What is data sharing?

Sharing personal data is one of the processing operations defined under Article 4(2) of the GDPR. It constitutes the transfer of personal data outside the data controller's organization. As a result of sharing personal data, meaning the transfer of specific information to another entity, the data controller loses control over the processing of that data and thus does not decide on the manner and purposes of processing the transferred personal data by the entity that received the aforementioned data.
When is data sharing voluntary and when is it mandatory?
In our series of articles on data sharing, we have already indicated when we will be dealing with mandatory data sharing. Now it is time to explain what voluntary or, in other words, request-based data sharing is.
When a request for the sharing of information, documents, or a request for the sharing of data is submitted to the data controller, it is essential to examine it closely first. The data controller is obliged to verify whether the submitted request contains a legal basis that is appropriate for the specific situation and whether it is current.
It is also necessary to investigate whether, based on the request, there is a possibility to verify the requester and their entitlement to receive the requested data. Furthermore, it should be assessed whether the request contains any other errors and – if necessary – whether there is a need for it to be corrected or supplemented by the requester.
Data sharing at the request of the data subject
Receive a package of free GDPR guides and micro-trainings
Data sharing at the request of another external entity
Another example of data sharing is the transfer of specific information to another entity. In order for the data controller to transfer information or documents containing personal data to another entity, they must have specific legal grounds for doing so. The basis for the data controller to share personal data may be both a contract and provisions of generally applicable law. In this case, at the moment of data sharing, the data controller no longer exercises control over the shared personal data, and this control is assumed by the entity that received the data.
Example - Article 155(3) of the Real Estate Management Act
The relevant authorities, agencies referred to in paragraph 1 point 6a, housing cooperatives, courts, and tax offices are obliged to provide property appraisers with the registers and documents referred to in paragraph 1, including enabling the preparation of copies of documents in any form.
Referring to the specified legal provision, the property appraiser may submit a request to the relevant authority for access to the registers and documents, often containing personal data.
Request without legal grounds – what to do?
It is also worth mentioning that a request for data access submitted to the data controller does not always have a specified legal basis. What should the controller do in such a situation? First and foremost, the request should be carefully examined. If the absence of a specified legal basis is due to an error or oversight, it would be appropriate to ask the requester to supplement or correct the request. However, if there is no legal provision that the requester could invoke, an assessment of the requester's entitlement to receive personal data should be conducted. In this case, it is the role of the controller to consider whether there is a legitimate interest or a justified reason for providing such personal data to the requester.
How to comply with GDPR?
To avoid getting lost in the maze of regulations and to prevent accusations of violating GDPR provisions, the data controller should primarily adhere to the applicable principles arising from GDPR regulations. It is therefore advisable to refer to Article 5 of GDPR and ensure that when providing personal data, accountability is maintained, the appropriate legal basis or legitimate interest defining the purpose and the adequacy of that purpose is indicated, and that personal data is provided in compliance with the principle of data minimization. A good practice for every data controller would therefore be to establish appropriate procedures governing the handling of requests for data access.
Do you need support in creating such procedures? Schedule a meeting with Cezary Lutyński – our data protection advisor. You will receive the assistance you need.


