New Rulebook on the Security of Personal Data Processing: What Does It Mean for Your Company?

On 26 December, the Agency for Personal Data Protection announced the adoption of the new version of the Rulebook on the Security of Personal Data Processing, which will apply as of 1 July 2025 and introduces higher standards for data controllers. In addition to updated technical requirements, this version of the Rulebook places greater emphasis on transparency and data minimization.
Under the new version of the Rulebook on the Security of Personal Data Processing, controllers must implement measures that limit processing to only the data that is necessary and ensure clear communication with data subjects regarding how their personal information is used.
In addition, through risk assessments, controllers are provided with a structured approach to addressing threats, with documentation becoming a central element in demonstrating compliance. Although the new Rulebook introduces additional obligations, it also represents an opportunity for controllers to improve their data protection systems and build trust among data subjects.
The new Rulebook on the Security of Personal Data Processing specifically focuses on:
Protection Objectives: The new Rulebook introduces concepts such as “personal data minimization,” “transparency,” and “intervention,” emphasizing that controllers must focus on limiting data processing to what is necessary and ensuring that data subjects have clear insight into, and the ability to exercise and protect, their rights.
Risk Assessment: Under the new Rulebook, the risk management process is more clearly defined. Controllers are required to identify risks, analyze threats, and propose mitigation measures using standardized procedures.
Expanded Documentation: The new Rulebook requires more detailed documentation, including records of processing activities, detailed descriptions of technical and organizational measures, and their relationships with other systems.
Adaptation of Systems: Controllers are now required to ensure a functional and sustainable information system that meets the technical and organizational requirements prescribed by the applicable regulations.
The Rulebook will apply as of 1 July 2025. During the six-month period preceding its application, controllers and processors are required to align their operations with the requirements of the new Rulebook on the Security of Personal Data Processing.
Disclaimer: This article has been prepared for informational purposes only and does not constitute legal advice or instructions for taking action in a specific case. Legal matters can be complex, and each case has its own specific circumstances that must be assessed individually. For this reason, we recommend consulting a qualified legal professional who can provide a solution tailored to your specific legal needs.е.


