With the introduction of Regulation (EU) 2016/679, known as the General Data Protection Regulation (GDPR), the role of the Data Protection Officer (DPO) was established. The DPO fulfils a key role in ensuring compliance with the provisions of the GDPR and is among those principally responsible for the protection of personal data within organisations.
I. Options for appointing a DPO
The Data Protection Officer may be:
- An internal employee of the organisation — the controller or processor of personal data;
- An external person or company, engaged under a service contract to perform the duties of a DPO.
Where the officer is an internal employee, they may also hold other duties, but only provided that this does not give rise to a conflict of interests. The principal responsibilities of the DPO include ensuring compliance with the internal policies and data protection rules by all employees who process personal data. A person entrusted with the decisions concerning the purposes and methods of processing personal data cannot be appointed as a DPO, as this would amount to self-monitoring.
Important: The person performing the functions of a DPO is not permitted to combine this position with managerial roles such as:
- chief executive officer,
- chief operating officer,
- chief financial officer,
- head of the Human Resources department,
- head of the Information Technology department.
The employer must carefully assess the scope of duties that may be combined with the work of a DPO. The job description must specify what proportion of working time will be devoted to the duties of the DPO, in order to avoid conflict situations and the inadequate performance of duties.
Additional-work contract for performing the functions of a DPO
Where the volume of the principal employment duties is large, it is advisable for the functions of the DPO to be performed under an additional-work contract pursuant to Article 110 of the Labour Code (КТ), in cases where the employee will assume these responsibilities outside their principal working hours.
Practical problems for small and medium-sized enterprises
In small and medium-sized enterprises, employees are often assigned to perform the functions of a DPO alongside other duties. Usually these employees lack the necessary expert knowledge or the time to perform these functions. Should unforeseen circumstances arise, such as resignation, or absence due to illness or maternity, employers may be left without a data protection officer and expose themselves to the risk of an inspection by the supervisory authority for the protection of personal data.
II. Appointing a joint DPO within a group of undertakings
A group of related undertakings may appoint a joint DPO for all of the legal entities. In this case, however, each undertaking must have easy and unrestricted access to that person. The relations between the undertakings and the DPO may be governed by a contract under Article 111 of the КТ (an employment contract for external secondary employment) or by a civil service contract.
III. Requirements for the education and qualifications of a DPO
According to the GDPR, there are no special requirements for the education and qualifications of a DPO in the private sector. The person must, however, have knowledge in the field of personal data protection legislation and experience of the processes within the organisation of the controller or processor, including the information systems and the methods for ensuring security. The employer itself assesses what qualifications are necessary for the position according to the specific nature of the activity and the volume of the data processed.
Special requirements for a DPO in the public administration: The appointment of a DPO in the public administration is subject to specific requirements set out in the Classifier of Positions.
IV. Notifying the supervisory authority of the appointment of a DPO
The controller of personal data is obliged to publish the contact details of the DPO and to communicate them to the supervisory authority . The details may include an address, a telephone number and an e-mail address. Stating the name of the employee is not required, but it is good practice for it to be publicly available.
If the notification is submitted electronically, it must be signed with a qualified electronic signature. Where the DPO is a legal entity, the supervisory authority must be informed of the specific natural person performing these functions.
V. Duties of the Data Protection Officer
The DPO is obliged to:
- Advise and inform the controller or processor, as well as the employees processing data, of their responsibilities under the GDPR.
- Monitor compliance with the requirements for the protection of personal data.
- Oversee the application of the personal data protection policies within the organisation, including the training and awareness of staff.
- Provide advice on the data protection impact assessment and carry out monitoring.
- Ensure confidentiality in the performance of their duties.
- Cooperate with the supervisory authority on all matters relating to the processing of personal data.
- Maintain a register of the processing activities for which they are responsible.
- Act as a point of contact for the supervisory authority and, where appropriate, for consultations on other matters.
The additional duties of the DPO may include drawing up and updating internal data protection policies and other similar duties.
VI. Liability of the DPO
The DPO does not bear personal liability for non-compliance with the GDPR. Liability for breaches of the regulation remains with the controller or processor of the data. If the DPO is appointed under an employment contract, their liability is governed by the Labour Code and includes:
- Disciplinary liability for failure to perform the duties,
- Material liability in the event of damage caused through negligence in the performance of the official duties.
Upon termination of the DPO's contract, the employer is obliged to comply with the requirements and compensation provided for by law.
Advantages of the external DPO service: Appointing the DPO as an external contractor affords the controller greater flexibility upon termination of the contract and the possibility of including greater liability for damages within the contract itself.
Should you require assistance in preparing documents or a consultation in the field of personal data protection, please contact us on tel.: 0887550706 or by e-mail: [email protected]
