Personal data protection system – with a DPO or without?

08 kwietnia 2015

The amendment to the Personal Data Protection Act of January 2015 allows for the implementation of one of two alternative models for internal compliance with personal data protection regulations within an organization: a) based on the appointment of a data security administrator (ABI), b) directly by the data controller.

This is made possible by the repeal of Article 36(3) of the Act and the addition of provisions introducing the possibility of appointing a data security administrator, regulating their core tasks, the conditions of their appointment, and their organizational positioning within the data controller's entity.

Until the end of 2014, according to the interpretation of the Inspector General for Personal Data Protection (GIODO) expressed, among others, in the report for the year 2011, a data controller could perform the tasks of the information security administrator only if they were a natural person conducting business activity. However, a data controller that is not a natural person conducting business activity was required to designate a specific natural person as the information security administrator – only such a person, in light of Article 37 of the Personal Data Protection Act, could be authorized to process personal data, and such authorization was necessary for the proper performance of supervisory activities by the information security administrator.

GDPR Bulletin
Receive a package of free GDPR guides and micro-training sessions
Join the ranks of our newsletter readers, receive a free package, and stay up to date.
RECEIVE PACKAGE

The question remains open regarding the choice of the best course of action. Considering the general purpose of the personal data protection system in the organization, which is to process the personal data held in accordance with applicable law and under conditions that ensure their confidentiality, integrity, and availability, it must be stated that this is one of the key issues. The extrapolation of existing case law suggests that the possibility of independently supervising the data protection system by the data controller is a concession to small and medium-sized enterprises whose business profile is not directly related to the processing of personal data.

When deciding to independently oversee the personal data protection system, the management of the organization must assess whether it has the knowledge and actual supervisory capabilities over the processes related to the flow of personal data and take into account the following criteria:

  • the number of employees in the organization,
  • the categories of individuals whose data is being processed,
  • the categories of personal data held (ordinary, sensitive),
  • the complexity of the IT infrastructure used in the organization,
  • knowledge of legal regulations concerning information security (including personal data),
  • outsourcing of services outside the organization,
  • the scale of marketing activities,
  • physical security measures.

ODO Nawigator PRO
Personal Data Processing
Under Control
ODO Nawigator PRO will help you organize the GDPR topic in your organization.
Before it is too late.
SEE MORE

It should be noted that independently supervising the personal data protection system does not relieve the data controller of other obligations arising from the Personal Data Protection Act, namely:

  • fulfilling the conditions for the legality of personal data processing,
  • meeting the information obligation,
  • creating and continuously updating the documentation required by regulations,
  • registering personal data sets in the register maintained by the Inspector General for Personal Data Protection,
  • ensuring proper physical security of the processed sets,
  • providing appropriate training for employees.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.