Back to the insights archive
Legal updates

Inspector of Personal Data (IOD) – new office and its competence

From 25 May Almost every person will have to have a personal data inspector.

From 25 May Almost every person will have to have a personal data inspector.

Such a person can be hired, but an interesting alternative is also outsourcing of this position.

GDPR, that is Regulation (EU) 2016/679 concerning data protection...

From 25 May Almost every person will have to have a personal data inspector. Such a person can be hired, but an interesting alternative is also outsourcing of this position.

GDPR, that is Regulation (EU) 2016/679 concerning the protection of personal data which has entered into force 24 May 2016, and will be applied and enforced from 25 May This year, it introduces significant changes to the personal data protection sector.

On the one hand, increase the rights of persons whose data are processed, second and to the controller in this data imposes new obligations. one of these is the introduction of the function of Data Protection Officer (IOD, also called DPO from Data protection officer).

Its task, like the current data security administrator (ABI), will be to act in the interests of data protection, public administration and private sector.

Obligation and not entitlement

As the General Data Protection Officer recalls, the tasks of the Data Protection Officer in the general Data Protection Regulation have been formulated in a general manner, without indicating the mode and time limit for their implementation.

This is an important difference in relation to what is currently foreseen by the Act on the Protection of Personal Data and its implementing acts in relation to ABI's tasks. In addition, as GIODO recalls, the new legislation significantly strengthens the role and position of the IOD.

one the most important demonstration is that the appointment of a data protection officer will in many cases become a duty and not, as yet, the right of the data controller.

Who can and who must appoint a Data Protection Officer?

The Regulation provides for the compulsory appointment of an inspector when processing is carried out by a public authority or body, with the exception of a court in the exercise of its judicial powers, where the main activities of the controller or processor consist of processing operations which, due to their nature, scope or objectives, require regular and systematic monitoring of persons whose data relate to a large scale, and where the main activities of the controller or processor consist in processing on a large scale of specific categories of personal data. In other cases, the appointment of the inspector will be optional.

Tasks of the inspector

The Data Protection Officer will need to demonstrate the theoretical and practical knowledge of the general Data Protection Regulation and the provision of national data-processing rules.

Its duties will include, inter alia, informing and advising the controller, processor and employee who processes personal data on their obligations under the Regulation and other provisions in the Union or Member States on data protection.

The inspector will also be responsible for monitoring compliance with the Regulation and other provisions on data protection and the policies of the controller or processor in the field of personal data protection. In this respect, he will be the one who will share the responsibilities of and train staff, as well as audits.

The IOD will also have to cooperate with the supervisory authority and act as a contact point for the supervisory authority on processing issues. It will also act as a contact point for those concerned by the data, in all matters relating to the processing of their personal data and to the exercise of their rights under the Regulation.

Its task will also be to keep a register of activities or a register of categories of activities. More about the tasks of the personal data inspector: abi.giodo.gov.pl

Form of employment of IOD

According to Article 37(6) The GDPR may be extended to the controller or processor, as well as to a non-member of the staff member. It will therefore be possible to continue to act as a data protection inspector in the outsourcing model, under a service contract.

Although the function of ABI is currently performed by persons who are employees of the controller in the data as well as persons who have entered into a civil agreement with the data controller, the Personal Data Protection Act does not contain a provision specifically relating to this issue.

However, it should be borne in mind that the person performing the IOD function under the service contract must comply with all the requirements imposed by the GDPR, e.g.

requirements concerning the avoidance of conflicts of interest, guarantees of independence, ease of contact with him, proper and timely inclusion of him in all matters concerning the protection of personal data. The new provision in the Regulation is the possibility of establishing one Data protection officer for several entities

Author:

Wojciech Ośka

Managing Partner responsible for the Department of Marketing and Training and Outsourcing of Personnel and Pay. From 2013 related to the firm Russell Bedford Poland. At Russell Bedford responsible for shaping and developing training and outsourcing services, company marketing and media contact.

In years 2005 – 2013 during cooperation with BDO participated in creating an image, one of the leading audit and consulting companies, in the field of the development of training services and the image of the whole group, acting, among others, as head of sales department and as the person responsible for designing and implementing promotional materials, including a web network of websites.

He has extensive, long-standing professional experience in sales advice and marketing. He participated in the implementation of numerous IT projects at the interface between computer science and widely understood finances. Author of publications on training and human resources training.

He completed economic studies and postgraduate studies in management.

Continue exploring our insights.

View the full archive
Legal updates

Obligations of traders to provide non-cash payments

As part of the amendment package under the noisy name Polish Deal, which most of the solutions entered into force at the beginning of January 2022, to stimulate a new impetus for the gradually growing trend in the market for non-cash payments, and at the same time to counter and combat the gray...

Legal updates

Deduction – what is involved and when possible

Deduction is a legal institution regulated in Article 498-505 KC.

Legal updates

Business secrecy in the context of changes to the Public Finance Act - comment

From 1 July 2022 information on all contracts exceeding the value 500 PLN, which from the beginning of this year have been concluded by public authorities (including JST), will be public and will be entered in the register kept by the Minister of Finance.