09/07/2026 | Press release | Archived content
On 2-4 September 2024, the President of the Personal Data Protection Office, Mirosław Wróblewski, together with experts from the Personal Data Protection Office, visited the Opole and Lower Silesian Voivodeships. These were three intense days, during which the "Personal Data Protection Office on tour across Poland" stopped in Kluczbork, Opole and Wrocław. Meetings with residents, data protection officers and controllers, entrepreneurs, representatives of local governments and cultural institutions took place from morning to afternoon, and some of the events took place simultaneously in several places.
Over the course of three days, Personal Data Protection Office experts shared their knowledge and experience, answered participants' questions and provided individual consultations to the inhabitants of these regions.
Kluczbork, 2 September 2026
The first stop on the route was Kluczbork. A meeting was held at the Local Activity Centre - Bajka Cinema, organized jointly with the Kluczbork Land Association, addressed to residents, data protection officers and personal data controllers. Over 80 participants attended the meeting.
The President of the Personal Data Protection Office, Mirosław Wróblewski, opening the meeting, presented statistical information related to the activities of the supervisory authority. He drew attention to the fact that with the same staffing capacity, the Office completed 25 percent more individual cases in the previous year than in the previous year. Meanwhile, the number of complaints and breaches notified to the President of the Personal Data Protection Office is increasing. In 2025, the President of the Personal Data Protection Office received 61 percent more complaints than the year before. Controllers reported 51 percent more data breaches, and the amount of fines increased by a total of 363 percent.
Mirosław Wróblewski drew particular attention to the need for more effective protection of personal data, the need to disperse data collected in large registers in such a way that they are not processed in one central database. As an example of the consequences of data centralisation in one place, he pointed to the recent hacker attack on MyDr, whose services were used by 12 thousand medical entities or more, and the data of 19 million patients were to be collected in one place.
- "A data breach at the controller causes costs for the controller and loss of customer trust. In the case of the public sector, a data breach also leads to a loss of citizens' trust in a given institution, but due to the wide range of data processed, it may also be associated with discrimination, use of data for criminal purposes, lack of a sense of security in contacts with a particular institution" - said Mirosław Wróblewski.
During the meeting, a lot of space was devoted to the key role of the DPO in building an effective data protection system. Monika Krasińska, Director of the Law and New Technologies Department at the Personal Data Protection Office, emphasised in her speech that it is the DPO who very often draws the attention of the controller to the need to have an appropriate legal basis for processing data for a specific purpose. The controller, inspired by the instructions of the DPO, can take appropriate actions. That is why it is so important that he or she is included in all processes related to the processing of personal data.
The experts of the Personal Data Protection Office told the participants, among others, about the inspection carried out by the Office, how to proceed in the event of a data breach and why one should not delay notifying personal data breaches.
Opole, 3 September 2026
The second day showed the scale of the initiative " Personal Data Protection Office on tour across Poland". In Opole, almost at the same time, the Office's experts conducted meetings and consultations in several places in the city.
A meeting with data protection officers and personal data controllers of local government units was held at the Marshal's Office of the Opole Voivodeship, the main topic of which was the role and position of the DPO. About 110 participants took part in the meeting.
The event was opened by Mirosław Wróblewski, President of the Personal Data Protection Office. On this occasion, he referred to the increasingly widespread use of artificial intelligence, which poses risks to data protection. He recommended reading the list of initial questions prepared by the Personal Data Protection Office that controllers should ask themselves before implementing artificial intelligence systems in their organisation. The use of AI should be carried out in compliance with personal data protection regulations.
During her presentation, Monika Krasińska, Director of the Law and New Technologies Department at the Personal Data Protection Office, pointed out, inter alia, that controllers often analyse many processes without the participation of personal data protection officers. She emphasized that such an analysis will then not be comprehensive and will not guarantee that it will serve a given organisation in terms of its further development.
At the same time, a specialist from the Complaints Department at the Personal Data Protection Office was waiting for residents at the Opole Voivodeship Office, who answered questions about personal data protection during individual consultations.
