731 901 601

GDPR General Data Protection Regulation

With our help, you will implement GDPR

Certyfikat Certificate with guaranteed certification
Czas Fast implementation
Puzzle Tailored to your company's needs
Bez papierologii No unnecessary paperwork

Over 5,000 small, medium, and large companies have trusted us over 25 years:

Request a free quote

fill out the form or call us

787 974 136 731 901 601
Certificate guarantee

What We Provide to Our Clients

Certyfikat
Guarantee of obtaining certification
Procedury
Development of all procedures and instructions
Zegar
Fast and efficient implementation
Certyfikat
Training confirmed with certificates

Information about GDPR

Who does it apply to?

The General Data Protection Regulation (GDPR) applies to all organisations that collect and use personal data in connection with their business or statutory activities carried out within the European Union. Every business is required to implement the relevant regulations, regardless of its sector, size or legal form – international industrial groups, sole traders, public institutions, non-profit organisations, etc. Both businesses and entities that process personal data on their behalf, such as accountancy firms and transport companies, must comply with the Regulation.

The GDPR must be implemented where:

  • the company processes the data of natural persons, e.g. customers, patients, employees, job applicants, but also contractors who are natural persons (e.g. sole traders),
  • the natural persons whose data is being processed are located within the EU (their nationality is irrelevant),
  • the business operates within the EU, regardless of the location of the company’s head office and the place where customers’ personal data is processed,
  • the company processes the data of natural persons from outside the EU, but has its head office within the EU.

Information about the Regulation

The GDPR is Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data. All Member States are required to comply with it. In Poland, the provisions on personal data protection based on the GDPR are regulated by the Act of May 10, 2018, published in the Journal of Laws 2018, item 1000.

The GDPR contains general guidelines regarding the proper protection of personal data—maintaining its confidentiality, integrity, and availability to authorized persons—but does not specify concrete security measures. The measures implemented in individual companies should be selected based on an individual risk analysis. In practice, data security systems in organizations—often with very similar profiles—can differ significantly from one another. In every case, however, the fundamental objectives of the GDPR must be achieved:

  • effective protection of individuals’ personal data under changing conditions (technological, organizational, etc.),
  • ensuring the free flow of personal data within the EU by guaranteeing uniform law,
  • equipping individuals (as well as supervisory authorities) with tools to effectively respond to GDPR violations.

The GDPR requires businesses to:

  • developing appropriate measures to protect personal data,
  • documenting the processing of personal data,
  • monitoring breaches and notifying supervisory authorities, as well as the individuals affected by the breach (i.e. those at risk of their data falling into the wrong hands), within 72 hours of such an incident occurring,
  • appoint a Data Protection Officer (this applies to organisations where data processing forms the basis of their business).

Under the GDPR, individuals have gained:

  • unrestricted access to information regarding what data a business holds about them and to what extent it processes it,
  • the ability to correct their data, transfer it or even have it completely deleted.

Benefits of implementation

Implementation of the GDPR is the responsibility of every entity that processes the personal data of natural persons. Failure to comply with the provisions set out in the Act may result in a financial penalty of up to 4% of the company’s annual turnover, as well as significant reputational damage. It is therefore advisable to seek the support of specialists to develop a GDPR-compliant personal data protection system for your organisation.

As part of a professional GDPR implementation, a business gains, amongst other things:

  • a record of activities related to the processing of personal data,
  • procedures for risk analysis and risk management should a risk arise,
  • ongoing supervision of its personal data protection system,
  • the opportunity for continuous improvement of the personal data protection system,
  • contract templates tailored to their business activities for consent to the processing of personal data.

Testimonials

See what our clients say about our implementations

Philips
"PHILIPS POLSKA SP. Z O.O., headquartered in Warsaw, is pleased to recommend the consulting services provided by DJB Doradztwo Marcin Chorąży.

The work carried out by DJB Doradztwo fully met our quality expectations. It was individually tailored to the needs and specific nature of our organization, as well as to the expectations we had defined. The consultant assigned to the project demonstrated the appropriate competencies and extensive knowledge of the ISO 9001:2015 standard, and was always available to offer help and advice whenever needed."
PHILIPS POLSKA SP. Z O.O.
Wojewódzki Specjalistyczny Szpital im. M. Pirogowa w Łodzi - logo
Wojewódzki Specjalistyczny Szpital im. M. Pirogowa w Łodzi
On behalf of the Wojewódzki Specjalistyczny Szpital im. Pirogowa, I recommend DJB Doradztwo Marcin Chorąży as a firm that prepares organizations for the implementation of a Quality Management System in accordance with the requirements of the ISO 9001:2015 standard. We began our cooperation with DJB Doradztwo in 2017 and continue it to this day. The scope of our collaboration focused on issues related to the implementation of the system. The consultant working with our hospital demonstrated extensive subject matter expertise and conveyed a great deal of valuable information regarding the requirements of the standards, their application, and the principles of conducting the internal audit process in an accessible and engaging manner. In our opinion, DJB Doradztwo Marcin Chorąży is a reliable and highly recommended contractor for the implementation of the ISO 9001:2015 system.
Director of the M. Pirogov W.S.S.Roman Bocian, MD, PhD
CONTROL SYSTEM FMN - logo
CONTROL SYSTEM FMN Sp. z o.o. collaborated with DJB Doradztwo on the comprehensive adaptation of the ISO 9001:2009 system to the requirements of the new ISO 9001:2015 standard, DJB Doradztwo undertook to perform all necessary activities to enable our company to obtain the ISO 9001:2015 certificate, in particular: The employees of DJB Doradztwo performed their tasks in a professional manner. The company is characterized by timeliness and flexibility in problem-solving, as well as respect for the Client's interests.
The DirectorBożena Zawalska
Urząd Lotnictwa Cywilnego - logo
Urząd Lotnictwa Cywilnego is delighted to recommend the services of DJB Doradztwo Marcin Chorąży in the area of implementing the new ISO 9001:2015 quality management system standard. All of the consultant's activities were tailored to our specific needs and expectations. The consultant demonstrated extensive knowledge of the ISO 9001:2015 standard, which enabled him to suggest many valuable solutions. The documentation was prepared with care and precision. The training sessions conducted as part of the implementation were engaging and allowed us to gain a deeper understanding of the requirements of the new ISO 9001:2015 standard.
Director of the CEO's OfficeMagdalena Kapuśniak