Archive for: Polish Act on Protection of Personal Data

Personal data protection, case II SA/Wa 1009/11

December 28th, 2011, Tomasz Rychlicki

A Polish farmer who owns an agriculture tourism farm and is advertising his services and business on a personal website, has found negative comments about his services at one of the Internet forum websites. He asked the administrator of the forum to remove his personal data. Some posts have been removed, but the farmer has demanded the removal of all statements and comments, and the access to personal data of forum’s users. He requested the Inspector General for Personal Data Protection (GIODO) to order the forum administrator to remove all comments and to disclose all necessary personal data. The GIODO refused to issue such a decision and ruled that the farmer himself published such information as his name and address on his website in connection to the conducted economic activity. According to the GIODO, the processing of information on the farmer’s name on the Internet forum website, has its justification in Article 23(1)(v) of the Polish Act of 29 August 1997 on the Protection of Personal Data – PPD – (in Polish: Ustawa o ochronie danych osobowych), unified text published in Journal of Laws (Dziennik Ustaw) of 6 July 2002, No. 101, item 926, with subsequent amendments.

1. The processing of data is permitted only if:
1) the data subject has given his/her consent, unless the processing consists in erasure of personal data,
2) processing is necessary for the purpose of exercise of rights and duties resulting from a legal provision,
3) processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract,
4) processing is necessary for the performance of tasks provided for by law and carried out in the public interest,
5) processing is necessary for the purpose of the legitimate interests pursued by the controllers or data recipients, provided that the processing does not violate the rights and freedoms of the data subject.

According to the GIODO, the purpose of the legitimate interests is based on providing a service that allows for posting on the internet forum. The dissatisfied farmer filed a complaint against this decision.

The Voivodeship Administrative Court in its judgment of 16 November 2011 case file II SA/Wa 1009/11 dismissed it and decided that personal data published on a website that advertises agritourism services, are closely related to his business activities, and therefore subject to much weaker protection. These services may be subject to different assessments of people using them, there may be also some negative comments. The Court noted that the farmer could file a civil suit for the infringement of his interests against persons who wrote such comments.

Personal data protection, case I OSK 1208/10

July 11th, 2011, Tomasz Rychlicki

Katarzyna S. had a website where she published information on breeding dogs. There was also another forum with such information. Grzegorz W. was a dog breeder and he noticed that his personal data and information on his breeding appeared on this websites. Some users posted also negative comments. Grzegorz W. requested the Inspector General for Personal Data Protection (GIODO) to issue an administrative decision ordering the removal of his personal data and all threads and posts connected with his name. He also requested the GIODO to check whether Katarzyna S. as a controller has registered the collection of personal data that was gathered during the operation of her website and the forum.

GIODO learned that the forum website was administered by another person who claimed that the questioned website had nothing to do with her ​​professional activity, it was only a hobby. She never received any paid advertising, nor any funds from anyone. Moreover, she informed that the forum was removed from the net for several months. GIODO discontinued the proceedings. GIODO ruled that Katarzyna S. was not involved in the processing of personal data as a part of her business or professional activity. Jerzy W. filed a complaint against this decision.

The Voivodeship Administrative Court in its judgment of 14 April 2010 case file II SA/Wa 2130/09 ruled that dogs breeding may be directed to gain profits, because it can be associated with the sale of dogs. The Court decided that GIODO should reconsider the case. GIODO filed a cassation complaint.

The Supreme Administrative Court in its judgment of 28 June 2011 case file I OSK 1208/10 overturned the questioned judgment and sent the case back for reconsideration. The SAC ordered the VAC to examine whether the processing of personal data on the internet website had something to do with breeding activities.

Personal interest, case I OSK 1217/10

July 4th, 2011, Tomasz Rychlicki

The Inspector General for Personal Data Protection (GIODO) ordered Axel Springer Polska to disclose addresses of three authors who wrote a critical article in “Dziennik” newspaper about Polish businessman, however, information presented in the article proved to be incorrect. He wanted to sue all authors but Axel Springer refused to provide addresses, therefore, the lack of addresses of the defendants in the lawsuit was the reason for the civil court to dismiss the action.

Axel Springer Polska filed a complaint against the decision of the GIODO but the Voivodeship Administrtive Court in its judgment of 8 April 2010 case file II SA/Wa 1488/09 dismissed it. Axel Springer filed a cassation complaint.

The Supreme Administrative Court in its judgment of 18 June 2011 case file I OSK 1217/10 ruled that if the addresses of journalists are required to bring an action for the protection of personal interest, the publisher must disclose them to the requesting party.

Personal data protection, I OSK 1086/10

June 3rd, 2011, Tomasz Rychlicki

The Supreme Administrative Court in its judgment of 19 May 2011 case file I OSK 1086/10 acknowledged the principle that in case of a disclosure of personal data in the media, the press law and civil law regulations are applicable, and not the provisions of the Polish Act of 29 August 1997 on the Protection of Personal Data – PPD – (in Polish: Ustawa o ochronie danych osobowych), unified text published in Journal of Laws (Dziennik Ustaw) of 6 July 2002, No. 101, item 926, with subsequent amendments.

See also “Polish regulations on personal data protection” and “Polish case law on personal data protection“.

Personal data protection, case II SA/Wa 2037/10

May 12th, 2011, Tomasz Rychlicki

The Polish branch of McDonald’s Corp. has made a promotional campaign based on the issuance of the so-called “bonificards” i.e. discount cards entitling the holder to purchase certain McDonald’s products at a reduced price. Only employees and business partners were allowed to use such cards. The terms of the promotion explicitly stated that the cards cannot be resold. McDonald’s learned that cards were offered for sale or as a free bonus to other items sold on Allegro – Polish Internet auctions website.

