BAS strengthens its team with the arrival of Luciana Sousa Santos Read more
The intriguing figure of the Data Protection Officer
From the DPO as an exception to the DPO as a rule. Since the publication of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, one of the most discussed topics in forums about the new regime and which causes greater curiosity has been the “data protection officer” or “DPO”.
It is true that this figure already existed in several countries, even before the GDPR, like in Germany, however only now it becomes legally obligatory, having verified the conditions of article 37/1 of the GDPR, namely:
- the processing is carried out by a public authority or body, except for courts acting in their judicial capacity;
- the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale;
- the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 and personal data relating to criminal convictions and offences.
About the definition of “grand scale”
One of the difficulties that Article 37/1 offers is the definition of “large scale”, which the Article 29 Working Party (Data Protection Working Group created by Article 29 of Directive 95/46/EC of the European Parliament and of the Council) has, however, helped to interpret (v. Guidelines on Data Protection Officers (´DPOs´), p. 9).
Therefore:
“(…) WP 29 recommends that, in particular, the following factors be taken into account in determining whether the processing is carried out on a large scale:
- The number of data subjects concerned – either as a specific number or as a proportion of the relevant population
- The volume of data and/or the range of different data items being processed
- The duration, or permanence, of the data processing activity
- The geographical extent of the processing activity”
At the same time, recital 91 of the GDPR also provides some guidelines, adding that “large-scale processing operations which aim to process a considerable amount of personal data at regional, national or supranational level and which could affect a large number of data subjects and which are likely to result in a high risk”. As a specific example, “personal data should not be considered to be on a large scale if the processing concerns personal data from patients or clients by an individual physician, other health care professional or lawyer”.
About the designation of a DPO as a good practice
Although the GDPR only requires the designation of a Data Protection Officer when the above requirements are met and is therefore optional outside of these cases, the Article 29 Working Party (see Guidelines on Data Protection Officers (´DPOs´), p. 6), recommends that, even though it is not clear that an organization is not required to designate a DPO, one should be designated. In any case, the appointment of a DPO will always be understood as a good practice in data protection.
If the controller chooses, even if he is not obliged to do so, to designate a DPO, he is obliged from then on to fulfil all the underlying obligations as if the designation was mandatory, namely to give access to existing platforms and databases to the Data Protection Officer.
About the resources that should be provided to the DPO
The GDPR does not define the resources that the controller or subcontractor must grant to the DPO. However, the Article 29 Working Party (v. Guidelines on Data Protection Officers (´DPOs´), p. 27) recommends that:
“Depending on the nature of the processing operations and the activities and size of the organisation, the following resources should be provided to the DPO:
- active support of the DPO’s function by senior management
- sufficient time for DPOs to fulfil their tasks
- adequate support in terms of financial resources, infrastructure (premises, facilities, equipment) and staff where appropriate
- official communication of the designation of the DPO to all staff
- access to other services within the organisation so that DPOs can receive essential support, input or information from those other services
- continuous training
About the tasks of a DPO– article 39/1 of the GDPR
From the moment he is designated, the DPO becomes the central figure of the organization regarding the processing of personal data, assuming the tasks of (i) to inform and advise all parties involved of their obligations pursuant to this Regulation (ii) to monitor compliance with this regulation, with other Union or Member State data protection provisions and with organization’s privacy policy (iii) to provide advice on the subject and (iv) monitor the performance of the data protection impact assessment, cooperate with the supervisory authority. It will also act as the contact point, not only for the supervisory authority, on issues relating to processing, but also to the data holders, in particular for the exercise of their rights, and their contacts must be made publicly available and communicated to the supervisory authority.
About the professional profile of the DPO
Another thorny issue is the DPO’s professional profile.
The GDPR in its article 37/5 states that “the data protection officer shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39.” The much-debated question remains if it should be someone more connected to law or to information technologies or someone combining the two areas of knowledge.
