Personal Data Protection
Legal basis for data protection
The current collection of legal acts concerning personal data protection can be found on the website of the Personal Data Protection Office. https://uodo.gov.pl/pl/p/prawo
Data Protection Officer
Definition IOD
A Data Protection Officer is a person appointed by the controller or processor to assist in complying with personal data protection regulations within a company or organisation. The DPO acts as an intermediary between the parties concerned (the Data Protection Authority, the data processor and the data subject). In addition, the Data Protection Officer ensures the implementation of the principle of accountability – he or she assists in the preparation of risk assessments or personal data protection impact assessments.
Tasks IOD
Pursuant to Article 39 of REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as the GDPR, the Data Protection Officer shall have the following tasks:
a/ to inform the controller, the processor and the employees who process personal data of their obligations under this Regulation and other Union or Member State data protection provisions and to advise them on these matters;
b/ to monitor compliance with this Regulation, other Union or Member State data protection provisions and the policies of the controller or processor in relation to the protection of personal data;
b/ monitoring compliance with this Regulation, other Union or Member State data protection provisions and the policies of the controller or processor in the area of personal data protection, including the allocation of responsibilities, awareness-raising measures, training of staff involved in processing operations and related audits;
c/ making recommendations on data protection impact assessments where requested and monitoring their performance pursuant to Article 35;
d/ cooperating with the supervisory authority;
e/ acting as a contact point for the supervisory authority on issues related to processing, including the prior consultation referred to in Article 36, and, where appropriate, consulting on any other matter.
The data protection officer shall perform his or her tasks in accordance with
