Back to insights
Legal updates

All about GDPR. Part 4. Data protection measures

In the GDPR cycle we will present the most important data protection records.

In the GDPR cycle we will present the most important data protection records.

Today we learn about the resources that are used to collect, organize and store data.

In the GDPR cycle we will present the most important data protection records. Today we learn about the resources that are used to collect, organize and store data.

Technical and organisational measures

The controller and the processor shall ensure the security of the processing of personal data by implementing appropriate technical and organisational measures, before and during processing. Technical measures may be of a material nature relating to the premises where the data are processed and to the IT nature in the case of processing through information systems. Organisational measures may concern internal legal standards and security policies.

They are free to choose technical and organisational measures, while bearing responsibility for the choice made. When choosing, those operators should take into account both the processing conditions and the types of processing risks.

The processing conditions affecting the choice of measures include: the degree of security with regard to violations of the rights and freedoms of individuals, the state of technical knowledge, the cost of implementing those measures, as well as the characteristics of the processing, such as its nature, scope, context and objectives.

The risk of choice is accidental or unlawful destruction, loss, modification, unauthorised disclosure or unauthorised access to the personal data processed.

Technical measures taken to ensure adequate safeguards that affect the processing of data:[1]

access to the computer operating system in which personal data are processed is protected by the authentication process using the user ID and password;

change of passwords at least every 30 days;

the use of antivirus programmes and other regularly updated security tools;

Firewall system;

screen savers;

automatic system access block for longer user inactivity;

systematic backup of data sets processed in information systems;

the application of individual login passwords to individual programmes;

use the correct password construction

The organisational measures taken to create appropriate safeguards that affect the processing of data are as follows:[2]

The processing of personal data may only take place in the performance of business tasks. The scope of the powers derives from these tasks.

Each administrative staff member shall have a computer position designated for himself, reducing the risk of personal data integrity being breached.

Workers working on one computer station have separate user accounts for the computer.

Identification of the work area

Operating procedures and instructions (internal and external transport, treatment of waste and waste equipment, storage of biological material, sampling)

Position manuals (equipment support)

Emergency instructions taking into account all possible exposure pathways ( spillage, leakage, spray, cut)

Clean Desk Policy

Protection measures under programme tools and databases

Measures to protect programming tools

Only authorised users have access to electronic systems.

Authorisation and authentication of users shall comply with the Regulation.

Cryptographic protection of data transmitted by electronic means is used.

Solutions are used to protect IT systems against the effects of power failure.

Anti-virus programs are used to protect against malware.

In order to protect against unauthorised access to personal data by electronic means, the firewall system is used.

All personal data is processed in RAID disk arrays e.g. 1, 5, 10 against the effects of storage failure.

In the event of a failure of a disk containing personal data, the data shall be erased by means of data-masking programs before it is transmitted for repair. If it is impossible to repair the disk, it is physically destroyed after logical data removal. In the scope not regulated in this document, the provisions of the Act, Regulations and other provisions of law apply.

Personal data sets are processed using a desktop and portable computer . The computer for the processing of personal data is connected to the local computer network. UPS devices are used, and a separate power grid is used to protect the IT system for the processing of personal data against the effects of power failure.

Access to personal data sets that are processed at a separate computer station and a portable computer was protected from unauthorized activation using a password. Access to the computer operating system in which personal data is processed is protected by the authentication process using the user ID and password.

Measures to prevent unauthorized copies of personal data processed using information systems. Systemic mechanisms force periodic change of passwords.

Data cryptographic protection measures for personal data transmitted by teletransmission. Access to teletransmission means shall be secured by means of authentication mechanisms. I use protective measures against harmful software such as worms, viruses, Trojan horses, rootkits. Firewall can be used to protect access to a computer network.

Equipment, IT and telecommunications infrastructure

The question of equipment, IT and telecommunications infrastructure is, in fact, all the systemic actions which have been implemented, for example in a particular undertaking, in order to protect data from being taken over by individuals through them. third. A number of different procedures should therefore be met. The data controller must inform the data subjects what measures he has used to ensure their safe storage.

first the step is to identify the computer network to which computers are connected, which can process personal data. It is therefore important to determine whether the equipment is connected to a local area network in a specific area, such as an office.

The administrator shall inform the recipients of whether or not the computers are connected to the local computer network[3]. Another information is where personal data are processed. It could be a separate computer station, but it could also be portable.

Both of these options nevertheless require security in the form of a password, which is intended to prevent unauthorized launch.

In the event of a power failure, it is important that there are a number of security features that are able to protect the data from its effects. For example, it can be a separate power grid that will protect the information system for the processing of personal data, or an emergency power supply (other than a UPS - uninterruptible power supply), which has a battery to which it switches when there are problems with the supply of electricity[4].

A disk memory failure is also possible, so it is also necessary to protect yourself against this possibility and to use a disk matrix to protect data in case of problems. Backups are therefore created, i.e. backups of data. This solution, according to the GDPR, is not required, but recommended. It is very important that, after storage or after completion of the target, these data should be permanently deleted. The administrator should prepare a backup procedure[5].

To access the operating system of the computer processing personal data, a user authentication system should be introduced. This uses the user ID and password, the change of which should be periodically forced by system mechanisms. In addition, there are also some guidelines for entering a new password, for example, it cannot be the same as the username, it must have one big point (e) hand, one small point (e) hand, one digit and one Special sign.

Each person should be given appropriate rights, but there is a danger of mishandling the password. This is notable, for example, in saving it in the vicinity of the computer, or when passing it on to other employees in the event of absence.

That is why it is so important to change the passwords regularly, for example during the quarterly period. Two-stage password authentication is also very popular, i.e. when logging in or changing the password, you should confirm the action data on another platform or using another device[6].

