{"id":1589,"date":"2018-01-17T19:08:55","date_gmt":"2018-01-17T19:08:55","guid":{"rendered":"https:\/\/crigroup.com\/?post_type=blog&#038;p=1589"},"modified":"2022-11-14T15:27:55","modified_gmt":"2022-11-14T15:27:55","slug":"gdpr-data-protection-officer","status":"publish","type":"post","link":"https:\/\/crigroup.com\/ar\/gdpr-data-protection-officer\/","title":{"rendered":"Appointment of Data Protection Officer under GDPR"},"content":{"rendered":"<p>There is the growing misconception surrounding the need for appointing a Data Protection Officer (DPO) under GDPR which is effective on 25th May 2018. The role of DPO is critical for correct implementation of the newly drafted regulation. Relating to this, the organisation needs to ask itself four main questions before appointing a DPO which are:<\/p>\n<ol>\n<li>Do they even need to appoint a DPO?<\/li>\n<li>Should they need a DPO anyway for safe measures of compliance?<\/li>\n<li>Can the role of DPO be outsourced?<\/li>\n<li>Will the DPO be personally liable?<\/li>\n<li>When should a DPO be appointed?<\/li>\n<\/ol>\n<p>I will start by answering the first question. According to article 37(1), GDPR requires data controllers and processors to designate a DPO in any case where:<\/p>\n<ul>\n<li>The processing is carried out by a public authority or body;<\/li>\n<li>The \u2018core activities\u2019 of the controller\/ processor consist of processing operations which \u2018require regular and systematic monitoring of data subjects on a large scale\u2019; or<\/li>\n<li>The core activities of the controller\/ processor consist of processing on a large scale of \u2018special categories of data\u2019 or personal data relating to criminal convictions and offences.<\/li>\n<\/ul>\n<p>As per the definition private sector companies will not need to appoint a DPO. Majority of the private companies do not engage in monitoring of personal data, therefore in their course of administration they will not need a DPO. For ready and seamless implementation of the three criteria stated above guidance of Article 29 of Working Party Guidelines on DPO\u2019s issued in 2016 and then 2017 can be sought so that correct measures are taken.<\/p>\n<p>The second question of whether DPO is needed anyway for safe measure of compliance can be answered by making use of Article 37(5) which basically lays down the requirements and puts an organisation under obligation to appoint someone which has adequate knowledge of data protection law and practices, in short, the qualification required for appointment of DPO. Generally, there may be someone who will be fulfilling the role of DPO to be required to meet the standard under GDPR for compliance under Article5(2). The Guidelines also suggest that the knowledge must commensurate with experience, complexity and sensitivity of data with expertise in European data protection laws and with in-depth GDPR knowledge.<\/p>\n<p>It is important to note that the actual role of DPO will be different from that of a normal employee or a contractor in that case as DPO are independent species not bound by the administration and are to operate freely out of their will. This means that they cannot be assigned task or instructed to do tasks assigned by the CEO or the central administration. The level of impartiality needs to be maintained separately from the organisation so there is no corruption and bias in the process of compliance structure when adhering to the GDPR regulation.\u00a0 In line with this the DPO\u2019s employment status is protected under Article 38(3) of the GDPR, which means they cannot be dismissed or be sanctioned by the organisation from performing or not performing tasks. Therefore, the appointment of a DPO will be a critical juncture in the implementation of GDPR as this will determine the future of compliance standards set and met in the organisation.