Analysis of personal data protection regulations (GDPR) – 4. The obligations of operators who perform personal data processing activities

Analysis of personal data protection regulations (GDPR) – 3. To whom the Regulation (EU) 2016/679 it is applied
February 19, 2018
Analysis of personal data protection regulations (GDPR) – 5. Explanations related to getting the consent
February 26, 2018

Regarding the personal data operators, new obligations have been introduced by Regulation (EU) 2016/679 on the protection of individuals regarding the processing of personal data and the free movement of such data (GDPR):

  • Obligation to use appropriate technical and organizational measures to implement data protection principles; (ex: writing of rules and data security procedures).
  • Obligation to minimize the data required for processing (the obligation to process only the data required for each specific purpose). For example, it does not require to ask commercial partners or employees for more data than they strictly need.
  • Obligation to notify the supervisory authority in the event of a breach of personal data security (within the time limits imposed by the Regulation).
  • Obligation to carry out an impact assessment of the processing and consulting operations of the supervisory authority.
  • Obligation to adapt all the provisions of the contracts of collaboration, service provision, etc.

Regarding the DPO (Data Protection Officer – Data Protection Officer), we specify that not all companies (operators) have the obligation to designate it. This obligation applies only to those companies that process large-scale special categories of data. However, we emphasize that all operators performing activities of the kind mentioned above are required to implement the regulation, even if only a number of operators are required to designate a DPO.

However, both the EU regulation and the national supervisory authority recommend the appointment of a DPO. It may be a person in the company, but which for the data protection services will conclude with the company a separate contract. They also have to attend certain courses and get some certifications. Under these circumstances, it is preferable for the service to be outsourced.

As regards the conditions a DPO must fulfill, it must be designated on the basis of professional qualities and, in particular, knowledge of the field of law and practice in the field of data protection, so as to have the ability, and fulfill the task.

The Data Protection Officer shall at least have the following tasks:

  1. information and advice to the operator or the person empowered by the operator, as well as to the staff dealing with the processing of obligations under the Regulation and other laws of the Union or national provisions on data protection.
  2. monitoring compliance with the Regulation, other laws of the Union or internal law regarding the protection of personal data, including the allocation of responsibilities and awareness-raising and training actions to the personnel involved in processing operations, and related audits.
  3. providing on-demand advice on data protection impact assessment and monitoring of its operation.
  4. cooperation with the supervisor authority.
  5. being the point of contact for the supervisor authority regarding the processing issues, including prior consultation, and, where appropriate, consultation on any other matter.

These are just a schematic and succinct presentation of the provisions of the new GDPR Regulation. For any questions or clarifications, please contact us by email at office@paulopol.ro.

How can we help you to implement GDPR correctly

We present you further on just a few examples of services you can get from the Paulopol Attorneys and Counselors Law Firm by outsourcing the Data Protection Officer (DPO), in order for you to implement GDPR correctly:

  1. Specialized consulting on the protection of personal data.
  2. Drafting or reviewing internal policies and data protection rules
  3. Legal opinions on the measures to be taken in order to comply with the legal provisions.
  4. Data protection audit based on the analysis of all operating regulations and internal policies.
  5. Drawing up codes of conduct.
  6. Database management consulting.
  7. Drawing up the transfer policies of the databases.
  8. Drafting and consulting on the implementation of policies on the protection of employees personal data,

These are just some of the services we can offer you related to GDPR. For details and legal assistance, please contact us by email at office@paulopol.ro.