EU GDPR: The Special Role and Responsibilities of the DPO

Berlin

The role and responsibilities of the Data Protection Officer (DPO) in helping an entity to comply with the European Union General Data Protection Regulation (EU GDPR) presents unique challenges in-and-of-itself. However, it also requires a unique working relationship both internally and externally in order to avoid conflicts of interest. This post will explore the delicate balance that must be struck by the DPO in being simultaneously employed by an entity, while maintaining an appropriate distance and autonomy from that same entity in the performance of his/her duties. Although employed by the entity that collects, stores, and processes data, the DPO’s ultimate loyalty is owed to the Data Subject.

The EU GDPR describes the role and responsibilities of a DPO. While not required in every organization, Data Controllers/Processors must designate a DPO if: data processing is regularly carried-out by a public entity and systematic monitoring of Data Subjects occurs on a large scale. Many global firms are likely to fall into this category. The DPO may be a staff member of the Data Controller/Processor or fulfill those duties on the basis of a service contract. Although the DPO reports directly to the highest management level of the Data Controller/Processor, that same management cannot instruct the DPO, nor dismiss or penalize him/her for performing said duties. In fact, the Data Controller/Processor must support the DPO in all his/her duties and must include the DPO in all issues related to the protection of personal data. The DPO is bound by secrecy/confidentiality in performing his/her duties, and this extends even after employment in this capacity ends. And, while the DPO may perform other tasks, those tasks cannot result in a conflict of interest. The DPO’s contact details must be published and communicated to the Supervisory Authority (SA), as well as to Data Subjects.

Once a DPO is hired/assigned, he/she should reach-out to the appropriate Supervisory Authority (SA) in order to establish and develop a good working relationship. The SA will be critical in an entity’s compliance with the Reg and can offer much-needed guidance and advice.

An Information Audit and Data Protection Impact Assessment should be performed soon after a DPO is hired/assigned. These audits and assessments are likely to reveal gaps in processes and insufficient IT systems. While process corrections are easy enough to identify and implement, securing the budget for IT system upgrades or rip-and-replace overhauls may present greater challenges due to budget constraints. Periodic reviews will also be necessary when new technologies become available or are deployed, if they may impact/influence data protection risk. If the Impact Assessment indicates a high risk, the SA must be consulted. The SA will respond within one month, and written advice will be provided within eight weeks (a six-week extension beyond that is possible).

The result should be the development of a Code of Conduct, which establishes processes for data breach detection and notification, among other things. While records maintenance is often a defining feature of any well-run organization, it is critical to not only complying with the Reg, but in providing a “paper trail,” should one be needed.

*Read my prior posts covering the highlights of the EU GDPR, some of the definitions pertinent to the Reg, and my recommendations in preparing for compliance with the Reg.

Author: Donna Taylor

Donna Taylor has 20 years’ experience in the IT industry, including 12 years as an analyst & advisor. She has worked at such high-profile companies as IBM, Gartner, IDC, and Ford Motor Company. She has a diverse skill set with extensive global experience in corporate development & strategy, M&A, venture capital, consulting, market research, competitive analysis, marketing, finance, and international tax & transfer pricing. Taylor is expert at developing & implementing strategic initiatives that drive growth and establish significant market presence and brand awareness, as well as identifying trends, disruptive technologies, and emerging business opportunities. She excels at research, writing, presenting, and advising both the vendor community and end-users. Her areas of expertise include: computer storage, data security, privacy, and protection, EU GDPR, GRC, cloud, Big Data & Analytics, archiving, backup, & recovery, business continuity, and data centres. She has a successful track record of managing and leading global teams and projects. Her business development acumen has led to revenue growth, cost containment, and operational improvements for companies with whom she has worked. Taylor has developed ideas which have led to the identification and segmentation of new areas of research and product development with a global focus and a particular affinity for Europe. She provides insightful perspectives on GTM strategies by addressing the unique characteristics of local markets, while maintaining the cohesive initiatives of a company. She has presented her thought-provoking research at worldwide industry events, which has enabled organizations to take advantage of rapidly-changing market conditions in a timely manner. Taylor holds three university degrees…an MBA in International Management, a JD with a concentration in International Corporate Law, and a BS in both Finance and Multinational Business Operations. These degrees, as well as her extensive experience in the international corporate world, have provided her with a unique perspective on the global marketplace. She has lived in Europe for many years (Munich, Paris, & London), traveled to over 20 countries, and has studied seven foreign languages. As a result, she has a deep understanding of the nuances of global markets, particularly in the EMEA region. *If your organization could benefit from insightful consulting and analysis, please contact Donna Taylor. - consultant/advisor - white papers & reports - guest blogging - speaking engagements

Leave a Reply

Your email address will not be published. Required fields are marked *