• Who We Are
  • Our Services
    • Outsourced DPO (Data Protection Officer) Services
    • Data Protection Advisory
    • Data Protection Training & Awareness Services
    • Onion Architecture
    • Helpline Service
  • Resources
    • Do I need a DPO (Data Protection Officer)?
    • Benefits of Outsourcing your DPO
    • Why you need GDPR Representation
  • Contact Us
DPO Placement & Consultancy Limited
  • Who We Are
  • Our Services
    • Outsourced DPO (Data Protection Officer) Services
    • Data Protection Advisory
    • Data Protection Training & Awareness Services
    • Onion Architecture
    • Helpline Service
  • Resources
    • Do I need a DPO (Data Protection Officer)?
    • Benefits of Outsourcing your DPO
    • Why you need GDPR Representation
  • Contact Us
DPO Placement & Consultancy Limited

Do I need a
DPO (Data Protection Officer)?

The GDPR requires organisations to designate a Data Protection Officer (DPO) if they:

  • Are a public body (except parish councils in the UK) or
  • Process data on a ‘large scale’ or
  • Use data to “regularly and systematically” monitor individuals

Whilst not necessarily a full-time role, DPOs do require specialist data protection expertise. The Information Commissioner’s Office (ICO) power to impose significant financial penalties and the danger of reputational damage from failing to protect personal data means the role is increasingly important.

Contact Us

WHAT THE LEGISLATION REQUIRES OF DATA PROTECTION OFFICERS

Responsibilities

The DPO should:

  • Keep the organisation informed and advised about data protection
  • Monitor the organisation’s compliance with the legislation
  • Make sure personal data protection is considered ‘by-design’ in new processes and technologies
  • Co-operate with and act as the contact point with the ICO or other supervisory authorities

The Person and the Position

The DPO should:

  • Have expert knowledge of data protection law and practices.
  • Report to the highest management level
  • Avoid conflicts of interest with any other role they perform in the organisation
portrait-two-african-colleague-standing-front-building-talking-each-other

WHAT DATA PROTECTION OFFICERS DO IN PRACTICE

DPOs should champion data protection in the organisation – this means they should:

Inform and advise

  • Facilitate staff training including board members, managers and data facing staff
  • Share best practice for data protection across the organisation
  • Advise on the impact of other data protection regulations
  • Answer queries on all aspects of personal data protection

Ensure individuals can exercise their rights to:

  • Request access to their data using a Data Subject Access Request (DSAR)
  • Be informed about processing
  • Be forgotten
  • Rectify incorrect data
  • Restrict processing
  • Port their data elsewhere
  • Object to processing, automated decision-making and profiling

Review and update policies

  • Keep policies up to date with data protection requirements
    • Privacy and cookie policy
    • Consent forms
    • General data protection policy
    • Retention policy
    • Employee policies etc.

Oversee evaluation of new and high risk processes

  • Privacy by design
  • Data protection and privacy impact assessments (DPIAs and PIAs)

Oversee sharing of personal data

  • Ensure appropriate agreements are in place and monitor compliance including:
    • Data Sharing Agreements
    • Data Processor Agreements

Manage and oversee communication

  • Be the named point of contact with the ICO and other European supervisory authorities
  • Oversee and monitor responses to DSARs

Monitor, report and demonstrate accountability

  • Ensure all compliance records are maintained including:
    • Records of Processing Activity (RoPA)
    • Data asset register
    • Breach register
    • Risk register
    • Log of individuals’ exercised rights
    • Supervisory authority contact records
    • Training record
    Report to senior management on how risk and compliance is evolving
Logo-03

28, Oka Akoko Street, Off Lagos Street Garki 2, Abuja.

+234 809 989 5658

contact@dpoplacement.com

Services

  • Outsourced DPO Services
  • Data Protection Advisory
  • Data Protection Training & Awareness Services
  • Helpline Service
  • Privacy Notice
  • Cookie Notice
  • Best Forex White Label Solutions

Subscribe to newsletter

© 2022 DPO Placement. Designed by ArtEkindle World

in
F.A.Q
Support Forum
Video Tutorials

Search panel can contain any widgets and shortcodes.

Call us: 0 800 255 22 55