<\/p>\n<p>Can the role of DPO be outsourced? This is answered under the Article 37(6) of the GDPR which makes it simplistically clear that DPO can be an employee or a contractor. Giving the concerns and apprehensions raised in the above paragraph, many experts in the field of compliance are of the opinion such role needs to be outsourced, rather than being in-house. However, there is no straightforward answer and depends on the requirement and load of the organisation compliance setup. The DPO needs to be involved as per the regulation in a \u201cproper and timely manner, in all issues which relate to the protection of personal data\u201d. The Guidelines state that controllers and processors must develop data processing guidelines or programmes that set out when can the DPO be consulted. If this method is conducted, organisations can perform much productively and meet their compliance goals.<\/p>\n<p>Is DPO personally liable? The Working Party Guidelines state that DPO will not be personally liable in case of noncompliance with GDPR. However, the GDPR text is silent on the issue of liability and the text does not say much and is in fact silent on this. DPO\u2019s will need to be cautious regardless.<\/p>\n<p>Organisations need to decide on the appointment of the DPO and who will be the best one for their need. For this they must conduct their <a href=\"https:\/\/crigroup.com\/ar\/solution-category\/background-investigations\/\">background screening<\/a> through tools such as EmploySmart\u2122\u00a0and finalise candidate fit for this role so that it sits well with the newly identified governance structure of the organisation. Using <a href=\"https:\/\/crigroup.com\/ar\/solution-category\/background-investigations\/\">appropriate background checks<\/a> will ensure that Data Protection Officers skills are identified before the finalisation of the job. Ultimately what is a better fit for the business, will be determined by the decision-making heads of the organisation as the time is shrinking. Consensus on DPO is the need of the hour.<\/p>\n<p><strong>Who is CRI Group?<\/strong><\/p>\n<p>Based in London, CRI Group works with companies across the Americas, Europe, Africa, Middle East and Asia-Pacific as a one-stop international <a href=\"https:\/\/crigroup.com\/ar\/third-party-risk-management\/\">Risk Management<\/a>, <a href=\"https:\/\/crigroup.com\/ar\/employee-background-checks\/\">Employee Background Screening<\/a>, <a href=\"https:\/\/crigroup.com\/ar\/business-intelligence\/\"><div id=\"h1-9\">\u0630\u0643\u0627\u0621 \u0627\u0644\u0623\u0639\u0645\u0627\u0644<\/div><\/a>,\u00a0<a href=\"https:\/\/crigroup.com\/ar\/due-diligence\/\"><div id=\"h1-2\">\u0627\u0644\u0639\u0646\u0627\u064a\u0629 \u0627\u0644\u0648\u0627\u062c\u0628\u0629 <span class=\"rtl-1\">360\u00b0<\/span><\/div><\/a>, <a href=\"https:\/\/crigroup.com\/ar\/compliance-solutions\/\"><div id=\"h1-1\">\u062d\u0644\u0648\u0644 \u0627\u0644\u0627\u0645\u062a\u062b\u0627\u0644<\/div><\/a>\u00a0and other professional <a href=\"https:\/\/crigroup.com\/ar\/investigative-solutions\/\">Investigative Research<\/a> solutions provider. We have the largest proprietary network of background-screening analysts and investigators across the Middle East and Asia.\u00a0Our global presence ensures that no matter how international your operations are we have the network needed to provide you with all you need, wherever you happen to be. CRI Group also holds <strong>BS 102000:2013<\/strong>\u00a0and <strong>BS 7858:2012 Certifications<\/strong>, is an HRO certified provider and partner with Oracle.<\/p>\n<p>In 2016, CRI Group launched <a href=\"https:\/\/abacgroup.com\/\">Anti-Bribery Anti-Corruption (ABAC\u00ae) Center of Excellence<\/a> &#8211; an independent certification body established for <a href=\"https:\/\/abacgroup.com\/iso-37001-certification\/\">ISO 37001:2016 Anti-Bribery Management Systems<\/a>, <a href=\"https:\/\/abacgroup.com\/iso-37301-certification\/\">ISO 37301 Compliance Management Systems<\/a> and <a href=\"https:\/\/abacgroup.com\/iso-31000-risk-management\/\">ISO 31000:2018 Risk Management<\/a>, providing <a href=\"https:\/\/abacgroup.com\/iso-37001-training\/\">training<\/a> and <a href=\"https:\/\/abacgroup.com\/iso-37001-certification\/\">certification<\/a>. ABAC\u00ae operates through its global network of certified ethics and compliance professionals, qualified auditors and other certified professionals. As a result, CRI Group&#8217;s global team of certified fraud examiners work\u00a0as a discreet white-labelled supplier to some of the world\u2019s largest organisations.