Use promo code:
CTA20

Expert Advice Community

Guest

DPO requirement for online company who has 1 employee

  Quote
Guest
Guest user Created:   Aug 27, 2018 Last commented:   Aug 27, 2018

DPO requirement for online company who has 1 employee

Can I myself be a DPO for my own online multivendor marketplace? I am in progress of creating a membership-based online multivendor marketplace for digital products. The purpose of this business module is not to have employees and give the option to earn for others and I would be the only person working and operating the website. I would be keeping the costumes/members data to a minimum, however, IP address and customer purchases are still necessary to keep for business analytics and accountancy purposes. My website is able to offer costumers to remove/rectify their data by themselves independently as well as to contact the DPO (which would be me). I see me the most suitable person to do the task as I am the one who created the site, will be doing the future development of the site, a provider of security applications/doing the weekly scanning and backups. I can't find on the internet clear sentence which would agree with mycase, therefore I wish you could give me an advice. Also, I am wondering if there is some kind of insurance/auditor s, what would assure/ensure I am safe to make the site Live - to the moment it is almost ready- I am just afraid that there may be some small aspect/point what somebody could pick on. I am just at startup position and wouldn't be able to afford an independent DPO. please advise.
0 0

Assign topic to the user

EU GDPR DATA PROTECTION OFFICER ONLINE COURSE

Become a certified Data Protection Officer according to GDPR.

EU GDPR DATA PROTECTION OFFICER ONLINE COURSE

Become a certified Data Protection Officer according to GDPR.

Expert
Andrei Hanganu Aug 27, 2018

Answer:

Appointing a DPO is only compulsory if (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; or (b) the core activities of the legal entity consist of processing operations which, by their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or (c) the core activities of the legal entity of processing on a large scale of special categories of data pursuant to Article 9 of the EU GDPR and personal data relating to criminal convictions and offences referred to in Article 10 of the EU GDPR.

So, as you can see there is no need for you to be appointed DPO.

To learn more about the role of the DPO check out our webinar “Role of the DPO according to EU GDPR” (https://advisera.com/eugdpracademy/webinar/role-of-the-dpo-according-to-eu-gdpr-free-webinar-on-demand/).

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Aug 27, 2018

Aug 27, 2018

Suggested Topics