Designation of a Data Protection Officer Under Specified Conditions, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 37(1).
Assessment Step
1
Designation of a Data Protection Officer Under Specified Conditions (DesignationofaDataProtectionOfficerUnderSpecifiedConditions)
If the entity is a public authority or body (excluding courts), or if its core activities involve large-scale regular and systematic monitoring of data subjects, or large-scale processing of special categories of data or data on criminal convictions, does the entity designate a data protection officer?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Designation of a Data Protection Officer Under Specified Conditions
The data controller and the data processor must designate a data protection officer when: the processing is carried out by a public authority or body (except for courts acting in a judicial capacity); the core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale; or the core activities consist of processing special categories of data or personal data relating to criminal convictions and offences on a large scale.
Citation
GDPR
Art. 37(1), Recital 97
|