On May 25, 2018, the new European regulations on the protection of personal data (hereinafter referred to as the GDPR “ General Data Protection Regulation) came into force. This regulation is known for its extraterritorial action: it is mandatory for use in all the EU countries, and under certain conditions, its action extends to non-European companies and compels them to align their activities with the requirements of the GDPR in order not to lose their European partners.
The GDPR enhances the previously established personal data protection procedure and introduces new obligations for organizations that process such data.
In particular, the regulations carried out the modernization of the already existing profession of the person responsible for data protection (hereinafter DPO “ Data Protection Officer). This post was created by the 1995 framework directive, which was replaced by the new text. The previous legislation regulated the activities of such specialists but did not insist on their mandatory appointment.
When Should DPO Be Assigned?
Today, in the era of the GDPR, the appointment of the DPO became mandatory in the following cases (Article 37 of the GDPR):
- In the companies that systematically and regularly carry out large-scale monitoring of users (most often it is monitoring for the purpose of contextual advertising);
- In the companies that carry out large-scale processing of special categories of personal data, such as health data, etc.;
- In any public agency that handles the processing of personal data.
In all the other cases, the appointment of DPO remains optional. However, the European regulators unanimously call for not neglecting such a specialist and for delegating the personal data protection authority to a professional in this field.
Such an innovation of the European legislation is easily explained by the philosophy of the regulation itself: the enhanced data protection procedure; the increased responsibility of data processing personnel; huge sanctions in case of the GDPR dispositions violation. In order to bring their activities in line with the new requirements, companies need the support of highly specialized specialists.
Shortage in the DPO Service Market
However, the parliamentarians did not take into account or simply ignored the fact that the current market for personal data protection services is not ready to withstand such an influx of new customers forced to recruit DPOs. Despite the fact that this profession exists for quite a long time, the number of the specialists leaves much to be desired even in the European market. So, according to the IAPP research (International Association of Privacy Professionals), 28 thousand specialists should be hired in 2018 only in the EU and the US. And worldwide this figure will grow up to 75 thousand.
Obviously, such demand cannot be satisfied solely with the in-house professionals (internal employees of companies). In this regard, many companies turn to external consulting organizations that provide DPO services. For example, for middle and small businesses, that can be much easier than hiring a new employee. In any case, the external or internal status has almost no effect on the activities of the DPOs themselves.
DPO: Lawyer or IT Specialist?
First of all, it is necessary to understand that the DPO must have legal knowledge. This conclusion follows directly from Article 39 of the European Regulations, which lists the tasks and missions of the DPOs. To a greater extent, they are, of course, lawyers. In addition, they should be lawyers who have strong management skills and due to technical expertise, that is, managers.
Less often, the DPOs are IT experts who have only basic ideas about the law. However, this situation is typical of Western countries. The IT specialists dominate the personal data protection market, not the lawyers.
Either way, large corporations, of course, prefer to hire some specialists to provide IT security and others for personal data protection. Small and medium businesses are trying to make a choice in favor of just one employee competent in both areas. Why does it happen? The answer lies on the surface: the GDPR places a wide variety of responsibilities on companies.
On the one hand, it is necessary to ensure the security of personal data and react correctly in case of their leakage. This is usually done by IT specialists. On the other hand, it is necessary to conclude treaties that legally meet the requirements of the regulations, maintain specially provided registries, contact supervisors, and perform other paperwork. And this is usually done by lawyers, sometimes by managers.
As a result, a good specialist in the field of personal data is a kind of mix of all these professions.
What Does DPO Do?
As for the scope of the DPO’s activities, such an employee will do everything necessary to ensure that the company fully complies with the European regulations and other acts in the field of personal data protection and thus avoids major sanctions and contractual risks with their partners.
The DPO will conduct a general audit of activities, identify all categories of personal data processed by the company, propose measures to ensure their safety, as well as a general development strategy of the legal use of data. He will also negotiate with the supervisory authority, if necessary. He will also help to correctly respond to the requests of persons whose data is processed by the company. In general, almost everything related to personal data will fall within the scope of the DPO.
Whether it is worth to neglect such an employee in the era of the GDPR, as well as in the midst of major scandals with malware outbursts and data leakages, “ that is to be decided by the companies themselves. But once again, this option exists only for those who do not have a direct duty to appoint a DPO.
Features of DPO Services
When an organization think about recruiting a DPO, it is important to understand that there are two main types of services in this area: the above-mentioned in-house and consulting. In the first case, the hiring of an employee takes place under an employment contract, in the second one an external consulting company renders DPO services under a civil law contract. Regardless of the option chosen, the company will remain the legally responsible entity. The DPO is in no case responsible for the company’s non-compliance with the dispositions of the GDPR.
In addition, the European regulations strictly provide for the complete independence of a personal data protection specialist. In the case of an in-house, the DPO can be accountable only to the person occupying the highest post in the hierarchy. In the case of external consulting, the DPO should not be in a situation of the conflict of interest, which is often the case if that is, for example, a lawyer.
In any case, the conflict of interest and the independence of DPOs are always checked by the personal data protection supervisory authority. This is an obligatory process, and any appointment of the DPO must be declared to the regulator. In other words, every time a DPO is appointed, the supervisory authority should be notified of this.
More details about the various subtleties associated with the appointment of the DPOs, either mandatory or not, as well as their functions and missions, can be found in the WP29 Guidance. This organization had already existed in the era of the framework directive of 1995, and its main task was to interpret legislation in the field of personal data protection. With the entry into force of the GDPR, the European Data Protection Board has replaced the working group, but the work of WP29 has not lost its significance.
A little insider about the DPO profession
Many international organizations have long been providing various methods of certification. For example, the already mentioned IAPP offers a preparatory course for the GDPR and certifies those who passed the exam successfully. This course is available to everybody, and the IAPP accreditation is highly appreciated around the world.
As for the profitability of the profession, for example, the French association responsible for personal data protecting believes that the average DPO earnings in Europe range from 2.5 thousand to 4 thousand euros per month. This fork approximately corresponds to the average income of a European programmer. As a conclusion, we should expect an approximate equality between the incomes of these two professions in the domestic market, too.
Summary
It is necessary to emphasize that Data Protection Officer is a young profession that received a significant impetus to its development due to the entry into force of the new European GDPR regulations. To date, the personal data protection according to GDPR is a scientific trend which should be paid attention to by the companies around the world, not just in Europe. Soon, full cooperation with European partners will be possible only if the GDPR is observed, which is difficult to imagine without integrating the DPO profession at least in the consulting services sector.