
Reading time: 10 minutes
Companies are required to comply with data protection legislation in a variety of roles, including as employers, customers, and suppliers. Data controllers and processors must not only establish their own internal policies but also ensure compliance with the applicable European Union and national data protection legislation.
One of the obligations that medium-sized and large companies should carefully assess is whether they are required to appoint a Data Protection Officer (“DPO”). Our firm acts as an external Data Protection Officer for a number of clients and regularly encounters questions of legal interpretation regarding the obligation to appoint a DPO. For this reason, we consider it useful to provide a more detailed overview of this service.
This topic may also be relevant to clients with whom our law firm cooperates in the context of data protection advisory services. Subject to compliance with the applicable conflict of interest rules, we are also able to provide DPO services to such clients. The purpose of this two-part series is to provide practical guidance on the rules governing the appointment of a Data Protection Officer and their application in practice.
The General Data Protection Regulation (GDPR) requires the appointment of a DPO in certain circumstances. In other cases, although not legally required, appointing a DPO may be strongly recommended to ensure compliance with data protection requirements and lawful processing of personal data.
In this article, we summarise the circumstances in which the appointment of a Data Protection Officer is mandatory and when it may be advisable in the course of a company’s operations. In the second part of this series, we will discuss practical considerations regarding who should be appointed as a DPO and the benefits of having an external expert fill this role..
When is the appointment of a Data Protection Officer mandatory?
Not every business is required to appoint a Data Protection Officer. Under the GDPR, this obligation does not depend on the size of the company or its annual turnover, but rather on the nature of its processing activities.
The appointment of a DPO is mandatory where the organisation’s core activities consist of:
processing, on a large scale, special categories of personal data (such as health data) or personal data relating to criminal convictions and offences; or
processing operations that require regular, systematic and large-scale monitoring of data subjects.
In our experience, the second scenario is the most common among our clients.
However, the concepts used in the GDPR are not always self-explanatory. Below, we explain what is meant in practice by “core activities” and “regular, systematic and large-scale monitoring”, as well as the factors that should be considered when determining whether a business is required to appoint a DPO. Since data processing activities may change significantly over time, it is advisable to review these criteria periodically during the course of the company’s operations.
What are “core activities”?
The term “core activities” does not merely refer to the company’s registered main business activity. Rather, it encompasses the key operations that are essential for achieving the organisation’s objectives and form an integral part of its business activities. Here are a few examples:
The core activity of a manufacturing company is the production and sale of its products (for example, paper products, tobacco products or machinery). During these operations, personal data processing forms an inseparable part of the business, for example when employees and visitors are granted access to company premises, when the personal data of business contacts are processed on a daily basis, or when CCTV systems are used to secure company facilities.
If a company provides healthcare services or services directly related to healthcare as part of its core business, it necessarily processes health data. This also constitutes a case where the appointment of a Data Protection Officer is mandatory.
In the case of temporary staffing agencies or recruitment service providers, the company processes large volumes of employee and applicant data in connection with payroll, taxation, human resources administration and other employment-related matters.
What constitutes regular and systematic monitoring?
The GDPR does not provide a precise definition of this concept. According to established practice, it includes all forms of online tracking and profiling. Processing personal data for the purposes of behavioural advertising also falls within this category. However, regular and systematic monitoring is not limited to the online environment. Monitoring may also be regarded as regular where it is continuous, carried out at recurring intervals, or repeated at predetermined times. For example:
the employer continuously monitors the work performance of employees performing customer service duties using IT tools to ensure quality,
a transport or logistics company tracking the activities and routes of its employees during the performance of their work.
What constitutes large-scale monitoring?
The GDPR does not establish specific quantitative thresholds for determining whether processing is carried out on a large scale. In practice, personal data processing is generally considered large-scale where the data are processed, stored or analysed not merely at a local level but across an entire country or internationally (for example, within the European Union). A typical example is a corporate group employing a large number of employees across multiple locations nationally or internationally, where employee or customer data are processed centrally across several countries for HR, IT or compliance purposes.
The following factors should be taken into account when assessing whether processing is carried out on a large scale:
the number of data subjects concerned,
the volume of personal data processed,
the range of different categories of personal data processed,
the duration or permanence of the processing activities,
the geographical scope of the processing activities.
