Structure of the Guide for the Data Protection Officer
Moving on to identify the most important elements of the manual, it should be noted that it is divided into three main parts.
Receive a package of free GDPR guides and micro-trainings
The second part includes an introduction to the GDPR. It addresses issues related to the status and approach to the application of GDPR provisions and emphasizes the importance of the accountability principle, presenting various ways of demonstrating it. This part describes the GDPR provisions regarding the required experience and qualifications of the Data Protection Officer.
The third part of the publication contains practical tips regarding both the tasks of the Data Protection Officer and actions where their involvement is crucial and required to maintain compliance with the GDPR.
This last part of the guide is divided into seven main sections: preliminary task, organizational tasks, functions for monitoring compliance with the law, advisory functions, cooperation and consultations with the data protection authority, handling requests from data subjects, and informing and raising awareness. Such a broad range of tasks indicates that the authors of the publication go well beyond the catalog of tasks outlined in Article 39 of the GDPR.
-
Preliminary Task Regarding the Inventory of Personal Data Processing Activities
In the preliminary task of determining the scope of the data controller's environment, it is worth noting the actions of the Data Protection Officer (DPO) that will allow them to understand the principles and functionalities of the technical information systems operating within the organization as well as the architecture of these systems. The manual states:
„Furthermore, it is essential that at this stage the Data Protection Officer (with the assistance of the IT and security department staff) thoroughly familiarizes themselves with the technical information systems, architecture, and policies applied in their organization: the computers used (or, if manual cataloging systems are still in use, those as well) and whether they include portable and/or mobile devices (and/or personal 'own devices' of the relevant employees – to which the 'Bring Your Own Device [BYOD]' policy should apply); whether personal computers and devices are used online or only offline, on-site or also outside the office; what security software and encryption are used and whether it is fully up to date; what connections and external objects are utilized (taking into account cloud servers, especially if they are located outside the EU/EEA, e.g., in the USA, in which case the relevant arrangements and agreements regarding data transfers should be checked); whether any part of the processing is carried out by data processors (in which case the agreements concluded with them should be reviewed); what physical security measures are in place (doors, rooms, network and computer passwords, etc.); whether security policies and training have been implemented, etc. At the preliminary stage, it is not necessary to consider and resolve so many issues, but at least they should be noted, outlined, and recorded” (p. 132).”
-
Organizational tasks – records of processing activities, review of inventoried processing operations, conducting a risk assessment and Data Protection Impact Assessment
The authors of the publication recognize organizational tasks such as creating a record of processing activities, reviewing personal data processing operations, conducting a risk assessment arising from personal data processing operations, and managing operations that may pose a "high risk," including conducting a Data Protection Impact Assessment (DPIA).
The authors of the manual point to a correct approach regarding the inventory of personal data processing operations throughout the organization. An initial list of personal data processing operations should be prepared, which will contain only a general outline of these operations. The second step is to prepare a complete list, which should lead to the creation of records of processing activities (Article 30(1) GDPR) and, in certain cases, a record of all categories of processing activities (Article 30(2) GDPR). The discussed publication includes sample templates: a basic record of data processing by the data controller (p. 139), a basic record of data processing by the data processor (p. 141), and a detailed record of personal data processing activities (p. 145).
-
Monitoring Compliance with Personal Data Protection Regulations
In terms of monitoring compliance with the law, the authors of the publication recommend continuously repeating the previously indicated tasks. They also describe procedures for dealing with personal data breaches and investigative tasks that include addressing complaints from, for example, employees of the organization. As they indicate:
“It is assumed that the data controller ‘ascertains’ a breach when the data processor informs them of it; subsequently, the controller must notify the data protection authority, unless there is an exception that stipulates that the data breach is unlikely to pose a risk to the rights and freedoms of natural persons” (p. 191).
-
Advisory Tasks of the Data Protection Officer
As part of the advisory tasks, the Data Protection Officer supports the data controller by informing them of the obligations arising from the provisions of the GDPR, promotes data protection by design and by default, and assists the controller in its implementation, as well as advising them on ensuring and monitoring compliance with data protection policies, the provisions of agreements between co-controllers and data processors, two controllers and a data processor, and a controller and a data processor, binding corporate rules, and data transfer clauses. Additionally, they may participate in the certification process or the creation of codes of conduct.
In this section of the manual, the authors indicate actions that will demonstrate compliance with the provisions of the GDPR, including:
- “drafting and formally adopting internal data protection policies [...] to regulate matters such as:
- paper forms, online forms, and data/privacy protection statements on websites used by the organization, the use of cookies and other tracking files;
- accessing and modifying records, etc., in appropriate software and hardware;
- issuing ‘licenses’ for their own software)
- etc.;
- entering into administrative agreements (‘arrangements’) between authorities or public entities, particularly if they act as ‘co-controllers’ in relation to specific processing operations;
- drafting and agreeing on appropriate agreements with other data controllers and data processors, as well as signing or drafting standard or individually approved data transfer agreements” (p. 212).
The authors rightly emphasize that the above tasks are assigned to the data controller; however, in practice, the Data Protection Officer (DPO) should be significantly involved in all such matters.
-
Cooperation and consultations with data subjects and the supervisory authority
Another task of the Data Protection Officer (DPO) is to cooperate and consult with the national supervisory authority. This involves responding to requests from the authority or initiating contact with it. It should be noted that the Data Protection Officer (DPO) plays a crucial role in supporting the data controller and the supervisory authority during the course of the inspection proceedings.
The Data Protection Officer (DPO) is also responsible for handling requests from data subjects. The authors of the manual indicate that these requests may concern general questions or complaints regarding the processing of personal data, and the Data Protection Officer (DPO) should not be afraid to make decisions. They should either write or at least review the response that will be provided to the data subject and ensure that the response includes information about the possibility of lodging a complaint with the supervisory authority.
Tasks related to informing and raising awareness should include both informing employees about their rights and instructing data controllers and owners of specific business processes regarding their obligations and scope of responsibility. Such informing of individuals involved in the processing of personal data may take place within the framework of training sessions that demonstrate practical ways to implement, for example, the principles of data processing. Basic information regarding the operations of personal data processing by the data controller should always be easily accessible on their website and presented in brochures and forms. Importantly, such sources of information should be adapted to the needs of individuals with disabilities (appropriate font size or the ability to read the text).
On the other hand, tasks related to planning and reviewing the activities of the Data Protection Officer should take place within the framework of preparing annual action plans. Such plans should account for the anticipated time needed to complete each of the planned tasks and to implement the expected new changes. Furthermore, regular reviews and updates of this plan should be conducted to enable necessary actions to be taken.
Summary
It should be noted that the presented manual certainly organizes the issues related to the performance of the tasks of the Data Protection Officer and standardizes the approach to activities in which their involvement is necessary. It is worth mentioning that the updated “Practical Guide for Data Protection Officers” (publication by the author of this article) will contain the most important elements of the manual approved by the European Commission.