McDonald’s requested Allegro to disclose personal data of persons engaged in the above mentioned auctions, on the grounds that these buyers and sellers violated the terms and rules of promotion, and thus McDonald’s intended to take steps to – on one hand – to deprive sellers of their wrongfully obtained benefits, on the other hand – to take away all bonificards from people who bought them. Allegro refused to provide requested data, indicating that there was no reason to assume that there was any kind of illegal action, arguing that disclosure may be classified as unlawful conduct of the controller that violates personal interests of the users and that may result in Allegro’s responsibility that is based on civil law regulations.

McDonald’s requested the Inspector General for Personal Data Protection to order Allegro the disclosure of information previously requested. The GIODO refused and pointed out that in this case the interests of McDonald’s cannot prevail over the interests of persons affected by the request. The disclosure of such data would be, in fact, too far-reaching interference with the privacy of the person concerned. McDonald’s filed a complaint against these decisions.

The Voivodeship Administrative Court in Warsaw in its judgment of 16 March 2011 case file II SA/Wa 2037/10 overruled GIODO’s decisions. The VAC held that McDonald’s has the right to know who offers promotion cards at online auctions provided by Allegro. The Court ruled that the provisions of the PPD cannot be interpreted as meaning that the disclosure of personal data of a person who offer to sell someone else’s property, violates that person’s interests. The protection of interests of one person cannot be done without prejudice to the rights of others. Especially, when such persons knew that they were trying to dispose of someone’s else things whose value was measured in money (the value of the Company’s products that were available in the promotional terms). The court ordered to reconsider the case, where the GIODO shall take into account all comments made ​​by the VAC. The GIODO decided to file a cassation complaint.

The Supreme Administrative Court in its judgments case files I OSK 834/11 and I OSK 1137/11 agreed with the GIODO. The Court held that in the case of electronic services, personal data may be disclosed only for the purposes of criminal proceedings.

See also “Polish regulations on personal data protection” and “Polish case law on personal data protection“.

Personal data protection, case II SA/Wa 1212/10

February 4th, 2011, Tomasz Rychlicki

The case of Tomasz W. and his image treated as personal data still continues. See “Personal data protection, case I OSK 667/09“. GIODO annulled its earlier decision, however it also refused to take account Tomasz W. requests in its new decision. GIODO ruled that personal data (photos and captions) of Tomasz W. are not presented on the website, and are not publicly available because they were removed from the specified address. GIODO also noted that Nasza-Klasa is still processing the personal data treating it as evidence, because it keeps them on its servers and in the system’s memory. GIODO finally held that the Company, as controller, is processing these data under provisions of Article 23(1)(v) of the PPD, under which such the processing of data is permitted because it is necessary for the purpose of the legitimate interests pursued by the controller and that the processing does not violate the rights and freedoms of the data subject. Among the reasons justifying the data processing, GIODO mentioned the possibility of establishing the responsibility of the recipient for violations of the Terms of Service that were set by the Company. This judgment is not final yet. GIODO filed a cassation complaint.

The Voivodeship Administrative Court in Warsaw in its judgment of 1 December 2010 case file II SA/Wa 1212/10 ruled that, these circumstances do not fulfill the conditions for legitimate interests of data processing. It should be noted that the condition relates to the existing and unquestionable situation, so if there is a need to demonstrate a need to claim in business, not a situation where the data are processed for eventual trial and the possible need to prove that personal data obtained without the consent of the person concerned shall be processed in accordance with the law. The Court also noted that Tomasz W. only announced but he did not initiate any courts proceedings against Nasza-Klasa. Therefore, according to the Court, Nasza-Klasa was not allowed to process personal data only to protect itself against any future and uncertain claims mentioned by Tomasz W. Otherwise, there are doubts how long to process personal data if Tomasz W. fails to comply with his announcement.

See also “Polish regulations on personal data protection” and “Polish case law on personal data protection“.

Personal data protection, case DOLiS/DEC-1013/10 concerning DOLiS-440-276/10

September 27th, 2010, Tomasz Rychlicki

The Inspector General for Personal Data Protection (GIODO) in its decision of 13 September 2010 case file DOLiS/DEC-1013/10 concerning DOLiS-440-276/10 ruled that according to the wording of Article 18(1) pt 2 of the Polish Act of 29 August 1997 on the Protection of Personal Data – PPD – (in Polish: Ustawa o ochronie danych osobowych), unified text published in Journal of Laws (Dziennik Ustaw) of 6 July 2002, No. 101, item 926, with subsequent amendments, in the event of the breach of provisions on personal data protection, the GIODO ex officio or at the request of the person concerned, by an administrative decision, shall order the restoration of the situation in accordance with the law and, in particular, to complete, update correct, disclose or not to disclose of personal data.

Article 18
1. In case of any breach of the provisions on personal data protection, the Inspector General ex officio or upon a motion of a person concerned, by means of an administrative decision, shall order to restore the proper legal state, and in particular:
1) to remedy the negligence,
2) to complete, update, correct, disclose, or not to disclose personal data,
3) to apply additional measures protecting the collected personal data,
4) to suspend the flow of personal data to a third country,
5) to safeguard the data or to transfer them to other subjects,
6) to erase the personal data.
2. The Inspector General’s decisions referred

Given the circumstances of the case, the GIODO considered that he is authorized – by the established rules – to order the Company to disclose to the applicant information about a person who, on in 2010, at 20:29 had registered on www.gowork.pl web portal using the nickname “anonymous”, i.e. information about IP address of a computer used to post the questioned entry.

