21/02/2024 - The Data Protection Officer (DPO) plays an essential role in enforcing compliance with the GDPR. However, recent research by the European Data Protection Board (EDPB) shows that DPOs still encounter a number of problems in the execution of their duties, which prevent them from exercising their function optimally. This blog will discuss some interesting insights and recommendations from the study.

The study  

In cooperation with 25 national supervisory authorities, the EDPB conducted a large-scale study on the designation and position of DPOs. The study was conducted through a questionnaire addressed to organisations and DPOs. About 15,000 organisations and 2,000 DPOs completed this questionnaire. 

The main objective of the study is to understand the position of DPOs in practice to support enforcement actions by national supervisory authorities. In addition, the aim is to raise awareness within organisations about the requirements for DPOs and explore whether they can properly fulfil their important role.

Insights and recommendations  

The study contains several interesting insights and recommendations regarding the position of the DPO, including:

  1. Conflicts of interest and lack of independence of DPOs:
     A worrying aspect is the potential conflict of interest and lack of independence faced by some DPOs. A wide range of additional tasks or roles for DPOs, instructions from the organisation and the sharing of DPOs between multiple organisations can compromise the independence of DPOs. This is therefore not desirable yet appears to happen regularly in practice.
    - Recommendations: organisations can conduct awareness-raising activities and education on DPO independence. Organisations can also work with the DPO to formally define the tasks and conditions for performing these tasks. For DPOs themselves, it is important that they should be able to collect evidence if their independence is compromised. 
  2. Lack of reporting to highest management:
    The study shows that some DPOs lack the ability to report directly to highest management, which can lead to ineffective data protection policies and oversight. The study found that about half of the DPOs only report to the highest management once or twice a year. If there is no regular reporting to the highest management, chances are that management is not aware of the DPOs work, which can affect GDPR compliance. The lack of direct access to highest management prevents the DPO from sharing opinions and ultimately undermines the role of the DPO.
    - Recommendations: it is recommended that organisations effectively comply with the legal requirement for DPOs to report to the highest management level of the organisation. They should promote the direct access of DPOs to top management. This is essential for ensuring their independence and effective performance of their duties.
  3. Absence of appointment of an DPO, despite legal obligation:
    organisations are obliged to appoint an DPO in some cases. However, the study shows that a DPO is not always appointed, despite the legal obligation. The lack of clarity about the obligation, especially in the public sector, appears to be an obstacle.
    - Recommendations: organisations should become more aware of their obligations to appoint a DPO. Awareness campaigns and guidance from national supervisory authorities can play a crucial role in clarifying this obligation.
  4. DPO not fully assigned required tasks:
    Although the GDPR prescribes specific tasks for DPOs, organisations do not always assign these tasks to the DPO. For example, the study shows that the task of monitoring the implementation of a Data Protection Impact Assessment (DPIA) is least assigned to DPOs. Even the core task of informing and advising on GDPR obligations are not universally assigned to DPOs. This can affect the effectiveness of data protection within organisations.
    - Recommendations: the EDPB advises organisations to promote the role of the DPO internally and to work together with DPOs to develop their roles appropriately and independently. It is important that organisations actively evaluate and improve the DPO's involvement within the organisation. 
  5. Insufficient resources allocated to DPOs:
    Another issue is the lack of adequate resources for DPOs, which may hinder their ability to perform tasks effectively. These include a lack of deputy DPOs and the lack of a support team for DPOs.
    - Recommendations: It is recommended that organisations carefully consider whether the DPO has sufficient resources to properly perform his function. An analysis of the DPO's specific needs can help allocate the necessary resources effectively.
  6. Insufficient expertise and knowledge of DPOs:
    The study highlights shortcomings in the expertise and knowledge of DPOs. These include both a deficiency in the required expertise and knowledge of DPOs upon entry into service and a deficiency in the training and knowledge provided after DPOs are hired. DPOs are not given enough time to acquire the required expertise after hiring.
    - Recommendations: organisations should document the knowledge and training needs of their DPOs and provide sufficient opportunities, time and resources for ongoing professional development.

The six insights highlight where the problem areas are and where improvements are needed for DPOs to properly perform their role. By following the recommendations under these insights, organisations can work in collaboration with DPOs to strengthen the role of the DPO and ensure the protection of personal data in line with the GDPR.

Meer weten?

For more information on whether your organisation needs to appoint a DPO, whether your current DPO can fulfil its role properly and what you need to do to comply with the requirements from the GDPR, please contact Considerati. Our DPO as a Service (DPOaas) offers you a qualified DPO without large investments. In addition, our DPO Support offers tailored support to your current DPO, specifically tailored to your organisation's needs.

Ontdek onze diensten orNeem contact op