{"id":6887,"date":"2020-12-21T09:00:56","date_gmt":"2020-12-21T09:00:56","guid":{"rendered":"https:\/\/letslaw.es\/?p=6887\/"},"modified":"2023-01-23T10:16:12","modified_gmt":"2023-01-23T10:16:12","slug":"dpo","status":"publish","type":"post","link":"https:\/\/letslaw.es\/en\/dpo\/","title":{"rendered":"Data Protection Officer"},"content":{"rendered":"<p>The General Data Protection Regulation (GDPR) introduces new data protection novelties. One of these novelties is the obligation imposed of appointing a new person, the Data Protection Officer (DPD or DPO in English). This obligation will affect the from data proccesing is carried out.<\/p>\n<p>This obligation is framed within the principle of proactive responsibility of the data controller in the field of data protection. It provides a better control and efficiency in line with the above regulations.<\/p>\n<p>&nbsp;<\/p>\n<h2>Who is the Data Protection Officer?<\/h2>\n<p>&nbsp;<\/p>\n<p>The Data Protection Officer is a new figure introduced by the General Data Protection Regulation (GDPR).<\/p>\n<p>In order to obtain the data protection delegate certification, the <a href=\"https:\/\/letslaw.es\/en\/privacy-data-protection-lawyers\/security-data-protection-audits\/\"><strong>AEPD<\/strong><\/a> (Spanish Agency for Data Protection) has promoted a Certification scheme so that those responsible can select professionals whose skills as DPO have been certified by entities accredited by ENAC.<\/p>\n<p>&nbsp;<\/p>\n<h2>What are the duties of Data Protection Officer?<\/h2>\n<p>&nbsp;<\/p>\n<p>According to the Certification scheme promoted by the AEPD, the DPO is a professional whose functions are included in article 39 of the GDPR (RGPD in Spanish) and in articles 26 and 27 of the Organic Act on Protection of Personal Data and guarantee of digital rights.<\/p>\n<p>This includes the application of privacy and data protection law.<\/p>\n<h3>The DPO shall have at least these following functions:<\/h3>\n<ol>\n<li>To inform and advise the person in charge, or the person in the charge of the processing, and the persons authorized to process personal data under their direct authority, by virtue of the GDPR, the LOPDPGDD and other data protection provisions of the EU or its States members;<\/li>\n<li>To supervise compliance within the provisions of the GDPR, the LOPDPGDD and other data protection provisions of the EU and its Member States\u2019 data protection laws, as well as he policies of the responsible person or person responsible for the processing of personal data;<\/li>\n<li>To supervise the assignment of the responsibilities;<\/li>\n<li>To supervise the awareness and training of the personnel involved in the processing operations;<\/li>\n<li>To supervise the corresponding audits;<\/li>\n<li>To provide advice on the data protection impact assessments and monitor their application in accordance with Article 35 GDPR;<\/li>\n<li>To cooperate and act as an interlocutor with the supervisory authority in matters related to the processing of personal data, including prior consultations reoffered to in art. 36 GDPR<\/li>\n<\/ol>\n<p>The Data Protection Officer will perform his duties while paying attention to the risks associated with the processing operations, taking into account the nature, scope, context and purpose of the processing.<\/p>\n<p>The DPO will always carry out its functions with complete independence and in an autonomous manner, without instructions, and being directly accountable to the highest hierarchical level.<\/p>\n<p>To perform his functions, the DPO must have specialist knowledge of data protection law and practice, so that DPO is able to carry out his advisory and supervisory tasks, inter alia, the following areas:<\/p>\n<ol>\n<li>Compliance with processing rules such as the limitation of purpose, minimization or accuracy of data.<\/li>\n<li>Identification of the legal ground for processing.<\/li>\n<li>Compatibility assessment for purposes other than those that led to the initial collection of data.<\/li>\n<li>Establishment of the existence of sectoral regulations that may set specific processing conditions other than those set out in the genral data protection law.<\/li>\n<li>Creation and implementation of information measures for those affected by data processing.<\/li>\n<li>Establishment of procedures for the receipt and management of applications for the exercise of rights by interested parties.<\/li>\n<li>Assessment of requests to exercise rights by interested parties.<\/li>\n<li>Employing the processors, including the content of the contracts or legal acts that regulate the data processor relationship.<\/li>\n<li>Identification of instruments for international data transfers that responds to the needs and characteristics of the organization and the reasons that justify the transfer.<\/li>\n<li>Creation and implementation of data protection policies.<\/li>\n<li>Data protection audit.<\/li>\n<li>Establishment and management of records of processing activities.<\/li>\n<li>Risk analysis of the processing carried out.<\/li>\n<li>Implementation data protection measures from creation and default data protection appropriate to the risk and nature of processing.<\/li>\n<li>Implementation of safety measures appropriate to the risk and nature of processing.<\/li>\n<li>Establishment of procedures for managing data in case of security breaches, including the risk assessment for the rights and freedom of those affected and procedures for notifying the supervisory authorities and those affected.<\/li>\n<li>Determination of the nedd to carry out the impact assessment on data protection.<\/li>\n<li>Conducting the data protection impact assessments.<\/li>\n<li>Relations with supervisory authorities.<\/li>\n<li>Implementation of training and awareness programs for employees on data protection.