Driving Schools (OSK)

GDPR – Not as Scary as It Seems

24 September 2026 • Dla instruktorów

DAY „ZERO”

May 25th of this year marked the first day of application of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ EU L 119 of 04.05.2016, p. 1). Commonly, this legal act is known as GDPR (or RODO in Poland). This abbreviation can be encountered in the press, on television, as well as while reading electronic mail, which in recent weeks was flooded with messages sent by websites informing their clients about the compliance of processing their personal data in accordance with GDPR. In the face of this information, a question arises: where did all this fuss come from, since personal data protection is not something new? After all, since 1997 we have had regulations dedicated to this in Poland. It is precisely there that one should seek the answer. For those entities that complied with the rules of personal data protection – GDPR is an evolution. While it does introduce new principles for processing personal data, it does not change the essence of the personal data protection system functioning to date. GDPR is, however, a revolution requiring the adoption of a range of organizational and legal measures for entities that failed to fulfill obligations arising from the Personal Data Protection Act in force until May 24th of this year.

„THE INCENTIVE”

Undoubtedly, the „incentive” for implementing GDPR within an organization is the administrative financial penalties that may be imposed by the new authority – the President of the Personal Data Protection Office (UODO) – on entities processing personal data in breach of the provisions in force in this scope. These entities must also remember the possibility of civil claims being brought against them by individuals to whom the personal data relates, where the limit of liability is determined by the amount of financial damage caused or the extent of harm suffered by those persons in connection with non-compliance with GDPR. Employees and associates of entities processing personal data who participate in processing operations must also remember to observe the principles of personal data protection, e.g., regarding the clients of their employer or counterparty. Breach of these principles may indeed result in employment liability (warning, reprimand, termination of employment contract, disciplinary dismissal, material liability up to three times the remuneration due to the employee on the day the damage was caused), and in the case of persons performing work under civil law contracts – contractual liability covering, among others, contractual penalties. Regardless of the above, every person who commits the offense of unlawful processing of personal data or the offense of obstructing the conduct of an inspection of compliance with personal data protection regulations is subject to criminal liability, including imprisonment.

What to do then in order to be „GDPR-compliant”?

In the first place, an inventory of all personal data processing flows within the organization must be taken. During GDPR implementation, data controllers frequently discover previously unidentified datasets, processing flows unknown to them, learn about dusty binders in basements, forgotten databases in IT systems, or files created just in case or for working purposes on employees’ company computers or on various other data storage media. Data inventory allows for determining the fundamental issue, which is the existence of a legal basis for processing personal data. The data controller must establish whether they are permitted to process personal data, as well as whether they do not process personal data to a greater extent than is necessary for the purpose for which they collect and use such data. GDPR indicates these legal bases in Article 6 (concerning ordinary data) and in Article 9 (referring to special categories of data, e.g., health data). It also provides guidance on what actions to take in order to properly secure the processed personal data. It does not, however, give specific technical solutions. On the contrary – the burden of selecting these solutions is shifted onto the entities processing personal data. It obliges them to carry out a risk assessment regarding the violation of the rights and freedoms of data subjects, and then to select organizational and technical measures appropriate to that risk. In practice, this does not necessarily mean carrying out revolutionary changes in the organization. Frequently, it may be sufficient to take such measures as changing the storage location of documentation containing personal data (e.g., moving it to lockable cabinets instead of storing it in open cabinets in a room where clients are received). Implementing GDPR may also involve organizational and formal changes resulting in modifications of procedures, regulations, customer service rules, etc. The assessment of what actions should be taken in a specific case depends precisely on the inventory of personal data processing flows and the analysis of the risk of violating the rights and freedoms of the persons concerned. Personal data security is such an important element of processing that GDPR introduced the obligation to inform the President of UODO (Personal Data Protection Office) of personal data breaches within 72 hours after detecting the breach, and in specified cases – to inform the individuals affected by the breach as well. The next stage of GDPR implementation concerns formal matters, i.e., verifying contracts concluded with entities cooperating with the data processing entity and participating in the processing, as well as developing personal data protection documentation. GDPR does not specify an exhaustive catalog of this documentation; however, analysis of the regulation’s provisions and practical implementation allow for defining the minimum scope of required documents. It is recommended to prepare, in particular, a record of processing activities (GDPR specifies the cases when maintaining a record is mandatory), procedures for exercising data subject rights, reporting data breaches, selecting processors, destroying or deleting personal data, risk management, and authorizing employees and other individuals to process personal data.

