5 ms·
A small shop absolutely does not need a DPO. See guidance here: http://gdprandyou.ie/data-protection-officer/ http://gdprandyou.ie/data-protection-officer/ If
by donogh 8y ago
A small shop absolutely does not need a DPO. See guidance here: http://gdprandyou.ie/data-protection-officer/ http://gdprandyou.ie/data-protection-officer/
If the small shop happens to be collecting sensitive personal data -- health data, political affiliations or union membership, etc. -- (a) they should probably stop and (b) they would need a DPO.
Highly unlikely in any case !
As to the DPO, it is meant to be an independent person within the organisation, who cannot be unduly influenced by management, etc. Assigning the role to a regular employee who, e.g., reports to the principal and is a teacher by day, would not seem to satisfy the requirement.
Bear in mind that a DPO has to have "expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39".
- jamescostian 8y agoThe link you provided says you need a DPO in an organization > Where the core activities of the organisation (controller or processor) consist of data processing operations, which require regular and systematic monitoring of individuals on a large scale Small shops contain things that they sell, and they also keep records of selling things for tax purposes, and may even have video cameras to avoid getting robbed. IANAL but isn't that a lot of data processing operations, and isn't there lots of systematic monitoring of individuals? Or are you saying that because it's not "large scale" (e.g. only 100 people walk in a day) and it doesn't have sensitive data, then it's immune?
- PeterisP 8y agoThe core activities of a small shop do not consist of data processing operations which require monitoring people. The core activities of a small shop include some data processing operations that don't require monitoring people (e.g. records of what they sell), and an anti-robbery video camera isn't a core activity of their business; I'd even assume that it's not looked at most of the time and is even more likely to be outsourced to some security company (which would have a DPO).
- tscs37 8y agoKeeping things for tax purposes requires no consent, same for anything you are legally required to keep record off. Video cameras most certainly fall under legitimate interest (as long as you follow the law about using surveillance in your country). From what I recall on the info I've seen locally is that you don't need a DPO until you hit 250 employees.
- deleted 8y ago[deleted]
- jdietrich 8y agoA DPO is only mandatory if the core activities of your business include regular and systematic monitoring of individuals on a large scale, or include the processing on a large scale of specially protected information. A shop only processes personal data as a secondary activity, with their core activity being selling merchandise. The data they do process is not in a specially protected category under the GDPR and pertains only to their business rather than the wider lives of their customers. They do not need a designated DPO. A social media network, an ad tech company or a credit reference agency does need a DPO. A manufacturer of IoT gadgets that constantly phone home with a stream of usage data almost certainly needs a DPO. If the IoT gadget I sold you tells me what time you get home from work and what time you go to bed, that sounds an awful lot like "regular and systematic monitoring". A manufacturer of IoT gadgets that only phone home occasionally with fully anonymised error logs probably doesn't need a DPO.
- jamescostian 8y agoThis sounds pretty reasonable - I misjudged how bad the DPO requirement was. Thanks for explaining it to me!