The General Data Protection Regulation (the “GDPR”) will come into force on the 25th May 2018, replacing the existing data protection framework under the EU Data Protection Directive.
This is the third of a series of Guidance Notes that the Gibraltar Regulatory Authority (“GRA”), as the Data Protection Commissioner, will issue in the run up to the 25th May 2018.
This Guidance Note provides general advice on the GDPR’s requirement for organisations to appoint a Data Protection Officer (“DPO”).
Under the GDPR, it will be mandatory for some data controllers and data processors to appoint a DPO, for example, all public authorities (with some minor exceptions) and organisations which carry out regular and systematic monitoring of data subjects on a large scale.
The DPO requirement introduced by the GDPR is not a new concept. Although current data protection law under the EU Data Protection Directive 95/46/EC does not include a mandatory obligation for organisations to appoint a DPO, the practice of appointing a DPO has developed and been adopted by organisations throughout the EU to ensure compliance with data protection law. Prior to the GDPR, the Article 29 Working Party already considered the appointment of a DPO as a “cornerstone of accountability” that can facilitate compliance and also become a competitive advantage for business.
A DPO will act as an intermediary between its employer and relevant stakeholders, such as data subjects and regulators. Although appointing a DPO will facilitate compliance with the GDPR and its requirements, it is important to know that DPOs are not held personally responsible for non-compliance with the GDPR.It is clear, within the GDPR, that it is the data controller or the data processor who is required, at all times, to ensure and demonstrate that its data processing complies with the GDPR.
The GDPR recognises the DPO as an important player in the new data protection regime.
The aim of this guidance note is to provide advice on the GDPR’s requirement relating to the appointment of the DPO and also assist DPOs in their role.
Annex to Letters from Art. 29 Working Party to MEP Jan Philipp Albrecht and to Commissioner Věra Jourová in view of the trilogue
<http://ec.europa.eu/justice/data-protection/article-29/documentation/other-document/files/2015/20150617_appendix_core_issues_plenary_en.pdf > Accessed 11 August 2017