Back to the insights archive
Legal updates

GDPR and personal data in the housing community

Currently in Poland personal data is processed on the basis of Act dated 29 August 1997 on the protection of personal data, to which a number of regulations have been issued specifying the methods and techniques for the protection of such data (including detailed procedures).

Currently in Poland personal data is processed on the basis of Act dated 29 August 1997 on the protection of personal data, to which a number of regulations have been issued specifying the methods and techniques for the protection of such data (including detailed procedures).

From 25 May 2018, I think everyone knows the rules...

Currently in Poland personal data is processed on the basis of Act dated 29 August 1997 on the protection of personal data, to which a number of regulations have been issued specifying the methods and techniques for the protection of such data (including detailed procedures). From 25 May 2018, As everyone knows, the rules on the protection of personal data will change with the entry into force of the EU General Data Protection Regulation (GDPR).

Importantly and different from the current legal order, GDPR does not provide detailed guidelines which should be used for the processing of personal data. The choice and implementation of mechanisms allowing the lawful processing of such data will be the responsibility of the data controller.

The new rules only indicate that these mechanisms should be ‘adequate’ (in line with the so-called accountability principle) and ‘adapted’ to the risk posed by the processing of personal data in a specific case. The fact that in certain circumstances the procedures used are ‘adequate’ will have to be demonstrated by the data controller.

With the entry into force of the GDPR, the agreement on the processing of personal data by the entity managing the property should meet certain requirements under Article 28 GDPR. Therefore, the property manager will have to demonstrate that it meets the conditions of GDPR in terms of security of personal data. Otherwise, the community will not be able to conclude such an agreement, which will in practice prevent the manager from administering the property lawfully.

Housing community as data controller

According to the current position of GIODO, the administrator of personal data of members of the housing community is the community itself. This is due to the content Article 6 Act dated 24 June 1994 the ownership of the premises which provides that it is the subject of the rights and obligations under that law.

It is therefore the responsibility of the current Data Protection Act. Personal data in the housing community shall include in particular data on members of the community and on its counterparties and persons. landlords service facilities located in the community building.

Furthermore, in view of the upcoming changes in the rules on personal data protection, it is also mentioned that the property ownership of the premises should be amended to include an additional Article 6a the following: ‘The housing community shall be the controller of personal data relating to the property management.’ This provision would clearly indicate that, by law, each housing community is the controller of personal data, which will have to ensure adequate security of personal data.

As GIODO points out in its replies to questions concerning sectoral legislation: “The Community’s management, if appointed, acts as its body. The property manager usually acts as the entity in question under Article 31 Personal Data Protection Act – the entity to which the data controller has entrusted the data processing. However, its status depends on the construction of the contract it has concluded with the community."

At this point, it is also worth pointing out that the owners of the premises may, in a contract establishing separate ownership of the premises or in a contract concluded later in the form of a notarial act, determine the manner in which the management of the common property is managed, and in particular may entrust the management to a natural or legal person (Article 18(1) Local Property Act).

The management or administrator entrusted with the management of the common property is obliged to draw up a report on the acquisition of the property and its technical documentation (building, execution and building book) on behalf of the housing community, to keep the technical documentation of the building and to maintain and update the list of owners of the premises and their shares in the common property (Article 29(1) b Act).

Consequently, the common property manager is not only authorized, but also obliged to collect personal data concerning owners of premises, within the limits laid down in that provision.

This is confirmed by the GIODO position set out above, according to which ‘the common property manager may process the data of members of the community only as an entity to which, according to Article 31 Act dated 29 August 1997 the protection of personal data, the processing of data has been entrusted.”

With the entry into force of the GDPR, the agreement on the processing of personal data by the entity managing the property should meet certain requirements under Article 28 GDPR. Therefore, the property manager will have to demonstrate that it meets the conditions of GDPR in terms of security of personal data.

Otherwise, the community will not be able to conclude such an agreement, which will in practice prevent the manager from administering the property lawfully. Furthermore, the property management agreement will have to provide that the managing entity will keep the personal data entrusted to it confidential.

In summary, both administrators i.e. the housing community and the entity entrusted with the processing of personal data i.e. The administrator, must apply the requirements relating to data security in accordance with GDPR provisions.

Penalties for violating GDPR

It is worth noting that unlike the Personal Data Protection Act, GDPR introduces high fines for improper processing of personal data. These penalties may be imposed on both the data controller, the housing community and the processor, i.e. the administrator. The possible maximum amount of penalties is the amount up to 20,000,000 EUR.

While possible sanctions will be imposed taking into account the nature of the administrator and the infringements, the contrary to the current state of the law since May 2018 a penalty may be imposed on the community as a data controller.

Civil liability

According to the GDPR, any person who, as a result of a violation of the regulations, will be entitled to receive appropriate compensation from the controller or the processor.

In principle, therefore, both the community and the administrator will be liable for any damage caused by the processing of personal data in case they fail to fulfil the obligations which GDPR directly imposes on them.

Moreover, in the event of participation in the processing more than one the controller or processor is jointly and severally liable for the damage. Therefore, where one from entities (e.g. the defendant administrator) to pay the full amount of the compensation, he will have the right to require other controllers or processors (e.g.

the Community) to reimburse the part of the compensation corresponding to the damage for which they are liable.

Every housing community and property manager should already take steps to prepare for the entry into force of the new GDPR regulations.

We recommend a conference Revolution in the protection of personal data from May 2018 - GDPR Regulation.

Author:

Ewa Buchowiecka

Lawyer. At Russell Bedford deals with comprehensive legal and process services of economic operators, including the handling and consulting of construction investments. He has experience in civil, economic and labour law, as well as in the creation and transformation of commercial law companies.

Graduate of postgraduate studies in Tax and Economic Criminal Law conducted at the Jagiellonian University Department of Criminal Law. During her professional practice, she published opinions and articles on industry magazines and websites and collaborated as editor in C.H. Beck's publishing house.

Continue exploring our insights.

View the full archive
Legal updates

Obligations of traders to provide non-cash payments

As part of the amendment package under the noisy name Polish Deal, which most of the solutions entered into force at the beginning of January 2022, to stimulate a new impetus for the gradually growing trend in the market for non-cash payments, and at the same time to counter and combat the gray...

Legal updates

Deduction – what is involved and when possible

Deduction is a legal institution regulated in Article 498-505 KC.

Legal updates

Business secrecy in the context of changes to the Public Finance Act - comment

From 1 July 2022 information on all contracts exceeding the value 500 PLN, which from the beginning of this year have been concluded by public authorities (including JST), will be public and will be entered in the register kept by the Minister of Finance.