1. Who is a Data Protection Officer?
Section 24 of the Data Protection Act 2019 creates a new professional role and requirement for organisations to designate a Data Protection Officer. The DPO’s primary responsibility is to spearhead an organisation’s privacy compliance program. In addition, the DPO acts as liaison between the organisation and regulators, key among them being the Data Commissioner.
2. Do all organisations need to appoint a Data Protection Officer?
- the controller or processor is a public or private body involved in processing personal data (apart from the judiciary when acting in its judicial capacity);
- the core activities consist of processing operations which, by nature, scope or purposes require systematic monitoring of data subjects; or
- the core activities consist of processing sensitive categories of personal data
A plain reading of section 24(1) implies that all corporate organisations (whether public or private) that process or handle personal data should designate or appoint a Data Protection Officer. Additionally organisations whose core activities consist of systematic monitoring of data subjects or processing of sensitive personal data should also designate or appoint a DPO. The Act does not define the term “systematic monitoring” nor “core activities”. The draft Regulations do not offer any guidance on the matter meaning that the definitions are open interpretation. In the EU, the European Data Protection Board has issued some interpretation guidelines that may be useful. However, unless the courts or legislation clarifies the issue, the matter is still open to debate.
3. What are the DPO's responsibilities?
- advise the organisation on important compliance requirements
- train staff involved in data processing
- advise and make recommendations about the interpretation or application of the data protection rules
- monitor compliance and address potential issues proactively
- advise on data protection impact assessments
- serve as the key contact person with the Data Commissioner and any other regulator in matters relating to data protection
- maintain records of data processing activities






