance with personal data protection regulations." Although this change appears very innocuous, the term "personal data protection regulations" is significantly broader than the previous provision regarding compliance with the act.
7) Law on the Prosecutor's Office
There are no stupid GDPR questions.
There are free answers
8) Act on the Profession of Psychologist and the Professional Self-Government of Psychologists
The act introduces a brief but significant provision safeguarding the rights of individuals using the services of psychologists. If the results of assessments are to serve not only for the client's information, the provisions on the protection of personal data must be applied to them. Consequently, in such cases, psychologists should be implicitly regarded as data controllers.
9) Act on Court Guardians
The legislator has proposed changes to the act concerning the profession of court guardians, which have long been awaited by them. After analyzing the provisions, it can be inferred that a court guardian is a data processor.
This is a rather logical assumption, as the guardian does not decide on the purpose of data processing – this is determined by the court and other entities (Police, social assistance center, etc.) that provide personal data of the convicted individual. The amended Article 9a, paragraph 2 includes the provision: “The data controller referred to in paragraph 1 is obliged to provide personal data also concerning health status, financial situation, living conditions, employment, education, addictions, or family life, as well as data regarding compliance with legal order, convictions, penalties, and fines, as well as other rulings issued in judicial or administrative proceedings.” The word “also” deserves attention here. In my opinion, not closing the catalog of data that may be provided to the guardian is a justified postulate, as the specificity of this profession requires processing various information concerning the supervised individual.
Important
It is also commendable to grant the same rights to process data to social guardians as those held by professional guardians.
Additionally, the act also specifies the entities that are data controllers of professional guardians and guardianship trainees. It is also commendable to grant the same rights to process data to social guardians as those held by professional guardians. However, the issue arising from the specificity of the guardian's work, namely fieldwork, has not been further resolved. Guardians often move around to gather information about their charges, collecting large amounts of data in the process, which makes it extremely difficult to secure them in accordance with the requirements of the GDPR during their fieldwork. Furthermore, the possibility of data leakage during the guardian's work seems probable (e.g., a bag containing paper documents may be stolen).
Above, we have presented changes in the "professional" laws. The GDPR will change the rules governing certain professions; time will tell whether these changes will be for the better or not. We encourage you to read the upcoming posts regarding changes in laws significant for state institutions and laws important for citizens.
In the next part