\u00a0<a href=\"https:\/\/abacgroup.com\/contact\/\">Contact\u00a0ABAC\u00ae for more<\/a> on ISO Certification and training.<\/p>","protected":false},"excerpt":{"rendered":"<p>There is the growing misconception surrounding the need for appointing a Data Protection Officer (DPO) under GDPR which is effective on 25th May 2018. The role of DPO is critical for correct implementation of the newly drafted regulation. Relating to this, the organisation needs to ask itself four main questions before appointing a DPO which [&hellip;]<\/p>","protected":false},"author":1,"featured_media":21384,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[16,23,146],"tags":[],"class_list":["post-1589","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance-solution","category-industry-insights","category-resources"],"gutentor_comment":0,"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v16.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"Appointment of Data Protection Officer under GDPR is surrounding misconception - the organisation needs to ask itself 4 main questions.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/crigroup.com\/ar\/gdpr-data-protection-officer\/\" \/>\n<meta property=\"og:locale\" content=\"ar_AR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Appointment of Data Protection Officer under GDPR\" \/>\n<meta property=\"og:description\" content=\"Appointment of Data Protection Officer under GDPR is surrounding misconception - the organisation needs to ask itself 4 main questions.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/crigroup.com\/ar\/gdpr-data-protection-officer\/\" \/>\n<meta property=\"og:site_name\" content=\"National-Grade Workforce Integrity &amp; Safe Hiring Framework\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/crigroup\/\" \/>\n<meta property=\"article:published_time\" content=\"2018-01-17T19:08:55+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-11-14T15:27:55+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/crigroup.com\/wp-content\/uploads\/2018\/01\/Appointment-of-Data-Protection-Officer-under-GDPR.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1280\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@crigroup\" \/>\n<meta name=\"twitter:site\" content=\"@crigroup\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/crigroup.com\/#organization\",\"name\":\"CRI Group\\u2122\",\"url\":\"https:\/\/crigroup.com\/\",\"sameAs\":[\"https:\/\/www.facebook.com\/crigroup\/\",\"https:\/\/www.linkedin.com\/company\/corporateresearchandinvestigations\/\",\"https:\/\/www.youtube.com\/channel\/UCn-EXXdew6XIApQm0kyGPMw\/\",\"https:\/\/twitter.com\/crigroup\"],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/crigroup.com\/#logo\",\"inLanguage\":\"ar\",\"url\":\"https:\/\/crigroup.com\/wp-content\/uploads\/2022\/04\/CRI-Group-Copy.jpg\",\"contentUrl\":\"https:\/\/crigroup.com\/wp-content\/uploads\/2022\/04\/CRI-Group-Copy.jpg\",\"width\":1920,\"height\":796,\"caption\":\"CRI Group\\u2122\"},\"image\":{\"@id\":\"https:\/\/crigroup.com\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/crigroup.com\/#website\",\"url\":\"https:\/\/crigroup.com\/\",\"name\":\"National-Grade Workforce Integrity &amp; Safe Hiring Framework\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/crigroup.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":\"https:\/\/crigroup.com\/?s={search_term_string}\",\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"ar\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/crigroup.com\/gdpr-data-protection-officer\/#primaryimage\",\"inLanguage\":\"ar\",\"url\":\"https:\/\/crigroup.com\/wp-content\/uploads\/2018\/01\/Appointment-of-Data-Protection-Officer-under-GDPR.jpg\",\"contentUrl\":\"https:\/\/crigroup.com\/wp-content\/uploads\/2018\/01\/Appointment-of-Data-Protection-Officer-under-GDPR.jpg\",\"width\":1920,\"height\":1280,\"caption\":\"Appointment of Data Protection Officer under GDPR\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/crigroup.com\/gdpr-data-protection-officer\/#webpage\",\"url\":\"https:\/\/crigroup.com\/gdpr-data-protection-officer\/\",\"name\":\"Appointment of Data Protection Officer under GDPR\",\"isPartOf\":{\"@id\":\"https:\/\/crigroup.