GDPR in Driving Schools (OSK)

The specific nature of activities conducted by driving schools allows for stating that processing students’ personal data is one of the most important characteristics of this activity. Thus, the actions described above related to GDPR implementation could not bypass driving schools. These centers are the controllers of students’ personal data. They process them on a smaller or larger scale, depending on the size of the school, yet in each case they are obliged to process them for strictly defined purposes arising from the legal basis of processing (this basis consists of the relevant provisions of the Road Drivers Act, but it can also be consent if the school intends to process data for purposes other than conducting the training) and to appropriately protect this data (an inventory of personal data processing operations and risk analysis will help in fulfilling these obligations). Driving schools are obliged to fulfill the information obligation toward students, and thus explain to them the principles of personal data processing, including indicating the purposes for which personal data are collected, the period for which they will be stored, or the entities to which the data will be disclosed. The information clause must also present students with their rights, which are regulated in detail in Articles 15-22 of GDPR, as well as inform them about the right to lodge a complaint with the President of UODO against unlawful processing of personal data by the driving school. Regardless of the above, students have the right to receive this information upon every (with few exceptions) request. Driving schools frequently cooperate with instructors under civil law contracts, process students’ personal data in IT systems on servers of external companies, and use the services of entities providing accounting or HR services. In all these cases, it is necessary first to identify the status of such an entity (whether, for example, it is a processor), and then to regulate personal data protection issues in an agreement between that entity and the school. Many of the measures presented above, constituting stages of implementing GDPR personal data protection principles in an organization, should have already been carried out under the 1997 Personal Data Protection Act. If, however, this was not done – it must be remembered that GDPR has equipped both the President of UODO and data subjects with tools to enforce compliance with its provisions. Personal data protection in entities such as driving schools must therefore be incorporated into business processes as one of their most important factors.

Sylwia Ratajczyk, Legal Counsel

Publikacje i materiały dla OSK

Driving Schools (OSK)
September 21, 2026 • 3 min read

Who Needs Changes?

What the job of a driving test examiner looks like from the inside. The complicated relationships between the learner, driving school instructor, examiner, director, and the voivodeship marshal. Who cares about what. And what the result of these desires is.

Frequently Asked Questions (FAQ)

Didn't find your answer? Contact our support team.

Customer Service Office
Partnerships & Driving Schools
Technical Support
Available Monday to Friday 8:00 AM - 4:00 PM
Click the "Register" button in the top right corner of the page, fill out the short form (email, password, driving category), and click the activation link sent to your email.
Didn't find the answer to your question? Go to Help Center →

Let's stay in touch

Have questions regarding driving courses or driving schools? Contact us.

Wydawnictwo Liwona SmartTesty Publisher

Office

Mon. - Fri. 8:00 AM to 5:00 PM

Liwona sp. z o.o.
ul. Rakuszanki 5, 02-496 Warszawa
NIP: 5222507848

Contact Form

Write to us - we usually reply within a few hours.

Testy na prawo jazdy

Additional learning materials

Learn with Smart Testy - everything you need in one place.

Frequently Asked Questions (FAQ)

Didn't find your answer? Contact our support team.

Customer Service Office
Partnerships & Driving Schools
Technical Support
Available Monday to Friday 8:00 AM - 4:00 PM
Click the "Register" button in the top right corner of the page, fill out the short form (email, password, driving category), and click the activation link sent to your email.
Didn't find the answer to your question? Go to Help Center →