At first glance, it appears that the profile of the DPO should be shaped according to criteria relating to the controller, to the data subjects and the type of data being processed. That is, if it’s a large business structure, a DPO supported by a multidisciplinary team is advisable. If patient medical data is involved, someone with specific experience and/or training in the health sector should be designated. The level of skills and support will be all the greater as the complexity of the data processing activity or the share of sensitive data.
Also here the Article 29 Working Party (v. Guidelines on Data Protection Officers (´DPOs’), p. 26) gives a contribution:
“Relevant skills and expertise include:
- expertise in national and European data protection laws and practices including an in-depth understanding of the GDPR
- understanding of the processing operations carried out
- understanding of information technologies and data security
- knowledge of the business sector and the organisation
- ability to promote a data protection culture within the organisation
About the functional position of the DPO
The GDPR allows, in Article 37/6, that the data protection officer be a member of the staff of the entity responsible for the processing or of the subcontractor or perform his duties on the basis of a service contract, as an external DPO.
Here the concern was raised about, if an employee is chosen, how to reconcile the nature of an individual employment contract with the technical independence of the DPO and the absence of disciplinary power over the subject of the audits. That is, we will have, in these cases, an employee with double duties, worker, subordinate, subject to the directive and disciplinary power of the employer, and simultaneously, a data protection officer, who audits the performance of the organization, namely his superiors, who receives no instructions and cannot be penalized or dismissed for the performance of his duties.
About the responsibility of the DPO
Lastly, and contrary to what is the concern of future data protection officers, the DPO is not responsible for personal data breaches, being liable, in case of fines or obligations to pay damages, only the person responsible for the processing or the subcontractor.
In any case, if it is found that the violation was caused by an indifferent performance of the DPO, there may be a right of recourse of the controller or the subcontractor to the data protection officer, in general terms.
Jane Kirkby, lawyer and partner at BAS
More in Communication
- Public Protection
- law firm
- BAS
- Covid-19
- 10 years
- anniversary
- Best Lawyers
- Portugal
- Who's Who
- Video surveillance
- Privacy
- Minors
- Health and Sciences
- Public Policies
- Coronavírus
- Atividade
- Real Estate 2020
- Corporate Law
- Legal Persons
- Companies
- Professional Secret
- Confidentiality
- Changes
- Public Law
- Life Sciences
- Awards
- Labour Awards
- Law
- Exceptional Measures
- State Budget
- Contracts
- Iberian Lawyers
- Lay-Off
- Lay-Off
- Mental Health
- Stress
- Saúde mental
- Leaders League
- Actualidade Ibérica
- Almedina
- Idealista
- APMEP
- Congress
- MIPIM
- SIGI
- REIT
- Imobiliário
- Mozambique
- ICLG
- Moçambique
- Secrecy
- Professional secrecy
- Labor
- ILO
- International Labor Organization
- RCBE
- sociedades
- pessoas coletivas
- Expo Real
- National Health Service
- NHS
- Hospitals
- Book
- PhD thesis
- Schools
- CNPD
- Gig Economy
- Emprego Público
- Public Sector Employment
- Contratação Pública
- Staff Costs
- Fiscal Law
- PPC
- Whistleblower
- Direito Civil
- Flextime
- Direito da Saúde
- Family Law
- Environmental Law
- Global Mobility
- ranikings
- Medicina Law
- pessoas coletivas
- M&A
- Proteção de
- international
- Laboral Law
- Public Employment Law
- Health Law and Social Security
- Labour and Social Security Law
- Electronic Invoice
- Tax Law
- Civil Law
- Commercial Law
- Public Contracts
- Electronic Invoicing
- Gender Equality
- Medical Error
- Forty Under Forty
- Self-Employed Workers
- Competition Law
- Employment Law
- Directory
- law firms
- Digital Era
- Global Business
- European Congress
- medical law
- Money Laundering
- Transparency