The next two events, which were attended by several dozen participants, took place simultaneously in the Science and Technology Park in Opole. The first of them, entitled "Implementation of the Act on Amendment of the Act on the National Cybersecurity System in accordance with the GDPR, or how to protect an organisation from cyber threats", was devoted inter alia to the challenges related to ensuring the security of the organisation.
Piotr Drobek, Director of the Data Management Department at the Personal Data Protection Office, discussed, inter alia, the issue of verifying a person's criminal record before admitting him or her to implementation of the information security management system and the person responsible for reporting and handling cybersecurity-related incidents. He explained that the verification of the absence of a criminal record for such persons is the fulfilment of the legal obligation to which the controller is the subject (Article 6(1)(c) of the GDPR), which results from the Act on the National Cybersecurity System and is in accordance with the requirement of the EU legislator allowing the processing of data relating to convictions, if it results from national law (Article 10 of the GDPR).
At the same time, Personal Data Protection Office's workshops for entrepreneurs entitled "Building the resilience of an organisation, or how to weave GDPR principles into the company's daily processes" were held, which were conducted by Andrzej Zieliński, Deputy Director of the Inspections and Breaches Department at the Personal Data Protection Office.
He discussed the optimal approach to the implementation of personal data protection principles, proving that their structural interweaving into business processes brings measurable benefits to both the organisation and the data subjects. He also indicated the areas that should be paid special attention to in order to effectively minimise the risk of breaches.
In the second, practical part of the meeting, the participants worked in teams, analysing cases based on example notifications of breaches to the President of the Personal Data Protection Office and presented their recommendations on how to manage these incidents.
Wrocław, 4 September 2026
The last stop of the September route of the Personal Data Protection Office was Wrocław.
The day began with the conference "25 years since the adoption of the Act on Access to Public Information - the specificity of the practice of interpretation and application of applicable regulations" at the University of Wrocław.
- "25 years is a very long time, although the foundation of the Act on Access to Public Information is Article 61 of the Constitution. Perhaps a quarter of a century of the Act is indeed a good time for reflection and revision of the regulations. There are many problems. In practice, there are many tensions in the implementation of the right of access to public information in the context of privacy and personal data protection, and we have to find the right balance in these matters, although it is often not easy" - said Mirosław Wróblewski, President of the Personal Data Protection Office, opening the conference.
The course of that event we will describe soon in the separate communication.
Also in Wrocław, the program included several events addressed to various groups of recipients. At the Wrocław City Hall, experts of the Personal Data Protection Office conducted individual consultations for residents, presenting issues related to the protection of personal data.
There was also a meeting devoted to the protection of personal data in cultural and art institutions - both local and state, as well as private. The meeting was attended by over 70 participants.
Monika Krasińska, Director of the Law and New Technologies Department at the Personal Data Protection Office, in her speech entitled "Data processing in cultural and art institutions in the light of the GDPR", pointed out that the supervisory authority provides expert support, among others, to the Minister of Culture and National Heritage in issuing opinions on legal acts dedicated to the activities of cultural and art institutions in their various areas. It also supports data protection officers of cultural and art institutions in their analyses for the controllers of this sector.
She also explained the exception contained in the Act on Protection of Personal Data concerning statements made in the context of literary or artistic activity, according to which certain provisions of the GDPR do not apply, e.g., relating to the principles of personal data protection or the prerequisites for processing. She noted that it refers only to the processing of data as part of this statement concerning literary or artistic activity. Therefore, it is necessary to take a narrow look at this scope of the subject-matter exclusion, because in any other scope, any other activity that is immanently related to the processing of personal data, certain obligations resulting from the GDPR must be applied.
Three cities, three days and many meetings - the September edition of "Personal Data Protection Office on tour across Poland" is behind us. Why is the Office implementing this initiative? Because it wants to be closer to the data subjects, as well as to those who professionally deal with data protection and processing. Face-to-face meetings allow experts of the Personal Data Protection Office to learn about the problems and challenges faced by citizens, data protection officers, controllers, entrepreneurs and representatives of public institutions, as well as to answer questions and clarify doubts related to personal data protection.