The protection of personal data has gone slightly further towards the events in which we participate, which does not mean that its rules are no longer in force. In the GDPR cycle we will present the most important records that concern them. In the first part Let us look at the basis, which is what the basic principles define the protection of personal data.
In the GDPR regulations are formulated seven rules on the processing of personal data [1], which we discuss below.
Principle of legality, fairness and transparency - Article 5(1) (a) processed in accordance with the law, in a fair and transparent manner for the data subject ("lawfulness, reliability and transparency")
Principle of limiting the purpose of data processing - Article 5(1) (b) collected for specific, explicit and legitimate purposes and not further processed in a manner incompatible with those objectives; (‘the limitation of the objective’)
Principle of data minimisation - Article 5(1) (c) adequate, appropriate and limited to what is necessary for the purposes for which they are processed (‘minimum data’)
Principle of correctness of data - Article 5(1) (d) correct and updated where necessary; any reasonable action should be taken to ensure that personal data which are incorrect in the light of the purposes of their processing is immediately deleted or corrected (the ‘correctity’)
The principle of limiting data storage - Article 5 (e) kept in a form that enables the data subject to be identified for a period of no longer than is necessary for the purposes for which the data are processed; personal data may be stored for a longer period if they are processed solely for archival purposes in the public interest, for scientific or historical research purposes or for statistical purposes under Article 89(1), subject to the implementation of the appropriate technical and organisational measures required under this Regulation to protect the rights and freedoms of data subjects (‘retention restrictions’)
Principles of data integrity and confidentiality - Article 5(1) (f) processed in such a way as to ensure adequate security of personal data, including protection against unauthorised or unlawful processing and accidental loss, destruction or damage, by appropriate technical or organisational means (integrity and confidentiality)
The principle of accountability means that the administrator must be able to demonstrate that the activities undertaken by him comply with the above-mentioned rules.
The Personal Data Protection Act provided for the maximum penalty for wrong processing of sensitive data. For unacceptable or unauthorised processing of ordinary data, 2 years of imprisonment, while with regard to the catalogue of closed sensitive data – to 3 years. GDPR contains no criminal regulations.
The national legislature may add them in the bill. But there are two categories concerning the punishment of Data Administrators (ADOs), on administrative fines. Any person who feels injured by the administrator may submit appropriate notice on this subject requesting compensation.
To 10,000,000 EUR (or in the case of an entrepreneur, to 2% its entire global turnover in the previous year) should be paid for the lack of information on the processing and use of personal data, the failure to take account of data protection at the time of design, incorrectly keeping a record of the processing of data or its lack.
In addition, such a penalty also applies to the securing of information systems incorrectly or to the absence of a Data Protection Officer at the time when the situation so requires.
But until 20,000,000 EUR penalties (or in the case of an entrepreneur - to 4% its entire world turnover in the previous year) should be ADO at the time of its breach of the basic principles of data processing.
These include negligence such as failure to ensure that consent is obtained, violation of the rights of those who have consented, and incorrect transmission of such data to countries third or international organisations.
The President of the Office for Data Protection shall examine each case individually and shall determine on the basis of many factors whether such a penalty will be imposed and in what amount.
It is important in this case to state whether such an offence was created intentionally or unintentionally, whether other negligence occurred earlier, what is the gravity of the offence and the duration of the offence, the categories of personal data concerned, the way in which it worked with the supervisory authority to remedy the problem or to minimise the damage.
There is, of course, a possibility of appeal against the penalty imposed, but it must be demonstrated that such effects were not due to negligence by the administrator [2].
[1] Act dated 10 May 2018, o-cit., Article 5.
[2] Jagiellonian University in Krakow, Principles for the processing of personal data, source: https://iod.uj.edu.pl/aktualnosci/-/journal_content/56_INSTANCE_FXVpkOlZ7X7Q/138774264/139187454 (access: 8 July 2020).