Data Sharing Upon Request - How to Comply with GDPR?

19 maja 2021

Data controllers frequently receive requests for the provision of information or documents, often containing personal data. How should the data controller proceed? Should they always provide the requested information or documents? What steps should be taken to avoid getting lost in the maze of regulations and to prevent allegations of violating the provisions of the regulation?

What is data sharing?

Sharing personal data is one of the processing operations defined under Article 4(2) of the GDPR. It constitutes the transfer of personal data outside the data controller's organization. As a result of sharing personal data, meaning the transfer of specific information to another entity, the data controller loses control over the processing of that data and thus does not decide on the manner and purposes of processing the transferred personal data by the entity that received the aforementioned data.

When is data sharing voluntary and when is it mandatory?

In our series of articles on data sharing, we have already indicated when we will be dealing with mandatory data sharing. Now it is time to explain what voluntary or, in other words, request-based data sharing is.

When a request for the sharing of information, documents, or a request for the sharing of data is submitted to the data controller, it is essential to examine it closely first. The data controller is obliged to verify whether the submitted request contains a legal basis that is appropriate for the specific situation and whether it is current.

READ MORE: Data Sharing – We Know When We Can and When We Cannot

It is also necessary to investigate whether, based on the request, there is a possibility to verify the requester and their entitlement to receive the requested data. Furthermore, it should be assessed whether the request contains any other errors and – if necessary – whether there is a need for it to be corrected or supplemented by the requester.

Data sharing at the request of the data subject

GDPR Bulletin
Receive a package of free GDPR guides and micro-trainings
Join the ranks of our newsletter readers, receive a free package, and stay informed.
RECEIVE PACKAGE
Firstly, the aforementioned request for data access may be fulfilled within the framework of the procedure regulated in Article 15(1) of the GDPR (access to data), as well as Article 15(3) of the GDPR (obtaining a copy of the data). The applicant, i.e., the data subject, should clearly specify whether they wish to exercise their right of access to their personal data or their right to obtain a copy of the processed personal data. The above procedure grants data subjects the right to control the processing of their personal data.

Data sharing at the request of another external entity

Another example of data sharing is the transfer of specific information to another entity. In order for the data controller to transfer information or documents containing personal data to another entity, they must have specific legal grounds for doing so. The basis for the data controller to share personal data may be both a contract and provisions of generally applicable law. In this case, at the moment of data sharing, the data controller no longer exercises control over the shared personal data, and this control is assumed by the entity that received the data.

Example - Article 155(3) of the Real Estate Management Act
The relevant authorities, agencies referred to in paragraph 1 point 6a, housing cooperatives, courts, and tax offices are obliged to provide property appraisers with the registers and documents referred to in paragraph 1, including enabling the preparation of copies of documents in any form.

Referring to the specified legal provision, the property appraiser may submit a request to the relevant authority for access to the registers and documents, often containing personal data.

DPO Function - it transfers well

Request without legal grounds – what to do?

It is also worth mentioning that a request for data access submitted to the data controller does not always have a specified legal basis. What should the controller do in such a situation? First and foremost, the request should be carefully examined. If the absence of a specified legal basis is due to an error or oversight, it would be appropriate to ask the requester to supplement or correct the request. However, if there is no legal provision that the requester could invoke, an assessment of the requester's entitlement to receive personal data should be conducted. In this case, it is the role of the controller to consider whether there is a legitimate interest or a justified reason for providing such personal data to the requester.

How to comply with GDPR?

READ MORE: When does the data controller have an obligation to provide personal data?

To avoid getting lost in the maze of regulations and to prevent accusations of violating GDPR provisions, the data controller should primarily adhere to the applicable principles arising from GDPR regulations. It is therefore advisable to refer to Article 5 of GDPR and ensure that when providing personal data, accountability is maintained, the appropriate legal basis or legitimate interest defining the purpose and the adequacy of that purpose is indicated, and that personal data is provided in compliance with the principle of data minimization. A good practice for every data controller would therefore be to establish appropriate procedures governing the handling of requests for data access.

Do you need support in creating such procedures? Schedule a meeting with Cezary Lutyński – our data protection advisor. You will receive the assistance you need.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.