Annual report on the implementation of DPO obligations under the GDPR - we provide a template.

18 February 2020

A period is approaching that requires exceptionally intensive work from Data Protection Officers (DPOs) designated mandatorily by data controllers applying the Personal Data Protection Act related to the prevention and combating of crime (DODO). In particular, this concerns their obligation to prepare an annual report on the performance of tasks related to data protection and the manner of processing personal data, and subsequently to submit it to the data controller. Although this is a labor-intensive task, in light of the legal provisions, the time for fulfilling this obligation is not long – it expires at the end of March (this applies to reports for the previous year).

GDPR Bulletin
Receive a package of free GDPR guides and micro-trainings
Join the ranks of our newsletter readers, receive a free package, and stay informed.
RECEIVE PACKAGE
One of the tasks imposed directly on DPOs by the DODO Act is to prepare and submit a report to the data controller regarding the execution of a number of other activities, such as raising awareness among individuals involved in processing operations and organizing training for them, acting as a contact point for data subjects regarding their rights, and preparing recommendations for conducting Data Protection Impact Assessments.

The obligation of DPOs to undertake, among other things, the aforementioned activities arises directly from Article 47(1) of the DODO Act. In principle, their scope aligns with that provided for in the GDPR.

In light of the above, with respect to the report in question, a critical issue is that its preparation is not reflected in the GDPR regulations. This document is, in fact, a completely new tool, which may ultimately make its creation exceedingly problematic.

Sample Report
In order to support DPOs in this demanding task, ODO 24 provides you with a sample report that will certainly facilitate its preparation.
Download  

However, before we delve into the structure and necessary elements of the discussed document, it is worth emphasizing that the current report should concern actions taken over the past year – 2019. It should be noted that the DODO Act came into force on February 6, 2019, meaning that the period covered by this first report will not start at the beginning of the year, but from the indicated date.

Performing the tasks of the Data Protection Officer

In the first part of the report, the DPO should indicate specific actions taken in connection with the performance of the obligations imposed on him (mentioned above) as specified in Article 47(1) of the DODO Act. According to the regulation of the Prime Minister dated May 31, 2019, regarding the procedure and method of performing tasks by the Data Protection Officer, individual tasks are carried out by the DPO through specific, indicated, and described actions. The template we propose – taking into account the requirements of both the DODO Act and the regulation – will allow for a straightforward and transparent demonstration of the steps taken by the DPO.

GDPR Compliance Diagnosis - Do it Yourself!

Method of Processing Personal Data

Furthermore, it should not be overlooked that the indicated regulation obliges the DPO to conduct an analysis of the factual state of personal data processing in the organization before preparing the report. One possible way to fulfill this task is to conduct an audit of the specified personal data protection system.

During the audit, it is necessary to:

  • analyze the existing personal data protection documentation for its compliance with personal data protection regulations and its currency,
  • verify the substantive accuracy of the data and its adequacy in relation to the purpose of processing,
  • analyze the security of the IT infrastructure (physical and logical security of the IT infrastructure),
  • analyze the security policies, backup procedures, and access management, and determine their impact on the level of security of data sets processed in electronic form,
  • verify the functionalities of applications and the level of their security,
  • check the level of security for data sets processed in paper form,
  • verify the contracts in terms of the potential need to supplement them with data processing agreements.

Submission of the Report

The provisions of both the DODO Act and the implementing regulation clearly indicate the data controller as the recipient of the report prepared by the DPO. A significant caveat regarding the act of transmitting the report is that it must be done in a manner that prevents other individuals from accessing the content of this document. This requirement can be fulfilled by sending the data controller an electronic version of the report, provided it is appropriately encrypted. The password should be communicated through a different means of communication, such as in person or by phone.

Marcin Kuźniak – our data protection advisor – is at your disposal. Schedule a free consultation and clarify your doubts.

Summary

There is no denying that the tasks of the DPO as envisaged by the legislator in the DODO Act are neither the easiest nor the least demanding. Therefore, we should be even more mindful that the time we can dedicate to preparing the discussed report is relentlessly passing, and we should confront this challenge as soon as possible.

READ MORE: Criminal Liability in the Context of DODO

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.