Who should use GDPR documentation work
Putting GDPR documentation in place makes sense for any organisation that collects personal data, whatever its size. A well drafted policy and sound procedures serve as the foundation of legal security, protect above all the people whose data is processed, and at the same time limit the exposure to administrative fines. The rules call less for a prohibition on processing than for transparency and order in what is actually done.
When the work becomes unavoidable
Documentation becomes necessary once an organisation starts to collect personal data systematically, including where this is only a list of clients, employees or interested parties. Procedures are best prepared from the outset, although they can also be organised while the business is running, ahead of the risk. Contracts with counterparties point the same way, since a partner is expected to keep control over the data entrusted to it.
Foreign groups operating in Poland
Where a Polish entity belongs to a foreign group, the documentation has to sit alongside the group standards already in place and reflect the flows of data between the entities. We map the roles of controller and processor, align the processing agreements with the arrangements adopted in the group, and prepare the Polish language versions of the information clauses used in relations with employees and clients.