Get in Touch

Course Outline

Fundamentals of Personal Data Processing

  • Sources of national and international law.
  • Scope of application for personal data protection laws.
  • Authority powers regarding data protection.
  • Judicial remedies for the right to personal data protection.
  • GDPR overview: key information, definitions, and selected topics.
  • Sector-specific GDPR applications.
  • Definition and classification of personal data.
  • Process of personal data processing.
  • Legal bases for processing personal data.
  • Responsibilities of the Data Controller.
  • Rights of data subjects.
  • Administrative fines and penalties.
  • The Personal Data Protection Act of May 10, 2018 – regulatory scope.
  • Procedures for appointing a Data Protection Officer.
  • Legal proceedings for violations of personal data protection laws.
  • Monitoring compliance with personal data protection regulations.
  • Civil, criminal, and administrative liability.
  • Conditions for lawful processing of personal data (standard and sensitive categories).
  • Legal requirements for delegating personal data processing to third parties.
  • Data Protection Impact Assessment (DPIA).
  • Principles of privacy by design and privacy by default.
  • Legal bases for transferring personal data to third countries.
  • Personal data protection within employment relationships.

Appointment of a Data Protection Officer

  • Mandatory requirements for DPO appointment.
  • Voluntary appointment of a data protection representative.

Eligibility for the Data Protection Officer Role

  • Qualifications required to serve as a DPO.
  • Forms of employment for the DPO.

Status and Authority of the Data Protection Officer

  • Direct reporting lines to senior management.
  • Ensuring adequate resources and support for the DPO.
  • DPO involvement in all matters related to personal data protection.
  • Prohibition on giving instructions regarding how the DPO performs their duties.
  • Avoiding conflicts of interest within the organization – defining DPO tasks.
  • Prohibition against dismissing or penalizing the DPO for performing their duties.
  • Duty to maintain confidentiality of performed tasks.

Information Security Management

  • Discussion of organizational security management systems, referencing Polish standards.
  • Identifying privacy risks and their legal implications.
  • Principles of risk assessment and evaluating the effectiveness of safety solutions.
  • Understanding and applying a risk-based approach through practical completion of Risk Analysis templates.
  • Managing the lifecycle of personal data.

Executing Data Protection Officer (DPO) Duties

  • Legal basis for DPO appointment.
  • Criteria and procedures for appointing a DPO.
  • DPO status and necessary qualifications.
  • DPO responsibilities and rules for planning task execution.
  • Conducting compliance reports for data processing in traditional and IT systems.
  • Documenting DPO activities.
  • Preparing audit reports.
  • Guidelines for supervising personal data processing documentation.
  • Powers of the Office for Personal Data Protection (UODO) concerning DPOs.

Practical Guide to Inspections by the Office for Personal Data Protection

  • Requirements imposed on audited entities.
  • Preparation strategies for inspections.
  • Case studies.

Hands-on Exercises

  • Drafting an exemplary Information Security Policy.
  • Developing management directives.
  • Creating a Record of Processing Activities (RoPA).
  • Preparing concise personal data protection documentation.
  • Case studies.
  • Identifying common errors in documentation preparation.

Supplementary Materials for Participants:

Useful Forms and Templates:

  • Consent for image use and dissemination.
  • Event newsletter subscription form.
  • Consent to receive offers.
  • Templates for sending offer emails.
  • Templates for general correspondence.
  • Example of a personal data protection policy.
  • Template for preparing information notices in accordance with GDPR, including instructions.
  • Risk analysis template.
  • Record of processing activities – template.
  • Register of processing categories – template.
  • GDPR Breach Log – Template.
  • GDPR Compliance Checklist Template.
  • Guidelines for handling personal data protection breaches.
  • Data Protection Breach Report Template.
  • Register of security incidents and corrective/preventive actions.
  • Corrections register.
  • Restorations register.
  • Model correction form.
  • Restoration pattern/form.
  • Model objection form.
  • Model contract for excluding further processing of personal data.
  • Sample consents for competitions, marketing, and publications.
  • Information obligation form for ferry crossings.
  • Information obligation form for meeting monitoring.
  • Information obligation form for recruitment processes.
  • Information obligation form for the National Revenue Administration.
  • LES information obligation form.
  • Public Procurement Law (UCoC) information obligation.
  • Labour Code information obligation.
  • Tax-related information obligation.
  • Employee personal data processing authorization – template with example.
  • Data subject breach notification – template.
  • Controller's Personal Data Processing Agreement – template.
  • Processor's Personal Data Processing Agreement.
  • And many more resources.

Requirements

Target Audience

  • Individuals currently beginning their role as Data Protection Officers.
  • Professionals scheduled to be appointed to this position in the near future.
 21 Hours

Number of participants


Price per participant

Testimonials (1)

Provisional Upcoming Courses (Require 5+ participants)

Related Categories