Who is who in the personal data protection system?

30 October 2023

Every branch of law has its own terminology, including its own definitions of the functions performed by various entities. For example, in labor law, we have the employer and the employee; in civil law – the principal and the contractor; and in data protection law – the data controller, the information security administrator, and the persons authorized to process personal data. In data protection, understanding who is who is particularly important, as most of the obligations specified in the GDPR rest with the data controller. Below, we explain who performs each function and what their responsibilities entail.

President of the Polish Data Protection Authority (PUODO)

This is the supervisory authority that, with the assistance of the Polish Data Protection Authority, oversees compliance with legal provisions regarding personal data protection (hence in practice the terms PUODO and UODO are used interchangeably). In other words, PUODO conducts checks on compliance with regulations. It may carry out explanatory activities both as a result of receiving information about irregularities, e.g., in a breach notification, and ex officio, when, for example, a data leak is reported in the media. It is to PUODO that data breaches are reported. Additionally, it is the competent authority for lodging complaints regarding violations of the rights of individuals arising from the GDPR (e.g., if a seller did not provide a copy of the data requested by a customer).

The most well-known power of PUODO is the ability to impose administrative fines – even up to PLN 20 million. PUODO has powers in the area of administrative enforcement, used to compel compliance with administrative decisions. However, not every violation of regulations must result in the imposition of a monetary penalty. PUODO has a number of other powers; for example, it may choose to issue a warning, order the data controller to adjust processing operations to comply with regulations (e.g., to cease collecting excessive data), or prohibit the data controller from processing personal data or order the restriction of processing (as happened in this case).

PUODO's decisions are made available on a dedicated subpage of the Authority. They can be filtered by topic (e.g., employee, data processing delegation, consent), by institution (e.g., insurers, courts, telecommunications), and by date of issuance. PUODO's decisions are a fascinating read for anyone interested in personal data protection in Poland, as they provide insight into how the regulations "live," how they are interpreted and applied in practice, and for what offenses one can be penalized.

Data Controller (ADO)

The data controller is an individual or entity that determines the purposes and means of processing personal data. Simply put, it is the owner of the personal data. This can be either a natural person (e.g., a sole proprietorship) or a legal person (e.g., a joint-stock company). We automatically become a data controller when we start processing personal data in connection with our professional or business activities. Therefore, we will not be a data controller if we process personal data solely for personal use.

Most of the requirements of the GDPR pertain specifically to data controllers – they determine the shape of the internal system for the protection of personal data. Consequently, any potential penalties are primarily imposed on data controllers, very rarely on data processors. However, in practice, it is not always easy to determine who is actually the data controller of a specific set of personal data or the controller of a specific processing activity. Identifying the decision-maker (who decides on the purposes and means of processing) can be problematic due to difficulties in establishing the factual state. Who really decides about what? – this question often arises, for example, in capital groups. The guidelines 07/2020 on the concepts of controller and processor contained in the GDPR come to the rescue in such cases. The Polish DPA also publishes positions on its website regarding the determination of the roles of individual entities in a given processing activity (e.g., an auditor).

DPO Function - it transfers well

Data Processor (also known as Processor)

The processor is an entity that processes personal data on behalf of the data controller. Therefore, it acts not to achieve its own objectives, but simply performs operations on personal data as instructed by the data controller. The relationship of data processing entrustment (between the data controller and the processor) is associated with the obligation to conclude a data processing agreement. The processor cannot do anything with the data entrusted to it that has not been instructed by the data controller. In practice, it is quite common – and incorrectly – to attribute the status of data controller to any entity that physically possesses some personal data. Nothing could be further from the truth: the data controller does not even need to have access to the data in order to decide on the purposes and means of their processing. This can be compared to your money in a bank account – the bank physically holds it, but you decide what to do with it. Typical examples of processors include, for instance, external accounting firms, marketing agencies, security companies, and IT firms – all external entities that have access to personal data owned by another company. And it is the owner (data controller) who decides what will happen to the personal data. For example, a security guard employed to monitor a building cannot use footage from surveillance for his own purposes, such as posting it on his Facebook profile.

