November 8, 2023
Designating a data protection officer (DPO) is one of the statutory obligations on the controller and the processor in some particular circumstances according to the EU’s General Data Protection Regulation (GDPR). Here is an overview of GDPR regulations on DPO that enterprises and organisations can refer to, in the context that Decree No.13/2023/ND-CP does not specify this obligation.
Both the controller and the processor shall be under the obligation to designate DPO if they are in statutory cases that require a DPO assigned or where required by Union or Member State[1].
The controller and the processor shall designate a DPO in the following case[2]:
GDPR does not prescribe a quantitative standard for enterprises and organizations to designate DPO, instead, the subjects shall appoint a DPO according to statutory factors, including professional qualities; expert knowledge of data protection law and practices; ability to fulfil the DPO’s tasks stipulated in Article 39 of GDPR[3],[4]. The necessary level of expert knowledge should be determined according to the data processing operations carried out and the protection required for the personal data processed by the controller or the processor[5].
Each enterprise and organization in cases where required shall need at least 01 DPO. Besides, a group of undertakings may appoint a single DPO provided that the DPO is easily accessible from each establishment.
A DPO may be a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract.
In case the DPO is an employee of the controller or the processor, the following specific principles are required to apply:
Yes. Enterprises and organizations must communicate the contact details of the DPO to the supervisory authority. Additionally, the controller and the processor must publish such information so that data subjects can contact in need[9].
To ensure the effectiveness of the DPO’s activities, enterprises and organizations need to adhere to the following responsibilities:
The data protection officer shall have at least the following tasks[14]:
Throughout his or her performance, the DPO shall be bound by secrecy or confidentiality concerning the performance of his or her tasks, in accordance with Union or Member State laws[15].
The intentional or negligent violation of DPO regulations from enterprises and organizations which are under the scope of GDPR shall be subject to administrative fines up to 10.000.000 EUR, or in the case of an undertaking, up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher [16]./.
PrivacyCompliance provides solutions related to ensuring compliance with personal data, assessing the impacts of personal data processing, and DPO service. |
PrivacyCompliance
#GDPR #personaldata #DPO #sensitivepersonaldata #dataprotectionofficer
[1] GDPR, Article 37.1
[2] GDPR, Article 37.1 và 37.4
[3] GDPR, Article 37.5,
[4] Guidelines on Data Protection Officers (‘DPOs’) (wp243rev.01)
[5] GDPR, Recital 97
[6] GDPR, Article 38.3
[7] GDPR, Article 38.6
[8] GDPR, Recital 97
[9] GDPR, Article 37.7
[10] GDPR, Article 38.1
[11] GDPR, Article 38.2
[12] GDPR, Article 38.3
[13] GDPR, Article 38.4
[14] GDPR, Article 39
[15] GDPR, Article 38.5
[16] GDPR, Article 83.4
Territorial Scope of GDPR In the modern world, data is flowing across borders at an unprecedented rate. This creates risks for the data since most laws are only effective within their respective borders and cannot guarantee adequate protection when the data is transferred abroad. It is for this reason that the General Data Protection Regulation […]
Learn more
Independent Supervisory Authorities Under GDPR The EU’s General Data Protection Regulation (“GDPR”) is an incredibly useful framework to protect personal data. However, all rules are only as good as our ability to enforce them, a legal framework alone cannot protect personal data. As such, independent enforcement agencies are required to put the regulations into practice. […]
Learn more
E-Privacy Directive The Directive 2002/58/EC or e-Privacy Directive (ePD) – also known as the Privacy and Electronic Communications Directive, is a regulatory framework established by the European Union (EU) to protect the privacy of individuals. With similar functions to the General Data Protection Regulation (GDPR), the ePD remains in effect alongside the GDPR with the […]
Learn more