- Personal Data
- Minimum Wage
- Healthcare
- Secutity
- State
- Labour
- Sport Law
- Employment
- Partnership
- Chambers and Partners
- Public Employment
- Directories
- Business Law
- Students
- Trainees
- Administrative Law
- Administrative Litigation
- Guide
- conference
- Local Housing
- Public Procurement
- Health
- Innovation
- Data Protection
- Advertising
- Medicines
- Medical Devices
- Sports Law
- Real Estate
- Fairs
- Sports
- Guides
- Ranking
- Lawyers
- Magazine
- Law School
- Job
- Sport
- Press
- Women's Human Rights
- Women
- Human Rights
- Independent Workers
- Health and Life Sciences
- Health Law
- Chambers
- webinar
- Infarmed
- Helpo
- Workshop
- Football
- Iberian Lawyer
- Equality
- Man
- Woman
- Equal Pay
- Real Estate Law
- Immigration
- Foreign Investment
- Jornal Económico
- Marketing
- Chambers Europe
- In-Lex
- Emails
- Golden Visa
- traffic accident
- Team
- Labor Law
- Social Security
- Em
- Labour Code
- Family
- GRDP
- Research
- Clinical Research
- GDPR
- Children
- Industrial Property
- Social Security Law
- Europe
- Award
- Health and Scieces Law
- Labour Law
- Right of Preference
- Civil and Labour Litigation
- Local Accommodation
- Lawyer
- Social Responsability
Cláudia Monge analyses new data protection regulation Read more
Dália Cardadeiro wins Lawyer of the Year award Read more
Information session on the main changes to labour legislation Read more
The exceptional and temporary regime for price revision and award Read more
Chambers Europe 2018 recognizes BAS partners in the area of Labor Law in Portugal Read more
Pedro Madeira de Brito takes part in APODIT colloquium Read more
Best Lawyers Distinguishes Pedro Madeira as Lawyer of the Year in Portugal Read more
Lisbon 2020 – Work in a Digital Era – Legal Challenges Read more
The impact of the new Data Protection Regulation on the Schools Read more
Life-long Learning One Health Read more
Family Mediation Read more
Pedro Madeira de Brito speaker at the ILO centenary Read more
BAS is a finalist in the Labour Awards Read more
Cláudia Monge speaks at the Judicial Protection of Health as a Fundamental Right seminar Read more
Paulo Pinto Pereira joins the BAS team Read more
COVID-19 – Exceptional Measures for Public Procurement and Expenditure Authorization Read more
BAS celebrates its 10th anniversary Read more
SB2020: Overall charges paid for service contracts Read more
News from MIPIM 2019 Read more
BAS at the European Employment Lawyers Association conference Read more
BAS lawyers distinguished by Leaders League Read more
What has changed in the contribution regime for self-employed workers? Read more
Sustainability and efficiency in the hospital sector Read more
Football: The Right of Preference Read more
BAS in the Iberian Lawyer’s Lisbon Annual Report Read more
BAS listed in the 15th edition of In-Lex Read more
The new Equal Remuneration Law under review Read more
BAS integrates two associate lawyers and a consultant, strengthening strategic areas and betting on new areas of expertise Read more
Pedro Madeira de Brito distinguished by Best Lawyers Portugal 2017 Read more
BAS at SIPP Read more
BAS represents Portugal in EU Employment and Social Security Law Webinar Read more
The consent of minors and the GDPR Read more
10 years, 10 partners, 10 stories: Marco Aurélio Constantino Read more
Pedro Madeira de Brito spotlighted in Life Sciences Read more
Developments in data protection and compliance can mean employment laws are quickly outdated Read more
Health: When data protection demands special attention Read more
“Infarmed Conference – Use of data in health” Read more
JM Seminar: Sports Law and Sports Policies Read more
COVID-19: Exceptional and temporary Measures in Response to the Epidemiological Situation Read more
Advogar: BAS distinguished with The Best Health Law Firm 2018 Award Read more
Course on “Health Law Read more
Do you still receive advertising emails to which you did not give consent? Read more
Best Lawyers recognise BAS lawyers Read more
BAS authors a chapter on Mozambique at ICLG Read more
The Women’s Human Rights Summit Read more
BAS named Marco Aurélio as new partner Read more
