Get in Touch

Course Outline

Foundational Principles of Personal Data Processing

  • National and international legal sources
  • Applicability of personal data protection laws
  • Jurisdiction and powers of the data protection authority
  • Judicial safeguards for the right to personal data protection
  • GDPR: Core concepts and definitions (selected topics)
  • Sector-specific provisions within the GDPR
  • Definition and classification of personal data
  • Mechanics of personal data processing
  • Legal grounds for processing personal data
  • Responsibilities of the Data Controller
  • Rights afforded to data subjects
  • Administrative penalties and fines
  • Personal Data Protection Act of 10 May 2018 – regulatory scope
  • Appointment of the Data Protection Officer
  • Proceedings concerning violations of personal data protection laws
  • Oversight of compliance with personal data protection regulations
  • Civil, criminal, and administrative liability
  • Admissibility criteria for processing personal data (standard and sensitive categories)
  • Legal requirements for outsourcing personal data processing to third parties
  • Data Protection Impact Assessments (DPIA)
  • Data protection by design and by default
  • Legal frameworks for transferring personal data to third countries
  • Personal data protection in the context of employment relationships

Appointment of the Data Protection Officer

  • Mandatory appointment of a DPO
  • Voluntary appointment of an Inspector

Eligibility for the Role of Data Protection Officer

  • Qualifications required to serve as an Inspector
  • Employment status and contractual arrangements for the Inspector

Professional Status of the Data Protection Officer

  • Direct reporting line from the Inspector to top management
  • Arranging adequate support for the Supervisor
  • Involvement of the Inspector in all matters concerning personal data protection
  • Prohibition on issuing instructions to the Supervisor regarding the execution of their duties
  • Managing conflicts of interest within the organization – specific duties of the Supervisor
  • Protection against dismissal or disciplinary action for the Inspector
  • Obligation of the Inspector to maintain confidentiality regarding their tasks

Information Security Management

  • Analysis of organizational security management systems, including references to Polish standards
  • Identifying privacy risks and their corresponding legal implications
  • Principles of risk assessment and evaluating the impact of specific solutions on safety management effectiveness
  • Understanding and applying a risk-based approach – practical completion of a Risk Analysis template
  • Management of the Personal Data Lifecycle

Executing the Duties of the Data Protection Officer (DPO)

  • Legal basis for appointing the DPO
  • Entities and timing required for DPO appointment, and the procedure involved
  • Status and required qualifications of the DPO
  • DPO responsibilities and planning guidelines for their execution
  • Reporting on data processing compliance with personal data protection provisions in traditional and IT systems
  • Documentation of activities performed by the DPO
  • Preparation of audit and inspection reports
  • Rules for overseeing documentation related to personal data processing
  • Scope of UODO powers in relation to DPOs

Practical Guidance on Inspections by the Office for Personal Data Protection

  • Requirements imposed on audited entities by the Office
  • Strategies for preparing for an inspection
  • Case study analysis

Practical Activities

  • Drafting a model Information Security Policy
  • Developing administrative instructions and procedures
  • Creating a Register of Processing Activities
  • Preparing the 'Small Personal Data Protection Documentation' set
  • Case study application
  • Identifying common errors in documentation preparation

Supplementary Materials for Participants:

Useful Forms and Templates:

  • Consent for the use and dissemination of images
  • Event newsletter subscription form
  • Consent to receive commercial offers
  • Guidelines for sending offer emails
  • Guidelines for sending general correspondence
  • Sample personal data protection policy
  • GDPR information obligation template with accompanying instructions
  • Risk analysis template
  • Register of personal data processing activities – template
  • Register of categories of processing activities – template
  • GDPR Breach Register – Template
  • GDPR Compliance Checklist Template
  • Procedure for handling breaches of personal data protection regulations
  • Data Protection Breach Report Template
  • Register of security incidents, corrective, and preventive actions
  • Register of corrections
  • Register of data restorations
  • Model correction document
  • Data restoration pattern
  • Model objection form
  • Model contract excluding further processing of personal data
  • Sample consents for competitions, marketing, and publications
  • Information obligation for ferry crossing services
  • Information obligation for meeting monitoring
  • Information obligations in recruitment processes
  • Information obligation to the National Revenue Administration
  • LES information obligation
  • Public Procurement Law (UCoC) information obligations
  • Information obligations under the Labour Code
  • Tax-related information obligations
  • Employee personal data processing authorization: template with example
  • Notification to data subjects of a breach – template
  • Personal Data Processing Agreement for the Controller – template
  • Personal Data Processing Agreement for the Processor
  • And additional resources

Requirements

Target Audience

  • Professionals assuming the role of Data Protection Officer for the first time
  • Individuals preparing for future appointment to this position
 21 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories