The registration form consists of six chapters (A-F), divided into 18 sections. Thus:
Receive a package of free GDPR guides and micro-trainings
Step 1.
In Chapter A, we specify the type of notification. We have three options to choose from:
- notification of a new dataset (based on Article 40 of the Personal Data Protection Act),
- updating a previously reported dataset (based on Article 41(2) of the Personal Data Protection Act),
- notification of a new dataset containing sensitive data (based on Article 27(1) of the Personal Data Protection Act).
Step 2.
In Section B1, we specify the name of the dataset and indicate the data controller – in our case, we provide the name of the company and its registered address. The name of the dataset should reflect its general purpose. It does not have to be unique, and we should not be discouraged if we find datasets named "Online Store Customers" or even "Customers" in the national register maintained by the Polish DPA.
Step 3.
We leave Section B2 blank, as it is intended to be filled out only by entities based outside the European Economic Area (e.g., in Russia, China, Belarus, the USA) that are required to appoint a representative in Poland under Article 31a of the Personal Data Protection Act.
Step 4.
In Section B3, we indicate the entities to which we have entrusted the processing of personal data under the agreements concluded, e.g., an IT company managing our store. If we anticipate entering into a relevant agreement in the future, we have the option to inform the Polish DPA by checking the appropriate "checkbox".
Do you like to keep order in GDPR?
So do we!
Step 5.
In section B4, we indicate the legal basis that authorizes us to process data in the dataset. In the case of an online store, there will be three clauses:
- the consent of the data subject to the processing of their data (e.g., managing a customer account in the online store),
- information that the processing of data is necessary for the performance of a contract when the data subject is a party to it or when it is necessary to take steps prior to entering into a contract at the request of the data subject (e.g., execution of sales contracts),
- information that the processing of data is necessary for the fulfillment of legitimate interests pursued by the data controllers or data recipients (e.g., marketing of their own goods or services).
Step 6.
After proceeding to section C, it is necessary to specify the purpose for which personal data will be processed. For the online store, this will naturally be customer service.
Step 7.
Next, we provide the category of individuals whose data are being processed. It is worth noting here to include more than just store customers. For example, one might also consider users who have an account in the online store but have not yet made any purchases, and it is unknown whether they will.
Step 8.
We specify what data will be processed within the reported dataset. For the purposes of fulfilling an order in the online store, the following will undoubtedly be needed:
- first and last name,
- residential address,
- shipping address,
- tax identification number (NIP),
- phone number,
- email address.
Of course, there is nothing to prevent the processing of other data than those suggested in the form. However, it should be remembered that the Polish DPA, when registering the dataset, will analyze whether the provided scope of data is adequate for the purpose of processing we have indicated.
Step 9.
If the store does not process sensitive data, the last two questions in section C can be omitted. However, the situation will change if we sell, for example, maternity clothing and collect information about the month of pregnancy of the customer. In that case, omitting this part of the form will constitute a "serious sin," which may be addressed by the inspectors of the Polish DPA.
Provide employees
with valuable e-training - for free
It's simple - just copy and send them the appropriate links.
Step 10.
After proceeding to section D, we determine the method of data collection. Our online store checks both boxes (i.e., from the data subject).
Step 11.
We inform whether we share personal data with entities other than those authorized under the provisions of law. With a conviction bordering on certainty, we can state that we will not do this. However, if we decide to share or sell the data, this field must definitely be checked.
Step 12.
In the last part of section D, we are asked whether we transfer the personal data sets we possess to third countries.
Step 13.
Section E, although consisting of only two parts concerning the applied security measures for data sets, poses considerable difficulties for those filling it out. It also serves as a kind of test of honesty, because if we do not meet the basic requirements, we must admit it here (which may mean refusal to register the data set, or even an inspection by the Polish DPA), or we can lie and attest to falsehood.
Step 14.
In section E15, we specify whether our data sets are processed centrally or in a so-called distributed architecture (in different IT systems, in different locations, entrusted to other entities for processing).
Step 15.
We indicate specific organizational and technical solutions we have implemented to protect the data sets we possess.
Step 16.
In the last part of the registration form, in section F, we must indicate the level of security measures applied to the IT systems. If we previously checked the box “at least one device in your system is connected to the Internet,” we must select a high level of security measures here (according to the provisions of the regulation of the Minister of the Interior and Administration regarding the documentation of personal data processing and the technical and organizational conditions that devices and IT systems used for processing personal data should meet).
Step 17.
We provide the email address to which we will receive confirmation of the data set submission.
Step 18.
The completed application is sent to the Polish Data Protection Authority. We can do this in three ways:
- by mail, via registered letter (to obtain proof of dispatch),
- delivered in person to the Polish Data Protection Authority's office,
- online (if we have a qualified electronic signature).
Finally, it is worth noting that ordinary personal data can be processed immediately after sending the registration notification to the Polish Data Protection Authority, while sensitive (special category) data can only be processed after such a dataset has been registered.


