CLVPartners

DPO

New service of CLVPartners© – Provision of Data Protection Officer (DPO) services with the involvement of a cooperating partner

We are pleased to inform our Clients that CLVPartners© has expanded its service portfolio: with the involvement of our trusted partner, we now also undertake the provision of Data Protection Officer (DPO) services in accordance with the GDPR requirements for organisations for which this is a legal obligation or a business necessity.

What does the DPO service mean?

The appointment of a DPO is not merely a formal requirement – CLVPartners© ensures real, substantive, and active involvement in data protection compliance. The appointed DPO:

carries out the registration required for the commencement of its activities and establishes appropriate communication channels for data subjects

monitors the compliance of personal data processing with GDPR requirements,

participates in, provides information and professional advice on the development and review of data protection documentation, as well as on new processes to be introduced or any other data processing issues, in order to ensure compliance with the GDPR and other EU or Hungarian data protection provisions,

maintains contact with the National Authority for Data Protection and Freedom of Information (NAIH) and with data subjects,

supervises the enforcement of data subject rights,

supports the organisation in data protection incidents and data protection impact assessments.

What is the difference between the DPO and our Law Firm’s advisory role?

The DPO performs an independent supervisory function and carries out only the tasks defined in the GDPR. The DPO provides information and advice to ensure compliance and maintains contact with the supervisory authority on behalf of the organisation; however, it may not act as legal representative before the authority.

In contrast, our Law Firm continues to provide support to Clients in the field of data protection law in reviewing their data protection practices, preparing implementation plans, and, where necessary, adjusting practices to ensure compliance with the GDPR. Our data protection services cover the following areas:

Supporting GDPR implementation in line with Hungarian legislation and the guidance of the data protection authority

Periodic mandatory review of existing policies and privacy notices, including client support in their practical application

Training for employees involved in the processing of personal data (e.g. HR, IT, controlling, payroll)

Addressing data protection issues arising in connection with employment, including the preparation of information materials, policies and employment contract clauses, drafting whistleblowing regulations, and examining “bring-your-own-device” data protection aspects

Advising on technological solutions based on the use of personal data (AI applications, user profiling, targeted marketing activities, social media solutions, database monitoring, maintenance of internal communication systems)

Professional cooperation – real added value

The DPO and our Law Firm work closely together in the development and documentation of data processing practices. The review and preparation of documentation is always carried out with the professional support of our Law Firm.

Ez a modell lehetővé teszi, hogy szervezete:

megfeleljen a törvényi előírásoknak,

biztosítsa a függetlenséget és szakértelmet a DPO szerepkörben,

továbbra is számíthasson Irodánkra mint adatvédelmi jogi tanácsadóra.

Vegye fel velünk a kapcsolatot, ha szeretné felmérni, szükséges-e DPO-t kijelölni a szervezeténél – és ha fontos Önnek, hogy ez a feladat valóban hozzáadott értéket is jelentsen.

Photo source: pexels.com, shox

New service of CLVPartners© – Provision of Data Protection Officer (DPO) services with the involvement of a cooperating partner Read More »

The Data Protection Officer – Part 1: Appointment Requirements

Reading time: 10 minutes

Companies are required to comply with data protection legislation in a variety of roles, including as employers, customers, and suppliers. Data controllers and processors must not only establish their own internal policies but also ensure compliance with the applicable European Union and national data protection legislation.

One of the obligations that medium-sized and large companies should carefully assess is whether they are required to appoint a Data Protection Officer (“DPO”). Our firm acts as an external Data Protection Officer for a number of clients and regularly encounters questions of legal interpretation regarding the obligation to appoint a DPO. For this reason, we consider it useful to provide a more detailed overview of this service.

This topic may also be relevant to clients with whom our law firm cooperates in the context of data protection advisory services. Subject to compliance with the applicable conflict of interest rules, we are also able to provide DPO services to such clients. The purpose of this two-part series is to provide practical guidance on the rules governing the appointment of a Data Protection Officer and their application in practice.

The General Data Protection Regulation (GDPR) requires the appointment of a DPO in certain circumstances. In other cases, although not legally required, appointing a DPO may be strongly recommended to ensure compliance with data protection requirements and lawful processing of personal data.

In this article, we summarise the circumstances in which the appointment of a Data Protection Officer is mandatory and when it may be advisable in the course of a company’s operations. In the second part of this series, we will discuss practical considerations regarding who should be appointed as a DPO and the benefits of having an external expert fill this role..

When is the appointment of a Data Protection Officer mandatory?

Not every business is required to appoint a Data Protection Officer. Under the GDPR, this obligation does not depend on the size of the company or its annual turnover, but rather on the nature of its processing activities.

The appointment of a DPO is mandatory where the organisation’s core activities consist of:

processing, on a large scale, special categories of personal data (such as health data) or personal data relating to criminal convictions and offences; or

processing operations that require regular, systematic and large-scale monitoring of data subjects.

In our experience, the second scenario is the most common among our clients.