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/crigroup.com\/gdpr-data-protection-officer\/#primaryimage\"},\"datePublished\":\"2018-01-17T19:08:55+00:00\",\"dateModified\":\"2022-11-14T15:27:55+00:00\",\"description\":\"Appointment of Data Protection Officer under GDPR is surrounding misconception - the organisation needs to ask itself 4 main questions.\",\"breadcrumb\":{\"@id\":\"https:\/\/crigroup.com\/gdpr-data-protection-officer\/#breadcrumb\"},\"inLanguage\":\"ar\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/crigroup.com\/gdpr-data-protection-officer\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/crigroup.com\/gdpr-data-protection-officer\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/crigroup.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"All Solutions\",\"item\":\"https:\/\/crigroup.com\/all-solutions\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Compliance Solution\",\"item\":\"https:\/\/crigroup.com\/all-solutions\/compliance-solution\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Appointment of Data Protection Officer under GDPR\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/crigroup.com\/gdpr-data-protection-officer\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/crigroup.com\/gdpr-data-protection-officer\/#webpage\"},\"author\":{\"@id\":\"https:\/\/crigroup.com\/#\/schema\/person\/1fa7c310a7670e7d554b30e5d4c94d78\"},\"headline\":\"Appointment of Data Protection Officer under GDPR\",\"datePublished\":\"2018-01-17T19:08:55+00:00\",\"dateModified\":\"2022-11-14T15:27:55+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/crigroup.com\/gdpr-data-protection-officer\/#webpage\"},\"wordCount\":1030,\"publisher\":{\"@id\":\"https:\/\/crigroup.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/crigroup.com\/gdpr-data-protection-officer\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/crigroup.com\/wp-content\/uploads\/2018\/01\/Appointment-of-Data-Protection-Officer-under-GDPR.jpg\",\"articleSection\":[\"Compliance Solution\",\"Industry Insights\",\"Resources\"],\"inLanguage\":\"ar\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/crigroup.com\/#\/schema\/person\/1fa7c310a7670e7d554b30e5d4c94d78\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/crigroup.com\/#personlogo\",\"inLanguage\":\"ar\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/3c599f0f92bce780dd3dc1c2b4dcc284?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/3c599f0f92bce780dd3dc1c2b4dcc284?s=96&d=mm&r=g\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/crigroup.com\/\",\"Admin\"],\"url\":\"https:\/\/crigroup.com\/ar\/author\/admin-2\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","_links":{"self":[{"href":"https:\/\/crigroup.com\/ar\/wp-json\/wp\/v2\/posts\/1589","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/crigroup.com\/ar\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crigroup.com\/ar\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crigroup.com\/ar\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/crigroup.com\/ar\/wp-json\/wp\/v2\/comments?post=1589"}],"version-history":[{"count":5,"href":"https:\/\/crigroup.com\/ar\/wp-json\/wp\/v2\/posts\/1589\/revisions"}],"predecessor-version":[{"id":21385,"href":"https:\/\/crigroup.com\/ar\/wp-json\/wp\/v2\/posts\/1589\/revisions\/21385"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crigroup.com\/ar\/wp-json\/wp\/v2\/media\/21384"}],"wp:attachment":[{"href":"https:\/\/crigroup.com\/ar\/wp-json\/wp\/v2\/media?parent=1589"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crigroup.com\/ar\/wp-json\/wp\/v2\/categories?post=1589"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crigroup.com\/ar\/wp-json\/wp\/v2\/tags?post=1589"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}