Back to the insights archive
Legal updates

Data Protection Officer (IOD) — its role and position in the organisation’s structure

With entry into force on 25 May 2018 Regulation (EU) 2016/679 ((hereinafter referred to as ‘GDPR’) cases of compulsory appointment of the so-called Data Protection Officer hereinafter referred to as ‘IOD’) will be introduced into the legal order.

With entry into force on 25 May 2018 Regulation (EU) 2016/679 ((hereinafter referred to as ‘GDPR’) cases of compulsory appointment of the so-called Data Protection Officer hereinafter referred to as ‘IOD’) will be introduced into the legal order.

Such a duty will apply in principle to all...

With entry into force on 25 May 2018 Regulation (EU) 2016/679 ((hereinafter referred to as ‘GDPR’) cases of compulsory appointment of the so-called Data Protection Officer (hereinafter referred to as ‘IOD’) will be introduced into the legal order.

Such an obligation will apply in principle to all public authorities and bodies and entities which monitor persons regularly and on a large scale in their main activities, and where the activities of the controller or processor consist in the processing of specific categories of personal data on a large scale.

The IOD is to be appointed by both data controllers and data processors on their behalf.

Interestingly, the GDPR does not contain in its content the definition of a data protection inspector. It only indicates the conditions for its establishment, the tasks to be carried out and its status in the structure of the company.

Therefore, it should be assumed that it is a person who, under the authority of the administrator, monitors compliance with the measures used in the organisation to protect the processing of personal data and the provisions of the GDPR and other provisions in force in the field of personal data.

It can be concluded, therefore, that the Data Protection Officer is a design introduced by the GDPR, whose assumptions are similar to the data protection controller (ABI) which still operates under the provisions of the Act on the Protection of Personal Data.

What will change, however, is not only the name of the position from the information security administrator to the Data Protection Officer, but also, as already indicated above, its competences and tasks will change.

The IOD has become an extremely important element of professional support for ensuring that the processing of personal data is compatible with the GDPR.

So what happens to the current ABI?

Draft dated 8 February 2018 Data Protection Act provides that the person performing on 24 May 2018 as a Data Security Officer (ABI), becomes a Data Protection Officer by law and performs its functions until 1 September 2018, Unless by that date, the administrator shall notify the President of the Office of the appointment of another person as the Data Protection Officer. In addition, a person who holds the current function of ABI may be cancelled by the data controller without informing the President of the Office of the appointment of another person as a data protection officer, in case the data controller is not obliged to designate a data protection officer on the basis of the GDPR.

Of course, the administrator, who, by the date of the entry into force of the new Data Protection Act, has not appointed an ABI, and under the provisions of the GDPR meets the conditions requiring him to appoint a Data Protection Officer, appoints a Data Protection Officer and by the date of 31 July 2018 notify the President of the Office.

Outsourcing function IOD

It is important that, under the provisions of the GDPR, a data protection officer may be an employee or associate of a data controller or data processor. GDPR also explicitly indicates that the IOD can also perform its tasks under a service contract and therefore according to Article 37(6) GDPR is allowed outsourcing this function.

In addition, it is worth noting that an inspector may become a person who has adequate professional qualifications and expertise in the field of personal data protection law and practices. The level of expertise required by the provisions is not specifically defined, but it must be kept in mind that it must be appropriate to the nature and complexity of the processing processes of personal data within a particular unit.

It is also worth mentioning that the new rules provide for the possibility of establishing one Inspector for several entrepreneurs. Therefore, a group of undertakings may designate one The personal data protection officer, however, shall be provided that it can be easily contacted by any establishment.

Without doubt, such a solution should be considered as a facilitation for entrepreneurs who operate on the basis of companies linked to each other in capital, personal or organisational terms.

Of course, it should be remembered that the number of these organisations cannot be excessive, which could only make the possibility of the IOD performing its tasks illusory.