However, the concepts used in the GDPR are not always self-explanatory. Below, we explain what is meant in practice by “core activities” and “regular, systematic and large-scale monitoring”, as well as the factors that should be considered when determining whether a business is required to appoint a DPO. Since data processing activities may change significantly over time, it is advisable to review these criteria periodically during the course of the company’s operations.

What are “core activities”?

The term “core activities” does not merely refer to the company’s registered main business activity. Rather, it encompasses the key operations that are essential for achieving the organisation’s objectives and form an integral part of its business activities. Here are a few examples:

The core activity of a manufacturing company is the production and sale of its products (for example, paper products, tobacco products or machinery). During these operations, personal data processing forms an inseparable part of the business, for example when employees and visitors are granted access to company premises, when the personal data of business contacts are processed on a daily basis, or when CCTV systems are used to secure company facilities.

If a company provides healthcare services or services directly related to healthcare as part of its core business, it necessarily processes health data. This also constitutes a case where the appointment of a Data Protection Officer is mandatory.

In the case of temporary staffing agencies or recruitment service providers, the company processes large volumes of employee and applicant data in connection with payroll, taxation, human resources administration and other employment-related matters.

What constitutes regular and systematic monitoring?

The GDPR does not provide a precise definition of this concept. According to established practice, it includes all forms of online tracking and profiling. Processing personal data for the purposes of behavioural advertising also falls within this category. However, regular and systematic monitoring is not limited to the online environment. Monitoring may also be regarded as regular where it is continuous, carried out at recurring intervals, or repeated at predetermined times. For example:

the employer continuously monitors the work performance of employees performing customer service duties using IT tools to ensure quality,

a transport or logistics company tracking the activities and routes of its employees during the performance of their work.

What constitutes large-scale monitoring?

The GDPR does not establish specific quantitative thresholds for determining whether processing is carried out on a large scale. In practice, personal data processing is generally considered large-scale where the data are processed, stored or analysed not merely at a local level but across an entire country or internationally (for example, within the European Union). A typical example is a corporate group employing a large number of employees across multiple locations nationally or internationally, where employee or customer data are processed centrally across several countries for HR, IT or compliance purposes.

The following factors should be taken into account when assessing whether processing is carried out on a large scale:

the number of data subjects concerned,

the volume of personal data processed,

the range of different categories of personal data processed,

the duration or permanence of the processing activities,

the geographical scope of the processing activities.

Examples commonly regarded as large-scale processing include personal data processed by internet search engines for behavioural advertising purposes, as well as the processing of HR records, working time records, access control data and CCTV recordings relating to a large workforce.

Cases recommended by the European Data Protection Board

Even where the GDPR does not expressly require the appointment of a Data Protection Officer, doing so may nevertheless be justified. According to the guidelines of the European Data Protection Board (EDPB), involving a DPO in processing operations that present a higher level of data protection risk may facilitate compliance with the GDPR and support effective management of data protection risks.

In particular, organizations should consider appointing a DPO where they:

process the personal data of a large number of data subjects,

carry out extensive or complex processing operations,

regularly need to conduct Data Protection Impact Assessments (DPIAs).

Although the appointment of a DPO is not a legal obligation in such case, it may nevertheless constitute an important element of an effective data protection governance framework.

Cases requiring a Data Protection Impact Assessment

A Data Protection Impact Assessment (DPIA) may be required where a particular type of processing – especially where new technologies are used – is likely to result in a high risk to the rights and freedoms of natural persons, taking into account the nature, scope, context and purposes of the processing. Examples of processing activities that may present a high risk include:

Systematic monitoring, for example where a manufacturing company operates CCTV systems on its premises to protect the life and physical integrity of employees, investigate workplace accidents or prevent criminal offences.

The use of GPS tracking in company vehicles in order to monitor employees’ movements.

A temporary staffing or recruitment agency maintaining a database containing the personal data of a large number of job applicants across numerous categories of personal information.

The processing of large volumes of health data or other special categories of personal data.

According to the EDPB’s guidance, where it is not clear whether a particular processing activity presents a high risk, a DPIA should be carried out in order to demonstrate compliance.

Although the obligation to conduct a DPIA does not automatically create an obligation to appoint a Data Protection Officer, the two issues are closely linked in practice. Organizations whose processing activities regularly require DPIAs should consider appointing a DPO. A DPO can assist in identifying risks, preparing Data Protection Impact Assessments and ensuring the continuous compliance of processing activities with the GDPR.

Large-scale processing of personal data

Even where data processing does not form part of an organization’s core activities and does not involve regular and systematic monitoring, processing large volumes of personal data may significantly increase the risk of data protection incidents. In such circumstances, the professional support of a Data Protection Officer can contribute to reviewing existing processing activities, identifying potential weaknesses and reducing data protection risks before they materialize.

