Auratech Legal Solutions

Data Protection Officer Service

Consejos para tener un servicio correcto Protección de Datos

The Data Protection Officer Service can be provided internally by means of an employment contract or externally in the framework of a contract of services provided.

The General Data Protection Regulation (GDPR) establishes a series of “proactive responsibility measures”. These measures include the figure of the Data Protection Officer (DPO), a figure that did not exist in the previous LOPD.

Which companies need a Data Protection Officer service?

The Spanish and European legislation maintains a non-exhaustive list of the sectors that must have a Data Protection Delegate (DPD) service. The following are some of the sectors mentioned in the GDPR and LOPDGDD legislation:

When and why is it recommendable to hire the service of a Data Protection Officer?

As explained in the previous section, not all organizations must hire the services of a Data Protection Officer. Appointing a DPO may be advisable in the following situations:

Functions of the Data Protection Delegate service:

Informing and advising

companies and their employees about the different data protection requirements.

Supervise

compliance with the legislation, as well as with the different protocols put in place.

Advise

on the need to carry out a personal data protection impact assessment (PIA), as well as to supervise its correct application.

Cooperate

with the different European supervisory authorities in relation with any request of information or in the exercise of their functions.

To act

as a contact point for the supervisory authorities and the people making the complaint.

Intervene

in the case of a complaint or requirement to mediate and solve any problems that may have occurred.

The legislation itself allows the outsourcing of this figure because it may be almost impossible for the company’s own employees to have the necessary training to accomplish all the DPD functions.

In order to accomplish this need, in Auratech we offer the service of Data Protection Delegate in an external way. We cover the functions of informing and advising the person in charge and the employees of their obligations in accordance with the regulation. We supervise compliance of the legislation in order to sensitize and train the personal involved in the processing operations.

Auratech will permanently monitor compliance of the requirements of the legislation, including those associated with the implementation of new treatments, such as the realization of the privacy impact analysis.

Communication:

We provide a communication service in which we are direct interlocutors between the competent European supervisory authority and the complaining data subject. This communication activity is complemented with the communication to the controller/responsible of the data treatment and to the employees about their obligations.

The service will be offered following a semi-presential provision model, with Service Level Agreements (SLA) and procedures agreed between Auratech and each client, depending on their situation and size.

If you are considering implementing the figure of the DPO by externalizing your service, Auratech offers you this possibility through its expert lawyers in Data Protection. Avoid increasing your personnel costs by being able to comply with the legislation in a technical and independent way.

Exit mobile version