Let us welcome our guests – control

03 April 2019

The President of the Polish Data Protection Authority has the right to conduct an inspection of the data controller to verify whether there is a violation of the regulations in this area. Experience indicates that every data controller is most interested in the course of the inspection, the rights that are granted to the inspector, and whether it is possible to prepare for the inspection at all.

Implementation Actions

First and foremost, implementation actions must be taken. It is not advisable to postpone activities related to compliance with the GDPR until the day of receiving a notification of an inspection. Assuming that the inspection will be announced at all, it will still be extremely difficult, if not impossible, to promptly undertake implementation actions in such a way as to complete all necessary obligations by the start date. It is worthwhile to continuously maintain the personal data protection system so that upon receiving a notification of an inspection, only those actions are performed that will allow us to ascertain that all necessary measures have been effectively taken and there are no reasons for concern.

Time to Prepare for the Inspection

Every entity is subject to inspection if it processes personal data—regardless of whether it is an entrepreneur. The Personal Data Protection Act regulates issues related to inspections but does not address the topic of notification about them. It should therefore be inferred that if the inspected entity is an entrepreneur, the provisions of the Act of March 6, 2018 – Entrepreneurs' Law (Journal of Laws of 2018, item 646, as amended) will apply to it. According to these provisions, the inspection must be announced in such a way that its initiation occurs no earlier than 7 days and no later than 30 days from the date of delivery of the notification. This means that in the worst-case scenario, an entrepreneur who is to be inspected will have no less than 7 days to take preparatory actions.

UODO Inspection Scheme
If you do not know what actions the President of the Polish DPA may take in the course of inspection and post-inspection activities against you as a data controller, we explain!
Scheme  

It should not be forgotten that the Entrepreneurs' Law applies only to entrepreneurs—only this category of entities is subject to the regulations described therein, which stipulate the obligation to provide prior notification of an inspection. Therefore, the indicated rules do not apply to associations or foundations.

It must be remembered that in specific cases, inspections of entrepreneurs may also occur without prior notification. However, it is difficult not to notice that according to current practice, the supervisory authority notifies about inspections not only in writing but also often by phone.

Actions After Receiving Notification of Inspection

GDPR Bulletin
Receive a package of free GDPR guides and micro-trainings
Join the ranks of our newsletter readers, receive a free package, and stay informed.
RECEIVE PACKAGE
Upon receiving notification of an inspection, the inspected entity has the opportunity to take verification actions to ensure that all obligations arising from the GDPR have been fulfilled. During the period between the inspection and the receipt of notification about it, it is possible to check the principles of operation of the databases held, as well as to determine whether documentation has been implemented, whether obligations related to employee monitoring and the information obligation have been fulfilled, and whether a risk analysis has been conducted, etc. Assuming that something may be unfulfilled – although it is clear that it should have been completed earlier – we can take corrective actions aimed at achieving a state of legal compliance.

Let us welcome our guests

When the designated day of the inspection arrives, it is advisable for the data controller or a person authorized by them to await the individuals appointed to conduct it. In the event of the absence of one of them, it will be necessary to select a person active in the premises of the enterprise or a summoned witness who is a public official, which will certainly not positively affect the perception of the inspected entity. At this point, it is worth addressing the repeatedly asked question of whether it is possible to deny entry to authorized individuals conducting the inspection and thereby prevent its execution. Such a solution is unacceptable, considering that in the long run it will bring no benefits to the inspected entity, only – inconveniences. It should not be forgotten that the inspectors have the right to enter the land, buildings, premises, and all other rooms. If access is denied, it can be assumed with a probability bordering on certainty that the inspectors will seek assistance from law enforcement officers to gain entry to the premises of the inspected entity.

Importantly, before allowing the commencement of control activities, it is essential to ensure that individuals claiming to be authorized to conduct the inspection indeed have full rights to do so. It is mandatory to verify the named authorization for the inspection and the official identification, particularly whether these documents contain all required information and whether the person presenting the identification is indeed who they claim to be. If there are significant doubts, we may attempt to contact the supervisory authority for verification. Although the regulations do not impose an obligation to verify the content of the identification and the named authorization for the inspection, it should be considered mandatory on the part of the inspected entity.

Thoroughly reviewing the content of the named authorization is recommended for another, extremely important reason. Namely, the named authorization should specify the scope of the inspection, that is, the boundaries within which the inspecting individuals are permitted to operate. They are not allowed to exceed the designated scope of the inspection.

The inspected entity is obliged to provide both the inspectors and individuals authorized to participate in the inspection (e.g., experts) with the means and conditions necessary for the efficient conduct of the inspection. This includes preparing copies or prints of requested documents and information stored on media, devices, or information systems. It is particularly important to note that the inspected entity must provide the conditions necessary for conducting the inspection. Although the data protection law does not specify what this term entails, it can be indicated that individuals authorized to conduct the inspection should be provided with a room that allows for its efficient execution without disruptions. An absolute minimum seems to be a separate room with basic office equipment.

Powers of the Inspector

The inspector has the aforementioned right of access to the premises of the inspected entity from 6:00 AM to 10:00 PM. Additionally, they have a closed catalog of powers, which includes the following actions:

  1. requesting assistance in performing actions from the locally competent Police commander;
  2. access to documents and information related to the scope of the inspection;
  3. conducting inspections of locations, objects, devices, media, information systems, and teleinformatics systems;
  4. requesting written or oral explanations;
  5. interrogating an employee of the inspected entity as a witness;
  6. commissioning the preparation of expert opinions and assessments;
  7. recording the course of the inspection or individual actions using devices that record audio or video, after prior notification of the inspected entity.

The controller is not permitted to perform any actions other than those specified in the regulations. The catalog of actions that may be undertaken during the inspection is closed.

There are no stupid questions regarding GDPR - there are free answers!

Protocol

The inspector establishes the factual state based on the evidence collected during the inspection. The course of the inspection activities is presented in the inspection protocol, which is signed by the inspector. It is then forwarded for signature to the inspected party, who has 7 days to respond to its content. After analyzing the submitted protocol, the inspected party may sign it and return it to the inspector or submit written objections to its content. The inspected party may also choose not to perform any of the indicated actions, i.e., remain completely passive, which constitutes a refusal to sign the protocol, of which the inspector will make a note in the protocol.

Conclusion of the Inspection

The inspection concludes on the day the protocol is signed by the inspected party or – in the case where the inspected party has not signed the protocol and has not submitted objections to its content – on the day a note is made regarding the refusal to sign the inspection protocol. After the completion of the inspection activities and the entire inspection process, the supervisory authority analyzes the collected evidence. If it determines that there may have been a violation of data protection regulations, it promptly initiates administrative proceedings. In such a case, the administrative proceedings constitute a separate stage of actions taken by the supervisory authority, distinct from the inspection. If the supervisory authority does not identify any violations, its activities conclude upon the completion of the inspection.

UODO Inspection Scheme
If you are unsure what actions the President of the Polish DPA may take against you as a data controller during inspection and post-inspection activities, we explain!
Scheme  

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.