Blog
Understanding the Data Protection Officer Role
Many UK organisations still have yet to achieve compliance with GDPR. Over a year after its implementation in 2018, a study conducted by Egress discovered that more than half of businesses (52%) are not fully compliant with GDPR regulations.
GDPR compliance is an involved process that can't be achieved overnight. Rather, it is an ongoing learning curve that requires time as well as someone qualified and well-versed to oversee its implementation and long-term compliance as part of the business’ operations. That person is a Data Protection Officer (DPO) and, among the many new rules GDPR has implemented, is a further tightening of the requirements and criteria for this key role.


Everything Your Oranisation Needs to Know About a DPO
While there are certain scenarios that legally demand the appointment of a data protection officer, most organisations will likely handle large amounts of personal data and risk jeopardising their reputation among its existing and potential customers if breached.
As such, it remains advisable for any and all organisations to appoint a DPO. The key point to note is they'll need to conform to the criteria set forth by the European Data Protection Board, as we explain below.
1. Acting as the liaison between the company, the data subjects and regulatory bodies
The DPO acts as the contact point for both the data subjects and the supervisory authority (in the UK this is the Information Commissioners Office (ICO)). They have to be prepared to answer any questions, offer advice and respond to any data subject access requests. The DPO will be registered with the ICO and their contact details will be made available to data subjects via privacy notices.
2. Identifying and ensuring the delivery of training and awareness programmes for employees and contractors
The DPO needs to understand the roles and responsibilities within the business, identify training needs and source suitable training solutions. In addition to this, awareness raising through regular updates and notification emails will be the responsibility of the DPO to promote a culture of data protection within the company.
3. Complying with article 30 of GDPR
The DPO will need to have a complete and regularly updated record of the processing activities of the business. This will involve working closely with different departments to understand how personal data is processed across the business. This might also involve activities such as data flow mapping.
4. Conducting regular audits to ensure compliance is maintained and ensuring policies and procedures are regularly reviewed and updated where required
The DPO will need to ensure that compliance is being maintained by implementing an audit plan to review existing policies and procedures and ensure they are being followed. Equally, as the business changes, policies and procedures will need to be updated to reflect these changes.
5. Overseeing/supervising Data Protection Impact Assessments (DPIAs)
The DPO will need to have a good understanding of when a DPIA is mandatory, a good understanding of risk and be able to guide different departments in the business through the DPIA process. The DPO will also be responsible for any prior consultation with the ICO relating to high-risk activities identified by a DPIA that cannot be mitigated.
6. Managing a data breach
The DPO has to fully understand the requirements of GDPR in relation to reporting breaches and ensure there is a fully tested process in place to deal with breaches in the business. DPOs will need to ensure breaches are recorded correctly and lessons are learnt to prevent the same thing happening again.
7. Keeping up to date with the latest data privacy legislation and rulings by the EDPB and Supervisory Authorities
Given that GDPR is a relatively new law, there are still a lot of unknowns regarding its interpretation. The DPO plays a key role in ensuring the business is informed of new guidance from regulatory authorities and also understands how new privacy legislation might affect the business.
As such, the European Data Protection Board stipulates that the DPO must have an in-depth understanding of GDPR as well as information technology and data security. They should also be well-informed about the business and its industry.
When a company appoints a DPO, it needs to meet the requirements of the role as defined in GDPR and by later guidance from the EDPB.
Having an in-depth understanding of GDPR as well as information technology and data security
This can sometimes be a difficult skillset to find. Many DPOs come from a legal background as they need to be able to understand and interpret the law, however many may not have a solid understanding of data security and technology.
Avoiding a conflict of interest
Alongside the necessary expertise and attributes, one of the key requirements is that the DPO needs to act in an unbiased and independent manner. In other words, any other tasks that an individual performs outside of their DPO role cannot cause a conflict of interest. Frequently, organisations believe that because of the overlapping skills and qualifications, a CISO or IT Manager can also be the DPO.
However, this would lead the CISO/IT Manager monitoring themselves, essentially marking their own homework, which is a conflict of interest. The IT Manager or a CISO (see guide to whether you need a CISO) can play a supporting role but should not be the DPO. The same can be said of an individual working in human resources, marketing, customer service etc. If they are a controller or processor of personal data, they can't be a DPO.
Reporting to highest levels of management and autonomy
DPOs must directly report to the highest management level and should not receive any instructions about their overall performance of duties. They should have full authority of their own budget, which allows them to:
Conduct site visits
Hire a team to fill in any skills gaps, or to provide support in case of a crisis/security issue
Ensure employees receive the necessary security training
Invest in educational material and events
Become a member of associations for DPOs and privacy professionals, including the IAPP
Furthermore, they should have the mandate to conduct investigations without fear of reprisals. No disciplinary action can be enacted against the DPO for the advice they offer. Equally, they are not personally liable if the advice given was not actioned by the organisation.
The role should not be underestimated or taken for granted. With an experienced and knowledgeable DPO, an organisation will fare much better in achieving regulatory compliance. This is both beneficial in avoiding the steep fines that come with non-compliance, as well as maintaining their reputation as a respected and dependable company in the eyes of the public. Unfortunately, selecting a DPO is often not a straightforward undertaking.
For instance, the DPO’s scope of work might be dependent on the organisation they work in. On the one hand, taking someone on part-time may not be sufficient to address all duties. On the other, having someone full-time might leave them without enough to do. In the latter case, difficulties may also arise when seeking other tasks they could undertake which do not lead to a conflict of interest.
Another consideration is whether there is someone within the organisation with the necessary expertise. For smaller organisations, employees tend to wear many hats, making it difficult to single out an independent DPO. For other, perhaps larger organisations, they might come from a legal background however, they might not be as acquainted with information technology and data security. Even if a business were to invest both the money and time to train the individual, this does not guarantee that they will have sufficient experience to successfully manage the challenging ordeal of a data breach. Moreover, if the DPO were to fall sick or go on a holiday, the organisation would also have to be prepared to have someone competent to cover for their absence.
Looking to Outsource Your DPO Needs?
There are many factors to consider when looking to appoint a DPO and there is no one size fits all. While the search for the right one may at first present itself as a burden, it is worth investing the time – especially as the stakes have never been higher, both on a reputational and financial front. You can enhance your data protection security today by contacting us for a free consultation.
Share your challenge with us and we’ll help you find the right level of support for your business.














