ARTICLE
2 October 2018

GDPR, The Data Protection Officer: Do You Need to Appoint a Dedicated Officer?

I
Intertrust

Contributor

Intertrust logo
Intertrust is a global leader in providing expert administrative services to clients operating and investing in the international business environment. The Company has over 2,500 employees globally. Intertrust delivers high-quality, tailored corporate, fund, capital market and private wealth services to its clients, with a view to building long-term relationships.
The GDPR contains a large section about Data Protection Officer (DPO) requirements: it reads almost like an extensive job description with detailed information on appointment, position and tasks of the DPO.
Netherlands Privacy
To print this article, all you need is to be registered or login on Mondaq.com.

The GDPR contains a large section about Data Protection Officer (DPO) requirements: it reads almost like an extensive job description with detailed information on appointment, position and tasks of the DPO. But how do you know if a DPO is mandatory for your organisation and whether you should consider outsourcing the DPO role?

Appointment of a DPO is mandatory for companies who are:

  • public authority
  • regularly and systematically monitoring data subjects on a large scale
  • processing special categories of data (medical/ethnic)

 Think of companies which are state financed or owned with a focus on tracing or monitoring  individuals through portable devices; companies with customer loyalty programmes; or organisations in the health care environment.

Even if you don't meet the mandatory DPO criteria, you can chose to appoint a DPO voluntarily, you might base this decision on on best practice for your specific business sector.

Why outsource your DPO?

Once you've decided to appoint a DPO, you might consider whether appointing an external DPO would be more suitable than appointing someone from within your organisation. Outsourcing a DPO can be the best option if you're searching for a part-time, cost effective solution; if your organisation needs independent expertise; or you want to avoid any possible conflict of interest. An outsourced DPO can provide your organisation with best practice guidance and independent sector expertise to help you comply with the GDPR requirements. By outsourcing the DPO, your organisation can benefit from an independent contact person towards the supervisory authority.

At Intertrust, we can offer pragmatic DPO solutions and provide an outsourced DPO service, ensuring continuity and designed to your specific needs. Find out more, get in touch with our experts.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More