See also “Polish regulations on personal data protection” and “Polish case law on personal data protection“.

Personal interest, case I C 144/10

August 15th, 2010, Tomasz Rychlicki

A Polish citizen filed a civil suit against Nasza Klasa company – the owner and operator of social networking website. He seek an apology and a payment for the infringement of his personal interest by the fact that Nasza Klasa refused to provide the plaintiff with personal data of the person who set up a fake profile, and allowed for the creation of such a profile, which was finally closed after several unsuccessful requests.

The Inspector General for Personal Data Protection in its decision of 5 March 2010 ordered Nasza Klasa to provide the plaintiff with information (full name, address, e-mail and IP address of a computer) of the person who set up the profile of the YYY number on nasza-klasa.pl website, ordering at the same time, to fulfill the obligation referred to in Article 33(1) of the Polish Act of 29 August 1997 on the Protection of Personal Data – PPD – (in Polish: Ustawa o ochronie danych osobowych), unified text published in Journal of Laws (Dziennik Ustaw) of 6 July 2002, No. 101, item 926, with subsequent amendments.

Article 33
1. At the request of the data subject, within the period of 30 days, the controller shall be obliged to notify the data subject about his/her rights, and provide him/her with the information referred to in Article 32 paragraph 1 point 1-5a as regards his/her personal data, and in particular specify in an intelligible form:
1) the category of personal data contained in the file,
2) the means of data collection,
3) the purpose and the scope of data processing,
4) the recipients of the data and the scope of access they have been granted.

While executing this decision Nasza Klasa informed the plaintiff that the fictional profile was set up on behalf of a person of a first name “s d.”, the second name “w. I’m gay”, having e-mail address xyz@wp.pl. At the same time the company informed the plaintiff that it has no data with regard to IP addresses from which the profiles are set on its website, these data are not collected, and kept or archived. However, as it was also clear from the order of the District Court in Poznań of 16 June 2010 on an ongoing parallel criminal proceedings that Nasza Klasa provided the Police with the IP number, host and e-mail address of the person who has registered this fictitious profile containing personal information of the plaintiff.

The District Court in Wrocław in its judgment of 23 July 2010 case file I C 144/10 ruled that the way that Nasza Klasa has executed the decision bears hallmarks of malignancy, where the repetition of the contents of the fake profile certainly violated the plaintiff’s dignity. The Court noted also that the activity of Nasza Klasa which allows its users for the opening of online accounts, including fictitious accounts does not have the characteristics of illegality. Therefore, the plaintiff was not allowed to infer the responsibility of Nasza Klasa, because during the use of legal mechanisms, there was an infringement of his personal interests. In other words, the illegal nature has only the act of the direct infringer – an unknown person who registered fictional profile on nasza-klasa.pl website, that was containing personal information of the plaintiff, including his image, in the context of information insulting him.

The mere creation of a registration/login mechanism within defendant’ hosting services, without any specific negligence in the performance of duties imposed by law cannot justify the defendant’s liability for the infringement of personal rights of the plaintiff. According to the Court such reasoning would justify shifting the liability of the direct offender of personal right to the hosting service provider.

The Court, held that Nasza Klasa committed a violation of personal rights by refusing to grant the plaintiff an access to personal data of the person who set up a fake profile infringing on his personal interest and being opprobrious to his identity, despite the fact that the plaintiff was entitled to obtain it, which was confirmed by final decision of the GIODO. The Court ruled that Nasza Klasa company as a professional hosting provider, which created and maintains a social networking website – in accordance with its TOS – should be aware of how the decision of Inspector General for Personal Data Protection should be executed. Moreover, Nasza-Klasa was aware of the circumstances of the plaintiff’s case, which lasted almost a year. At that time, the plaintiff has shown a determination to assert his rights, despite the fact that without a personal data of the offender, has repeatedly been put in a kind of a hopeless situation, not only by law enforcement, but also by Nasza-Klasa company. Since Nasza-Klasa did not have the name of the person who registered the fictitious profile with the data of the plaintiff, it shall inform the plaintiff and explain the problem and execute the decision of the GIODO with regard to available data (IP, e-mail address of the perpetrator). Nasza Klasa decided to file an appeal complaint. The Appelatte Court in Wrocław in its judgment of 18 Nobember 2010 case file I ACa 1129/10 reversed the previous judgment and dismissed the suit.

Telecommunications law, case I OSK 1079/10

August 3rd, 2010, Tomasz Rychlicki

This is the continuation of a story described in “Personal data protection, case II SA/Wa 1598/09“. The Supreme Administrative Court in its order of 15 July 2010 case file I OSK 1079/10 decided to stay the execution of the decision issued by the Inspector General for Personal Data Protection (GIODO) and ruled that the Polish Act of 16 July 2000, Telecommunications Law – TLA – (in Polish: Prawo telekomunikacyjne), published in Journal of Laws (Dziennik Ustaw) No 171, item 1800 with subsequent amendments, provides broader protection of personal data because of telecommunications confidentiality, than the provisions of the Act of 29 August 1997 on the Protection of Personal Data – PPD – (in Polish: Ustawa o ochronie danych osobowych), Journal of Laws (Dziennik Ustaw) of 29 October 1997, No. 133, item 883, unified text published in Journal of Laws (Dziennik Ustaw) of 6 July 2002, No. 101, item 926, with subsequent amendments.

The Court held that the disclosure of IP addresses which enable identification of specific individuals, that was ordered during administrative proceedings initiated with regard to disclosure of such data, while such proceedings did not ended with judgment in force, may violate the provisions of Article 160 of the TLA.

