Abstract
The article discusses issues relating to the status and responsibilities of the information security administrator (ABI) following the amendment to the Personal Data Protection Act. The presented analyses concerned optionality of ABI appointment, the requirements to be met, the scope of duties and issues relating to registration of data sets with GIODO and registration of ABI. Changes of regulations and their practical consequences have been indicated, and an assessment of new legal solutions has been attempted.