BAS shortlisted for the Iberian Lawyer Labour Awards Read more
New sports law magazine Read more
Rebenta a Bolha! (The game is over) Read more
Catholic University’s Law JobShop: BAS at the market of opportunities Read more
Data Protection, Digital Security, and Compliance Course Read more
Iberian Lawyer: “10 years of BAS Law Firm” Read more
General Data Protection Regulation and Health Data Read more
Advogar: BAS partners discuss Public Purchases in Health Read more
Company Agreement under the microscope Read more
Leaders League ranking recommends BAS in Labour Law Read more
Amendments introduced to the Labour Code Read more
BAS presence in Expo Real 2016 Read more
Dália Cardadeiro in the Who is Who in Business Law in Portugal directory Read more
BAS lawyers at the annual EELA meeting Read more
BAS celebrates its ninth year Read more
Local accommodation: will a global problem have a national solution? Read more
General Regulation on Data Protection and the processing of personal data Read more
“The role of Ethics Committees” Read more
BAS at the Portuguese Real Estate and Tourism Show in Paris Read more
Lauch of the book “Inventário Judicial” Read more
BAS and the outcomes of MIPIM Read more
Cláudia Monge will be a speaker at the conference on General Regulations for the Protection of Personal Data Read more
The Employment Law team participate in the conference of EELA Read more
Data Protection: BAS joins APDPO Read more
Claúdia Monge coordinates Medical Law course Read more
BAS at the 20th anniversary of JobShop Read more
Real Estate Consulting Read more
EELA Conference 2017 Read more
Beneficiary Central Registry BCR Legal Regime – What are the obligations of a Company After the First Declaration Read more
BAS is recognized in Data Protection by the Leaders League ranking Read more
Partnerships for innovation, for what and how? Read more
Cláudia Monge opens workshop intended to review the first year of GDPR Read more
BAS has welcomed two new Trainee Lawyers Read more
Alexandra Almeida Mota took part in the conference on Global Mobility Read more
Engaging and terminating managing directors in Europe Read more
Registrations open for the workshop on GDPR implementation Read more
Press: BAS with five lawyers listed in Best Lawyers Read more
“Whistleblowing” alerts for companies with 50 or more employees Read more
Video surveillance, GDPR Implementing Law and the Labour Code Read more
Changes to the Labour Code Read more
COVID-19 – Support clients in times of mutual assistance of all and for all Read more
Labour Law: changes to the Labour Code Read more
EELA annual conference 2024 Read more
50 Years of Law in Portugal Read more
Master of Sports Law Read more
10 Key steps for compliance with the GDPR Read more
BAS organizes the workshop “Two years of General Data Protection Regulation. Are we ready?” Read more
IBL Read more
Cláudia Monge at the “Dignity, Autonomy and Duration of Human Life” course Read more
BAS joins the Helpo sponsorship program Read more
Marco Real Martins nominated for the Forty Under Forty awards Read more
Updated Version: BAS Simplified Lay Off Guide Read more
Cláudia Monge speaks about medical secrecy and secrecy in law Read more
BAS grows stronger with the arrival of Isabel Sousa Castro as associate lawyer Read more
Read more
BAS debates restructuring processes in webinar on Labour Law Read more
Portuguese companies at the Real Estate Show in Paris Read more
ICLG: BAS writes about Labour and Employment Law in Portugal Read more
BAS lawyers at EELA meeting Read more
Press: Alexandra Almeida Mota practical talks about restructuring in Europe Read more
Artur Filipe da Silva e Diogo Moreira Ramos author a chapter on real estate in Portugal Read more
Seminar “New Employment Relations” Read more
Local Housing: Global Problem, National Solution? Read more
GDPR and consent for scientific research Read more
BAS integrates business mission to Dubai Read more
Debate and book on Public Procurement Legal Framework Read more
III Health Law Course Read more
Effects COVID-19: Extension of deadlines for implementation of electronic invoicing in public contracts Read more
BAS authors chapter on Labour Law in Portugal and Mozambique Read more
