Exemption of the data controller from the obligation to register the personal data set with the GIODO in the case of appointing a Data Security Administrator (ABI)
The amendment to the Personal Data Protection Act will enable the implementation of one of two alternative models for internal compliance with personal data protection regulations within the organization:
- with an appointed Data Security Administrator (ABI),
- without an appointed Data Security Administrator.
Receive a package of free GDPR guides and micro-trainings
This will be made possible by the repeal of the currently applicable Article 36(3) of the Act and the addition of provisions introducing the possibility of appointing a Data Security Administrator, regulating their basic tasks (the obligation to ensure compliance with personal data protection regulations and to maintain a public register of data sets processed within the organizational unit), the conditions for their appointment (full legal capacity and enjoyment of full public rights, possessing appropriate knowledge of personal data protection regulations, and being free from criminal conviction for an intentional offense), the possibility of appointing a deputy, and the organizational placement within the data controller's unit (direct subordination to the head of the organizational unit).
The amendment to the Act (Article 36 b) establishes an obligation for the data controller, in the absence of an appointed information security administrator, to perform the tasks of that role. It should be emphasized that, in light of the applicable regulations, the fulfillment of the obligations imposed on the data controller requires taking the same actions that are required of the information security administrator. It is difficult to accept that the data controller will process data correctly if the individuals processing the data under their supervision are not familiar with the provisions on personal data protection, if they do not have control over the data processing processes, and over actions aimed at implementing and updating documentation. Thus, the relevant regulation constitutes merely a necessary adjustment to the amended provisions, and the lack of an appointed information security administrator will not generate additional burdens for the data controller.
The obligation to report data sets to the GIODO for registration, and subsequently to update the information contained therein, constitutes a significant administrative burden for data controllers, including entrepreneurs.
The provisions of Chapter 6 of the Personal Data Protection Act concerning the obligation to register data sets implement the provisions of Directive 95/46/EC of the European Parliament and of the Council of October 24, 1995, on the protection of individuals with regard to the processing of personal data and on the free movement of such data, as set out in Chapter II, Section IX titled "Notification." This part of the Directive regulates the institution of so-called "notification," i.e., the obligation imposed on the data controller to inform the supervisory authority about intended operations of personal data processing. Under the aforementioned Directive, it is impermissible for a member state to waive the notification obligation, but it is possible to simplify it or exempt from the aforementioned requirement within the scope defined by the Directive. The obligation to notify is introduced by Article 18(1) of the Directive, while Article 18(2) specifies the cases in which the data controller may be exempted from this obligation.
In particular, this provision allows member states to simplify the notification obligation or exempt it if the data controller appoints a Data Protection Officer (DPO) who meets two conditions: ensuring compliance with national data protection regulations (based on Directive 95/46/EC) in an independent manner and maintaining a records of processing activities that contains the same elements as the national register maintained by the Polish Data Protection Authority (so-called simplified registration). This is the only comprehensive exemption provided for in the directive. Other exemptions pertain to specific categories of data (Article 18(4)) or depend on criteria affecting the rights and freedoms of the data subject (Article 18(2) first indent) or the availability of personal data (Article 18(3)). However, the Polish legislator has not yet taken advantage of the opportunity to regulate the institution of the Data Protection Officer. The information security administrator provided for in Polish law does not meet the conditions to be recognized as a Data Protection Officer within the meaning of the directive. The law does not guarantee their independence, defines their tasks too narrowly in relation to the provisions of the directive in this regard, and does not grant them the authority for simplified registration. Currently, there is only one provision regarding the ABI in the Personal Data Protection Act (Article 36(3)).
Data Protection Officer.
Time for practical skills!
The amendment therefore provides for a comprehensive exemption from the registration obligation for the data controller who has appointed and reported the information security administrator to the Polish Data Protection Authority (the office will maintain another register) and at the same time introduces changes to the provisions concerning the tasks and organizational positioning of the DPO within the data controller's unit. However, the exemption from the registration obligation does not apply to collections containing sensitive personal data (Article 27(1)), as the registration regulated by Polish law entails the obligation of prior checking of the processing of such data, i.e., operations that may pose a threat to the rights and freedoms of the data subject (Article 20 of Directive 95/46/EC).
