Jump to content

Recommended Posts

Posted

Hello all,

 

Our MAT has revealed its plans for GDPR, I'd be interested in your thoughts:

 

 

  • One DPO role as defined by the GDPR tagged onto an existing high-up admin post, the person has not had any DPO role before and presumably is taking it on as a necessary evil.
  • Each school to retain their existing DP person in a similar role with similar responsibilities, presumably reporting upwards but with no additional authority and no consideration of the GDPR role definitions, because they aren't DPOs..

 

My initial thoughts are that this is a weak attempt to circumvent the GDPR requirements, though I can see the attraction for the MAT itself - minimal upheaval.

 

Have any other MATs played their hand on this yet?

Posted (edited)
One DPO role as defined by the GDPR tagged onto an existing high-up admin post, the person has not had any DPO role before and presumably is taking it on as a necessary evil.

This would concern me for two reasons:

1) Possible conflict on interests?

from http://ec.europa.eu/information_society/newsroom/image/document/2016-51/wp243_annex_en_40856.pdf

The DPO cannot hold a position within the organisation that leads him or her to determine thepurposes and the means of the processing of personal data. Due to the specific organisational structurein each organisation, this has to be considered case by case.As a rule of thumb, conflicting positions may include senior management positions (such as chiefexecutive, chief operating, chief financial, chief medical officer, head of marketing department, headof Human Resources or head of IT departments) but also other roles lower down in the organisationalstructure if such positions or roles lead to the determination of purposes and means of processing.

 

2) Based on the brief outline above, it doesn't sound like the person has the expertise to fulfill the requirements of the role

The GDPR requires that the DPO ‘shall be designated on the basis of professional qualities and, inparticular, expert knowledge of data protection law and practices and the ability to fulfil the tasksreferred to in Article 39’.
Edited by sparkeh

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...