Article 160.
1. An entity participating in the performance of telecommunications activities within public networks and entities cooperating with it shall keep the telecommunications confidentiality.
2. Entities referred to in paragraph 1 shall maintain due diligence, within the scope justified by technical or economic reasons, while securing telecommunications equipment, telecommunications networks and data collections from disclosing the telecommunications confidentiality.
3. A person coming into possession of a message not meant to be read by him/her when using radio or terminal equipment shall keep the telecommunications confidentiality. The provisions of Article 159 (3) and (4) shall respectively apply.
4. The recording of a message acquired in a manner described in paragraph 3 by a body executing control of telecommunications activities in order to document a violation of a provision of the Act, shall not be a violation of the telecommunications confidentiality.

While assessing the validity of the request to stay the execution of GIODO’s decision to disclose the requested IP address at this stage of proceedings, the Court agreed with the author of the cassation complaint, that the execution of the questioned decision at this stage makes it impossible to reverse the actions taken after the disclosure of the IP addresses, and such action should be seen as causing the effects that are difficult to reverse according to Article 61(3) of the Act on the Law on proceedings before administrative courts – PBAC – (in Polish: Prawo o postępowaniu przed sądami administracyjnymi) of 30 August 2002, Journal of Laws (Dziennik Ustaw) No 153, item 1270, subsequent later amendments.

§ 1 Filing a complaint does not stay the execution of the act or actions.

(…)

§ 3 After the delivery of a complaint to the court, the court may issue at the request of the applicant, the order to stay the execution, in whole or in part of the act or actions referred to in § 1, if there is a risk of causing significant damage or cause to be difficult to reverse, with the exception of the provisions of local law which entered into force, unless the special Act excludes the stay of their execution. The refusal to stay the execution of the act or actions by the authority, does not deprive the applicant of action to the court. This also applies to acts issued or adopted in all proceedings conducted within the same case.

The SAC held that if the Supreme Administrative Court would agree with the cassation complaint filed against the judgment of the Voivodeship Administrative Court of 3 February 2010 case file II SA/Wa 1598/09, the effects of the execution of the questioned decision could not be reversed, because the IP address identifying a specific person is available to another participant in the proceedings. Accordingly, the court held that the correct solution at this stage of proceedings, is to stay the execution of the questioned decision also with a view to the impact of which its execution might result in, as well as the nature of the protection of personal data resulting from the relevant regulations such as, inter alia, the TLA.

See also “Polish regulations on personal data protection” and “Polish case law on personal data protection“.

Personal data protection, case I OSK 756/09

July 11th, 2010, Tomasz Rychlicki

A former entrepreneur (natural person) requested a telecommunications company to remove his personal data that were used for marketing purposes. The company did not want to take into account the above-mentioned demands, arguing that the rights provided in Article 33 of the Polish Act of 29 August 1997 on the Protection of Personal Data – PPD – (in Polish: Ustawa o ochronie danych osobowych), unified text published in Journal of Laws (Dziennik Ustaw) of 6 July 2002, No. 101, item 926, with subsequent amendments, are not afforded for persons who perform or performed professional business activity (entrepreneurs).

Article 33
1. At the request of the data subject, within the period of 30 days, the controller shall be obliged to notify the data subject about his/her rights, and provide him/her with the information referred to in Article 32 paragraph 1 point 1-5a as regards his/her personal data, and in particular specify in an intelligible form:
1) the category of personal data contained in the file,
2) the means of data collection,
3) the purpose and the scope of data processing,
4) the recipients of the data and the scope of access they have been granted.
2. At the request of the data subject, the information referred to in paragraph 1 shall be given in writing.

The Supreme Administrative Court in its judgment of 15 March 2010 case file I OSK 756/09 held that provisions of Article 6 of the PPD does not differentiate the rights of individuals, depending on whether they are performing business activity or not. In this situation, there was no reason to exclude information about natural persons conducting business/economic activity from the protection guaranteed by the PPD.

Article 6
1. Within the meaning of the Act personal data shall mean any information relating to an identified or identifiable natural person.
2. An identifiable person is the one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his/her physical, physiological, mental, economic, cultural or social identity.
3. A piece of information shall not be regarded as identifying where the identification requires an unreasonable amount of time, cost and manpower.

See also “Polish regulations on personal data protection” and “Polish case law on personal data protection“.

Personal data protection, case I OSK 963/09

May 13th, 2010, Magdalena Gad

The Supreme Administrative Court in a judgment of 11 May 2010, case file I OSK 963/09, held that an editorial office would have to disclose private addresses of the journalists it employs. Presspublica – the publisher of “Rzeczpospolita” should disclose the private addresses of those of the journalists, who its readers intend to sue in court for the infringement of their personal rights. This decision is binding on all media. The SAC referred to article 29 of the Polish Act of 29 August 1997 on the Protection of Personal Data – PPD – (in Polish: Ustawa o ochronie danych osobowych), Journal of Laws (Dziennik Ustaw) of 29 October 1997, No. 133, item 883, unified text published in Journal of Laws (Dziennik Ustaw) of 6 July 2002, No. 101, item 926, with later amendments.

1. In case of providing the access to the data for the purposes other than including into the data filing system, the controller shall disclose the data kept in the data filing system to persons or subjects authorised by the law.
2. Personal data, exclusive of data referred to in Article 27 paragraph 1, may also be disclosed, for the purposes other than including into the data filing system, to persons and subjects other than those referred to in paragraph 1 above, provided that such persons or subjects present reliably their reasons for being granted the access to the data and that granting such access will not violate the rights and freedoms of the data subjects.
3. Personal data are disclosed at written and justified requests, unless the provisions of another law state otherwise. Such requests should include information allowing for identification of the requested personal data within the filing system and indicating their scope and purpose.
4. Disclosed personal data shall be used only pursuant to the purpose for which they have been disclosed.

