It is better to cooperate with the authority! Analyzing the fines imposed by the President of the Polish Data Protection Authority in 2020, particular attention is drawn to what connects the vast majority of them. Namely, the decisions in the cases of Vis Consulting sp. z o.o., a data controller operating a non-public nursery and kindergarten, East Power sp. z o.o., and the Chief Geodesist of the Country largely focus on the lack of cooperation with the supervisory authority during the inspection.
Chief Geodesist under scrutiny
Receive a package of free GDPR guides and micro-trainings
What exactly was the Chief Geodesist reprimanded for? As factors deserving condemnation and punishment, the decision indicated the failure to provide the supervisory authority with access to premises, equipment, and means used for processing personal data, as well as access to personal data and information necessary for the President of the Polish DPA to perform his tasks during the inspection. Moreover, the Chief Geodesist did not cooperate with the President of the Polish DPA during this inspection.
In short, the employees of the Polish DPA did not have the physical ability to fully conduct control activities, as the Chief Geodesist of the Country questioned the scope of the controllers' authorizations and consequently refused to carry out the inspection, including the basis for processing personal data, sources of obtaining this data, the scope and type of personal data shared, as well as the manner and purpose of this sharing. It is undeniable that the areas mentioned are crucial for assessing the correctness of data processing by the organization. Although the Chief Geodesist, regardless of the above, accepted the possibility of conducting an inspection to verify the implementation of appropriate technical and organizational measures, due to the lack of actual access for the controllers to the IT systems of the Chief Geodesist and the inability to conduct an examination of the IT system, it was impossible to determine whether appropriate technical measures had been implemented in the institution to ensure data security. As a result, the inspection only established the types of organizational measures applied for data security, as well as whether the Chief Geodesist appointed a Data Protection Officer.
The President of the Polish DPA, in a decision regarding this matter, emphasizes that the attitude presented by the Chief Geodesist of the Country should be regarded as undermining the entire system of personal data protection, and for this reason, it is of great importance and reprehensible in nature. According to the supervisory authority, in the existing factual state, an aggravating circumstance is that the Chief Geodesist committed this violation as a public authority, from which exceptional and greater understanding and respect for the actions taken by other authorities in the performance of their duties is expected than in the case of private entities.
The above indicates that public entities cannot feel privileged in any way. On the contrary, the discussed decision of the President of the Polish DPA proves that such entities are subject to even higher standards of conduct, and their absence is subject to severe sanctions.
Nursery and kindergarten also under scrutiny
Equally interesting is the decision issued in July regarding one of the entities operating a nursery and kindergarten. The penalty imposed on the organization – although relatively low (5,000 PLN) – once again concerns unsatisfactory cooperation with the authority, despite the fact that the controlled entity did not fully influence the course of events. One of the organization's creditors changed the locks at the nursery and kindergarten premises, which meant that neither the owner nor the staff could access the building, and consequently, access to the personal data of the children and their parents stored there was lost. Given the obstacles to functioning, after reporting the breach to the President of the Polish DPA, the entity failed to collect the shipment containing the letter addressed to it from the Office three times, and subsequently remained passive in response to the request for the provision of specific information to the supervisory authority.
However, the mere failure to respond is not a key argument for the authority in favor of imposing a penalty. The President of the Polish DPA points out that the entrepreneur made no attempt to justify the lack of any reaction to the requests directed at him, which in turn constitutes a gross disregard for the obligations imposed on the data controller regarding cooperation with the supervisory authority. It is also worth noting that, in light of the position expressed in the described decision, receiving correspondence directed to the Entrepreneur related to the activities conducted by him is an obligation that should be required of an entity conducting business activity, especially when such activity involves the processing of personal data of children (which requires special protection, as stated in Recital 38 of Regulation 2016/679).
No Exceptions
Another "victim" of EU regulations recently was East Power sp. z o.o. from Jelenia Góra. The company was accused not only of failing to provide the supervisory authority with the information necessary to resolve the matter but also of obstructing the inspection at the organization's premises – first by failing to present the persons authorized to represent the company, and then by directly refusing to conduct it. The organization submitted explanations only after a considerable time, in response to the notification of the initiation of proceedings. Despite this, the President of the Polish DPA deemed this action insufficient in light of the lack of any justification for the earlier passivity, which demonstrated a failure to cooperate with the supervisory authority. As a result, a penalty of 15,000 PLN was imposed.
FREE
Why the President of the Polish DPA Imposes Fines – 10 Most Important Decisions of the Polish DPA
Watch the webinarNot every situation will be a justification
The cited cases are not the end. Vis Consulting sp. z o.o. from Katowice thwarted an inspection by the President of the Polish Data Protection Authority under rather specific circumstances. After obtaining information about the planned inspection from the supervisory authority two days before the start of the planned inspection, the company approached the landlord to terminate the lease of the premises it was using. Subsequently, the entity twice prevented the inspection activities, as no person authorized to represent the organization was present at the company's headquarters during the inspection. Shortly thereafter, a resolution was adopted regarding the dissolution of the company and the initiation of liquidation proceedings. Regardless of whether the cited events were caused by the announced inspection or had entirely different grounds, the authority concluded that these actions clearly demonstrated a lack of cooperation by Vis Consulting sp. z o.o. with the President of the Polish Data Protection Authority, which contributed to the imposition of a monetary fine of 20,000 PLN.
How much can the President of the Polish DPA impose?
In each of the decisions mentioned above, similar allegations and references to identical legal provisions appear. It cannot be denied that these principles and regulations play a significant role from the perspective of the supervisory authority, and consequently, every data controller or data processor should take a closer look at them.
Polish DPA Inspection.
For us, it's routine!
In light of the discussed decisions, among the powers of the supervisory authority, it is particularly worth noting Article 58(1)(f), according to which the authority may access all premises of the data controller and the data processor, including equipment and means used for data processing, in accordance with the procedures specified in EU law or the law of the Member State.
Under Polish law, the aforementioned procedures are found among Articles 78 – 91 of the Act of May 10, 2018, on the Protection of Personal Data, in Chapter 9. “Control of Compliance with the Provisions on the Protection of Personal Data.” Article 84 of the Act on the Protection of Personal Data specifies the content of the GDPR, indicating that the controller has the right, inter alia, to enter the land and buildings, premises, or other rooms, to inspect documents and information directly related to the subject matter of the control, to conduct inspections of places, objects, devices, media, and IT or teleinformatics systems used for data processing. It should also be emphasized that these powers are correlated with the obligations of the controlled entities, which are obliged to enable the supervisory authority to perform specific actions, primarily entering the organization's premises, obtaining appropriate explanations, and examining documents and applied security measures.
Polish DPA without Sentiment
Practice shows that failure to comply with the obligation to cooperate with the supervisory authority results in financial penalties imposed on the controlled entities. What determines the amount of the penalty? According to the provisions of Article 83(1) of the GDPR, the administrative fine imposed by the supervisory authority should be effective, proportionate, and dissuasive in each individual case. This was also the objective of the President of the Polish DPA in the decisions considered, who in each case asserted that the specified financial penalty would discipline its recipient to properly cooperate with the supervisory authority in future proceedings involving it. In the opinion of the President, the discussed penalties are intended to also serve a dissuasive function, being a clear message both for the punished entity and for other entities operating in the market that trivializing the obligations related to cooperation with the supervisory authority is a serious violation and will always result in financial sanctions.


