In the GDPR cycle we will present the most important data protection records. Today we are looking at what conditions must be met to process data legally.
An entity wishing to process personal data must ensure that any of the personal data protection conditions specified in the Act legalising the processing are established. The Act lists two closed catalogues of premises – one indicating situations where the processing of so-called ordinary personal data and the other concerning sensitive personal data is allowed. As a general rule, the processing of personal data shall be permitted only if at least one of the following conditions exists: [1]:
the data subject has agreed to the processing of his data
consent must be express and knowingly expressed, it must not be up to or implied by a statement of will of another content (agreement is not only necessary for the deletion of personal data); - processing is carried out on the basis of a legal provision laying down powers or obligations;
This is necessary for the implementation of the contract to which the data subject is a party or for action before the conclusion of the contract at the request of the data subject;
This is necessary for the performance of the legitimate tasks performed for the public good;
This is necessary in order to meet the legitimate objectives pursued by 6 data controllers or data recipients (legally justified objectives include direct marketing of the data controller's own products or services and claims for the conduct of business) and processing does not affect the rights and freedoms of the data subject.
Processing of sensitive data
The grounds for processing sensitive personal data are more stringent than the conditions for processing other categories of personal data. As a general rule, the processing of sensitive personal data is prohibited and only permitted under the following circumstances.[2]:
- if the data subject has agreed (unless the data relating to him or her is deleted)
- Whereas it should be borne in mind that, in the case of sensitive data, compliance must be given in writing;
- a provision of law (a law other than the Personal Data Protection Act) allows the processing of data without the consent of the data subject, and creates additional full guarantees for the protection of such personal data;
- the processing of data is necessary to protect the vital interests of the data subject or of another person (if the data subject is not physically or legally able to consent - pending the establishment of a legal guardian or curator);
This is necessary for carrying out the statutory tasks of churches and religious associations, associations, foundations or other non-profit organizations or institutions with political, scientific, religious, philosophical or union objectives
Whereas it is only possible to base the processing on this condition in relation to the members of those organisations or institutions or persons who maintain permanent contacts with them in connection with their activities; whereas it is also necessary to provide full guarantees for the protection of the personal data processed;
the processing relates to personal data which are necessary to assert rights before a court;
the processing is necessary to carry out the tasks of the controller of personal data relating to the employment of employees and other persons, and the scope of the data processed is specified in the Act; - the processing is carried out to protect the state of health, provide medical services or treat patients by professionals or provide other medical services, manage the provision of medical services and complete guarantees are created to protect personal data;
the processing relates to personal data which have been made public by the data subject;
Whereas this is necessary for the conduct of scientific studies, including the preparation of a trial required to obtain a degree in higher education or a degree in science;
the publication of the results of scientific research must not be carried out in such a way as to identify persons whose data has been processed (necessary anonymisation of results);
the processing of data is carried out by the party in order to exercise the rights and obligations arising from a decision given in judicial or administrative proceedings.
Information obligation related to the collection of data
Each personal data controller, regardless of the way in which he acquired personal data (whether he obtained it from the data subject or from another entity - e.g. through the purchase of the database), is obliged to inform the data subject that he processes his data. In the case of the collection of personal data from the person concerned, the controller of the personal data shall be required to inform him of the[3]:
- the address of its registered office and full name (where the controller of the data is a natural person, it shall inform the controller of its place of residence and of its name);
- the purpose of collecting personal data;
- expected recipients or categories of recipients of data;
- the right to access and improve the content of their data;
- voluntary or mandatory information (if any, on its legal basis).
In the case of the collection of personal data not from the person concerned, the controller of personal data shall be required to inform that person, immediately after the recording of the data collected, of the[4]:
- the address of its registered office and full name (where the controller of the data is a natural person, it shall inform the controller of its place of residence and of its name);
- the purpose of data collection;
- the scope of data collection;
- recipients or categories of recipients of data;
- the data source;
- the right to access and improve the content of their data;
- the right to lodge a written, substantiated request to stop processing of personal data due to its particular situation;
- the right to object to the processing of personal data when the controller intends to process it for marketing purposes or to transfer its personal data to another controller.
The obligation to exercise special care in the processing of data in order to protect the interests of data subjects. The data controller shall ensure that the processing of personal data by him complies with the following rules.[5]:
legality - processing is based on one of the grounds set out in the Act on the protection of personal data, is carried out in accordance with the principles laid down in this Act and is also compatible with 5 provisions of other laws (e.g. the processing of employees' personal data must comply not only with the Personal Data Protection Act but also with the regulations contained in the Labour Code);
propriety - correct implementation of this principle means collecting personal data for clearly identified, legitimate purposes;
binding the purpose of processing - it is prohibited to process personal data incompatible with the purpose for which they were collected;
substantive correctness - it is the administrator's duty to ensure that the personal data processed by him are true and up to date;
adequacy - the extent of the personal data processed must be adequate to the purpose for which they are processed; the processing of personal data is prohibited to a greater extent than is necessary for the purpose of processing;
limited processing time - personal data may only be processed for the time necessary to achieve the purpose of processing; when this purpose expires, it is necessary to delete data.
Processing of personal data contrary to the provisions of the Personal Data Protection Act involves criminal liability, for[6]:
- processing of personal data by an unauthorised person;
- making the data available to or allowing access to unauthorised persons;
- breach of the obligation to protect personal data;
- failure to report a set of personal data to a register kept by the General Inspector for Personal Data Protection;
- failure to comply with the information obligations of the data subject;
Obstruction of the performance of the inspection activity by inspectors of the Office of the General Inspector for Personal Data Protection. In any case, the controller of personal data shall be responsible, in some cases (e.g. for the non-security of personal data) also for the processor.
[1] T.Banyś, J.Łuchak, Personal data protection in practice. How to avoid errors and their legal consequences, PRESSCOM, Wrocław 2017.
[2] Ibid.
[3] Kołodziej M., Kluska M., Wanio G., Vademecum of Information Security Administrator, ed. Kołodziej M., C. H. Beck, Warsaw 2016.
[4] Ibid.
[5] J. Kamińska-Kasjaniak, Methodology of the Information Security Administrator, JDS Consulting, Warsaw 2016.
[6] T.Banyś, op.cit.