Get in Touch

Course Outline

Core principles of personal data processing

  • National and international legal frameworks
  • Application scope of personal data protection legislation
  • Authorities and powers of the data protection regulator
  • Judicial remedies for personal data protection rights
  • GDPR overview: key information, definitions, and selected topics
  • Sector-specific provisions within the GDPR
  • Definition and classification of personal data
  • Processes involved in personal data processing
  • Legal grounds for processing personal data
  • Obligations of Data Controllers (Administrators)
  • Rights afforded to data subjects
  • Administrative penalties and fines
  • The Personal Data Protection Act of 10 May 2018 – regulatory scope
  • Procedures for appointing a Data Protection Officer
  • Proceedings related to violations of personal data protection laws
  • Oversight of compliance with data protection regulations
  • Civil, criminal, and administrative liability
  • Conditions for the lawful processing of ordinary and sensitive data
  • Legal requirements for outsourcing data processing to third parties
  • Data Protection Impact Assessments (DPIA)
  • Data protection by design and by default
  • Legal bases for transferring personal data to third countries
  • Personal data protection in the context of employment relationships

Appointing a Data Protection Officer

  • Mandatory requirements for DPO appointment
  • Voluntary appointment of an Inspector

Eligibility for the Data Protection Officer role

  • Qualifications required to serve as an Inspector
  • Employment forms suitable for Inspectors

Status and standing of the Data Protection Officer

  • Direct reporting lines from the Inspector to senior management
  • Establishing support structures for the Supervisor (DPO)
  • Inspector involvement in all matters concerning personal data protection
  • Prohibition on issuing instructions to the Supervisor regarding duty execution
  • Managing conflicts of interest within the organization – Supervisor responsibilities
  • Protections against dismissal or disciplinary action for Inspectors
  • Inspector’s duty to maintain secrecy and confidentiality of tasks

Information Security Management

  • Reviewing organizational security management systems, including Polish standards
  • Identifying privacy risks and understanding their legal consequences
  • Risk assessment principles and evaluating the effectiveness of specific security solutions
  • Applying a risk-based approach – practical completion of Risk Analysis templates
  • Managing the lifecycle of personal data

Executing Data Protection Officer (DPO) duties

  • Legal framework for DPO appointment
  • Requirements and procedures for appointing a DPO
  • DPO status, qualifications, and role definition
  • DPO responsibilities and planning strategies for their execution
  • Reporting on data processing compliance in traditional and IT systems
  • Documentation of activities performed by the DPO
  • Preparation of audit and inspection reports
  • Supervising documentation related to personal data processing
  • Powers of the UODO (Office for Personal Data Protection) regarding DPOs

Practical insights on Office for Personal Data Protection inspections

  • Requirements imposed on auditees by the Office
  • Strategies for preparing for inspections
  • Analytical case studies

Practical workshops

  • Drafting an exemplary Information Security Policy
  • Creating management instructions
  • Compiling a Register of Processing Activities
  • Developing streamlined Personal Data Protection documentation
  • Applying case studies to real-world scenarios
  • Identifying common errors in documentation preparation

Supplementary resources for participants:

Useful forms and templates:

  • Consent form for image usage and distribution
  • Entry form for events and newsletters
  • Consent for receiving commercial offers
  • Templates for sending offer emails
  • Templates for general correspondence
  • Sample personal data protection policy
  • GDPR-compliant information obligation template with instructions
  • Risk analysis template
  • Template for Register of personal data processing activities
  • Template for Register of categories of processing activities
  • GDPR Breach Register template
  • GDPR Compliance Checklist template
  • Guidelines for responding to personal data protection breaches
  • Data Protection Breach Report template
  • Register of security incidents and corrective/preventive actions
  • Register of corrigenda
  • Register of restorations
  • Model corrigendum document
  • Restoration pattern document
  • Model objection form
  • Model contract prohibiting further processing of personal data
  • Sample consents for competitions, marketing, and publications
  • Information obligation for ferry crossing services
  • Information obligation for meeting monitoring
  • Information obligation in recruitment processes
  • Information obligation for the National Revenue Administration
  • Information obligation for LES (Electronic System for Electronic Procurement)
  • Information obligation under Public Procurement Law (UCoC)
  • Information obligation under the Labour Code
  • Tax-related information obligations
  • Employee authorization to process personal data: fillable template with example
  • Template for notifying data subjects of a breach
  • Personal Data Processing Agreement for Controllers – template
  • Personal Data Processing Agreement for Processors
  • And many more additional resources

Requirements

Target Audience

  • Professionals currently taking on the role of a Data Protection Officer
  • Individuals expected to be appointed to this position in the near future
 21 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories