Under the current legal framework, an entrepreneur may be fined to compel compliance with the decision of the Inspector General for Personal Data Protection (GIODO), with a maximum fine of up to PLN 200,000 for legal entities in a single proceeding. These fines are imposed in enforcement proceedings in the administration.
After May 25, 2018, the supervisory authority will be able to decide on the imposition of a monetary penalty at the moment of identifying a violation, rather than only as a result of non-compliance with an administrative decision.
In determining the amount of the penalty, the supervisory authority will take into account:
-
the nature, gravity, and duration of the violation, taking into account the nature, scope, or purpose of the processing, the number of affected individuals whose data were involved, and the extent of the damage suffered by them,
Receive a package of free GDPR guides and micro-training sessions
Join the ranks of our newsletter readers, receive a free package, and stay informed.RECEIVE PACKAGE - the intentional or unintentional nature of the violation,
- actions taken by the data controller or data processor to minimize the damage suffered by the individuals whose data were involved,
- the degree of responsibility of the data controller or data processor, taking into account the technical and organizational measures implemented by them,
- any previous violations by the data controller or data processor,
- the degree of cooperation with the supervisory authority to remedy the violation and mitigate its potential negative effects,
- the categories of personal data that were the subject of the violation,
- the manner in which the supervisory authority became aware of the violation, in particular, whether and to what extent the data controller or data processor reported the violation,
- if any corrective measures have been previously applied to the data controller or data processor in the same matter, and whether the entity complied with them,
- the application of approved codes of conduct or approved certification mechanisms,
- any other aggravating or mitigating factors relevant to the circumstances of the case, such as financial benefits obtained directly or indirectly in connection with the violation or losses avoided.
Important
Depending on the violation, the Regulation provides for two tiers of fines:
- up to 10,000,000 EUR, and in the case of an enterprise – up to 2% of its total annual worldwide turnover from the previous financial year, or
- up to 20,000,000 EUR, and in the case of an enterprise – up to 4% of its total annual worldwide turnover from the previous financial year.
A lower fine will apply in the case of violations of the provisions concerning:
- the obligation to obtain consent from the guardian of a child under 16 years of age when offering information society services to the child (Article 8 of the Regulation),
- the prohibition on processing personal data if such processing in a manner that allows the identification of the data subject is no longer necessary (Article 11 of the Regulation),
- the obligation to implement privacy by design and privacy by default mechanisms (Article 25 of the Regulation),
- the obligation to regulate the relationship between joint controllers in accordance with the guidelines of the Regulation (Article 26 of the Regulation),
- the obligation to appoint a representative in the EU (Article 27 of the Regulation),
- the compliance by the data processor with the obligations imposed on it in the agreement with the data controller and the provisions of the Regulation, the obligation to appropriately regulate the relationship with the data processor (Article 28 of the Regulation),
- the obligation to process data on behalf of the data controller or data processor (Article 29 of the Regulation),
- the obligation to maintain records of processing activities (Article 30 of the Regulation),
- the obligation to cooperate with the supervisory authority (Article 31 of the Regulation),
- the obligation to implement appropriate technical and organizational measures (Article 32 of the Regulation),
- the obligation to notify the supervisory authority of a personal data breach (Article 33 of the Regulation),
- the obligation to inform the data subject of a personal data breach (Article 34 of the Regulation),
- the obligation to assess the impact of planned processing operations on data protection (Article 35 of the Regulation),
- the obligation to conduct prior consultations with the supervisory authority if a particular type of processing would result in a high risk, as confirmed by the Data Protection Impact Assessment (Article 36 of the Regulation),
- the obligation to appoint a Data Protection Officer and provide them with adequate resources and guarantees of independence (Article 37 of the Regulation),
- the status of the Data Protection Officer (Article 38 of the Regulation),
- the performance of the tasks of the Data Protection Officer (Article 39 of the Regulation),
- obligations of the certifying body (Articles 42 and 43 of the Regulation),
- obligations of the monitoring body regarding compliance with the code of conduct in relation to its violation by the data controller or data processor, including the suspension or exclusion of the data controller and data processor from those applying the code (Article 41(4) of the Regulation).
A higher penalty will apply in the event of a violation of the provisions concerning:
- the fundamental principles of processing, including the conditions for obtaining consent (Articles 5, 6, 7, 9 of the Regulation),
- the rights of data subjects, including: the right of access to data, the right to rectification, the right to be forgotten, the right to restriction of processing, the right to data portability, the right to object, the right not to be subject to a decision based solely on automated processing, including profiling (Articles 12–22 of the Regulation),
- the principles of transferring personal data to third countries or international organizations (Articles 44–49 of the Regulation),
- any obligations arising from the law of a member state adopted in connection with ensuring freedom of expression and information, processing data in the context of employment, processing data for archival, scientific, historical, statistical purposes, processing data by churches and religious organizations (Chapter IX of the Regulation),
- non-compliance with an order, whether temporary or final, to restrict processing or suspend the flow of data issued by the supervisory authority,
- the right of the supervisory authority to access the premises of the data controller or data processor.
Fines for public authorities or entities may be reduced by any member state. In the draft of the new personal data protection law, the Polish legislator proposes to reduce fines to 100,000 PLN.
In light of the above, preparations to adapt the organization to the requirements of the GDPR should begin today.


