3 ms·
A designated DPO is only required for companies that have over 250 employees. Surely that can't be a huge burden? Just appoint the head of security to be the DP
by cuspycode 8y ago
A designated DPO is only required for companies that have over 250 employees. Surely that can't be a huge burden? Just appoint the head of security to be the DPO. He can google the GDPR requirements and then be all set after 15 minutes.
If you are smaller than that and you outsource processing of the personal data of your customers, then all you have to do is make sure the customers consent to this, and you are good to go with GDPR. It's practically effortless, unless your business model relies on monetizing innocent victimes without their consent.
- tzs 8y agoI'm not talking about the DPO. That's from article 37 and has nothing to do with the representative required under Article 27. The Article 27 representative must be in the Union, which is why it can be problematical for a company whose office and employees are all outside the Union.
- jacquesm 8y agoYes, this is a real problem. In fact, it is the only problem with the GDPR that has no obvious solution - yet - for small businesses.
- cuspycode 8y agoBut Article 27(2) explicitly excludes the requirement of designating a representative according to 27(1), if the processing of personal data is limited within perfectly sound limits.
- tzs 8y agoArticle 27(2) excludes that requirement for "processing which is occasional, does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing". To be excluded, the processing has to satisfy three requirements: • "is occasional" • "does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in Article 10" • "is unlikely to result in a risk to the rights and freedoms of natural persons" Most businesses probably won't process any of the Article 9(1) special categories or the Article 10 criminal stuff, so that shouldn't my much of a hurdle for most. All kinds of data pose a risk to the rights and freedoms of natural persons. See Recital 75 for examples. Of particular note, if it can lead to identity theft, fraud, or financial loss it poses such a risk. This is going to snag a lot of businesses. Then there is that "is occasional" requirement for being excluded. I have no idea how that is going to be interpreted.
- zerostar07 8y agoThe proposal for 250 employee limit was a request from Poland that got rejected.