Eight years after the GDPR took effect, the line between organisations no longer runs through whether they hold documentation, but through whether that documentation describes reality. Recent decisions of the President of the Personal Data Protection Office (UODO) illustrate the point well: the fine imposed on Poczta Polska concerned not a data leak but the lack of independence of its data protection officer; the fine on DPD concerned data processing agreements that were never concluded; and the fine following the hate-campaign affair concerned authorisations that nobody supervised. The common denominator is the same in each case: the paperwork existed, the process did not. Added to this is the plan of sectoral inspections for 2026, covering among others bodies operating the Public Information Bulletin, healthcare providers in respect of video surveillance, and organisations engaged in marketing. We help organisations move from documentation to accountability - and keep it in place once the implementation project has ended.
Local government, subordinate units and municipal companies, including those operating the Public Information Bulletin
Healthcare providers, clinics and laboratories processing special categories of data
Small and medium-sized companies with no in-house legal department and no full-time officer
Organisations running marketing, e-commerce and loyalty programmes
Controllers relying on an extended chain of processors and sub-processors
We match the form of engagement to the need - a one-off audit, an implementation project, or permanently holding the officer's role.
Opening audit - We establish what data the organisation actually processes, in which systems, and to whom it is entrusted. We talk to the people who carry out the processes rather than only reading documents - because the gap between the two is usually the heart of the problem.
Report with recommendations - you receive a list of irregularities ranked by risk, referenced to specific provisions and case law, with a realistic estimate of the effort each recommendation requires. No scare tactics and no inflated scope.
Implementation - We build or put in order the documentation: records, policies, information clauses, data processing agreements, the authorisation system. We work so that the documents withstand the least favourable interpretation by the authority, not the most convenient one for us.
Impact assessment where it is required - We carry out a DPIA for high-risk operations - video surveillance, profiling, systems based on artificial intelligence, and large-scale processing of special categories of data.
Training and putting it into practice - We train staff and the people responsible for individual processes. Documentation that nobody understands protects nobody - what protects is the documentation people actually work to.
Ongoing service or handover - We can take on the Data Protection Officer role and perform it on a continuing basis, with scheduled availability, monitoring of developments in case law and regular reporting to management. Alternatively we hand everything over to your team and remain available for consultation.
It is mandatory in the three cases set out in Article 37 GDPR: where the processing is carried out by a public authority or body; where the core activity consists of regular and systematic monitoring of individuals on a large scale; and where it consists of large-scale processing of special categories of data or of data relating to criminal convictions. Outside those cases the appointment is voluntary - but note that an officer appointed voluntarily is subject to exactly the same requirements as a mandatory one, independence included. What is voluntary is the decision to appoint, not the standard to which the role is performed.
Because the most common problem with internal officers is the conflict of interest that the authority asks about first. The role cannot be held by someone who themselves decides on the purposes and means of processing - so not the head of IT, HR or administration. The fine imposed on Poczta Polska in January 2026 concerned precisely the officer's position within the structure, not their competence. An external provider has no other duties inside the organisation, so the conflict cannot arise by definition. Added to that is continuity - an external officer does not take leave without cover and does not resign overnight.
Where the type of processing, in particular one using new technologies, is likely to result in a high risk to the rights and freedoms of individuals (Article 35 GDPR). The President of the Personal Data Protection Office has published a list of operations requiring a DPIA, covering among others video surveillance of publicly accessible areas, profiling with legal effects, the processing of biometric data and systems based on artificial intelligence. In practice it is worth carrying out the assessment whenever a doubt arises - a documented analysis concluding that there is no high risk is itself evidence of due diligence.
Timing and the order of steps are what matter. The controller has seventy-two hours from becoming aware of the breach to notify the President of the Personal Data Protection Office, unless the breach is unlikely to result in a risk to individuals - and that conclusion has to be documented. Where the risk is high, the individuals themselves must also be informed. The essential point is that the clock starts when the breach is identified, not when the investigation concludes. We provide our clients with a procedure and remain available at short notice - the first hours determine how the authority will view the whole matter.
Begin by checking whether the organisation falls within the sectoral inspection plan - in 2026 it covers, among others, bodies operating the Public Information Bulletin, healthcare providers in respect of video surveillance, with particular attention to children's data, and organisations engaged in marketing. The inspector will ask for the record of processing activities, the risk analysis documentation, data processing agreements, the register of authorisations and evidence that the information obligation has been met. We run an audit that simulates such an inspection and identify what needs to be completed - before the authority does.