Back to insights
Legal updates

All about GDPR. Part 2. – legal basis for the protection of personal data

In this GDPR series We will present the most important data protection records.

In this GDPR series We will present the most important data protection records.

In the second part We are looking at the law that governs it at national and EU level.

In this GDPR series We will present the most important data protection records. In the second part We are looking at the law that governs it at national and EU level.

In many aspects of everyday life, information is collected and used on individuals – called ‘personal data’. A person grants personal data when, for example, applying for a library card, enrolls in a gym, opens a bank account, etc. Personal data may be collected directly from persons or from an existing database.

This data may then be used for other purposes and/or may be exchanged with other parties. Personal data may be any data identifying the person, such as his name, telephone number or photo.

Progress in computer technology, with the development of new telecommunications networks, contributes to the freer flow of personal data across borders. As a result, data on citizens one Member States are sometimes processed in other EU Member States. It was therefore necessary to introduce rules governing data transfer.

In this context, national data protection rules require good data management practices by data processors, called "data controllers". The provisions include an obligation to process data in a fair and secure manner and to use data for clearly defined and justified purposes.

In addition, national legislation provides for a number of rights for individuals, such as the right to information about the time and the reason for the processing of personal data, the right to access data and, if necessary, the right to modify or delete data.

The provisions include an obligation to process data in a fair and secure manner and to use data for clearly defined and justified purposes. In addition, national legislation provides for a number of rights for individuals, such as: the right to information about the time and the reason for the processing of personal data, the right to access data and, if necessary, the right to modify or delete data

Some Member States do not have rules on data protection. For this reason, it was necessary to act at European level, which took the form of intra-European directives (EC).

Protection of personal data in the Basic Act and in national laws and regulations

Personal data protection issues have been regulated in Polish law for the time being first year 1997, under Article 51 Constitution of the Republic of Poland dated 2 April 1997 and – comprehensively – in Act dated 29 August 1997 on the protection of personal data. In addition to the basic Data Protection Act, in the Polish legal order there are also regulations (implementing acts for the abovementioned Act), the most important of which from the perspective of the entrepreneur processing personal data is the Regulation of the Minister of Internal Affairs and Administration dated 29 April 2004 on the documentation of the processing of personal data and the technical and organisational conditions to be met by information equipment and systems for the processing of personal data, Regulation of the Minister of the Interior and Administration dated 11 December 2008 on the model for filing the data set for registration to the General Inspector for Personal Data Protection and the Regulation of the Minister of Administration and Digitisation dated 10 December 2014 on templates for the appointment and cancellation of the information security administrator [1].

Personal data protection standards are included in the Constitution of the Republic of Poland under Article 47, who says that “Everybody has the right to the legal protection of private, family life, honor and good name and to decide on their personal life”.

Article 51(1) „No one may be required to disclose information concerning him or her (section 2). Public authorities cannot obtain, collect and make available information on citizens other than necessary in a democratic legal state. Each citizen has the right to access the official dataset documents relating to him.

The limitation of that right may specify the law. Everyone has the right to request rectification and the removal of false, incomplete or collected information in a manner contrary to the law. The rules and procedures for collecting and making available information are laid down in the Act [2].

An important event for Poland was the edition 29 August 1997 Personal Data Protection Act. These were completely unknown regulations in our legal system. A collision with something new and quite complicated has caused a lot of trouble for lawyers to analyze this matter today. Current Act dated 22 January 2004 amending the Act on the Protection of Personal Data and the Act on the remuneration of persons occupying managerial state positions.

Then on 27 April 2016 the GDPR Regulation was adopted, which entered into force 25 May 2018, replacing the Act with 1997. The Regulation was amended twice, including the last amendment entered into force 2019 [3].

EU Directives on the protection of personal data

one of the first and at the same time the fundamental legal acts defending human rights and freedoms is the European Convention for the Protection of Human Rights and Fundamental Freedoms (European Convention on Human Rights) with 1950.

It sets out and regulates the State's relationship to the protection of rights, the units of rights which it enjoys, and the measures which serve to enforce those rights.

On 28 January 1981 a document was issued by the Council of Europe in Strasbourg: Convention No 108 on the protection of individuals with regard to the automatic processing of personal data. This. one the most important acts of international law and the main aspects of personal data protection.

They are considered to be the most important documents of international law. On 23 September 1980 Guidelines on Privacy Protection and Transfer of Personal Data between Countries were issued. They shall be counted alongside the abovementioned Convention No.

108 Council of Europe to the most important documents of international law of recent time [4].

At European level, the protection of personal data has also been regulated in Directive 95/46 dated 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data.

It was valid until the day 25 May 2018, the date on which its provisions ceased to apply (according to Regulation (EU) 2016/679 dated 27 April 2016) and were replaced by a modernized regulation, adapted to the modern reality of data processing.

Since the entry into force of the Lisbon Treaty, the principle of the protection of personal data of every individual is also enshrined in a regulation of fundamental importance for the Union, namely the Treaty on the Functioning of the European Union - its Article 16 provides that ‘Every person has the right to the protection of personal data relating to him or her’ [5].

The rules for the transfer of personal data outside Poland vary depending on whether the country of the recipient belongs to the European Economic Area or not.