Interestingly, the EU legislature itself provided for the possibility to designate one However, the inspector for several entities did not provide for the possibility of appointing several inspectors or deputy inspectors in one You guys.

However, as the Working Group points out Article 29 in the Guidelines on personal data inspectors, the IOD function under a service contract may be performed not only by a natural person but also by another entity.

In such a situation, it is necessary that every person of the IOD team fulfil the qualifications indicated in the GDPR, and that he is guaranteed protection.

IOD Independence

At this point you should pay attention to Article 38 GDPR, which includes a certain range of guarantees, the assumption of which is to enable the IOD to perform its duties with an appropriate degree of autonomy in the structure of the company.

As the recital also points out 97 to GDPR – Data Protection Officers – regardless of whether they are employees of the controller – should be able to perform their duties and tasks independently, i.e. not to receive instructions from the administrator or the processor on the performance of their tasks.

These guarantees also include (Article 38(6) GDPR) entrusting the inspector with other tasks and duties only if there is no conflict of interest with other duties or tasks.

Moreover, only the highest management of the controller or processor is subordinate to the IOD one from the guarantee of an independent, high position of the inspector in the structure of the unit, and also shortens the way in which communication is to be made, in particular where rapid corrective action is necessary in the event of breaches of personal data protection procedures.

What's more, Article 38(3) The GDPR states that the IOD "is not revoked or punished by the administrator or the processor for fulfilling its tasks". Therefore, any penalties for IOD in the light of GDPR are not allowed only in cases where they are imposed in connection with the performance of their duties by the inspector.

However, in an area not linked to the role of an IOD inspector, it is subject to ordinary responsibility, including, for example, employee responsibility. It can therefore be appealed if it violates, for example, criminal law or labour law (stealing, mobbing, harassment, other serious violations of labour obligations).

The GDPR rules themselves do not indicate the situation and in what time the IOD can be cancelled or replaced by another person.

However, it may be assumed that, where personal data have been breached by the inspector, this could constitute a condition for the disciplinary release of the IOD or for an action against it by the administrator of the compensation claim.

In view of the above, however, we must not forget yet one An extremely important issue. As the Working Group reserves Article 29 appointment of a data protection officer does not mean that it is subject to full responsibility for infringements and non-compliance of the activities of a given entity from the GDPR.

The provision of this obligation rests strictly on the controller or processor.

Important to the list of infringements which will give rise to the imposition by GIODO of an administrative penalty in the amount up to 10,000,000 EUR or, where the penalty is imposed on the undertaking, to 2% its total annual world turnover from the previous financial year should also be the same as the failure to appoint a data protection officer in cases where that designation is mandatory Article 37 GDPR).

So it is worth preparing for the forthcoming changes in the area of data protection. In particular, they introduce many new responsibilities and sanctions for administrators.

Author:

Ewa Buchowiecka

Lawyer. At Russell Bedford, he deals with comprehensive legal and procedural services for business entities, including the handling and consulting of construction investments. He has experience in civil, economic and labour law, as well as in the creation and transformation of commercial law companies.

Graduate of postgraduate studies in Tax and Economic Criminal Law conducted at the Jagiellonian University Department of Criminal Law. During her professional practice, she published opinions and articles on industry magazines and websites and collaborated as editor in C.H. Beck's publishing house.

Continue exploring our insights.

View the full archive
Legal updates

Obligations of traders to provide non-cash payments

As part of the amendment package under the noisy name Polish Deal, which most of the solutions entered into force at the beginning of January 2022, to stimulate a new impetus for the gradually growing trend in the market for non-cash payments, and at the same time to counter and combat the gray...

Legal updates

Deduction – what is involved and when possible

Deduction is a legal institution regulated in Article 498-505 KC.

Legal updates

Business secrecy in the context of changes to the Public Finance Act - comment

From 1 July 2022 information on all contracts exceeding the value 500 PLN, which from the beginning of this year have been concluded by public authorities (including JST), will be public and will be entered in the register kept by the Minister of Finance.