According to Article 32 of the GDPR, taking into account the state of technical knowledge, the cost of implementation, as well as the nature, scope, context, and purposes of processing and the risk of infringement of the rights or freedoms of natural persons with varying probabilities of occurrence and severity of the threat, the data controller (ADO) and the data processor implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk.

Although the GDPR is "technologically neutral," it imposes an obligation on entities involved in data processing to adequately secure the data, without specifying the specific measures to achieve this. In an era of constantly changing data processing methods and the associated threats, such an approach by the European legislator is understandable.
It would be difficult to regulate the often very diverse conditions of personal data processing with a single legal act; however, such far-reaching discretion results in the data controller rarely sufficiently addressing the issue of possible unintended access to data by individuals other than those authorized to process it.
Where does the danger lurk?
It is not uncommon for employees of an organization to receive their colleagues or acquaintances in rooms designated for processing personal data. Additionally, contractors or their representatives, or various guests sometimes appear on the organization's premises, depending on the nature of the entity's activities.
Although at first glance we may not notice the danger associated with the presence of certain individuals, the consequences of possible access to "loosely" left personal data on a desk or visible on a computer screen can be painfully felt long after the fact. What if someone, for instance, accidentally sees the personal data of their despised acquaintance on a monitor while visiting a bailiff's office? There is a high chance that they will share the obtained information with others to tarnish the acquaintance's reputation, or even use the acquired data in a more sophisticated manner, such as notifying potential business partners of the acquaintance that enforcement proceedings have been initiated against them, thereby rendering them untrustworthy. The consequences of such an incident could therefore be negative not only for the mentioned acquaintance but also for the bailiff's office as the data controller of the compromised data.
Interestingly, among the management staff of many companies or institutions, there is a belief that the screen of company computer equipment should be visible to all coworkers to avoid suspicion of an employee using the equipment for non-work-related purposes, such as browsing social media. Thus, the confidentiality of personal data is placed lower in the hierarchy of values than the ability to control who in the company is "slacking off." The exception is made for finance and accounting departments, where, for example, transfers are made and the awareness of the need to protect information is higher, but even there, confidentiality is maintained not for the sake of personal data protection, but rather for financial information.
Clean Desk, or Cleaning Up Not Just Coffee Cups
The principle of a "clean desk" is simple – no documents containing personal data should be left unattended at the workstation during our absence. Moreover, even when we are at our workstation, there may be outsiders moving around. During busy work periods, employees, realizing they will not finish a given task that day, leave all documentation on the desk to save time needed for putting it away and taking it out again the next day. Such carelessness can prove very costly for the data controller, as in large companies, offices are usually cleaned in the evening or at night to avoid disturbing employees during working hours. Cleaning staff may come into possession of many "valuable" personal data, which creates an even greater risk in situations where the cleaning personnel have not signed any confidentiality clauses.
How to position monitors?
Monitors should be positioned in such a way as to prevent clients, stakeholders, or third parties from viewing personal data displayed on them. This is not always possible due to the layout of the premises, especially in small office buildings, where it is not uncommon for 6 people to work at computers in a room of 10 m2. The same applies to large open-plan offices, where dozens of people work in one room without any partition walls. Do such spatial difficulties exempt the data controller from the obligation to ensure the confidentiality of personal data? Absolutely not. Unfortunately, many data controllers disregard "inconvenient" rules, often personally approved in the security policy.
Importantly, the "clean screen" policy also applies to files placed on the desktop. Such files may contain personal data in their names, for example, when currently negotiated contracts with individual clients are named using their first and last names. A file named "termination_kowalski," noticed on the computer desktop by an unsuspecting Kowalski, may lead to unexpected consequences in the form of a desire for revenge for a decision that has been made but not yet communicated to him.
When stepping away from the computer, we must absolutely remember to lock it (e.g., using the Windows+L keyboard shortcut). It is also very important to set the computer to automatically lock after, for example, 5 minutes of inactivity.
A necessary golden mean
An interesting data protection breach occurred in connection with... an overly strict clean desk policy implemented by an Italian call center operator. Employees were prohibited from placing any personal items at their workstations, which was intended to ensure confidentiality during the processing of client data.
It was only permitted for an employee to have medication at their workplace, provided that they presented a medical certificate confirming the necessity of taking it during work hours. Such necessity had to be additionally confirmed by the occupational physician. Other items, including other medications, were to be stored in a publicly accessible cabinet. The trade union filed a complaint with the data protection authority, arguing that the employer unlawfully processes health-related data, and additionally, the information about the medications taken by employees is visible to other colleagues. Consequently, the supervisory authority imposed a fine of 20,000 euros on the call center operator.
Summary
In summary, let us be cautious of "our own" and "others," who do not have the authority to process data, yet still have the opportunity to access it on our desk and on our computer screen. As individuals authorized to process personal data, and – at least in theory – familiar with the relevant regulations and procedures, we are accountable to the data controller-employer for any inadvertent disclosure of protected information. Financial liability may even be at stake, based on the provisions of the Labor Code regarding employees' material liability (Article 114 of the Labor Code and subsequent articles). The Personal Data Protection Act of 2018 also introduces penal provisions, including Article 107(1), which states that anyone who processes personal data, even if such processing is not permissible or they are not authorized to process it, is subject to a fine, restriction of liberty, or imprisonment for up to two years. The Penal Code itself sanctions crimes against information protection (Articles 265 and subsequent articles). Finally, we must remember the general premise of tort liability contained in the Civil Code ("Anyone who causes damage to another through their fault is obliged to repair it").
You can talk to Marcin Kuźniak not only about the principle of a clean desk. Contact him if you are looking for practical tips regarding GDPR.