Transfer of personal data to the European Economic Area States It is now up to the European Economic Area to 31 The countries are European Union countries and Iceland, Norway and Liechtenstein.

The European Economic Area applies the principle of the free movement of personal data, which is why the transfer of personal data to its countries is carried out on the same terms as the transfer of data to entities established in Poland – it is necessary to apply the requirements of the Polish Data Protection Act.

Transmission of data to the State third – not belonging to the European Economic Area Transfer of personal data to the State third may occur if the target State ensures an adequate level of protection of personal data within its territory.

The relevant level of protection of personal data shall be assessed taking into account all circumstances relating to the transfer operation, in particular taking into account the nature of the data, the purpose and duration of the proposed data processing operations, the country of origin and the country of final destination of the data and the legal provisions in force in the country concerned third and the safety measures and professional rules applied in that country [6].

Country third do not need to give such protection guarantees if the conditions laid down in the Act are met, e.g. the data subject has given written consent to it or has obtained the consent of the General Inspector of Personal Data (the consent of the General Inspector is not required if the data controller provides adequate safeguards for the protection of privacy and the rights and freedoms of the data subject by means of standard contractual clauses for the protection of personal data approved by the European Commission or by rules or policies for the protection of personal data approved by the General Inspector of Personal Data) [7].

In order to eliminate obstacles to the free movement of data without reducing the protection of personal data, it has been developed Directive 95/46 (Data Protection Directive) harmonising national provisions in this area. As a result, the personal data of all citizens have identical protection throughout the Union. Until 24 October 1998 15 EU Member States had to bring national rules into line with the Directive[8].

The Directive is a European legal act addressed to the Member States. Once adopted at European level, each Member State must ensure its effective application in its legal system. The Directive defines the final result. It is up to individual Member States to decide on the form and methods of its application.

In principle, the Directive becomes effective through national implementing measures (national regulations). However, it is possible that even if a Member State has not implemented it, some of its provisions may have a direct effect.

This means that if a directive grants direct rights to natural persons, they may rely on such a directive in court without having to wait for national legislation to implement it.

Furthermore, if a natural person feels that he or she has suffered damage as a result of the failure of the national authorities to implement the Directive correctly, he or she may be entitled to claim compensation. These damages can only be obtained in national courts.

The Data Protection Directive applies to ‘any operation or set of operations carried out on personal data’, called ‘data processing’. Operations include the collection of personal data, their storage, disclosure, etc. The Directive deals with automatically processed data (e.g.

a computer database of consumers) and data which are part of or intended to be part of non-automatic ‘data sets’ where they are available on the basis of certain criteria (e.g. traditional paper files such as customer information files arranged in alphabetical order by names).

The Data Protection Directive does not apply to data processed solely for personal or household purposes (e.g. electronic diary or file with family and friends information).

Moreover, it does not concern areas such as public security, defence or criminal law enforcement which do not fall within the competence of the EC and remain the responsibility of the Member States. In these areas, national rules generally provide protection for citizens.

Moreover, there is a separate directive – Directive 2002/58, which specifically protects data privacy in the electronic communications sector.

The Directive contains provisions on network and service security, confidentiality of communication, access to information stored in terminal devices, processing traffic and location data, identification of incoming calls, public subscription lists and unsolicited commercial communications.

The Directive provides that Member States must ensure the confidentiality of communication through national rules. This means that any listening, recording, storing or other kind of acquisition of supervision of the message by unauthorised persons is unlawful.

If you are offered to display the identification of incoming calls, you must be able not to enter the service or block the display of your number while performing outgoing calls. On the other hand, users of this service must be able to reject incoming calls from those who have a blocked identification of outgoing calls.

In addition, the Directive stipulates that, in the event that there are directory subscribers issued in the form of print or in electronic form, natural persons have the right to be disregarded, in principle free of charge, in such lists. [9].

[1] P.Jatkiewicz, Personal Data Protection Theory and Practice, Polish Information Society, Warsaw 2015.

[2] Constitution of the Republic of Poland (Journal of Laws of 1997, item 483.), Article 47, Article 51.

[3] Regulation (EU) 2016/679 dn. 27 April 2016

[4] P.Fajgielski, Human rights policy on the example of protection of personal data (Wroclaw, 18–19 June 1999),[in:] State and Law of 1999 No 9.

[5] A.Dmochowska, op-cit.

[6] M.Krzysztofek, Personal data protection in the European Union. Transfer of personal data from the European Union in the current and upcoming legal state [in:] Personal data protection in the European Union, Wolters Kluwer, Warsaw 2014.

[7] Ibid.

[8] M.Krzysztofek, op-cit.

[9] M.Jagielski, Right to the protection of personal data. European standards, Wolters Kluwers, 2010, p.190-198.

Continue exploring our insights.

View all insights
Legal updates

Revolutionary Reform of the PiP

12 March 2026 The Senate accepted without amendment the amendment of the Act on State Labour Inspection.

Legal updates

Property Heritage: a simpler way to enter a perpetual book

From 17 March 2026 new rules are in force which significantly simplify the procedure for disclosing property rights acquired through inheritance or recovery.

Legal updates

Deformalisation of the cassation complaint

On 5 March 2026 a very important composition resolution has been passed 7 Supreme Court judges.