Application of GDPR - advice and document templates

25 May 2018

A year before the General Data Protection Regulation came into effect – as indicated by a study conducted by the Knowledge is Security Foundation titled "What Do We Know About Data Protection" – only half of the management staff were aware of the new obligations imposed on their companies by the GDPR. Has anything changed nearly a year after the GDPR came into force?

A year before the General Data Protection Regulation (GDPR) came into effect – as indicated by a study conducted by the Knowledge is Security Foundation titled “What Do We Know About Data Protection” – only half of the management staff were aware of the new obligations imposed on their companies by the GDPR.

Has anything changed nearly a year after the GDPR came into effect?

GDPR Bulletin
Receive a package of free GDPR guides and micro-trainings
Join the ranks of our newsletter readers, receive a free package, and stay informed.
RECEIVE PACKAGE
Certainly, the awareness of entrepreneurs has significantly increased, which we observe while collaborating with many companies and conducting numerous trainings and courses. However, many entities have still not adapted their operations to the requirements of the regulation, as evidenced by their websites, where we can still find clauses that are inconsistent with the content of the regulation. 

The following text refers directly to the General Data Protection Regulation (GDPR). We provide the content of the regulation free of charge in the publication titled “GDPR NAVIGATOR,” which you can find at this link. The publication contains the updated text of the GDPR itself (correction issued by the European Commission), the content of the Act of May 10, 2018, on the protection of personal data, a list of the most important guidelines from the Article 29 Working Party and the European Data Protection Board, along with links for downloading them, interactive connections between the GDPR and the Personal Data Protection Act, as well as interactive connections between the GDPR and specific guidelines that explain how to apply them.

Information Obligation

Before the implementation of the GDPR and during the recent months of the regulation's application, we have been inundated with emails in which companies inform us about their compliance with the new GDPR provisions. In particular, privacy policies, website regulations, privacy notices, and consent clauses required updates.

What information should be included in the information obligation?

At first glance, it is noticeable that under the currently applicable regulations, the amount of information that must be provided to an individual has significantly increased. The information obligation should include, among other things:

  • the data controller's details,
  • contact information for the Data Protection Officer (if appointed),
  • the purpose of processing,
  • the legal basis for processing,
  • the duration for which the data will be processed,
  • information about the rights of the individual in relation to the processing of their personal data.

For all entrepreneurs who have not yet adapted the content of their privacy notices to the requirements of the GDPR, we provide a sample content of the information obligation.

Important
The privacy notice should be made available to clients for review at the time of collecting their data. In the case of micro-enterprises (such as hairdressers, cobblers, etc.), it is best to simply place it in a visible location on the counter. On the other hand, online stores can include it as a link on the order submission screen and additionally, to exercise due diligence, send it via email along with the order confirmation message.

Records of Processing Activities and Records of Categories of Processing Activities

FREE

Data Protection Documentation – What It Should Include and What to Do to Make It Work

Watch the webinar

Under the GDPR, there is an obligation to maintain records of processing activities and records of categories of processing activities. In the initial months of the regulation's application, these documents caused concern among entrepreneurs; however, most companies have now managed to comply with this requirement. A sample record of processing activities, along with guidelines and explanations regarding the obligation to register processing activities and categories of processing activities specified in Article 30(1) and (2) of the GDPR, available on the Polish DPA website, has proven helpful in this regard. We emphasize that, according to the GDPR, almost every data controller is required to maintain records of processing activities. This document should include, among other things:

  • the name and surname or the name and contact details of the data controller,
  • the purposes of data processing,
  • description of the categories of individuals whose data is being processed and the categories of personal data,
  • description of technical and organizational security measures.

Of course, these are just some of the pieces of information that should be included in the records, a detailed list can be found in Article 30(1) of the GDPR.

In terms of the records of processing activities, the data controller is obliged to maintain the relevant records when acting as a data processor in any personal data processing process within their organization. The records of processing activities contain fewer mandatory pieces of information than the records maintained by the data controller. Article 30(2) of the GDPR lists all the information that must be included in the relevant records.

Records of processing activities maintained by the data controller is one of the first documents that the Polish DPA may request during an inspection, as this document allows for the best understanding of the personal data processing processes within the organization, and therefore, this obligation should not be underestimated.

GDPR. Support is useful!

