Tag Archives: data protection officers

The New Data Protection Regulation could cost businesses 3 billion a year due to employee data clause

123

Derek Mooney (public affairs director of the Brussels European Employee Relations Group – BEERG – ) writes for Euractiv.eu that contrary to what the EU Commission asserts, if the proposed General Data Protection Regulation is adopted with Article 82 as it stands, it will result in significant extra costs for all European business.

More precisely, if the GDPR is adopted with the Art 82 provision then business will have the “patchwork of 27 different rules in 27 countries” plus the additional obligations and burdens set out in the GDPR such as data protections officers; consent rules and 2% penalty on annual turnover without access to the costs savings the Commission claims.

So far from saving business €2.3 billion, this measure will cost business money EU wide – at a time when EU national governments are committing themselves to reducing employment costs.

BEERG research shows that at a conservative estimate the employee- data related data provisions alone could add  €3 billion each year in additional costs on business.

Article 82 of the GDPR excludes the area of employee data from the EU wide “one stop shop” by specifically providing that each member state shall also be empowered to regulate in this area.

Read the whole story: EU’s General Data Regulation could be Costly for Businesses

Data protection officers needed more and more: "Data Protection Officer Drought Predicted"

http://www.informationweek.com writes today about the increased necessity of properly trained DPOs, citing Google’s global privacy counsel Peter Fleischer:

“Soon, many thousands of companies operating in Europe will be looking to appoint [data protection officers] to meet legal obligations, and since there is no available pool of such people, companies need to start thinking now about how to recruit, train and resource a DPO, and/or an entire DPO team, for the large companies”.

I remind you that iblogpdp.com was also concerned with this issue previously this year. You found out then that Article 35 of the proposed EC data protection regulation states that a data protection officer shall be designated in the following cases:

– when the processing is carried out by a public authority or body;

– when the processing is carried out by an enterprise employing 250 persons or more;

– the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects.

Fleischer sees three viable approaches to the new rules, depending on the complexity of companies’ data processing requirements.

Companies that have relatively simply data operations can probably just train personnel from human resources or marketing, he suggests.

They might also be able to outsource the DPO role, which he sees as a potential business opportunity for entrepreneurs.

Companies with large, complex data processing and handling operations will have the most adjustment to do. “[T]oday, rather shockingly, some of the world’s largest data processing companies, with mega-databases of trillions of pieces of personal data, do not have a single heavy-weight DPO on staff,” he wrote.

Read the whole story HERE.

Good news for privacy specialists: EU will oblige big companies and public institutions to name data protection officers!

The data protection reform in the EU is serious. So serious, the European Union actually imposes through the new regulation a mandatory data protection officer for the public sector, and, in the private sector, for large enterprises or where the core activities of the controller or processor consist of processing operations which require regular and systematic monitoring.

There is an entire section (Section 4 of Chapter IV) in the proposed regulation dedicated to the “data protection officer”. It builds on Article 18(2) of Directive 95/46/EC which provided the possibility for Member States to introduce such requirement as a surrogate of a general notification requirement.

According to Article 35 of the proposed regulation, a data protection officer shall be designated in the following cases:

– when the processing is carried out by a public authority or body;

– when the processing is carried out by an enterprise employing 250 persons or more;

– the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects.

The Regulation, at Article 35(5) also imposes strict characteristics for the person who will be designated data protection officer, as he or she must be appointed “on the basis of “professional qualities and, in particular, expert knowledge of data protection”. By which we understand that companies and public institutions are not allowed to simply name one of their current employees in such a position, unless the current employee receives adequate qualifications in the data protection field.

Article 35(7) establishes a minimum period of employment to 2 years, while Article 35(10) states that data subjects shall have the right to contact the data protection officer on all issues related to the processing of the data subject’s data and to request exercising the rights under this Regulation.

A quite independent position

The data protection officer will enjoy as much independence as possible in the context of an employment relationship. As such, Article 36(2) imposes to the controller or processor to “ensure that the data protection officer performs the duties and tasks independently and does not receive any instructions as regards the exercise of the function. The data protection officer shall directly report to the management of the controller or the processor”.

These developments are huge in the data protection field and they show that EU takes as serious as possible the threats of intruding in individuals’ private life by a weak protection of their personal data.

Tomorrow I’ll write about the specific tasks a data protection officer will have, according to the proposed regulation.