4 ms·
Depending on the organization, it can be quite hard to find someone who does not have a conflict of interest while still having the necessary skills to act as a
by pfg 8y ago
Depending on the organization, it can be quite hard to find someone who does not have a conflict of interest while still having the necessary skills to act as a Data Protection Officer. As an example, someone working in IT might have the necessary skill, but is likely to have a conflict of interest because part of their duty as a DPO would be to inspect their own work.
- theptip 8y agoThe GDPR is pretty vague on that point -- from https://gdpr-info.eu/art-37-gdpr/ https://gdpr-info.eu/art-37-gdpr/, the regulation just says: > The data protection officer may fulfil other tasks and duties. The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests. It seems to me a bit of a stretch that working in IT is a conflict of interest with adhering to data processing regulations; ensuring that your infrastructure is compliant is generally one of the remits of the IT function. You could convince me that the head of "analytics and user data extraction" at Facebook might have a conflict of interest with the DPO hat, but I'm skeptical about the broader claim that these conflicts are hard to avoid.
- pfg 8y ago> It seems to me a bit of a stretch that working in IT is a conflict of interest with adhering to data processing regulations; ensuring that your infrastructure is compliant is generally one of the remits of the IT function. That's a bit like saying auditing/compliance is something that you might as well let the accounting department take care of. It's certainly true that making sure you're compliant with various regulations is a large part of what someone in accounting does, but it seems pretty clear that you can't let the same person be the auditor as well without a conflict of interest, and that's roughly what the role of a data protection officer is all about. There's some evidence that data protection authorities share this view; a German authority fined a company after they appointed the IT manager as their DPO[1] (sorry, German-only source). It might be too early to say for sure how this will play out, but I wouldn't gamble on data protection authorities accepting just any IT employee unless they're working in some very specific role that prevents any conflict of interest. [1]: https://www.lda.bayern.de/media/pm2016_08.pdf https://www.lda.bayern.de/media/pm2016_08.pdf
- theptip 8y agoThat's interesting, thanks for sharing -- but that linked article is from 2016, so not sure it can refer to the GDPR DPO. What DPO is that case about? Is it under the DPD (which GDPR supersedes)? If so, what does the DPD say about conflicts of interest and DPOs? If the law that this case was prosecuted under has as loose a definition as the GDPR, then you're right that this implies German regulators could well enact the GDPR under that interpretation too.
- pfg 8y agoPresumably the legal basis would've been the Bundesdatenschutzgesetz, which is Germany's implementation of the DPD. The DPD itself is not very specific, only saying "such a data protection official, whether or not an employee of the controller, must be in a position to exercise his functions in complete independence;". The language in the Bundesdatenschutzgesetz itself[1] is quite similar to the DPO language in the GDPR. [1]: https://www.gesetze-im-internet.de/bdsg_1990/__4f.html https://www.gesetze-im-internet.de/bdsg_1990/__4f.html
- craigsmansion 8y ago> Depending on the organization We're talking about a school here. If a school has to say, "We can't appoint our IT-person, because they're also the one aggregating and profiling the data-profiles of our students for advertisers, so it would be a conflict of interest," that school has bigger problems than GDPR compliance.
- pfg 8y agoThis is not about advertising or any kind of misuse of the data. Rather, IT's role is very much one where they they setup and maintain systems and procedures that process data. It's certainly true that GDPR compliance is something an IT person will have to think about, but making the same employee responsible for auditing that things are compliant is quite a bit of a conflict. Auditing versus accounting is a similar concept.
- oliwarner 8y agoThat isn't a conflict, that's a bloody huge incentive to get it right. They'd be responsible, liable for compliance.