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<h2>When do you need a Data Protection Officer?<\/h2>\n<p>According to Art.37 GDPR, the person in charge and the person in charge of data processing will designate a DPO when:<\/p>\n<ol>\n<li>It is a authority or public body that processes the personal data<\/li>\n<li>The main activities are processing operations that require a regular and systematic observation of interested parties on a large scale or,<\/li>\n<li>The main activities of the responsible or accountable person are the large-scale processing of special categories of personal data, as well as data related to criminal convictions and offenses.<\/li>\n<\/ol>\n<div class=\"cyp_post_formulario\"><h2>Contact Us<\/h2>\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f3074-o1\" lang=\"es-ES\" dir=\"ltr\" data-wpcf7-id=\"3074\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/en\/wp-json\/wp\/v2\/posts\/6887#wpcf7-f3074-o1\" method=\"post\" class=\"wpcf7-form init wpcf7-acceptance-as-validation\" aria-label=\"Formulario de contacto\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"3074\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.5\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"es_ES\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f3074-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/><input type=\"hidden\" name=\"_wpcf7_recaptcha_response\" value=\"\" \/>\n<\/fieldset>\n<div class=\"campo_nombre\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-name\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Name\" value=\"\" type=\"text\" name=\"your-name\" \/><\/span><\/div>\n<div class=\"campo_telefono\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-phone\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-tel wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-tel datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Phone\" value=\"\" type=\"tel\" name=\"your-phone\" \/><\/span><\/div>\n<div class=\"campo_email\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Email\" value=\"\" type=\"email\" name=\"your-email\" \/><\/span><\/div>\n<div class=\"campo_asunto\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-asunto\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Subject\" value=\"\" type=\"text\" name=\"your-asunto\" \/><\/span><\/div>\n<div class=\"campo_mensaje\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-mensaje\"><textarea cols=\"40\" rows=\"10\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Message\" name=\"your-mensaje\"><\/textarea><\/span><\/div>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"\" type=\"hidden\" name=\"cyp_form_url\" \/>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"cyp_zonaweb\" type=\"hidden\" name=\"zonaweb\" \/>\n<span class=\"wpcf7-form-control-wrap recaptcha\" data-name=\"recaptcha\"><span data-sitekey=\"6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" class=\"wpcf7-form-control wpcf7-recaptcha g-recaptcha\"><\/span>\r\n<noscript>\r\n\t<div class=\"grecaptcha-noscript\">\r\n\t\t<iframe loading=\"lazy\" src=\"https:\/\/www.google.com\/recaptcha\/api\/fallback?k=6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" frameborder=\"0\" scrolling=\"no\" width=\"310\" height=\"430\">\r\n\t\t<\/iframe>\r\n\t\t<textarea name=\"g-recaptcha-response\" rows=\"3\" cols=\"40\" placeholder=\"Aqu\u00ed la respuesta de reCAPTCHA\">\r\n\t\t<\/textarea>\r\n\t<\/div>\r\n<\/noscript>\r\n<\/span>\n<div style=\"width:100%\">\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important;margin-bottom:15px !important\">\nBy clicking on \"Send\" you accept our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup_ingles\">+ Info<\/a>\n<\/p>\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important\">\n<span class=\"wpcf7-form-control-wrap\" data-name=\"checkbox-173\"><span class=\"wpcf7-form-control wpcf7-checkbox wpcf7-exclusive-checkbox\"><span class=\"wpcf7-list-item first last\"><label><input type=\"checkbox\" name=\"checkbox-173\" value=\"\" \/><span class=\"wpcf7-list-item-label\"><\/span><\/label><\/span><\/span><\/span> I agree to receive outlined commercial communications from LETSLAW, S.L. in accordance with the provisions of our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup\">+ Info<\/a>\n<\/p>\n<\/div>\n<div class=\"vc_col-sm-12 botton-datos-contacto\"><input class=\"wpcf7-form-control wpcf7-submit has-spinner\" type=\"submit\" value=\"Send\" \/><\/div><input type='hidden' class='wpcf7-pum' value='{\"closepopup\":false,\"closedelay\":0,\"openpopup\":false,\"openpopup_id\":0}' \/><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<div>","protected":false},"excerpt":{"rendered":"<p>The General Data Protection Regulation (GDPR) introduces new data protection novelties. One of these novelties is the obligation imposed of appointing a new person, the Data Protection Officer (DPD or DPO in English). This obligation&#8230;<\/p>\n","protected":false},"author":2,"featured_media":6888,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[258],"tags":[],"class_list":["post-6887","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-law"],"_links":{"self":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/6887","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/comments?post=6887"}],"version-history":[{"count":3,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/6887\/revisions"}],"predecessor-version":[{"id":6891,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/6887\/revisions\/6891"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media\/6888"}],"wp:attachment":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media?parent=6887"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/categories?post=6887"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/tags?post=6887"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}