4 ms·
> It seems to me a bit of a stretch that working in IT is a conflict of interest with adhering to data processing regulations; ensuring that your infrastructure
by pfg 8y ago
> It seems to me a bit of a stretch that working in IT is a conflict of interest with adhering to data processing regulations; ensuring that your infrastructure is compliant is generally one of the remits of the IT function.
That's a bit like saying auditing/compliance is something that you might as well let the accounting department take care of. It's certainly true that making sure you're compliant with various regulations is a large part of what someone in accounting does, but it seems pretty clear that you can't let the same person be the auditor as well without a conflict of interest, and that's roughly what the role of a data protection officer is all about.
There's some evidence that data protection authorities share this view; a German authority fined a company after they appointed the IT manager as their DPO[1] (sorry, German-only source). It might be too early to say for sure how this will play out, but I wouldn't gamble on data protection authorities accepting just any IT employee unless they're working in some very specific role that prevents any conflict of interest.
[1]: https://www.lda.bayern.de/media/pm2016_08.pdf https://www.lda.bayern.de/media/pm2016_08.pdf
- theptip 8y agoThat's interesting, thanks for sharing -- but that linked article is from 2016, so not sure it can refer to the GDPR DPO. What DPO is that case about? Is it under the DPD (which GDPR supersedes)? If so, what does the DPD say about conflicts of interest and DPOs? If the law that this case was prosecuted under has as loose a definition as the GDPR, then you're right that this implies German regulators could well enact the GDPR under that interpretation too.
- pfg 8y agoPresumably the legal basis would've been the Bundesdatenschutzgesetz, which is Germany's implementation of the DPD. The DPD itself is not very specific, only saying "such a data protection official, whether or not an employee of the controller, must be in a position to exercise his functions in complete independence;". The language in the Bundesdatenschutzgesetz itself[1] is quite similar to the DPO language in the GDPR. [1]: https://www.gesetze-im-internet.de/bdsg_1990/__4f.html https://www.gesetze-im-internet.de/bdsg_1990/__4f.html