It turns out that, alongside numerous messages informing you about the processing of personal data, there are also messages that may be aimed at fraud.
Such messages include, in particular, information containing links or attachments with documents, using which is supposedly meant to ensure full compliance with the GDPR, but may in fact result in the installation of what is known as a virus on your device.
What should we do when we receive such a message?
Ministry officials:
Please read it carefully. Do not respond to messages or SMS texts from an unknown or suspicious source. This also applies to offers of advisory services in the area of personal data protection accompanied by information that refusing to use the services may result in a complaint being filed with the President of the Personal Data Protection Office. This may be an attempted fraud.
To false information about the legal necessity of purchasing cabinets ensuring GDPR compliance, window bars, special categories of shredders, monitor screen covers, padlocks and other GDPR-dedicated solutions. The GDPR does not impose such requirements.To information about mandatory examinations for Data Protection Officers, mandatory certificates and mandatory training. The GDPR says nothing anywhere about mandatory examinations or training.
The Ministry adds:
At the same time, we draw the particular attention of everyone administering personal data to how the obligations arising from the GDPR are carried out.
The numerous messages recently informing your customers, service users and others about data processing should, as a rule, be sent to the email address of the recipient of such a message. Sending such information, for example, to all customers without adding their email addresses, or sending it using so-called blind carbon copy, may constitute a breach of GDPR provisions.
More information is available on the website of the Ministry of Digital Affairs.