Provisions introducing the Act on the Polish DPA Part 2 Provisions relevant to state institutions

29 November 2017

The adaptation of the Polish legal environment to the Regulation of the European Parliament and of the Council on the protection of natural persons in relation to the processing of personal data and on the free movement of such data (GDPR) requires, in addition to the enactment of a new personal data protection law, the amendment of numerous sector-specific regulations.

The legislator, aiming to prepare as well as possible for the implementation of the GDPR, has drafted the bill "Provisions introducing the Personal Data Protection Act." In this text, we present the most significant changes in sectoral regulations proposed by the legislator. The draft bill consists of over 170 pages and includes changes to 133 laws. Due to the volume of the discussed text, we have divided the amended laws into three groups.

In the previous article, we presented the most significant changes in the "professional laws." The following text describes the proposed amendments to the laws concerning institutions important for the functioning of the state.

II. Laws significant for state institutions.

1) The Act on Enforcement Proceedings in Administration.

GDPR Bulletin
Receive a package of free GDPR guides and micro-trainings
Join the ranks of our newsletter readers, receive a free package, and stay informed.
RECEIVE PACKAGE
The President of the Polish Data Protection Authority will assume the rights and obligations of the General Inspector for Personal Data Protection in enforcement proceedings, which is, of course, a completely understandable proposal for change, as the President of the Polish DPA will take over not only these rights and obligations of the GIODO.

However, the provision added in Article 34 § 4 of the Act may raise doubts. It completely excludes the application of Articles 12 – 22 of the GDPR regarding the protection of information and explanations obtained at the request of the enforcement authority or creditor from the participants in the proceedings, which will enable the achievement of the enforcement goal in the form of fulfilling the obligation pursued in the proceedings.

The above exclusion concerns practically the entire Chapter III of the GDPR. As a result, it leads to depriving individuals of all rights related to the protection of personal data in connection with the enforcement proceedings conducted by the administrative authority.

2) The Act on the National Archival Resource and Archives.

The changes in this Act mainly concern issues related to the determination of the catalogs of data that may be processed by the Chief Director of the State Archives.

In matters concerning individuals applying for permission for the temporary export of archival materials abroad, the catalog that may be processed by the Chief Director of State Archives is as follows:

  • first and last name,
  • residential address or correspondence address,
  • phone number and electronic address, including email address,
  • other information identifying natural persons contained in the archival materials subject to proceedings.

In matters primarily concerning: supervision over operations involving archival data, scientific and publishing activities, as well as issues related to the recording of data, the Chief Director of State Archives may process the following personal data:

  • first and last name or pseudonym,
  • residential address or correspondence address,
  • phone number and electronic address, including email address,
  • place of work and position held or function performed,
  • image,
  • information identifying natural persons contained in archival materials or non-archival documentation subject to these activities.

The legislator, in order to collect fees for the use of public roads, proposes that the road authority or road manager may process data concerning vehicles and users of public roads. The data will be collected in connection with the operation of the electronic toll collection system.

Important
Data is to be stored for no longer than 12 months from the date of their acquisition, unless longer storage is necessary for the conduct of administrative, judicial, or enforcement proceedings or to ensure the proper collection of electronic fees by road users and their settlement.

The General Director of National Roads and Motorways is to verify this data at least every 3 months from the date of its acquisition, removing unnecessary data.

Furthermore, the General Director of National Roads and Motorways is to be exempt from the informational obligation arising from the provisions of the GDPR. He may also provide, based on a written request, the personal data collected by him to:

  • the Police,
  • Road Transport Inspection,
  • Military Gendarmerie,
  • Border Guard,
  • Internal Security Agency,
  • Intelligence Agency,
  • Central Anti-Corruption Bureau,
  • Military Counterintelligence Service,
  • Military Intelligence Service,
  • the prosecutor,
  • courts,
  • the Head of the National Revenue Administration, the director of the tax administration chamber, the head of the customs and tax office.

GDPR. Support is useful!

3) Act on the Commissioner for Human Rights and the Commissioner for Children's Rights.

The proposed amendment includes a provision allowing the Commissioner for Human Rights to process any information, including personal data, as well as so-called sensitive data, in order to fulfill their statutory tasks. An identical solution has been proposed in the Act on the Commissioner for Children's Rights in the context of their duties.

The objectives of both entities mentioned above are aligned and aim to ensure the protection of citizens' rights regardless of their age, thus the proposed solution raises no doubts.

4) Act on Public Statistics.

Many changes are to be introduced in the Act on Public Statistics. This is not surprising, as this act predates the Personal Data Protection Act and, according to some, has largely shaped the awareness of the necessity of personal data protection among citizens.

The changes have affected the definition of “statistical data,” which has been expanded to include information contained in non-public information systems. Such systems can be considered those used for collecting, gathering, and processing information conducted by entities other than public administration bodies and entities operating public information systems, particularly entities engaged in:

  • the sale or supply of electricity,
  • collective sewage disposal and collective water supply,
  • the transmission, distribution, and trading of gaseous fuels,
  • the trading, transmission, and production of thermal energy,
  • telecommunications,
  • insurance,
  • transportation and leasing,
  • airport management,
  • property management and administration.

The operation for statistical research will no longer concern only individual data along with their address identification; it will be replaced by tele-address identification. The catalog of data that can be collected from individuals solely on the basis of obligation in statistical research has also been expanded to include biometric and worldview data. Public statistics services, for statistical purposes, will additionally be able to process, beyond the data contained in the regulations prior to the proposed change, data concerning, among others:

  • country of birth and place of birth,
  • biometrics,
  • genetics,
  • sexuality or sexual orientation,
  • cohabitation,
  • income, including remuneration.

