Safeguards for the Independence and Non-Penalization of the Data Protection Officer, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 38(3).

Assessment Step

1
Safeguards for the Independence and Non-Penalization of the Data Protection Officer (SafeguardsfortheIndependenceandNon-PenalizationoftheDataProtectionOfficer)
Does the entity ensure that the data protection officer does not receive instructions regarding the performance of their tasks, is not dismissed or penalized for performing those tasks, and reports directly to the highest management level?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Safeguards for the Independence and Non-Penalization of the Data Protection Officer
The data controller and the data processor must ensure that the data protection officer does not receive any instructions regarding the performance of their tasks, is not dismissed or penalized for performing those tasks, and reports directly to the highest management level.
Citation
GDPR
Art. 38(3), Recital 97