In light of the above requirements of EU law regarding the admissibility of a comprehensive exemption for data controllers from the obligation to register collections, new provisions are being introduced concerning the status and tasks of the DPO, which will ensure compliance with the standards set by Directive 95/46/EC, namely: independence in performing tasks, the obligation to ensure the application of personal data protection regulations within the organizational unit, particularly by granting powers for internal control over compliance with personal data protection regulations, as well as maintaining an internal register of data collections.
At the same time, as part of the proposed solutions, the status of the DPO is defined, which includes the requirements placed on the person fulfilling this role, the organizational positioning of the function, and the allowance for imposing on the DPO other tasks than those specified in the Personal Data Protection Act. The amendment assumes that the DPO may perform other tasks assigned to them that do not violate their obligations regarding personal data protection.
It should be emphasized that the proposed change deliberately avoids regulating issues aimed at creating a new professional group. At the same time, the changes allow for the outsourcing of the tasks of the information security administrator. The possibility of appointing deputies for the information security administrator has also been permitted, which is particularly significant in situations where the DPO temporarily cannot perform their duties.
Regardless of the exemption from the registration obligation, it is proposed to introduce an exemption concerning data sets that are not maintained in an information system, except for sets containing particularly protected data as specified in Article 27(1). This solution will be in line with the directive that allows for the exemption from the registration obligation for all sets (regardless of the category of data) that are not maintained using information systems (Article 18(5) of the directive), while simultaneously reducing the administrative burdens on those data controllers (entrepreneurs) who cannot benefit from the exemption from the registration obligation due to the lack of appointing a Data Protection Officer (DPO). However, the obligation to register will apply to sets that are not maintained using an information system if they process particularly protected data. The obligation to register sets containing this special category of data, similar to the comprehensive exemption from the registration obligation for data controllers who have appointed a DPO, is maintained due to the preliminary control conducted by the Polish Data Protection Authority in the registration process concerning this data.
Registration of Information Security Administrators (ISA) instead of personal data sets.
The amendment to the act provides for the extension of the registration powers of the Chief Inspector of Personal Data Protection to include information about Information Security Administrators. As of January 1, 2015, the data controller (ADO) will be required to notify the Polish DPA of the appointment and dismissal of the Information Security Administrator within 30 days from the date of their appointment or dismissal. The notification of the appointment of the Information Security Administrator for registration will include:
GDPR Compliance Diagnosis.
Do it yourself
- 1. identification of the data controller and the address of their registered office or place of residence, including the identification number in the national economy register, if assigned,
- data of the data controller: name and surname, PESEL number or, if this number has not been assigned, the name and number of the identity document, correspondence address, if different from the address of the data controller,
- date of appointment,
- statement of the data controller confirming that the data protection officer meets the necessary conditions to perform the specified function.
Changes to the information covered by the above notification must be updated within 14 days from the date they occur.
The registration system for data protection officers is designed to provide a straightforward means of ensuring that the data controller has indeed met the necessary conditions to be exempted from the registration obligation applicable to entities that appoint a data protection officer. At the same time, similar to the registration system for personal data sets, the transparency of the data contained in the register will fulfill, in accordance with the provisions of the directive, the requirement for transparency in personal data processing operations.
The Polish DPA, due to the independent supervisory competence of the data protection officer, may delegate to them the task of verifying the compliance of personal data processing with data protection regulations. This represents a significant relief for data controllers (including entrepreneurs) compared to the current situation, where they are subject to direct supervision by the Polish DPA in every case that requires it (e.g., a complaint from a third party). The supervision conducted by the data protection officer in no way undermines the authority of the Polish DPA, which may at its discretion allow for simplified supervision and is not limited in its ability to conduct a subsequent review.
