Revised DPO Policy Paper Petra Candellier EDPS meeting with DPOs EMA, London, 13 October 2017
Background Existing Policy Paper on DPOs from 2005 Necessary to update the Policy Paper to reflect the novelties in the revised Regulation 45/2001 Part of EDPS’ work on transition to the new Regulation No revolutionary changes: builds on former Paper with some inspiration from WP29 DPO Guidelines
Designation of DPO Common/shared DPO External DPO Publication of contact details
Position of DPO Involve DPO properly and in a timely manner Necessary resources – includes training Independence – not dismissed or penalised – report to highest level of management – secrecy/confidentiality
Position of DPO Term of mandate Part time DPO – Conflict of interest
Tasks Monitor compliance Advise on necessity for notification/communication on personal data breach Advise on DPIAs, monitor its performance, and consult EDPS on the need for a DPIA in case of doubt Advise on the need for prior consultation and consult the EDPS on the need for a prior consultation in case of doubt Record keeping?
Your input needed! How do you see your new role? Thoughts, concerns, fears, challenges.... Please share! Anything missing?
Thank you! www.edps.europa.eu edps@edps.europa.eu @EU_EDPS EDPS European Data Protection Supervisor