All institutions in pre-school and school education, such as schools and kindergartens, are obliged to designate a Data Protection Officer (DPO), as they function as personal data controllers. This obligation arises from Article 37(1)(a) of Regulation (EU) 2016/679, as well as from § 1, item 17 of the Additional Provisions of the Personal Data Protection Act. The Commission for Personal Data Protection has also expressed the opinion that all schools and kindergartens must appoint a DPO.

It should be noted that the obligation to appoint a DPO applies to all types of schools and kindergartens – state, municipal and private. An exception is made only for private educational institutions whose principal activity does not require the expenditure of public funds.

Who can be a Data Protection Officer?

The DPO may be:

  • an internal employee of the educational institution, or
  • an external person or company with which a contract is concluded.

It is not mandatory for the school or kindergarten to appoint a dedicated employee for the position. It is possible for one of the current employees to take on the functions of a DPO while also performing other official duties, provided that this does not lead to a conflict of interest. For example, an employee whose work involves the processing of personal data cannot also perform the duties of a DPO.

Qualification and independence of the DPO

For the appointment of a DPO, there is no statutory requirement for a specific type or level of education. According to the General Data Protection Regulation, the only requirement is that the person possess expert knowledge in the field of personal data protection law and practices.

Another key requirement is that the person be independent of the controller. This independence ensures the effective performance of the DPO's functions. When an internal employee is appointed as a DPO, it is difficult to ensure such independence, since the employee is subordinate to the employer. In these cases, many institutions prefer to use an external DPO service.

Assigning DPO functions to an external company

Appointing an external company as a DPO has several advantages:

  • Costs of remuneration, social security contributions and training for an internal employee are saved;
  • The risk of resignation or absence due to illness or leave is eliminated;
  • Independence is guaranteed, since the external person has no direct interest connected with the organisation.
Main duties of the DPO

The Data Protection Officer has several key duties, including:

  • Informing and advising the controller and the employees engaged in data processing about their obligations under the statutory rules on personal data protection;
  • Monitoring compliance with personal data protection policies and procedures and organising training to raise awareness among employees;
  • Maintaining cooperation with the Commission for Personal Data Protection;
  • Acting as a contact point for the Commission for Personal Data Protection on matters relating to data processing, including prior consultations and other relevant matters.
Announcement of the DPO's contact details

Schools and kindergartens are obliged to publish the DPO's contact information and to submit it to the Commission for Personal Data Protection. This notification is filed in a standard form and, if filed electronically, must be signed with a qualified electronic signature.

The names and contact details of the DPO are entered in the public Register of controllers and processors of personal data who have designated a DPO. This register is maintained and published by the Commission for Personal Data Protection.

If you need consultation and assistance in the field of personal data protection, you can contact us on 0887550706 or by e-mail: [email protected]