Also, the teletransmission through which personal data is transmitted should be protected by authentication mechanisms and encrypted. All files should be password-protected, which the recipient should receive some additional path – i.e. not via e-mail, but by telephone, token or SMS.

As computers connected to the local network can connect to the Internet, there is always a risk of downloading accidentally harmful software such as worms, viruses, Trojan horses, rootkits, etc. It is therefore appropriate to inform the recipients of the application of security measures, such as antivirus at each workstation.

The most risky thing is to ship data through USB ports, business e-mail and private employee mail accounts. This is sometimes associated with the aforementioned harmful software, but also by creating unauthorized copies. Therefore, the administrator should take appropriate measures to block such activities and thus reduce the likelihood of such data leaks[7].

To prevent data from accessing the public network, it is necessary to create a firewall (Firewall). This is even defined by GDPR: The IT system for the processing of personal data is protected against threats from the public network by the implementation of physical or logical safeguards to protect against unauthorised access. There are many types of firewalls, but these can be, for example, filter dams, network address translation, i.e. IP change, proxy firewalls.

Physical data protection measures

After discussing protection measures under tools and databases, hardware, IT and telecommunications, the scope of the data protection measures should be explored. They involve physically preventing unauthorised persons from having data in the event of theft, vandalism, terrorist attack, or protecting documents from random situations such as fire or flood.

first The issue to be addressed when introducing such physical protection measures is to define the area of storage and to introduce appropriate measures proportionate to the required level of protection. There are several levels of confidentiality of stored data. They may be reserved, confidential, secret, top secret. Action on their protection is divided into passive safeguards (e.g. fences or safes), as well as active safeguards (e.g. monitoring, burglary systems, firefighting systems)[8].

first the means used may be physical barriers, i.e. any lock that cannot be accessed by persons outside. These include, above all, separate rooms, which are fenced off by walls and doors locked and only authorized persons can enter into possession of it.

In order to prevent document theft, such rooms can be equipped with an anti-burglary alarm system, and windows may have burglar blinds. The previously mentioned door, most often characterized by increased security for burglary. Equally important is the protection of data from random cases, such as fires.

Therefore, they are protected by a fire or free standing or hanging fire extinguisher[9].

Security personnel are another important issue. Namely, they are people properly trained and their actions can sometimes be supervised. If necessary, they shall be authorised to view the stored data.

A third party shall not have access to such premises and, in the absence of staff holding such permits, it shall be the responsibility of the security staff who are required to supervise access to the premises around the clock. They should run an entry and exit control system, for example in a specially prepared notebook.

It is also possible to use an access control system, which is only given to authorised persons. The monitoring system using cameras is also a common means of protecting physical data.

The monitoring records are reviewed by security staff on an ongoing basis, and kept for a limited period on the server, with the possibility of subsequent inspection, most often after the specified date, these records are automatically deleted.

Of course, there are already more technologically developed ways to monitor the identification of authorised persons on an ongoing basis. In addition to entry cards, these may be fingerprint readers, eye iris readers, or even sharing your own DNA sample.

However, these are not common methods, but used only in places where top secret information is found and are not available to the ordinary mortal.[10].

On the other hand, in places with normal access, the simplest solution is to store personal data in paper form in a metal or non-metal cabinet locked in a key, the same applies to backups of these documents or their archival versions. This method is often used in openspace.

When the usefulness of these data is finished, they should be destroyed mechanically, using a document shredder. They must then be handed over to professional companies dealing with these, and there they are destroyed by specially created industrial shredders.

When it comes to disks, data media or other media, you must first delete their writing. On the other hand, if this is not possible, you need to damage the file properly so that there is no possibility of reading it.

[1] Article 38 Personal Data Protection Act dated 29 August 1997

[2] Regulations of the Minister of the Interior and Administration dated 29 April 2004 (Journal of Laws of 2004, item 1024)

[3] Encyclopedia.com, Local Area Network (LAN), https://www.encyclopedia.com/science-and-technology/computers-and-electrical-engineering/computers-and-computing/local-area-network (access 2 July 2020)

[4] John E. Canavan, Fundamentals of network security, Boston, Artech House, 2001.

[5] K. Ingham, A History and Survey of Network Firewalls, 25 November 2011.

[6] Act dated 27 July 2001 on the protection of databases (Journal of Laws of 2001, item 128.1402, as amended)

[7] Cloud safe and flexible, MITSloan Management Review Poland, no. 1, 12 June 2019, https://mitsmr.pl/a/chmura-bezpieczna-i-elastyczna/DEKgAUQ9 (access 2 July 2020).

[8] Regulation of the Council of Ministers dated 29 May 2012 on the physical security measures used to secure classified information (Journal of Laws of 2010, item 1228).

[9] Regulation of the Minister for Administration and Digitisation dated 11 May 2015 on the mode and manner of performance of tasks to ensure that the data protection rules of the data controller are complied with (Journal of Laws of 2015, item 745).

[10] J.Andress, The basics of information security. Understanding the fundamentals of InfoSec in theory and practice, Syngress, 2011,  p.23-31.

Continue exploring our insights.

View all insights
Legal updates

Revolutionary Reform of the PiP

12 March 2026 The Senate accepted without amendment the amendment of the Act on State Labour Inspection.

Legal updates

Property Heritage: a simpler way to enter a perpetual book

From 17 March 2026 new rules are in force which significantly simplify the procedure for disclosing property rights acquired through inheritance or recovery.

Legal updates

Deformalisation of the cassation complaint

On 5 March 2026 a very important composition resolution has been passed 7 Supreme Court judges.