Jump to content

Recommended Posts

Posted

“Firstly, the GDPR does not provide for any specific liability for the DPO. However, the Art. 29 Working Party addresses this issue in its Guidelines on Data Protection Officers of 13 December 2016. These guidelines state that the controller or the processor remains responsible for compliance with the data protection laws, and accordingly it will be up to the controller or processor to demonstrate compliance, regardless of how much autonomy the DPO is granted.

 

Therefore, even though the DPO is responsible for assisting the controller or processor in monitoring the internal compliance, the DPO is not personally responsible for any non-compliance with the GDPR. In addition, the GDPR further clarifies that the DPO should not be dismissed or penalised by the controller or the processor for performing his or her tasks”

 

https://www.lexology.com/library/detail.aspx?g=ef6f8142-9283-4a98-be5f-54d1054fd646

 

Written late last year but still a good explanation.

 

Of course, this does not absolve DPOs from competency claims under their contract but that is employment law ... e.g. the DPO maliciously and wilfully withholding or falsifying information.

 

It will be case law the makes a point on all this ...

 

If anyone is a DPO there are membership groups out there you can speak with such as NADPO or DP Forum UK.

  • Thanks 2
Posted
Mr @GrumbleDook - you are a star, that's the perfectly succinct replt I need to be ale to pass on ! My reason for asking is we have recently had a new appointee and his accepted the role of DPO in addition to main role. Whist he perhaps just about has a sufficiently level of seniority, I'm pretty certain he's got close to zero idea on what he's signed up. I doubt passes on any of the four bullets of "What professional qualities should the DPO have?" that ICO publish. Additionally, I have recently enquired about a DPO assistant role at local school, so there was another level of interest. On the topic of membership groups, the school offering a DP role talked about membership of "International Association of Privacy Professionals" - any experience on them? Actually, if that's too off thread, let me know and I'll raise a more general discussion on this aspect.
Posted

IAPP have some fantastic courses and CIPP/E looks like it will cover most areas that will end up in the DPO certification accredited by some Supervisory Authorities ... but it is heavy going.

I’m doing the reading for it at the moment and it can be heavy going.

 

It probably could go into a different thread but as we are talking suitability of DPO I think it is still relevant.

 

We have to remember that certificates are a momentary thing, some courses are pretty much the same cost no matter which sector you come from (10% on a £1900 course means nothing if the school is struggling even to cover your expenses to get to London / Birmingham / etc.) and there is no accreditation yet (so be wary of ‘certified’ courses when it comes to GDPR)

 

There are courses to go on to get a certificate, courses to get knowledge, courses to be peer-recognised ... and this gets combined with experience to make the right person for the role.

 

There are people on LinkedIn who have done a mass of courses or run courses and in general there are a few that seem to stand out.

 

2040training always get a massive seal of approval within DP / IG circles as Tim Turner has a concise and precise knowledge of what he is talking about.

 

ActNow and Amberhawk are always well received.

 

IAPP courses are in depth and serious ... and everyone I’ve spoken with say they have great trainers.

 

Anyone who can show operational experience combined with MIS and records management courses, or FoI training, will be gold dust for you.

 

Realistically, a lot of schools will make do until the right person comes along or the skills are brought up to speed.

Posted
“Firstly, the GDPR does not provide for any specific liability for the DPO. However, the Art. 29 Working Party addresses this issue in its Guidelines on Data Protection Officers of 13 December 2016. These guidelines state that the controller or the processor remains responsible for compliance with the data protection laws, and accordingly it will be up to the controller or processor to demonstrate compliance, regardless of how much autonomy the DPO is granted.

 

Therefore, even though the DPO is responsible for assisting the controller or processor in monitoring the internal compliance, the DPO is not personally responsible for any non-compliance with the GDPR. In addition, the GDPR further clarifies that the DPO should not be dismissed or penalised by the controller or the processor for performing his or her tasks

 

It actually goes further than that - even if you have outsourced your DPO responsibilities, you the school are liable not the company, as they are almost certainly only advising you.

Posted

Yep, but again ... be aware if contract law and failure to complete contracts, etc.

 

In risk management terms, some schools are looking to transfer the risk. You can’t. You are not even sharing the risk. You are reducing it ... or putting in a fallback. Both valuable and worth the time / money.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...