# GDPR and the Need for a Data Protection Officer – What’s Your Obligation?
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2018-03-23
Category: BUSINESS
Category URL: https://financedigest.com/category/business
Meta Title: Why Organisations Need to Appoint a DPO Under GDPR
Meta Description: Learn why the GDPR mandates certain companies to appoint a DPO, their responsibilities, and the scenarios where the appointment is compulsory.
URL: https://financedigest.com/gdpr-and-the-need-for-a-data-protection-officer-whats-your-obligationhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/fd230318-1-1736842900416-compressed.jpg)

_The General Data Protection Regulation (GDPR) is the first EU wide legislation to mandate organisations appoint a Data Protection Officer (DPO) in certain circumstances. Jan Van Vliet, VP and GM, EMEA, Digital Guardian, examines why it makes sense for organisations to bring a DPO on board._

The concept of a Data Protection Officer (DPO) for organisations processing personal data has been around for many years. However, the appointment of a DPO is a mandatory requirement under GDPR for certain [types of companies](https://www.financedigest.com/immunology-drug-market-growth-by-top-companies-trends-by-types-and-application-forecast-analysis-to-2030.html "Immunology Drug Market Growth by Top Companies, Trends by Types and Application, Forecast Analysis to 2030"), regardless of their size or whether they are processing personal data in their capacity as a controller or processor.

With just weeks to go before the GDPR comes into effect on 25 May 2018, organisations will need to establish if they need to appoint a DPO and who should undertake this [important role](https://www.financedigest.com/the-importance-of-role-models-and-policy-in-encouraging-more-women-to-pursue-careers-in-the-finance-sector.html "The importance of role models and policy in encouraging more women to pursue careers in the finance sector").

**Who is required to appoint a DPO?**

Article 37 of the GDPR sets out three primary scenarios where the appointment of a DPO is mandatory:

1. [Data processing](https://www.financedigest.com/crowdsourcing-of-data-to-drive-the-high-throughput-process-development-market.html "Crowdsourcing of data to drive the High Throughput Process Development Market") is carried out by a public authority or body, or
2. The core activities of the controller or the processor consist of processing operations which require the regular and systematic monitoring of data subjects on a [large scale](https://www.financedigest.com/facebook-parent-meta-is-preparing-large-scale-layoffs-this-week-wsj.html "Facebook parent Meta is preparing large-scale layoffs this week – WSJ"), or

III.         The core [activities](https://www.financedigest.com/oil-slips-on-china-covid-curbs-weak-factory-activity-data.html "Oil slips on China COVID curbs, weak factory activity data") of the controller or the processor consist of [processing](https://www.financedigest.com/persistence-innovation-to-replenish-the-tissue-processing-system-market.html) on a large scale of sensitive personal data or personal data relating to criminal convictions and offences.

In other words, if you are doing any sort of analytics regarding people’s behaviour – [say tracking](https://www.financedigest.com/electric-car-maker-lucid-on-track-for-2022-2023-output-targets-ceo-says.html "Electric car maker Lucid on track for 2022, 2023 output targets, CEO says") purchases or page views on a website to provide personalised ‘you may like this’ recommendations – or regularly process and manipulate data relating to people’s health, ethnicity, sexual orientation, religious or philosophical opinions, then you are required to have a DPO. However, if your firm only processes HR data then a DPO is not required.

The Article 29 Working Party (WP29), one of the EU’s earliest commentaries on the detailed provisions of the GDPR, sets out a number of examples of large scale processing that include the processing of customer data in the regular course of [business by a bank or insurance](https://www.financedigest.com/business-insurance-what-does-it-cover.html "Business Insurance: What does it cover?") company, behaviouraladvertising by a search engine, and data (content, traffic, location) processing by telephone or internet companies. It also [points out that ‘regular and systematic monitoring’ is not restricted to online behaviour and gives examples of profiling for credit scoring](https://www.financedigest.com/how-to-raise-my-credit-score-40-points-fast.html "How to raise my credit score 40 points fast"), fraud or anti-money laundering prevention, location tracking, and health and fitness tracking by wearable devices which, if large scale, will trigger an obligation to appoint a DPO.

**What does a DPO do?**

The GDPR is explicit about the tasks that DPOs are required to perform. These include informing the organisation and its employees of their data protection obligations and overseeing the training of staff, monitoring the organisation’s compliance and performance with GDPR and internal data protection policies, providing advice on data protection impact statements (DPIAs), serve as a contact point for individuals (data subjects) on privacy matters, and engaging with the ICO and acting as its contact point.

The regulation stipulates the DPO must report to [top level](https://www.financedigest.com/zara-owner-inditex-sales-rebound-to-top-pre-pandemic-levels.html "Zara owner Inditex sales rebound to top pre-pandemic levels") management, be given all necessary resources to carry out their functions and should operate independently and without instruction from their employer about how they carry out their tasks.

The guidance also emphasises that the DPO is not personally responsible for non-compliance with GDPR. Liability remains with the controller or processor to demonstrate that processing activities are performed in accordance with the GDPR.

**Who should be appointed?**

There are currently no mandatory qualifications for who can be a DPO, although according to WP29 the following people cannot be a DPO: [chief executive, chief financial officer](https://www.financedigest.com/impact-com-names-hubspot-veteran-kim-walsh-as-chief-growth-officer.html "impact.com Names HubSpot Veteran Kim Walsh as Chief Growth Officer"), head of IT, head of marketing, chief operator officer or the head of HR, as this may result in a conflict of interest. Which makes it more likely that someone from in-house legal or compliance will be a popular choice and Article 37 does require the DPO to have ‘expert knowledge of [data protection](https://www.financedigest.com/how-financial-organisations-can-stay-protected-from-financial-data-breaches.html "How Financial Organisations can Stay Protected from Financial Data Breaches ") law and practices’.

It’s worth noting that the ICO confirms that firms can contract out the role of DPO externally with an individual or organisation. Having said that, any external DPO must have a good understanding of your firm’s data processing operations in [order to be of real value](https://www.financedigest.com/deliveroo-reports-doubling-in-gross-order-value-in-first-half.html "Deliveroo reports doubling in gross order value in first half").

Because DPOs [need to have a complete understanding of the IT infrastructure and technical and organisational structure of the business](https://www.financedigest.com/what-you-need-to-know-about-tax-savings-for-businesses-in-las-vegas-nv.html "What You Need to Know About Tax Savings for Businesses in Las Vegas NV"), the best place to start looking for a DPO will be within the existing employee base.

Even if your firm does not have to make a mandatory DPO appointment, there are [clear benefits](https://www.financedigest.com/clearing-out-your-garage-benefiting-from-corporate-simplification-2.html "Clearing Out Your Garage – Benefiting from Corporate Simplification ") to appointing one on a voluntary basis. Not will this demonstrate to the Information Commissioner’s Office that you are serious in your commitment to comply with your data protection obligations – it also [sends a strong message](https://www.financedigest.com/with-tighter-grip-beijing-sends-message-to-hong-kong-tycoons-fall-in-line.html "With tighter grip, Beijing sends message to Hong Kong tycoons: fall in line") to customers. A DPO is not required to be a permanent employee, but the [data security](https://www.financedigest.com/cyber-security-data-re-assurance.html "Cyber Security: Data ‘Re’-Assurance") knowledge and expertise they can bring to a business can be priceless.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