BAS on the directory Who’s Who in Business Law Read more
BAS at Firm’s to Watch in The Legal 500 Read more
Labour Law team participates in the Congress of the ASNALA Read more
Information session on the changes to the Labour Code Read more
The changes in the Public Procurement Code Read more
Summer Course on General Data Protection Regulation at the University of Lisbon School of Law Read more
How Portugal adopted the Real Estate Investment Trusts (REIT) regime Read more
Real Estate: BAS will be present at Expo Real in Munich Read more
Who’s Who in Business Law in Portugal: Dalia Cardadeiro’s expectations for 2020 Read more
Press: Best Lawyers distinguishes Portuguese law firms and lawyers Read more
BAS and Sports Law Read more
BAS and Cláudia Monge are finalists in Life Sciences at Iberian Lawyer Awards Read more
BAS becomes a member of CELIA Alliance Read more
Cláudia Monge participates in a book celebrating the 40th anniversary of the NHS Read more
Direct award and the re-enacting of prior consultation Read more
The reform of the employment contract of sports practitioners Read more
Sports Law under analysis at the Faculty of Law of the University of Lisbon Read more
II Workshop – The National GDPR Enforcement Act: What to Expect? Read more
General framework of the new GDPR and national law – Of medical data in particular Read more
5th European Conference: sustainable and innovative public procurement Read more
BAS represents the Portuguese jurisdiction in Employment & labour 2018 in the International Comparative Legal Guide Read more
Marco Real Martins reelected to the APMEP Read more
BAS celebrates eight years Read more
Three BAS lawyers recognized in the Leaders League in the labour area Read more
Smart work: The Law and the new trends in the labour market Read more
BAS supports the 4th Public e-Procurement Congress Read more
New BAS services: Immigration and Foreign Investment Read more
Catarina José focuses on the practical implications of GDPR Read more
BAS ranked in Chambers Europe 2019 Read more
Executive Program: “Contracting and Management of Public Works” Read more
CELIA ALLIANCE publishes article from BAS about Portugal Read more
António Gonilho joined the BAS team as a trainee lawyer Read more
Cláudia Monge in a conference in Sintra on Medical Error Read more
Cláudia Monge is a speaker at the Infarmed symposium Read more
Real Estate Brochure Read more
Paris opens its doors in May to receive Portuguese real estate Read more
Young lawyers and entry into the labor market Read more
Comments to the Public Procurement Code Read more
Preliminary consultation: the implementation of informality Read more
BAS Portuguese Simplified Lay Off Guide at Iberian Lawyer Read more
BAS at JobShop’23 Read more
BAS lawyers in the Best Lawyers’ Global Business edition Read more
Data Protection and Health Data Read more
Summer Internship Fair | FDUL Read more
Exclusion of people from a football stadium Read more
BAS in the 13th In-Lex Edition Read more
Advogar: BAS present at MIPIM Read more
Team BAS reinforced Read more
Award of public procurement Read more
Isabel Sousa Castro in the ranking Top 50 Iberian Lawyer Rising Stars Read more
Postgraduate Course in Public Procurement Management Read more
New legislation to fight against money laundering Read more
Pedro Madeira de Brito co-authors the ‘Commentary on the European Convention on Human Rights and Additional Protocols’ Read more
Priorities of the sector 2023 Read more
Public Health Policies in review Read more
2019 Highlights Read more
Chambers and Partners recognizes BAS lawyers Read more
Maísa Coutinho joins BAS Law Firm’s Read more
Sérvulo and BAS lawyers will debate about public procurement in Funchal Read more
BAS Agenda: 13th National Congress of Electronic Public Procurement Read more
Updating of Guaranteed Minimum Monthly Pay (“RMMG”) Read more
BAS named the Best Health Law Firm 2018 Read more
BAS reinforces its team with three trainee lawyers Read more
Cláudia Monge contributes to the book The Secrets in Law Read more
Decent Work Agenda Read more
In 2019, there will be more changes in the contributory scheme for Independent Workers Read more
