The key issue with regard to the institution of the Data Protection Supervisor (IOD) is whether the entity carrying out business activity is obliged to designate a person acting as such. We are looking at when and who should be interested in this subject and what to draw attention to in the field of IOD duties.
The Data Protection Officer’s institution (hereinafter ‘IOD’) is currently regulated in Regulation (EU) 2016/679 of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46, commonly referred to as ‘GDPR’, which entered into force 25 May 2018
What tasks does the Data Protection Officer have?
The data protection officer is a natural person who supports the controller[1] and any processor[2] in the supervision of compliance with GDPR regulations. As per content Article 39(1) The GDPR's tasks include:
- inform the controller, the processor and the employees who process personal data about their obligations under the GDPR and other provisions,
- monitoring compliance with the GDPR, other regulations and policies of the controller or processor in the field of personal data protection,
- giving recommendations on the assessment of the impact on data protection and monitoring the implementation of these recommendations
- cooperation with the supervisory authority[3],
- acting as a contact point for the supervisory authority.
High penalties for failure to fulfil the obligation to establish an IOD
In the context of conducting business activity, it should be considered a key issue to determine precisely whether the entity conducting business activity – a company or a natural person conducting one-person business activity – is required to appoint a data protection officer and to notify the supervisory authority, which is the President of the Office for Personal Data Protection in Poland. According to the disposition Article 83(4) (a) GDPR Infringement of this obligation may result in the imposition on the processor of a fine of up to 10,000,000 EUR, and in the case of an undertaking, up to 2% its total annual global turnover from the previous financial year, with a higher amount applicable.
Mandatory appointment of a Data Protection Officer
The cases where the appointment of a data protection officer is compulsory are regulated in Article 37(1) GDPR. These include situations where:
- the processing is carried out by a public authority or body, with the exception of courts with regard to their judicial activity;
- the main activities of the controller or processor consist of processing operations which, by reason of their nature, scope or objectives, require regular and systematic monitoring of data subjects on a large scale; or
- the main activity of the controller or processor is to process on a large scale the specific categories of personal data referred to in Article 9, or personal data relating to convictions and criminal offences, as referred to in Article 10.
For economic operators processing personal data, the case included in the Article 37(1) (b) GDPR. The other conditions relate to public authorities and bodies and to cases of processing of personal data of a particular type.[4], which typically remain outside the scope of processing by economic operators.
Article 37(1) lit. b) GDPR applies to cases where together the following conditions are met:
- the activity of the controller or processor is its principal activity;
- processing operations require regular and systematic monitoring of data subjects;
- processing operations shall be carried out on a large scale.
Establishment of the IOD and scope of activity
The verification of whether the activities carried on involve the obligation to appoint a Data Protection Officer shall each time take account of the specific factual situation, including in particular the business model of the entrepreneur (the administrator).
However, by limiting itself to comments of a general nature, at least in part the meaning of the above-mentioned considerations can be clarified. Article 37(1) (b) GDPR.
Theme 97 The preamble to the GDPR explains that in the private sector the processing of personal data is the main activity of the controller, if it means its essential and not lateral activities.
In this context, the doctrine indicates that this applies to situations where ‘data processing is a necessary element in the functioning and business of the entity’.[5].
Regular and systematic monitoring should be understood as a systematic process, following a specific plan, characterised by repetitiveness. The meaning of the concept of processing operations is made on a large scale clarifies the recital 91 GDPR preamble, according to which operations of this size are used to process a significant amount of personal data at regional, national or transnational level and which may affect a large number of data subjects and which may cause a high risk.
Given the general nature of the conditions Article 37(1) (b) GDPR, as well as potentially high administrative penalties, threatening to comply with the obligation to appoint a data protection officer, is worth taking advantage of professional legal advice. The lawyer will assess whether the IOD is necessary in your case.
[1] On the basis of GDPR, the concept of administrator means a natural or legal person, a public body, a unit or another entity, who independently or jointly with others determines the purposes and methods of processing personal data - por. Article 4(7) GDPR.
[2] "the processor" means a natural or legal person, public authority, entity or other entity that processes personal data on behalf of the controller - cf. Article 4(8) GDPR.
[3] "a supervisory authority" means an independent public body established by a Member State.
[4] These are (i) personal data revealing racial or ethnic origin, political views, religious beliefs or belief, trade union membership, (ii) genetic and biometric data processed to identify a natural person unequivocally, (iii) health, sexuality or sexual orientation data, and (iv) personal data relating to convictions and criminal offences or related security measures.
[5] A. Kidney in: General Data Protection Regulation. Commentary, ed. M. Sakowska-Baryl, comment on Article 37, thesis 5, Legalis/el.
Author: Paweł Postolko
Lawyer, graduate of Law at the Faculty of Law and Administration of the Jagiellonian University, where he then completed Postgraduate Studies in Economic and Tax Criminal Law. With the law firm Russell Bedford connected from 2021. His professional interests are economic law, taking into account criminal and economic issues. He has practical professional experience in handling court cases.