Year 2018 – what was it like for information security?

05 February 2019

The year 2018 was marked by significant events for information security, being yet another year in which the legislator (both national and European) sought to minimize the gap between advancing technological development and the existing legal framework, while simultaneously searching for a balance between two values: the protection of citizens' privacy and the innovation of the economy.

Regardless of the multitude of noteworthy events, one of them significantly overshadowed the others – the commencement of the General Data Protection Regulation (GDPR). This subjective overview of the most important events in the world of information security in 2018 adheres to this narrative and summarizes the past 12 months primarily through the lens of the changes that occurred in the personal data protection environment.

144 Days of a Deadly Race

The countdown timer placed on the website of the Inspector General for Personal Data Protection, counting down to May 25, perfectly captures the atmosphere of the first half of 2018. Everyone was racing: the legislator, working on the Personal Data Protection Act, which organized the national personal data protection system; the Inspector General for Personal Data Protection, adapting his office to fulfill new obligations while simultaneously providing advice and recommendations regarding the application of GDPR; and the organizations themselves, eager to implement the necessary changes on time.

In particular, the race for organizations tasked with fulfilling the obligations of data controllers or data processors was particularly challenging. This was primarily due to the fact that GDPR is a qualitatively different legal act compared to the previous framework. Implementing GDPR required a departure from a mere replicative implementation of legal requirements towards the organization’s engagement in building its own personal data protection system, appropriate to the profile of its business activities. GDPR did not explicitly specify the requirements regarding security measures. These should be defined by the organization itself based on a risk analysis process, which most organizations had not conducted until then and for which they were unprepared.

GDPR Bulletin
Receive a package of free GDPR guides and micro-trainings
Join the ranks of our newsletter readers, receive a free package, and stay informed.
RECEIVE PACKAGE
The implementation of the GDPR was not facilitated by the exceptionally late enactment of the law and the issuance of guidelines regarding the practical application of the GDPR. The Personal Data Protection Act, which specified, among other things, the issues concerning public entities required to appoint a Data Protection Officer (DPO), the procedures for handling breaches of personal data protection regulations, as well as criminal liability and administrative fines, was passed by Parliament only on May 10, just two weeks before the GDPR came into effect.

Moreover, it was only in the final stretch that the Article 29 Working Party issued or significantly revised opinions indicating how to obtain consent for the processing of personal data, how to conduct correspondence with data subjects in a clear and transparent manner, and how to report personal data breaches.

Adding to this atmosphere of fear, uncertainty, and unlimited demands from data subjects, such as employees, clients, or patients, who were intensively informed by the media, May 25 appeared to many as the end of the world.

Hour "0"

May 25 was the culmination of all fears associated with the largest reform of personal data protection regulations in over 20 years. On that day, all concerns related to the GDPR converged, and the nerves of those responsible for data security were stretched to the limits. However, during the frantic preparations, the objectives set by the EU legislator were completely forgotten, namely that by establishing a set of regulations directly applicable in the legal systems of all EU member states, the GDPR aims to ensure the free flow of personal data between EU countries and to strengthen two essential elements of the digital single market: consumer trust and their security.

The Sun Did Rise, However

Contrary to the bleak scenarios, the GDPR apocalypse did not occur. Employees of the Polish Data Protection Authority did not start knocking on organizations' doors en masse, and inboxes were not flooded with complaints from so-called GDPR terrorists. So what was the second half of 2018 for organizations? A time of relaxation and apparent calm. Apparent, because many organizations treated GDPR as a one-time activity rather than a process of continuous compliance maintenance. Observations from experts also indicate that many companies hid behind a "facade" of implementation, constructed from template document patterns, not reinforced by a properly conducted Data Protection Impact Assessment and risk analysis. This leads to the conclusion that 2019 may be a time of intensified "renovations" of personal data protection systems in many organizations.

How does the President of the Polish Data Protection Authority assess the first six months of the new regulations? Interesting information in this regard is provided by the Niebezpiecznik portal. According to information conveyed by the President of the Polish DPA:

  • since May 25, 3,700 complaints have been submitted by individuals. For comparison, in the entire year of 2017, there were 2,950,
  • organizations reported over 1,800 breaches (incidents) of personal data protection,
  • the President of the Polish DPA conducted several proceedings. These concerned breaches that were not reported by organizations but were brought to the authority's attention by individuals or were reported by another authority.

GDPR. Support is useful!

As for the most frequently reported breaches of data protection to the President of the Polish DPA, they include:

  • sending documentation to unauthorized persons (this applies to both email correspondence and paper correspondence),
  • loss/theft of electronic storage devices,
  • improper destruction of documentation (a common occurrence is when documentation intended for destruction is not destroyed at the organization's premises or with the involvement of a professional company, but is later found by third parties in public places or on private properties),
  • loss of paper documentation,
  • hacking attacks resulting in the acquisition and/or encryption of databases.

Among the complaints submitted to the President of the Polish DPA by individuals, the following are most frequently repeated:

  • the desire to delete personal data – primarily relates to the banking sector, companies engaged in debt collection, online services (social media, websites),
  • forcing consent for data processing for marketing purposes,
  • sending unwanted correspondence or making unwanted marketing calls by companies,
  • unauthorized disclosure of personal data to a third party,
  • collecting an excessively broad range of personal data,
  • conditioning the conclusion of a contract on the provision or sharing of a copy of an identity document, especially an ID card,
  • improper fulfillment of the information obligation,
  • processing biometric data of employees,
  • the use of video surveillance,
  • unauthorized disclosure of personal data in connection with the fulfillment of obligations related to access to public information (including through the publication in the Public Information Bulletin of documents containing personal data without appropriate anonymization).

What awaits us in 2019?

RODOmigawki
Provide employees
with valuable e-training - for free
Do you want to train employees for free?
It's simple - copy and send them the appropriate links.
SHOW MORE
What will 2019 be like for information security? Above all, it will be demanding, due to the shaping of practices related to the application of the GDPR. Many issues currently raising doubts will find resolution in decisions of the President of the Polish DPA, court rulings, or guidelines from the European Data Protection Board.

The imposition of administrative financial penalties, which are already being applied by foreign data protection authorities, is also a matter of time. Considering the level of implementation of GDPR requirements by Polish organizations, this risk should be regarded as real.

One should not overlook the issues related to ongoing legislative work, both at the national and European levels. This primarily concerns the draft law adapting the Polish legal order to the principles of data processing specified in the GDPR (the Act amending certain acts in connection with ensuring the application of Regulation 2016/679), the Act on the protection of personal data processed in connection with the prevention and combating of crime (which should implement Directive 2016/680, commonly referred to as the police directive), as well as the so-called ePrivacy Regulation, which brings changes for organizations equivalent to those resulting from the GDPR. Each of the mentioned legal acts will have significant consequences; therefore, those responsible for information security should monitor the legal environment of their organizations.

Undoubtedly, one can say already now - the year 2019 will be extremely interesting.  

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.