The decision is especially dangerous to media. Why? Because in a situation, where anyone can request the disclosure of the journalists’ personal data (justifying it i.e. with the intent to file a civil lawsuit against them) those journalists can find themselves in a real and tangible danger posed by the unpredictable readers, bashed by the newspaper. In the case at hand, Krzysztof W. requested the addresses of the authors of the article published in Rzeczpospolita in 2007 in order to sue them in court for the infringement of his personal rights.

The court rejected his lawsuit, requesting that the plaintiff provide the most recent residential addresses of the defendants. The publisher refused to disclose the addresses, citing the provisions of the Press Law and stressing the importance of the right to privacy. It also pointed out the alternative manners of serving the lawsuit (at the defendants’ business address). Nonetheless, the General Inspector for the Protection of Personal Data disagreed with the publisher and obliged it to promptly disclose the data in question. The VAC in Warsaw dismissed the appeal and the SAC rejected the cassation claim, stating that the readers cannot be deprived of the possibility to defend their rights before courts merely because the personal data of the infringers remains unavailable.

See also “Polish regulations on personal data protection“, “Polish case law on personal data protection

Personal data protection, case I OSK 633/08

March 11th, 2010, Tomasz Rychlicki

The Supreme Administrative Court in its judgment of 3 July 2009 case file I OSK 633/08 held that the processing/storage/retention of personal data in backup copies of bank’s IT system is nothing but the processing of these data, and such processing is possible only in all cases defined by the provisions of the Polish Act of 29 August 1997 on the Protection of Personal Data – PPD – (in Polish: Ustawa o ochronie danych osobowych), unified text published in Journal of Laws (Dziennik Ustaw) of 6 July 2002, No. 101, item 926, with subsequent amendments. In case, where the credit agreement was not concluded, the processing of personal data in backup copies has no justification in the provisions of the PPD and there is no such situation as referred in Article 26 of the PPD.

Article 26
1. The controller performing the processing of data should protect the interests of data subjects with due care, and in particular to ensure that:
1) the data are processed lawfully,
2) the data are collected for specified and legitimate purposes and no further processed in a way incompatible with the intended purposes, subject to the provisions of paragraph 2 below,
3) the data are relevant and adequate to the purposes for which they are processed,
4) the data are kept in a form which permits identification of the data subjects no longer than it is necessary for the purposes for which they are processed.
2. The processing of data, for the purpose other than intended at the time of data collection is allowed provided that it does not violate the rights and freedoms of the data subject and is done:
1) for the purposes of scientific, didactic, historical or statistical research,
2) subject to the provisions of Article 23 and Article 25.

The SAC also ruled that such processing is also not justified by the provisions of the Act on Banks Law.

See also “Polish regulations on personal data protection” and “Polish case law on personal data protection“.

Who is the controller in social networking sites?

February 14th, 2010, Tomasz Rychlicki

The question of who is the “controller” and the differences between a “controller” and “processor” as defined in the article 2(d) and (e) of the Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, in the context of social networking sites (SNS), are at least controversial not only in Polish case law. See for instance T. Zeggane, W. Maxwell, US and EU Authorities Review Privacy Threats On Social Networking Sites, Ent. L.R. 2008, 19(4), 69-74.

The second area requiring clarification is the concept of “data controller” in an SNS environment. Under European privacy law, the controller is the entity which determines the purposes and means of the processing of personal data. In an SNS context, there are two broad categories of data: the information that the user provides to the SNS platform to register (such as the user’s real name and email address), and the data that the user uploads onto his or her profile. The former is personal data which the SNS platform controls. The latter is “user generated content”, which the user controls and can choose to share (or not) with others. Some SNS platforms provide the user with tools to control the extent to which information such as photos, personal tastes and the like are used to develop targeted advertising. Where such tools exist, the argument can be made that the user (and not the SNS platform itself) is the “controller” of the content the user uploads onto the profile. The concept of data controller is the cornerstone of European privacy law. The concept of controller as it is traditionally interpreted does not fit easily into the SNS environment, where the user is the focal point

As you can read from the above, the authors suggest that the situation requires a clarification of the concept of “controller” in terms of SNS. A similar view was also presented in the report of the European Network and Information Security Agency (ENISA), “Security Issues and Recommendations for Online Social Networks“, PDF file, p. 25.

See also “Polish regulations on personal data protection” and “Polish case law on personal data protection“.

Personal data protection, case I OSK 667/09

February 13th, 2010, Tomasz Rychlicki

On 15 January 2008, Tomasz W. filed with the General Inspector for Personal Data Protection (GIODO) a complaint concerning an unauthorized processing of personal data carried out by the Polish company Nasza Klasa Sp. z o.o. from Wroclaw, the owner of nasza-klasa.pl website. He informed the GIODO, that this very popular Polish website on classmates, hosts a photo featuring his image together with a list of names of other photographed people attached to it. Tomasz W. has repeatedly appealed to the website administrators with the request to remove his name from the list. However, he received no response from Nasza Klasa company.

As a result of the investigation, the GIODO found that on 31 December 2007, a registered user of nasza-klasa.pl posted classmates’ photo featuring students of a primary school. On the same day, another registered user, placed the names of people who were portrayed at the photograph – including the name and surname of Tomasz W. On 2, 9 and 14 January 2008, Tomasz W. requested Nasza Klasa Sp. z o.o. the removal of his personal data.