Focusing on the prevention and management of personal data breaches

The appointment of a DPO may also be justified where, due to the nature of the organization’s processing activities or previous experience, there is an increased likelihood of personal data breaches. A Data Protection Officer can assist in establishing internal procedures aimed at preventing data protection incidents, increasing employees’ awareness of data protection obligations, and ensuring that any incidents that do occur are handled, documented and reported in accordance with the applicable legal requirements.

In all of the above cases, adopting a proactive approach by voluntarily appointing a DPO may facilitate compliance with data protection legislation, reduce data protection risks and support the implementation of the GDPR’s accountability principle.

Closing remarks

Where any of the mandatory criteria described above apply to your organization, the appointment of a Data Protection Officer is not optional but constitutes a legal obligation under the GDPR. Even where the appointment of a DPO is not legally required, the nature or risk profile of the organization’s processing activities may nevertheless justify such an appointment. In these circumstances, a DPO can provide considerable added value to the organization.

The role of the Data Protection Officer extends beyond supporting legal compliance. A DPO continuously monitors data processing activities, identifies potential risks and assists the organization in addressing them before they result in personal data breaches or regulatory investigations.

Today, effective data protection governance is no longer merely a matter of legal compliance; it has become an integral component of responsible corporate governance. A suitably qualified Data Protection Officer can contribute to greater transparency of processing activities, reinforce the GDPR’s accountability principle and strengthen the confidence of clients, business partners and other stakeholders in the organisation.

As the obligation – or practical need – to appoint a Data Protection Officer can only be assessed following a detailed review of an organisation’s processing activities, businesses should periodically reassess whether their operations require the appointment of a DPO and whether their existing data protection framework remains appropriate and effective.

Photo source: pexels.com Ron Lach

The Data Protection Officer – Part 1: Appointment Requirements Read More »

Data Protection Officers are under the spotlight in the European Data Protection Board’s latest coordinated enforcement action

Since 25 May 2018, there is hardly a company that has not had to deal with a Data Protection Officer, or DPO. It has been 5 years since the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC („General Data Protection Regulation”; hereinafter: “GDPR“) came into force, but this does not and cannot mean that “the machine is running, the creator rests.” In view of the continuous development of case law, a review of the regulations may be necessary from time to time.

In 2023, the European Data Protection Board (“EDPB“) decided to conduct a coordinated enforcement action focusing specifically on the designation and operation of DPOs. The coordinated action involves 26 European data protection authorities.

The Data Protection Officer is responsible for protecting the rights and freedoms of data subjects and ensuring compliance with data protection rules. Impartiality and independence are among the requirements for DPOs that most often come to the attention of the authorities. Impartiality and objectivity ensure that the officer is able to closely monitor data management processes, effectively manage data breaches and advise the organisation on compliance with the GDPR and other relevant data protection rules. Impartiality guarantees that the DPO represents data protection issues of all interested parties, be it the employees, contractors, or the management of the organisation. The DPO shall be an expert who has no interest in the organisation or its data processing activities. Conflict of interest also means that the appointed data protection professional must not be in a position or engage in an activity that could jeopardise objective and independent decision-making.

A number of decisions on DPOs have been taken by national authorities in previous years, with the following conclusions:

  • The DPO must not only be registered with the competent authority of the mother company, but the organisation must also notify other relevant authorities if the organisation has other branches and the DPO can operate there too.
  • It is not possible to hire an external company as an outsourced DPO and at the same time also appoint a third party as DPO.
  • If the DPO is in charge of compliance, audit and risk management, the independence or impartiality of the role may be compromised.
  • The DPOs are not allowed to engage in a role as the controller’s representative before the data protection authority, as this could jeopardize the impartiality or independence of the DPO.
  • The DPO can be withdrawn if the DPO no longer has the appropriate professional skills or fails to comply with data protection regulations.
  • The DPO cannot be ordered, and therefore it is a breach of the GDRP if the DPO cannot act on his or her own, but only on the instructions of the head of the company (or any other person with the right to make decisions in the company).

A control plan may formalise the DPO’s procedure, but a direct instruction does not comply with the GDPR.

  • It is also a breach of the GDPR to have several hierarchical levels between the DPO and the senior management of the organisation because this way the DPO is no longer directly accountable to the management.
  • It is not an appropriate solution if the DPO is appointed, but the DPO also performs compliance functions in the company, thus compromising independence and impartiality. The authority in the case confirmed that the DPO cannot perform a role that allows him or her to determine the purposes and means of processing personal data.
  • Similarly, it has been held to be contrary to the prohibition of conflicts of interest, if the DPO is also a managing director of two subsidiaries which are responsible for processing data for the main company. In this case there is a conflict of interest because the DPO supervises the adequacy of the data processing tasks, while having a legitimate interest in the profits and operations of the data processing companies.

As the EDPB will focus on DPOs in its coordinated enforcement actions in 2023, we can expect to see a growing number of decisions in which the determining data protection authority makes decisions in principle on the functioning and impartiality of the DPOs. Further guidelines or statements may be issued by national or EU authorities.

Data Protection Officers are under the spotlight in the European Data Protection Board’s latest coordinated enforcement action Read More »

CLVPartners
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.