ARGO INVESTIGATIONS

DPO – Data Protection Officer

Corporate Investigations: The Data Protection Officer

Who is the DPO, what are the requirements for this role, in which cases it is required, and what functions it performs.

The rapid pace of technological evolution and globalization has produced both positive and negative effects. Among the latter, one must note the significant risk to which personal data are exposed. The scope of data sharing and collection has increased considerably, and both private companies and public administrations now have the power to manage and use a vast amount of sensitive information compared to the past. Individuals today more frequently make personal content and information available, and for this reason, it is essential to establish security measures to protect such data.

EU Regulation 679/2016 responded to this need by introducing the professional figure of the Data Protection Officer (DPO) in order to ensure the effective protection of this information. Specifically, the DPO is understood as the Data Protection Officer (RPD). This regulation, which entered into force on May 25, 2016, has applied to all 28 EU member states since May 25, 2018.

The introduction of the DPO is not an entirely new concept in European legislation. Although no EU law had previously mandated such a professional figure, many member states had already recognized it through the implementation of Directive 95/46/EC. For example, in English-speaking countries, this role is known under various titles: Chief Privacy Officer (CPO), Privacy Officer, Data Protection Officer, or Data Security Officer.

The DPO or RPD is selected based on professional qualifications and expertise in data processing. This role may be filled by an employee of the data controller or by an independent external professional contracted through a service agreement. The Data Protection Officer, appointed by the controller or processor, must meet the following requirements:

  • Possess adequate knowledge of data protection laws and practices, including technical and organizational measures necessary to ensure data security. No formal certifications or professional registry memberships are required, although participation in master’s programs and professional training can serve as evidence of adequate expertise.
  • Perform duties with full independence and without conflicts of interest.
  • Operate under the controller or processor or based on a service contract (for external DPOs).

 

The controller or processor must provide the DPO with the human and financial resources necessary to carry out their duties.

This Regulation therefore requires that the DPO possess a combination of skills (legal, IT, risk management, process analysis, etc.) to ensure effective data protection. The DPO’s primary responsibility is to monitor, evaluate, and organize the management of personal data processing—and therefore their protection—within a company (public or private), ensuring compliance with European and national privacy laws.

The Regulation mandates that companies and public administrations processing sensitive or large-scale data must appoint a DPO in three cases:

  • When the processing is carried out by public administrations, public bodies, or public organizations (except for judicial authorities in the exercise of their functions[1]);
  • When the processing, by its nature, scope, or purposes, requires regular and systematic large-scale monitoring of individuals;
  • When the processing involves large-scale sensitive, genetic, biometric, criminal, health, or sexual life data.

 

Finally, even when the Regulation does not specifically require the appointment of a DPO, it may still be done voluntarily.

According to Article 39 of the European Regulation on personal data protection, the DPO must, in particular:

  • Monitor compliance with the Regulation and other EU or member state provisions on data protection, assessing the risks of each processing activity considering its nature, scope, context, and purposes;
  • Collaborate with the controller/processor, when necessary, in conducting a Data Protection Impact Assessment (DPIA);
  • Inform, raise awareness, and advise the controller or processor, as well as their employees, on obligations under this Regulation and other national or EU data protection laws;
  • Provide opinions, if requested, regarding the impact assessment and monitor its implementation under Article 35;
  • Cooperate with the supervisory authority and act as a point of contact for all issues related to data processing[2];
  • Support the controller or processor in all activities related to data processing, including maintaining a record of processing activities.

 

In carrying out their duties, the DPO must take into account the risks associated with processing, considering its nature, scope, context, and purpose.

The DPO must be promptly and adequately involved in all matters concerning data protection and must be supported by the controller and processor, who are required to provide all necessary resources both for their work and to allow continuous professional development. In all cases, the DPO’s work must be carried out with complete autonomy and independence: no one may instruct them on how to perform their tasks, and the DPO may not hold any other position or function that could create a conflict of interest. The DPO is also bound by confidentiality and secrecy obligations regarding the functions performed.

It is clear that the introduction of this role serves not only to shift responsibilities from one subject (controller/processor) to another (the DPO) but above all to assign these responsibilities to a specialized and knowledgeable professional dedicated exclusively to data protection. This ensures that such a person remains constantly updated on risks, issues, and security measures necessary to guarantee an adequate level of protection—reflecting the growing importance, diffusion, and complexity of privacy and data processing, particularly in the digital and online world.

The controller and processor must therefore implement all technical and organizational measures capable of ensuring an adequate level of security against risks such as destruction, loss, alteration, unauthorized disclosure, and accidental or unlawful access to transmitted, stored, or otherwise processed personal data[3].

Finally, data subjects have the right to contact the DPO for any matter concerning the processing of their personal data.

In conclusion, in light of the above, companies wishing to ensure adequate security standards are advised to appoint a DPO even when not legally required, preferably entrusting this task to external professionals. It is essential to rely on experts who invest continuously in the training of their staff. In this regard, Argo offers to the emerging market this professional figure, which over time will become indispensable for all companies acting as Controllers or Processors of personal and sensitive data, even when the appointment is not mandatory by law.

It is essential to rely on professionals when managing such sensitive data to ensure that they do not leak, that they are secured, and that they are handled with the utmost diligence and care.

 

Notes
[1] A group of companies or public entities may appoint a single DPO.
[2] Despite the legal guarantees of autonomy and independence, one must question how many employees would actually be willing to report improper behavior or incorrect assessments by the data controller or processor to top management.
[3] If the impact assessment indicates that the processing presents a high risk in the absence of specific risk mitigation measures, the data controller must consult the competent supervisory authority before beginning the processing. On that occasion, the controller must provide not only the impact assessment but also all other relevant information regarding the processing and the entities acting as controllers or processors.

Contact details

Take a few minutes and send us your requests, we will come back with a solution

Contact us