In a decision of 27 May 2008, case file DOLiS/DEC-314/08/13239, the GIODO, relying on the provisions of the Polish Act of 29 August 1997 on the Protection of Personal Data – PPD – (in Polish: Ustawa o ochronie danych osobowych), Journal of Laws (Dziennik Ustaw) of 29 October 1997, No. 133, item 883, unified text published in Journal of Laws (Dziennik Ustaw) of 6 July 2002, No. 101, item 926, with later amendments, ruled that information on the applicant’s full name, school and class to which he attended, together with his image, are personal data and the data collector is Nasza Klasa Sp. z o.o.

However, the GIODO also ruled that it should be borne in mind that according to the provision of the Polish Act of 18 July 2002 on Providing Services by Electronic Means – PSEM – (in Polish: ustwa o świadczeniu usług droga elektroniczną), Journal of Laws (Dziennik Ustaw) No. 144, item. 1204, as amended, Nasza Klasa sp. z o.o. provides electronic services for registered users of the portal website, consisting of the storage of data of these users in the computer system. This activity is the condition to legalize the processing of personal data in accordance with article 23(1) pt. 5 of the PPD. In addition, the GIODO found that in this case the applicant’s rights have not been violated, because the access to its data was limited to a group of people registered on nasza-klasa.pl website.

Tomasz W. asked the GIODO for the retrial. He pointed out that the reasons for the decision have many contradictions, inconsistencies and is ambiguous. He accused the GIODO of laconic and cursory treatment of his case. He again emphasized that his personal data have been published on the nasza-klasa.pl website without his knowledge or consent, in violation of his civil rights and liberties.

After the rehearing of the case, the GIODO annulled the contested decision, and discontinued the proceedings. GIODO claimed that the re-examination of the case leads to the conclusion that the disputed information about Tomasy W. did not fall within the definition of personal data. The name and surname have been given under his old image from many years ago. Hence, the combination of photos from the past, with a name and surname of a person and a primary school, which such person attended did not allow for the identification of a person without excessive costs and time. The findings that the disputed information is not personal data within the meaning of the PPD caused the proceedings in the matter to be groundless and on the basis of article 105 § 1 of the APC, it had to be discontinued.

Tomasz W. lodged a complaint with the Viovodeship Administrative Court (VAC) in Warsaw. The complainant asked for annulment of the decision of first and second instance. Tomasz W. claimed the violation of the substantive law, i.e. article 6(1) of the PPD, through its improper interpretation, of article 32(1) pt 7 and 8 of that Act, by recognizing that Tomasz W. is not entitled to request cessation of the processing of his data and the right to object, and a breach of article 7 of the APC by not explaining all the relvant facts. Tomasz W. disagreed with the statement of the GIODO that questioned information about his person is not personal data within the meaning of the PPD. He stated that any information about an identified or identifiable individual is personal data. Furthermore, he argued that the claim of the GIODO that the data are available only for specific people – registered users of the portal is not acceptable, because nasza-klasa.pl has no mechanisms for verification of users identity, which makes the questioned data easily accessible for everyone. Moreover, Tomasz W. also argued that a registered user who does not know him would have some difficulty in identifying his person but such obstacles would not happen to a person who knows about Tomasy W., and is looking for additional information.

The Voivodeship Administrative Court in a judgment of 3 March 2009 case file II SA/Wa 1495/08 ruled that the GIODO erred in its decisions, because information about the name and surname of Tomasz W., combined with information about the name and address of the primary school and the determination of the class to which he attended in 1978/79, even if it was thirty years ago, are personal data. According to the Court provisions of article 1 of the PPD introduced the principle of autonomy of human information, meaning the protection of information about human being. This provision is a kind of emanation of the general right guaranteed by the Polish Constitution in article 47, according to which “Everyone shall have the right to legal protection of his private and family life, of his honour and good reputation and to make decisions about his personal life”. This means that the protection of personal data is related to the protection of privacy rights. This follows from the wording of article 6 of the PPD, indicating that the personal data concern identified or identifiable natural or legal person and that the identifiable is a person is one whose identity can be determined. From wording of that provisions the VAC concluded that personal data are data that identify a person’s identity.

The VAC also relied on the content of recital 12 of the Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, which emphasized the protection of all data relating to a person, and therefore also information about someones past.

(12) Whereas the protection principles must apply to all processing of personal data by any person whose activities are governed by Community law; whereas there should be excluded the processing of data carried out by a natural person in the exercise of activities which are exclusively personal or domestic, such as correspondence and the holding of records of addresses

However, in recital 26 of the abovementioned Directive states that data protection rules must apply to any information concerning an identified or identifiable person. In order to determine whether a person is identifiable, all the means which can be used by the controller or any other person to identify a person, should be taken into the account. The rules of data protection do not apply to data rendered anonymously in such a way that a subject of the data can not be identified. The identification of a given person concerns also past information about a specific human being, by which information one can learn about such person’s identity. Accordingly, the VAC held that European law means the protection of personal data as the protection of all the facts concerning the past of a particular person, which corresponds with the content of article 6(2) of the PDP. So this means that such data would also be protected.

Referring to the foregoing facts of Tomasz W. case, the VAC ruled that that nasza-klasa.pl website published his image and name. In the opinion of the court these are the personal data which are protected by the PPD, because on their basis one is able to identify given person.

Nasza Klasa sp. z o.o. filed a cassation complaint with the Supreme Administrative Court (SAC) challenging in entirety the judgment of the VAC. The Supreme Administrative Court in a judgment of 18 November 2009, case file I OSK 667/09, rejected the complaint. The SAC held that the primary issue arising in this case was whether a classmates’ picture that was taken thirty years ago, at which Tomasz W. is potrayed, in the circumstances of the case, can be analyzed to determine his identity without necessarily involving excessive resources or time, and therefore, whether the data disclosed in the photo in question, constitutes personal data within the meaning of article 6 of the PPD, and whether it should be protected.