It should be noted that the verification referred to in Article 16a of the Personal Data Protection Act and the verification in Article 36a(2)(1)(a) are two different legal institutions. In the first case, the data protection officer, at the request of the Polish DPA, verifies the compliance of personal data processing with data protection regulations at the data controller who appointed them. The report from such verification is submitted, through the data controller, to the Polish DPA. In the second case, the verification conducted by the data protection officer is of an internal audit nature, and thus the resulting report is an internal document of the data controller.
Transitional provisions are anticipated to be introduced, under which the current information security administrator will perform this function in accordance with the old regulations until they are entered into the register, but no longer than until June 30, 2015. Furthermore, the existing provisions of the Personal Data Protection Act will apply to registration proceedings conducted by the Inspector General for Personal Data Protection (GIODO) based on notifications referred to in Article 41(1) and (2) that have not been completed before the date of entry into force of the provisions introducing new exemptions from the registration obligation.
Transfer of data to third countries and EEA member states without the consent of GIODO
The purpose of the amendments to Article 48 of the Personal Data Protection Act is for the Polish data protection authority to join the mutual recognition procedure. The changes involve transferring (with significant modifications) the existing content of Article 48 of the Personal Data Protection Act to the new Article 48(1). The amendment exempts the data controller from the obligation to obtain GIODO's consent for the transfer of data to a third country in the case of using standard contractual clauses approved by the European Commission, in accordance with Article 26(4) of Directive 95/46/EC, or binding corporate rules approved by GIODO. At the same time, GIODO is granted the authority to approve binding corporate rules after consulting with the data protection authorities of the member states of the European Economic Area.
In light of the European Commission's decision, the use of standard contractual clauses is considered a solution that provides adequate guarantees for the rights and freedoms of the data subject. Therefore, in the case of using standard contractual clauses in the process of transferring data to a third country, there is no justification for conducting administrative proceedings aimed at obtaining the consent referred to in the new Article 48(1) of the Act.
The application of binding corporate rules, which as a legal instrument should have a general character applicable to all international transfers within a corporate group and be approved by the Polish DPA, will not require the Polish DPA's consent for individual data transfers. Binding rules or data protection policies adopted within the corporate group for the purpose of transferring personal data by the data controller or the entity referred to in Article 31(1) (data processor) to another data controller or entity referred to in Article 31(1) within the same group in a third country (binding corporate rules) are legal instruments aimed at ensuring uniform and appropriately flexible standards for the protection of personal data within international corporate groups. This instrument is particularly significant in the global economy and is supported by both business environments and data protection authorities. The approval of binding corporate rules, as providing adequate guarantees, allows for the waiver of the need to obtain consent for individual operations of transferring personal data to third countries. Due to the global nature of binding corporate rules, it is important that their approval occurs after prior consultation regarding their content with the data protection authorities of EEA member states. The procedure for such consultations is currently defined within voluntary agreements between data protection authorities and includes, in particular, the mutual recognition of opinions of individual data protection authorities regarding binding corporate rules.
The amendment of Article 48 of the Personal Data Protection Act, aimed at enabling the data controller to transfer data to a third country that does not provide an adequate level of personal data protection without the need to obtain the Polish DPA's consent through an administrative decision each time, concerns two situations:
- when standard contractual clauses approved by the European Commission are applied in accordance with Article 26(4) of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data,
- when legally binding corporate rules approved by the Polish DPA are applied in accordance with Article 8(8) of the draft Act on the Facilitation of Business Activity and Article 48(3) of the Personal Data Protection Act.
There are no stupid questions regarding GDPR.
There are free answers
Moreover, the aforementioned rule will also apply to international corporations processing data on behalf of others (under a data processing agreement as referred to in Article 31 of the Personal Data Protection Act). The approval of binding corporate rules adopted by an international corporation providing data processing services will mean that the data controller commissioning such a service will not need to obtain the consent of the Polish Data Protection Authority for the data transfer related to this service to a third country that does not ensure an adequate level of personal data protection on its territory.