Advocatus: BAS distinguished with The Best Health Law Firm 2018 Award Read more
Public Procurement and Pre-contractual Litigation under discussion: Analysis and evaluation of the proposals Read more
Advogar: BAS lawyers author a chapter on real estate in Portugal at ICLG Read more
Press: Employment Law Webinar Read more
Isabel Sousa Castro joins BAS team (Advogar) Read more
Chambers & Partners distinguishes BAS Read more
Public Procurement and Innovation Read more
New regime of Article 256-A of the Public Procurement Code Read more
BAS in the 14th In-Lex Edition Read more
Marco Constantino takes part in the Biennale of Jurisprudence in Medical Law Read more
New minimum wage and update of service contract values Read more
Processing data of children and young people in light of the new GDPR Read more
Pedro Madeira de Brito participates in the new edition of the Annotated Labour Code 2020 Read more
Funchal debates Public Procurement and Litigation Read more
“Advocacy for Health Citizenship” Read more
Margarida Ferreira discusses European legislation and its application in Portugal Read more
National meeting on Public Contracts and Community Funds Read more
Transparency in the advertising of medicinal products and medical devices Read more
Lessons in Portuguese Commercial Law by João Espírito Santo Read more
Take a step back and reassess your priorities Read more
BAS and Legalline Mozambique in Employment & Labour Law 2018 Read more
Green Hospitals Read more
Law Firm of the Year – Life Sciences Read more
BAS ranked for Leaders League Best Firms in Portugal for Labor Law Read more
The recent changes in the assumption of multiannual liabilities by NHS entities Read more
BAS was present at Real Estate Fair in Paris Read more
Catholic Porto analyses the impact of the processing of personal data Read more
Data protection in Workshop Read more
New rules for transparency in advertising Read more
BAS joins business mission to Saudi Arabia Read more
Marco Real Martins finalist in the Iberian Lawyer’s Forty under 40 Read more
Clinical Research and GDPR: Are compromises possible? Read more
Cláudia Monge wins “Lawyer of the Year” in Privacy and Data Security Law Read more
IV Course in Health Law Read more
National Congress of Public Procurement Read more
Launch of the book “Civil Liability in Health” Read more
Partner of BAS on the Best Lawyers’ directory Read more
The draft law for a new Industrial Property Code Read more
JM Sports Seminar: Pedro Madeira de Brito opens afternoon session Read more
GDPR Organizational Technical Measure – What now? Read more
FDUL provides courses in Law, Finance and Justice of Sport Read more
BAS at the EELA annual conference Read more
New Decree-Law no. 73/2021, of 18 August Read more
New general regulation for data protection Read more
Press: BAS reinforces its team with two new associate lawyers Read more
BAS ranked in Chambers Europe 2020 Read more
Pedro Madeira de Brito Publishes Book on Labour Law Read more
BAS in the Advocatus Search a Lawyer Guide Read more
The framework of satellite clubs Read more
Iberian Lawyer Labour Awards 2024 finalists Read more
Women in Law Read more
Advanced Training Programme on Public Procurement Read more
BAS with three new trainee lawyers Read more
BAS and real estate trends Read more
Forty under 40 finalists Read more
Sports Law seen out of the box Read more
Law firm ot the Year in Life Sciences Read more
What changes with the new Local Housing Law? Read more
Healthcare security and State Civil Liability: imprisonment and mastery of guilt? Read more
Five lawyers of BAS were recognized in Best Lawyers Read more
5th European Conference on Sustainable and Innovative Public Procurement Read more
Smart work and the new trends on the labor sector Read more
Summary of the ruling of the Supreme Administrative Court (First section) of 16.11.2017, case No 0935/17, rapporteur: Teresa de Sousa Read more
BAS goes to college Read more
Key developments in the revised Public Procurement Code Read more
Sports Law in 5 questions Read more
Cláudia Monge in debate with patient organisations “Hospital without walls” Read more
The new restrictions on loans of professional football players Read more