Data Processing Agreement

Nowadays, almost everyone uses outsourcing services – we are increasingly transferring personal data externally, for example: payroll and HR services, hosting, website management, marketing. The transfer of data "outside" the organization, in order to remain compliant with the GDPR, must occur based on a contract or another legal instrument. Article 28 of the GDPR specifies the mandatory elements that should be included in the data processing agreement.

The biggest challenge and novelty for the data controller is the obligation to verify their supplier. The data controller should only use the services of those entities that provide appropriate technical and organizational measures to secure the data being shared. The regulation does not specify how the data controller should verify the entity to whom they entrust the processing of their personal data, so the data controller must independently choose the most effective method from their perspective.

The issue of the data processor's compliance with the GDPR and methods for its verification has been discussed in more detail here. At the indicated link, you will also find a checklist for data processors prepared by us, which serves as an alternative to conducting a data processor audit.

What elements should a data processing agreement contain?

  • subject matter of processing,
  • duration of processing,
  • nature and purpose of processing,
  • type of personal data,
  • category of data subjects,
  • obligations and rights of the data controller,
  • obligations of the data processor.

When should a data processing agreement be signed? Each time personal data of our employees or clients is shared, for example, when using an external occupational health and safety service, hosting, or accounting firm.

Template of a data processing agreement compliant with GDPR
It will regulate key issues within the relationship between the data controller and the data processor.
Download  

Consent Clauses

Practical DPO Course
Practical DPO Course
will confirm your high competencies
Prepare to perform the role of a Data Protection Officer. We invite you!
CHOOSE A DATE
Consent is one of the bases for processing personal data, as stated in Article 6(1)(a) of the GDPR. It seems that this basis has caused the most problems for data controllers, who have begun to misuse it in certain ways. This has led to confusion and resulted in data controllers obtaining consent "for everything," without considering whether, in a specific case, personal data is being processed based on another legal basis.

This is particularly evident in marketing activities, where entrepreneurs obtain consent from their clients for the processing of personal data for the purpose of sending commercial information electronically. Companies reaching out to their clients with information about new products constitutes direct marketing, which is a legitimate interest of the data controller as referred to in Article 6(1)(f) of the GDPR. This is reflected in Recital 47 of the GDPR preamble.

Important
However, it should be noted that when directing electronic direct marketing to their clients, it is necessary to obtain consent for the communication channel, which arises from specific laws such as the Telecommunications Law and the Act on Providing Services by Electronic Means. 

Another erroneous practice often encountered among entrepreneurs is including a requirement in job advertisements for written consent to process data for recruitment purposes in application documents (CV, cover letter). According to the position of the Polish DPA, there is no need for job candidates to include written consent for the processing of personal data in application documents, as the employer processes candidates' personal data based on Article 6(1)(b) of the GDPR, i.e., for the purpose of taking actions at the request of the data subject prior to entering into a contract. More on the issue of consent in the recruitment process can be found in the Guide for Employers published by the Polish DPA.

DPO – to appoint or not to appoint?

All public authorities must appoint a Data Protection Officer, except for courts in the exercise of their judicial functions. What about the private sector? Recital 97 of the preamble states that a DPO should be appointed by any data controller whose core activities consist of processing operations that require regular and systematic monitoring of data subjects on a large scale or if the core activities of the data controller or data processor consist of processing on a large scale special categories of personal data and personal data relating to criminal convictions and offenses. The interpretation of these concepts, particularly the term "large scale," may pose challenges. Guidance in this regard is provided by the Article 29 Working Party (WP 243) guidelines concerning Data Protection Officers.

Even if the data controller is not obligated to appoint a Data Protection Officer (DPO) under the GDPR, it is worth considering their designation. The DPO's task is primarily to oversee compliance with personal data protection principles within the organization, which will undoubtedly positively impact data processing security and contribute to building the organization's credibility. The DPO will also serve as a point of contact for individuals whose data is processed by the data controller, as well as for the supervisory authority, namely the President of the Polish Data Protection Authority, and is required to cooperate with them in accordance with clear requirements.

In light of the above, entrepreneurs are increasingly opting to appoint a DPO within their organization. The DPO may be an employee of the data controller or a company or individual from outside the organization. We discuss the advantages and disadvantages of each of these solutions in more detail here.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.