Appointment of a Data Protection Officer: What are their legal responsibilities?
In accordance with Art. 39 GDPR, an internal or external Data Protection Officer performs advisory, educational, and supervisory tasks in particular.
Their main activities include:
- participating in the design and implementation of IT systems in accordance with data protection regulations,
- raising awareness and training employees,
- monitoring compliance with data protection laws and internal guidelines and processes.
In addition, the Data Protection Officer must be consulted in an advisory capacity as part of a data protection impact assessment (DPIA) in accordance with Art. 35 para. 2 GDPR.
Furthermore, he or she acts as a point of contact for data subjects (e.g., in the event of requests for information or deletion) and for supervisory authorities.
Note: This information does not replace individual legal advice.