What Exactly Is a DPO?

The Data Protection Officer, or DPO, is responsible for ensuring that companies handle personal data properly and in compliance with the law.
Under the GDPR, organizations with core data processing activities requiring regular and systematic monitoring of EU data subjects on a large scale or which process sensitive data on a large scale are required to designate a DPO. To understand why appointing a DPO is a good thing even if you are not legally required to, read our article.

What is a DPO

The DPO is the person responsible for making sure that organizations handle personal data properly and in compliance with the law. Under the GDPR, the designation of a DPO is mandatory if your company’s core activities consist of data processing operations which require the regular and systematic monitoring of data subjects in the EU on a large scale, or if it processes sensitive data on a large scale. A DPO is not a CPO (Chief Privacy Officer) or a Privacy Officer. While the appointment of a CPO or Privacy Officer is not, in most cases, required by law, the appointment of a DPO is a legal requirement in certain situations (see below) and the DPO’s role and responsibilities are set out with a certain degree of specificity under the law. For more information on the roles and responsibilities of a DPO read our article.

touche clavier dpo

Although the function of a DPO initially originates from Europe, the concept of a DPO has now become an industry norm internationally. The DPO does not have to be based in the EU, however they must have expertise in EU data protection laws and practices and be able to communicate effectively with both EU data subjects and the relevant EU data protection authorities. For more information on why a EU-qualified privacy lawyer is ideally placed to act as your DPO read our article.

Privacy laws are becoming more and more complex. They are a mix of federal, state, provincial, national, sectoral-based, and sometimes even regional laws. 

Let’s take the EU as an example. EU data protection law is a combination of the GDPR alongside the rules prescribed by the national legislations of the 27 national EU member states. A number of these legislations are only available in foreign languages, and they cover more than 50 areas of the law  – the “national derogations” – that are not covered by the GDPR. For more on this read our article.

In addition, the EU privacy legal and regulatory landscape consists of a number of EU Directives that set the baseline for the legal principles for the area of law that they regulate and which have to be interpreted alongside EU in-country laws and regulations. This means that if your company collects the data of residents of several EU member states, it has to ensure that it complies with the law of each and every country from which it collects the data. For more information on the importance of hiring EU counsel to advise on EU law, including GDPR, read our article.

For more information on why privacy laws are so complex to understand read our article.

To help you navigate the GDPR terminology please read our GDPR Glossary of Terms.

Externalized DPO services are typically provided in the U.S. or Canada by either ...

  • U.S. or CANADIAN LAW FIRMS with expertise in U.S. or Canadian privacy laws but which have no foreign legal qualification or practical experience as international privacy lawyers. For more information on why you need a EU and UK qualified privacy lawyer to advise on UK and EU data protection laws, please read our article.
  • SOFTWARE SOLUTIONS PROVIDERS that help companies automate their privacy compliance. These service providers are rarely lawyers and would not give you a seal of legal compliance with privacy and data protection laws and regulations

Our Enhanced DPO Services

At The Transatlantic Lawyer, we provide externalized “enhanced” DPO services that are designed to meet the needs of organizations with activities and data processing operations on both sides of the Atlantic. Our legal qualifications and expertise in both European and U.S/Canadian privacy and data protection laws and regulations, together with our many years experience acting as in-house and external DPO for companies with multinational operations, enable us to take a holistic approach to personal data protection. We work closely with our clients to ensure that their data processing operations comply with the applicable laws and regulations in both Europe and North America. For more information on our expertise as international privacy lawyers please check our GDPR page.

Our Methodology

touch écran invisible text RGPD
At The Transatlantic Lawyer we take a comprehensive approach to providing DPO services. We begin by conducting a data mapping exercise to identify and categorize all of the personal data held by your organization. We then perform a risk analysis and work collaboratively with you to develop a tailored data protection compliance roadmap that ensures compliance with applicable privacy laws and regulations. In some cases, an audit may be necessary to fully evaluate your organization’s privacy posture. As lawyers admitted in both Europe and North America, we possess the legal expertise required to serve as your externalized DPO in support of your international operations. With our deep understanding of the regulatory landscape governing data protection, privacy, and cybersecurity on both sides of the Atlantic, we can ensure that your organization is compliant with all applicable U.S/Canadian. and European data protection requirements. As your DPO, we can provide practical and effective solutions tailored to your organization’s specific needs.
As your DPO we will perform the following tasks as they apply to your specific situation

Inform and advise your organization about your obligations under the GDPR and any other applicable data protection laws and regulations;

Inform your organization of any failures to comply and of any remedial measures to be undertaken;

Recommend and ensure that appropriate measures are implemented to enable you to demonstrate that processing activities are carried out in accordance with the law and, if needed, reassess and update such measures;

Recommend and ensure the appropriate implementation of privacy by default and privacy by design principles in all your projects involving a data processing activity;

Examine and monitor compliance with the GDPR and any other applicable data protection laws and regulations;

Monitor your strategies for the protection of personal data, including the allocation of responsibilities, awareness-raising and training of staff involved in processing operations and related verification;

On request, advise in connection with data protection impact assessments (DPIAs) and their implementations as well as transfer impact assessments (TIAs), as required under the GDPR. This involves evaluating the potential risks associated with processing personal data and assessing the measures in place to mitigate these risks;

Cooperate with EU supervisory authorities and other national data protection authorities;

Act as a contact point for regulators on issues related to data processing, including prior consultation on data protection impact assessments pursuant to Article 35 GDPR and, where appropriate, advise on all related issues;

Maintain or facilitate the maintenance of your registers of processing activities;

Act as a contact point for the exercise of data subjects’ rights under the applicable laws and for addressing their inquiries related to data processing activities;

Perform an annual report of our DPO activities.

Some of Our DPO Service Deliverables

Our Comprehensive Pricing Structure

3 dés DPO

We pride ourselves of offering a comprehensive pricing structure for our DPO services. 

This pricing ensures that our services are affordable for our clients while still allowing us to thoroughly perform our DPO mission to ensure your company’s compliance with the law. 

We will take the following elements into account when drafting a proposal for a DPO mission plan suitable to your business and needs:

  • the complexity of your data processing activities,
  • the number of relevant jurisdictions
  • the size of your company.

Contact us to request your Free and Personalized Quote!

 
Our Enhanced DPO Services use the GDPR as a foundation. By using the strictest standard for privacy compliance, we can then create a best-fit compliance roadmap. This enables us to provide our clients with a set of deliverables that allow them to check the box of compliance in both Europe and North America.