Examples commonly regarded as large-scale processing include personal data processed by internet search engines for behavioural advertising purposes, as well as the processing of HR records, working time records, access control data and CCTV recordings relating to a large workforce.
Cases recommended by the European Data Protection Board
Even where the GDPR does not expressly require the appointment of a Data Protection Officer, doing so may nevertheless be justified. According to the guidelines of the European Data Protection Board (EDPB), involving a DPO in processing operations that present a higher level of data protection risk may facilitate compliance with the GDPR and support effective management of data protection risks.
In particular, organizations should consider appointing a DPO where they:
process the personal data of a large number of data subjects,
carry out extensive or complex processing operations,
regularly need to conduct Data Protection Impact Assessments (DPIAs).
Although the appointment of a DPO is not a legal obligation in such case, it may nevertheless constitute an important element of an effective data protection governance framework.
Cases requiring a Data Protection Impact Assessment
A Data Protection Impact Assessment (DPIA) may be required where a particular type of processing – especially where new technologies are used – is likely to result in a high risk to the rights and freedoms of natural persons, taking into account the nature, scope, context and purposes of the processing. Examples of processing activities that may present a high risk include:
Systematic monitoring, for example where a manufacturing company operates CCTV systems on its premises to protect the life and physical integrity of employees, investigate workplace accidents or prevent criminal offences.
The use of GPS tracking in company vehicles in order to monitor employees’ movements.
A temporary staffing or recruitment agency maintaining a database containing the personal data of a large number of job applicants across numerous categories of personal information.
The processing of large volumes of health data or other special categories of personal data.
According to the EDPB’s guidance, where it is not clear whether a particular processing activity presents a high risk, a DPIA should be carried out in order to demonstrate compliance.
Although the obligation to conduct a DPIA does not automatically create an obligation to appoint a Data Protection Officer, the two issues are closely linked in practice. Organizations whose processing activities regularly require DPIAs should consider appointing a DPO. A DPO can assist in identifying risks, preparing Data Protection Impact Assessments and ensuring the continuous compliance of processing activities with the GDPR.
Large-scale processing of personal data
Even where data processing does not form part of an organization’s core activities and does not involve regular and systematic monitoring, processing large volumes of personal data may significantly increase the risk of data protection incidents. In such circumstances, the professional support of a Data Protection Officer can contribute to reviewing existing processing activities, identifying potential weaknesses and reducing data protection risks before they materialize.
Focusing on the prevention and management of personal data breaches
The appointment of a DPO may also be justified where, due to the nature of the organization’s processing activities or previous experience, there is an increased likelihood of personal data breaches. A Data Protection Officer can assist in establishing internal procedures aimed at preventing data protection incidents, increasing employees’ awareness of data protection obligations, and ensuring that any incidents that do occur are handled, documented and reported in accordance with the applicable legal requirements.
In all of the above cases, adopting a proactive approach by voluntarily appointing a DPO may facilitate compliance with data protection legislation, reduce data protection risks and support the implementation of the GDPR’s accountability principle.
Closing remarks
Where any of the mandatory criteria described above apply to your organization, the appointment of a Data Protection Officer is not optional but constitutes a legal obligation under the GDPR. Even where the appointment of a DPO is not legally required, the nature or risk profile of the organization’s processing activities may nevertheless justify such an appointment. In these circumstances, a DPO can provide considerable added value to the organization.
The role of the Data Protection Officer extends beyond supporting legal compliance. A DPO continuously monitors data processing activities, identifies potential risks and assists the organization in addressing them before they result in personal data breaches or regulatory investigations.
Today, effective data protection governance is no longer merely a matter of legal compliance; it has become an integral component of responsible corporate governance. A suitably qualified Data Protection Officer can contribute to greater transparency of processing activities, reinforce the GDPR’s accountability principle and strengthen the confidence of clients, business partners and other stakeholders in the organisation.
As the obligation – or practical need – to appoint a Data Protection Officer can only be assessed following a detailed review of an organisation’s processing activities, businesses should periodically reassess whether their operations require the appointment of a DPO and whether their existing data protection framework remains appropriate and effective.
Photo source: pexels.com Ron Lach