RODO can also be referred to as "GDPR" and "General Data Protection Regulation"
On 25 May 2018, provisions regarding the protection of personal data came into force in Poland. Individuals have the right to remove their personal data from any source, and companies and government institutions must make a number of changes.
RODO principles
The General Data Protection Regulation must comply with the following principles:
- adequate protection of stored personal data,
- providing customers with information on the processing of their personal data, as well as the ability to view and change it,
- obtaining consent for the use of personal data,
- keeping records of data processing,
introducing the principle of confidentiality by default – meaning putting in place measures (technical and organisational) to ensure that only data necessary for a specific operation is processed; notifying the supervisory authority of a data security breach – the so-called notification obligation, which must be fulfilled within 72 hours of an event that threatens security;
submitting, at the supervisory authority's request, documentation confirming compliance with the law;
keeping documents confirming who, when, and to what extent gave consent to the processing of personal data.
The provisions of the regulation set out the obligations that entrepreneurs and all companies processing and administering personal data must meet.
What is personal data?
Personal data is any data by which we can identify a natural person, for example:
- first name, surname,
- PESEL,
- genetic data,
- health data,
- political opinions,
- racial data,
- biometric data.
- biometric data
What do you need to do to comply with RODO in Poland?
Anyone who processes personal data must:
- determine what personal data is being processed
- identify the risk of infringing individuals' rights connected with data processing
- choose appropriate measures to ensure the security of personal data.
RODO does not specify any particular measures for the protection of personal data. RODO states that these measures must be appropriate.
Penalty for violating RODO principles
In the event of a breach of the obligations referred to in RODO, the Head of the Personal Data Protection Office in Poland has the right to impose a financial (administrative) penalty of between 10,000,000 euros or 2% of the given entrepreneur's turnover and 20,000,000 euros or 4% of the given entrepreneur's turnover, depending on the severity of the breach.