Wanneer moet je een Data Protection Officer DPO aanstellen | Global Knowledge
Skip to main Content
Article

When do you have to appoint a Data Protection Officer (dpo)?

Global Knowledge
The General Data Protection Regulation (GDPR) takes effect May 2018 and has many consequences for how we handle data security and privacy. All organizations that process personal data from EU citizens will have to deal with the GDPR. One of the issues that many people are asking themselves is "when am I obligated to appoint a Data Protection Officer and what is his/her role?".

What is a Data Protection Officer?

The DPO monitors compliance with the law regarding privacy and data and is also the corresponding contact person internally and externally. It is important that he/she recognizes privacy risks and can prevent them. Not only technically, but also especially by properly setting up processes and making sure that they are also properly executed. The DPO has the overview of all activities that regard data security. In addition, he/she ensures that the culture considers security and privacy issues. The creation of awareness is therefore also a role for the Data Protection Officer.

When are you Obligated to appoint a Data Protection Officer?

There are three cases in which an organization is obligated to have a DPO. The law describes it precisely, but basically you need to have a DPO when:
  1. Your organization is a governmental organization or government agency
  2. When your organization monitors people regularly or systematically on a large scale by processing data. Although there is no definition in the GDPR, monitoring is, in any event, every form of tracking and profiling on internet or offline. Therefore, behavioral advertising or email re-targeting are also included in monitoring
  3. When you process data that is in one of the special categories of personal data. This is personal data from which race or ethnic origin, political views, religious or ideological convictions or the membership in a trade union are apparent and processing of genetic data, biometric data with the view of unique identification of a person, or data about health, or data regarding someone's sexual behavior or sexual orientation, or data about criminal convictions and criminal offenses. In any event, in order to be able to process all of this data, special additional rules are applicable.
For that matter, Nederland ICT has developed a useful Quickscan that give you an idea whether your organization probably also requires a DPO. It appears from the first results that approximately 40% of the organizations that do the quickscan will also actually have to appoint a Data Protection Officer.

Why a DPO with commercial understanding is worth his/her weight in gold

It’s clear that the preparation for the GDPR will cost some time and effort. If you do not coordinate your commercial processes pragmatically with the GDPR, then marketing, sales, finance, HR and customer support will soon no longer be able to handle all the data that has been collected over the years. A DPO who can help think about the optimal arrangement of the commercial processes while they satisfy the GDPR is therefore particularly valuable. That will provide a particularly great competitive advantage after May 2018. Your databases are strong, everyone knows what is expected and you do not have to temporarily stop your organization at all because you simply do not satisfy the regulations.

Petra Eikenboom

Marketing Specialist