Data Protection Officer (DPO)

Legal provisions allow for the oversight of the personal data protection system to be entrusted to an individual serving as a DPO, and even encourage this. The Data Protection Officer can be an individual from within the organization (e.g., a full-time employee) or from outside it (so-called outsourcing DPO). In practice, the DPO ensures that all obligations imposed by law on the data controller are fulfilled. However, it is not the DPO's task to perform all the duties of the data controller (e.g., ensuring compliance with the information obligation), as this could lead to a conflict of interest. This conflict would arise from the fact that the DPO would be auditing and verifying their own work on an ongoing basis (more in guidelines for data protection officers -> 3.5. Conflict of interest).

In practice, however, particularly in smaller companies, such conflicts of interest occur quite frequently. This is due to the fact that the DPO is usually the only person in the organization who possesses knowledge about personal data protection. For example, only they know that access by an external IT service company to the data requires the conclusion of a data processing agreement. It is often also difficult for them to explain to the management that the data protection system will work best when one person implements it, while another checks it. Consequently, the DPO often performs a significant portion of the data controller's responsibilities, even though the GDPR does not provide for this and, in fact, prohibits it.

Cybersecurity training

Information Systems Administrator (ISA)

The role of the ISA arises more from practice than from the legal provisions themselves. The person holding this position supervises the security of personal data processing in information systems. They are akin to an "in-house IT specialist." The main responsibilities of the ISA include ensuring the security of the information system, maintaining system continuity, and efficiently executing backup procedures. Within the structure of personal data systems, due to the necessity of ensuring individual accountability for data oversight, the ISA should report to the DPO. Among the more important tasks of the ISA should be maintaining a report on current events occurring in the information system that directly or indirectly relate to personal data.

Considering that currently most personal data processing operations take place in a digital environment, the ISA is a key function in the organization, enabling the provision of physical data security. A good ISA is a treasure for the organization, as effective protection against data leaks or destruction also safeguards against, for example, business operation disruptions (ransomware) or reputational losses associated with customer data breaches.

Authorized Person for Personal Data Processing

The authorized person will be anyone who processes personal data at the request and under the supervision of the data controller. How to determine who processes personal data? The method is quite simple. If there is any action within the employee's duties that requires the processing of personal data, then we certainly have a person who must be authorized. The same applies in the case of cooperation based on civil law contracts – if the contract implies the necessity of processing personal data, then that person must also be authorized to process them. Of course, before granting authorizations, each person must be familiarized with the internal documentation on personal data protection, that is, the data processing procedures applicable to the specific data controller – covering both formal issues and matters of physical and IT security.

Process Owner

This is not a term derived from data protection regulations, but a concept commonly used in doctrine. The process owner is supposed to be the person responsible for the compliance of processing in the process they oversee, e.g., recruitment or organizing competitions. Not every organization decides to formally designate process owners, as it operates under the erroneous assumption that the DPO is solely responsible for personal data protection. This is an inappropriate approach for two significant reasons. First, the existence of both process owners and the DPO significantly reduces the risk of conflicts of interest (provided that the process owner is assigned appropriate tasks). Second, the process owner has the greatest knowledge of how "their" process functions and what changes are planned within it (e.g., a change of data processor). Without this knowledge, the DPO may not be able to properly perform their tasks as stipulated in the GDPR.

Summary

It is a truism to state that only a maximally precise and transparent division of competencies among the various entities and further – among the individual persons within those entities – will allow the personal data protection system in the organization to function efficiently. However, not everything is directly regulated by provisions. If you want to find out what tasks to assign to the company's management, DPO, ASI, process owners, and authorized persons, contact us – we have prepared ready-made procedures that properly allocate tasks among these participants in the data protection system.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.