Designation of the Data Protection Officer Based on Expertise and Professional Qualities, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 37(5).

Assessment Step

1
Designation of the Data Protection Officer Based on Expertise and Professional Qualities (DesignationoftheDataProtectionOfficerBasedonExpertiseandProfessionalQualities)
Does the entity designate a data protection officer based on professional qualities, including expert knowledge of data protection law and practices and the ability to fulfil the responsibilities described in Article 39?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Designation of the Data Protection Officer Based on Expertise and Professional Qualities
The data controller and the data processor must designate a data protection officer based on professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39.
Citation
GDPR
Art. 37(5), Recital 97