The concept of “personal data” on the Polish law includes any information concerning an individual if it is possible to define its identity and its identification. Personal data is a set of messages about a particular person such integrated that it allows for its individualization. It includes at least information necessary for identification (name, surname, place of residence), but this is not restricted, because it also include further information, strengthening the degree of identification. Such information will also include pictures of the individual, even if they were taken in the past, allowing to identify a person. In a situation where such a photograph is presented with a name and surname of the person portrayed, in a place accessible to an unlimited number of entities, it must be considered that it constitutes personal data subject to protection under the PPD. Mainly, the objective evaluation criteria decides for the qualification of given information as personal data, but it also should comprise of all information, including extralinguistic (context), to which third party may have or has an access. A different approach to the presented issues would maginalize the importance of the laws and it would not relate to its designated function.

Thus it should be considered that the image of Tomasz W. portrayed at the photograph that was taken 30 years ago, affixed with the class, his name and surname, and then published at nasz-klasa.pl website constitutes personal data within the meaning of article 6(2) of the PPD, and the cassation complaint was not justified. The SAC also noted that the consent for the processing of personal data cannot be in any way implied.

The SAC also stressed the fact the Internet as a source of information is increasing on a unknown scale and importance. It provides an access to specific information to a vast number of persons and allows for any of its processing within the meaning of the PPD. At the same time there are not yet developed appropriate mechanisms for the protection of individual rights when those rights have been violated as a result of the disclosure of information on the Internet. Then, it is a great role of law enforcement bodies, including the Inspector General for Personal Data Protection in creating practice to comply with applicable laws also on the Internet. It is an unacceptablr situation in which the entity seeks to remove its image from a particular website, and the administration fails to take action to ensure the protection of civil rights. The image is one of the very personal property rights and lack of consent to its publication, if it is not a public person, is a sufficient reason to believe that regulations of the PPD apply, if the conditions set in the article 6(2) of the PPD have been met. There is a legal sequel to this story. See “Personal data protection, case II SA/Wa 1212/10“.

See also “Polish regulations on personal data protection” and “Polish case law on personal data protection“.

Personal data protection, case II SA/Wa 71/07

February 12th, 2010, Tomasz Rychlicki

A lawyer representing one Polish entrepreneur, and as you already know personal data of the parties are removed from Polish courts’ judgments, requested the General Inspector for Personal Data Protection (GIODO) to issue an order to Home.pl company from Szczecin, to disclose personal data such as name, surname, the firm, address, office’s seat, phone number and e-mail address of a person, which had only published its caller id, and who registered a certain Internet domain name. The lawyer stated that his client is claiming the right to use the questioned domain name and the requested information is necessary for the initation of the arbitration proceedings before the Court of Conciliation at the the Polish Chamber of Information Technology and Telecommunications.

Home.pl refused to provide the abovementioned personal data, arguing that the parties of the legal relationship arising from the fact of the registration and maintenance of Internet domain names are the Research and Academic Computer Network (in Polish: Naukowa i Akademicka Sieć Komputerowa) – the national registry of the .pl domain, and the domain name subscriber.

The GIODO performed an investigation based on the administrative proceedings regulations. The GIODO did an inspection of the Company’s headquarters and found that Home.pl maintains a separate collection of data of subscribers who have registered their domain names in NASK through Home.pl services. NASK is the national domain name registrar, while Home.pl arranges for the registration and maintenance of Internet domain names. Home.pl represents an applicant for the domain name registration before NASK. A natural or legal person and Home.pl have to establish a legal relationship based on a registration contract in order to register the domain name in NASK. The legal relationship is based on registering and maintaining of the internet domain name. The GIODO found that in this case, the contested domain name was registered by a natural person.

In September 2006, the General Inspector for Personal Data Protection issued an administrative decision which ordered Home.pl to disclose personal data of the individual who registered the Internet domain name in question, the name, surname, address, phone number and e-mail address. Home.pl requested for a retrial of the case. The GIODO upheld the decision and Home.pl filed a complaint with the Voivodeship Administrative Court (VAC) in Warsaw.

The Court in a judgment of 30 Novmeber 2007, case file II SA/Wa 71/07 ruled that the complaint was based on articles 29(2) in connection with article 22 of the Polish Act of 29 August 1997 on the Protection of Personal Data – PPD – (in Polish: Ustawa o ochronie danych osobowych), Journal of Laws (Dziennik Ustaw) of 29 October 1997, No. 133, item 883, unified text published in Journal of Laws (Dziennik Ustaw) of 6 July 2002, No. 101, item 926, with later amendments.

Article 29
1. In case of providing the access to the data for the purposes other than including into the data filing system, the controller shall disclose the data kept in the data filing system to persons or subjects authorised by the law.
2. Personal data, exclusive of data referred to in Article 27 paragraph 1, may also be disclosed, for the purposes other than including into the data filing system, to persons and subjects other than those referred to in paragraph 1 above, provided that such persons or subjects present reliably their reasons for being granted the access to the data and that granting such access will not violate the rights and freedoms of the data subjects.
3. Personal data are disclosed at written and justified requests, unless the provisions of another law state otherwise. Such requests should include information allowing for identification of the requested personal data within the filing system and indicating their scope and purpose.
4. Disclosed personal data shall be used only pursuant to the purpose for which they have been disclosed.
(…)
Article 22
The proceedings with respect to the matters regulated by this Act shall be conducted pursuant to the provisions of the Code of Administrative Procedure, unless other provisions of the law state otherwise.

