SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

The scope of DPO's tasks

  Quote
Guest
Guest user Created:   Jan 18, 2019 Last commented:   Jan 18, 2019

The scope of DPO's tasks

Art. 35, 2. GDPR says explicitly "The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment." The DPO is involved as advisor in the execution of the DPIA, but it is not the DPO who executes the DPIA. This needs to be done by the business itself as they are the ones who understand the best their own project. It's necessary a cooperation by both the business and the DPO, but it's definitely wrong and contradictory to the wording of the GDPR that a DPO is to be indicated as responsible for executing a DPIA . This remains the responsibility of the Data Controller!
0 0

Assign topic to the user

EU GDPR DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

EU GDPR DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Andrei Hanganu Jan 18, 2019

Answer:

I would say you are interpreting this wrong. The phrase “seek advice” does not mean the same thing as "to perform the DPIA". The DPO's job is to design the DPIA process and the DPIA documents, and the business owner should be the one filling it in with the assistance of the DPO. Imagine that if it was up to the DPO to fill in all the documentation - this would mean that the DPO should be a n expert in IT, HR, Operations, Security, Health& Safety etc. The only area of the DPIA where the DPO is in charge is evaluating the identified risks and propose of the mitigation measures.
If you want to find out more about the duties of a DPO, check out our free webinar: Role of the DPO according to EU GDPR (https://advisera.com/eugdpracademy/webinar/role-of-the-dpo-according-to-eu-gdpr-free-webinar-on-demand/).

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 18, 2019

Jan 18, 2019

Suggested Topics

simmal Created:   Aug 16, 2022 EU GDPR
Replies: 1
0 0

GDPR Scope and applicability

Guest user Created:   Apr 13, 2021 EU GDPR
Replies: 1
0 0

Scope as a data controller