Personal data, once collected by public statistical services, shall be pseudonymized unless the purpose of their processing requires otherwise. The method and procedure for the pseudonymization of personal data shall be determined by a regulation issued by the President of the Central Statistical Office.

The new law is also intended to explicitly allow the statistical service to store, combine, and reuse the collected data (including personal data) for purposes defined by law. Data shall also be collected using automated electronic or IT tools. Article 6(5) has been amended to include the obligation to inform the individual about the legal basis for collecting their personal data, the guarantees of maintaining statistical confidentiality, and whether the survey is voluntary or mandatory. Statistical surveys concerning individuals conducting business activities shall always be conducted on a mandatory basis.

Note
The data controller for the data collected during statutory activities by the public statistical service shall be the President of the Central Statistical Office. Personal data, from the moment of their collection, shall become statistical data and, consequently, shall be subject to statistical confidentiality.

The obligation arising from Article 34 of the GDPR, which requires notifying the data subject of personal data breaches, shall be fulfilled by the statistical service by publishing information on this matter in the Public Information Bulletin of the office.

A new Chapter 2b concerning the organization of the census and Chapter 5a titled “Records for Statistical Research” shall also be added to the law.

5) Tax Ordinance Act.

The legislator has determined that the data controller for the personal data of taxpayers, collectors, their legal successors, and third parties using the tax portal is the Minister responsible for public finances. The legislator also plans to exclude the provisions of the GDPR concerning the rights of data subjects (Articles 12-22 and Article 34 of the GDPR) in relation to personal data covered by tax secrecy.

6) Act on the Institute of National Remembrance.

Free GDPR advice
There are no stupid GDPR questions.
There are free answers
Take advantage of free legal or IT advice.
I HAVE A QUESTION
The legislator proposes a change to the wording of Article 57f paragraph 1, which must be an obvious error and, upon analyzing the wording of the provisions of the Act, it is likely that it concerns a change to Article 53f paragraph 1, as it pertains to the establishment of the Genetic Material Database, of which the data controller is the President of the Institute of National Remembrance. Otherwise, this would lead to the maintenance of a Database whose legal status would be based on the provisions of the Personal Data Protection Act, rather than the provisions of the GDPR.

The main change resulting from the provisions is the limitation of the rights of individuals whose data is processed for archival purposes. Therefore, in the above case, the right to object, the right to rectification, the right to be forgotten, and the limitations on processing resulting from the provisions of the GDPR do not apply. Considering the nature of the work of the Institute of National Remembrance, these exclusions seem justified.

7) Act on the National Criminal Register.

The main change concerning the provisions relating to the National Criminal Register is the exclusion of the application of the GDPR provisions regarding the right to restrict processing, the obligation to inform a person about the rectification or deletion of their data from the register, and the right to object to the processing of personal data. This is a completely justified solution considering the nature of the personal data and the purpose for which the above register was created. Granting the individuals whose data is included in it the above rights would lead to absurdity and the impossibility of maintaining a register of convicted persons. The data controller of the personal data contained in the National Criminal Register is to be the Minister of Justice.

8) Act on the Organization of Common Courts.

The legislator, in the proposed amendment, enumeratively indicated the relevant data controllers for personal data processed in the broadly understood common judiciary. In this regard:

  • The data controllers for the personal data of expert witnesses, mediators, and lay judges are to be the presidents of district courts and the Minister of Justice in the scope of the tasks performed. The provisions of Articles 13-15 paragraphs 1 and 3, 18, 19, and 21 of the GDPR do not apply to the processing of personal data.
  • The data controllers of court information systems are to be the courts in the exercise of justice or in the performance of legal protection tasks, the presidents of the relevant courts, and the Minister of Justice.

In addition to defining the data controllers, the legislator also proposed which entities are to supervise the processing of personal data by the relevant courts. According to the above change, the supervision:

  • The president of the district court shall oversee the district court,
  • The president of the appellate court shall oversee the appellate court,
  • The National Judiciary Council shall oversee the activities of the appellate court.

The data controllers of personal data processed in court proceedings are to be the courts.

9) Act on the Organization of Administrative Courts.

Very similar changes to those proposed in the Act on the Organization of Common Courts have been suggested by the legislator regarding the Act on the Organization of Administrative Courts. Consequently, administrative courts are to become data controllers of personal data processed in court proceedings. The provisions concerning the designation of data controllers for expert witnesses, mediators, lay judges, and personal data contained in IT systems of the courts are to be applied analogously to the solutions proposed in common judiciary.

Supervision over the processing of personal data by provincial administrative courts in court proceedings is to be exercised by the President of the Supreme Administrative Court, while supervision over the processing of personal data by the Supreme Administrative Court in court proceedings is to be exercised by the National Judiciary Council.

10) Act on the Supreme Court.

The Supreme Court is to become the data controller in the performance of its tasks. The supervision over the processing of personal data by the Supreme Court is to be carried out by the National Judiciary Council.

Summary

The provisions of the GDPR have largely compelled the legislator to clearly indicate who the data controllers are in many state institutions, which is a favorable solution from the citizen's perspective, as the proposed changes will allow them to know which authority decides on the purposes and means of processing their personal data.

Upon analyzing the provisions, one can also observe a certain facilitation for the state administration regarding the obligation arising from Article 34 of the GDPR, which involves notifying the person concerned. The notification of the affected individual may take place via the website of the office or on its BIP page.

We encourage you to read the previous part of the article regarding „professional laws”.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.