Definition and Support of Data Protection Officer Responsibilities, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 39(1).
Assessment Step
1
Definition and Support of Data Protection Officer Responsibilities (DefinitionandSupportofDataProtectionOfficerResponsibilities)
Does the entity ensure that the data protection officer is responsible for: advising the entity and employees about GDPR obligations; monitoring compliance and promoting awareness; advising on and monitoring DPIAs; cooperating with the supervisory authority; and serving as a contact point for the authority on processing matters?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Definition and Support of Data Protection Officer Responsibilities
The data controller and the data processor must ensure that the data protection officer is entrusted with at least the following tasks: (a) informing and advising the data controller or the data processor and employees about their GDPR obligations; (b) monitoring compliance with the GDPR and internal data protection policies, including assignment of responsibilities, awareness-raising, and training; (c) providing advice regarding data protection impact assessments and monitoring their performance; (d) cooperating with the supervisory authority; and (e) acting as the contact point for the supervisory authority on issues related to processing.
Citation
GDPR
Art. 39(1), Recital 97
|