According to the VAC, provisions of article 29(1) and (2) allow third parties to request the disclosure of personal data for purposes other than inclusion in the collection. It should be noted that these provisions being in force until 1 May 2004, gave no grounds to demand the disclosure if the controller was the private sector. This situation changed after the amendment of 22 January 2004.

The VAC noted that the request for disclosure of personal data may be filed by any person i.e. natural person, any organizational unit, both public and private. It is important that the possesion of personal data is necessary to achieve intended goals, and the request for personal data is credible and reasonable. Such request does not require a collector to disclosure personal data because it must assess whether the conditions have been met to provide such data according to provisions of articles 29 of the PPD.

1. In case of providing the access to the data for the purposes other than including into the data filing system, the controller shall disclose the data kept in the data filing system to persons or subjects authorised by the law.
2. Personal data, exclusive of data referred to in Article 27 paragraph 1, may also be disclosed, for the purposes other than including into the data filing system, to persons and subjects other than those referred to in paragraph 1 above, provided that such persons or subjects present reliably their reasons for being granted the access to the data and that granting such access will not violate the rights and freedoms of the data subjects.
3. Personal data are disclosed at written and justified requests, unless the provisions of another law state otherwise. Such requests should include information allowing for identification of the requested personal data within the filing system and indicating their scope and purpose.
4. Disclosed personal data shall be used only pursuant to the purpose for which they have been disclosed.

However, the VAC stressed that fact that collector’s discretion cannot mean its arbitrariness. In the case of the unfounded refusal to provide personal data according article 29 (2) of the PPD, the General Inspector for Personal Data Protection shall have the right – in accordance with article 18(1) pt. 2 of the PPD – to require the disclosure of personal data.

1. In case of any breach of the provisions on personal data protection, the Inspector General ex officio or upon a motion of a person concerned, by means of an administrative decision, shall order to restore the proper legal state, and in particular:
(…)
2) to complete, update, correct, disclose, or not to disclose personal data,

Undoubtedly, the request for the disclosure of personal data must be credible and legitimate. Thus, if such request is do not precluded by provisions of article 27 of the PPD, the collector must disclose such data.

1. The processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, religious, party or trade-union membership, as well as the processing of data concerning health, genetic code, addictions or sex life and data relating to convictions, decisions on penalty, fines and other decisions issued in court or administrative proceedings shall be prohibited.
2. Processing of the data referred to in paragraph 1 above shall not constitute a breach of the Act where:
1) the data subject has given his/her written consent, unless the processing consists in erasure of personal data,
2) the specific provisions of other statute provide for the processing of such data without the data subject’s consent and provide for adequate safeguards,
3) processing is necessary to protect the vital interests of the data subject or of another person where the data subject is physically or legally incapable of giving his/her consent until the establishing of a guardian or a curator,
4) processing is necessary for the purposes of carrying out the statutory objectives of churches and other religious unions, associations, foundations, and other non-profitseeking organisations or institutions with a political, scientific, religious, philosophical, or trade-union aim and provided that the processing relates solely to the members of those organisations or institutions or to the persons who have a regular contact with them in connection with their activity and subject to providing appropriate safeguards of the processed data,
5) processing relates to the data necessary to pursue a legal claim,
6) processing is necessary for the purposes of carrying out the obligations of the controller with regard to employment of his/her employees and other persons, and the scope of processing is provided by the law,
7) processing is required for the purposes of preventive medicine, the provision of care or treatment, where the data are processed by a health professional subject involved in treatment, other health care services, or the management of health care services and subject to providing appropriate safeguards,
8) the processing relates to those data which were made publicly available by the data subject,
9) it is necessary to conduct scientific researches including preparations of a thesis required for graduating from university or receiving a degree; any results of scientific researches shall not be published in a way which allows identifying data subjects,
10) data processing is conducted by a party to exercise the rights and duties resulting from decisions issued in court or administrative proceedings.

The VAC had to consider the question of whether the application met the conditions set in article 29 of the PPD. The Lawyer proved that, the disclosure of personal data of a person who registered the disputed domain because was necessary for the initation of the arbitration proceedings before the Court of Conciliation at the the Polish Chamber of Information Technology and Telecommunications. The Court noted that the arbitration proceedings are held in accordance with article 1188 § 1 of the Civil Proceedings Code – CPC (in Polish: Kodeks Postępowania Cywilnego) of 17 November 1964, Journal of Laws (Dziennik Ustaw) No 43, item 296, with later amendments.

The proceedings before the Court of Conciliation starts with the lodging of the statement of claim (the suit), which means that the suit should comply with the conditions laid down in article 187 § 1 of the CPC. Under that provision, the statement of claim should meet the requirements of the pleading, and it also shall include: clearly defined demand in matters of property rights and the value of the claim, unless the case concerns the amount of money. The suit shall include all facts justifying the request and, if necessary, to justify the jurisdiction of the court. In accordance with article 126 § 1 pt. 1 of the CPC, every pleading shall also contain, inter alia, the designation of the court to which it is addressed, the name or names of the parties, their legal representatives and/or agents. Therefore, the essential element of the claim for infringement of personal rights is to show the person against whom the request is addressed, i.e. the defendant in future proceedings for infringement of personal rights, and defendant’s address. The VAC found that the request in the Home.pl case was fully justified.

The Court also confirmed that Home.pl is the controller within the meaning of article 7(4) of the PPD, because according to the agreement with NASK, Home.pl decides on the purposes and means of the processing of personal data related to people who registered domain names. Thus, the party of the case was Home.pl, not NASK.

See also “Polish regulations on personal data protection“, “Polish case law on personal data protection” and “Polish case law on domain names“.