“MojeIKP Junior” requires comprehensive statutory regulation
Mirosław Wróblewski, President of the Personal Data Protection Office, has shared his comments on the ‘mojeIKP Junior’ service with the Minister of Health, Jolanta Sobierańska-Grenda. The service is ultimately intended for young people aged between 13 and 17. It is a response to the health and systemic needs encountered in this age group.
It is essential to ensure a particularly high level of protection for personal data. This is because the service will be used by minors. It will also involve health-related data. Furthermore, communication with minors must be tailored to their age, level of maturity and level of understanding.
Therefore, technical and organisational measures to ensure the protection of personal data should be taken into account right from the design and development stage of a new service, as well as during its operation. Safeguards to ensure the protection of personal data cannot be implemented only after the planned service has been launched. At the same time, given the high risk associated with the processing of data relating to the health of minors, it is essential to carry out a data protection impact assessment before the service is launched.
There is a need for comprehensive statutory regulation for ‘mojeIKP Junior’
The President of the Personal Data Protection Office points out that the planned project will require systemic legislative changes. However, the draft guidelines presented do not take this issue into account. It is essential to establish a clear legal basis and to regulate the operating principles of the ‘mojeIKP Junior’ service. The proposed solution will involve the processing of special categories of data; therefore, the legislation must specify a legal basis for it, define its purpose, scope and categories of data, the group of entities authorised to process the data, and the period for which the data will be stored. The legislation must specify how the rights and freedoms of individuals will be protected, particularly in view of the increased risk of privacy violations.
Taking into account the rights of minors and their legal representatives
The proposed solution also requires a comprehensive analysis of the legislation governing the status of minor patients and the powers of their legal representatives. This is because the law regulates the scope of autonomy in the field of healthcare differently depending on the patient’s age. Polish law adopts a model of joint decision-making with a legal representative for individuals aged 16 and over. The scope of this autonomy increases with age. For those under the age of 16, the right to information is provided for. It is therefore necessary to determine whether a minor’s use of the ‘mojeIKP Junior’ service will be limited to technical or organisational tasks, or whether it will also involve giving consents, submitting applications or making declarations. If the proposed service is intended to be used to carry out actions giving rise to legal consequences, it becomes essential to define the rules governing the involvement of the minor’s legal representatives and to clearly regulate the scope of their access to data concerning, for example, the child’s health. Regulating these matters will help to avoid conflicts between the provisions on the protection of personal data, patients’ rights, civil law and the exercise of parental authority.
EU Regulation on the European Health Data Space
The project should also be assessed in terms of its compliance with the EHDS Regulation, which came into force on 26 March 2025. The sharing and further use of personal and non-personal health data processed in public registers is, after all, of significant importance to the interests of the state as well as to individual and collective interests. Account should also be taken of the obligation under the EHDS to enable the secondary use of electronic health data.
The issue of responsibility for data processing needs to be resolved
The proposer has not identified the entities responsible for data processing, nor the rules and methods for obtaining data from other systems and databases. The planned integration of the service with public registers requires particular attention. The mechanism enabling this should be based on an appropriate legal basis and take into account the principles of data protection by design and by default, as referred to in Article 25 of the GDPR. Appropriate technical and organisational safeguards must also be implemented. However, if the scope and manner of use of data obtained from public registers involve a high risk of infringing the rights or freedoms of natural persons, it may be necessary to carry out a data protection impact assessment in accordance with Article 35 of the GDPR. The drafters have not specified the entities responsible for data processing, nor the rules and methods for obtaining data from other systems and databases. The planned integration of the service with public registers requires particular attention. The mechanism enabling this should be based on an appropriate legal basis and take into account the principles of data protection by design and by default, as referred to in Article 25 of the GDPR. Appropriate technical and organisational safeguards must also be implemented. However, if the scope and manner of use of data obtained from public registers involve a high risk of infringing the rights or freedoms of natural persons, it may be necessary to carry out a data protection impact assessment in accordance with Article 35 of the GDPR.
The project proponent’s obligation to carry out a risk assessment
The data controller should identify the risks associated with the processing of personal data and assess their level, taking into account the nature, scope, context and purposes of the intended processing operations. Risks associated with the processing of special categories of data, which are subject to specific protection under Article 9 of the GDPR, also require particular analysis.
The President of the Personal Data Protection Office hopes that taking his comments into account will help to ensure an appropriate level of personal data protection in the proposed project.
DPNT.060.83.2026