Draft Act amending the Act – Criminal Code and some other laws (segment printing no. 867 Further: ‘Project’) is illegal in many places, for which the President of the Office for Personal Data Protection.
The Polish draft law amending the law - Criminal Code (hereinafter: KK) and some other laws are in the opinion stage. There are already doubts about the provisions related to the GDPR.
Penalisation for content likely to facilitate terrorist offences
In the first of the comments submitted by PIODO draw attention to Article 1(1) the proposed law, which amends Article 255a section 2 KK ‘the criminal is subject to a criminal offence of a terrorist nature which is likely to enable the criminal offence to be committed or itself to be familiar with the content in question.
Under section 1 (Ed. i.e. the content that may facilitate the terrorist offence). Such an imprecise record may lead to action against persons who have accidentally read such content.
In the meantime, only those persons who are familiar with the content that may facilitate the committing of a terrorist offence should be punished, accompanied by the intention to commit a terrorist offence.
Too laconic law on data security
Another remark refers to Article 2(2) point (a), that changes Article 218 section 1 KK. It refers to the security of IT data by telecommunications offices, institutions and entities or providers of electronic services and by digital service providers.
At the request of the D.A., they are not only to secure data, but also to prevent access to it. This record does not specify for whom this access is to be closed or to what extent the data is to be cut off from the view.
This may interfere with the principle of legality, the reliability of transparency according to which personal data must be processed in a transparent manner for the person concerned.
Electronic copies of the indictment
The introduction of the possibility of sending a copy of the indictment by e-mail raises doubts. President UODO points out that the amendment does not specify how e-mail addresses are to be obtained. In addition, Regulation (EU) 2016/679, known as GDPR, under Article 5 u. 1 point (f) points to the need to maintain the integrity and confidentiality of the transmission of sensitive data which may not be covered by digital correspondence.