Receive a package of free GDPR guides and micro-trainings
The obligation of DPOs to undertake, among other things, the aforementioned activities arises directly from Article 47(1) of the DODO Act. In principle, their scope aligns with that provided for in the GDPR.
In light of the above, with respect to the report in question, a critical issue is that its preparation is not reflected in the GDPR regulations. This document is, in fact, a completely new tool, which may ultimately make its creation exceedingly problematic.
Sample Report
In order to support DPOs in this demanding task, ODO 24 provides you with a sample report that will certainly facilitate its preparation.
Download
However, before we delve into the structure and necessary elements of the discussed document, it is worth emphasizing that the current report should concern actions taken over the past year – 2019. It should be noted that the DODO Act came into force on February 6, 2019, meaning that the period covered by this first report will not start at the beginning of the year, but from the indicated date.
Performing the tasks of the Data Protection Officer
In the first part of the report, the DPO should indicate specific actions taken in connection with the performance of the obligations imposed on him (mentioned above) as specified in Article 47(1) of the DODO Act. According to the regulation of the Prime Minister dated May 31, 2019, regarding the procedure and method of performing tasks by the Data Protection Officer, individual tasks are carried out by the DPO through specific, indicated, and described actions. The template we propose – taking into account the requirements of both the DODO Act and the regulation – will allow for a straightforward and transparent demonstration of the steps taken by the DPO.
Method of Processing Personal Data
Furthermore, it should not be overlooked that the indicated regulation obliges the DPO to conduct an analysis of the factual state of personal data processing in the organization before preparing the report. One possible way to fulfill this task is to conduct an audit of the specified personal data protection system.
During the audit, it is necessary to:
- analyze the existing personal data protection documentation for its compliance with personal data protection regulations and its currency,
- verify the substantive accuracy of the data and its adequacy in relation to the purpose of processing,
- analyze the security of the IT infrastructure (physical and logical security of the IT infrastructure),
- analyze the security policies, backup procedures, and access management, and determine their impact on the level of security of data sets processed in electronic form,
- verify the functionalities of applications and the level of their security,
- check the level of security for data sets processed in paper form,
- verify the contracts in terms of the potential need to supplement them with data processing agreements.
Submission of the Report
The provisions of both the DODO Act and the implementing regulation clearly indicate the data controller as the recipient of the report prepared by the DPO. A significant caveat regarding the act of transmitting the report is that it must be done in a manner that prevents other individuals from accessing the content of this document. This requirement can be fulfilled by sending the data controller an electronic version of the report, provided it is appropriately encrypted. The password should be communicated through a different means of communication, such as in person or by phone.
Marcin Kuźniak – our data protection advisor – is at your disposal. Schedule a free consultation and clarify your doubts.
Summary
There is no denying that the tasks of the DPO as envisaged by the legislator in the DODO Act are neither the easiest nor the least demanding. Therefore, we should be even more mindful that the time we can dedicate to preparing the discussed report is relentlessly passing, and we should confront this challenge as soon as possible.


