1.数据保护专员(DPO)
GDPR Proposal规定所有公共机构和所有拥有超250名永久职工公司的公司均需要任命DPO。集团公司可以仅在集团层面任命一名DPO。第35-37条规定了DPO的选任、角色、职位、任务等细节,包括其履职时必需出于完全独立的要求。同时需要任职至少2年。此外,员工人数未达250人的企业,如果其核心业务与处理业务相一致,且由于其性质、范围和/或目的,需要对数据主体进行定期和系统的监控,则还需要任命DPO。
Albrecht议员报告在很大程度上受德国法律框架的启发,加强了DPO的作用。其中一个主要变化涉及任命DPO的标准。报告规定,DPO的强制性任命不再基于企业的规模(即250名或更多员工),而是基于数据处理的规模和特征(即,一旦控制者或处理者每年处理500人以上的数据,就必须任命DPO)。报告还要求核心活动包括处理敏感数据或进行分析活动的控制者任命DPO。DPO的最低任职期限从2年延长到4年,DPO必须为公司管理层负责人的直接下属。此外,DPO将受到严格保密要求的约束,并有义务向DPA报告可疑违规行为。
LIBE委员会的折衷文本要求,当在连续12个月内处理超5000人个人数据时,控制者则必须任命DPO。一个企业集团可以为该集团指定一个主要DPO,只要该DPO可以很容易地触达到集团下属各主体。
欧盟委员会的版本废除了任命DPO的强制要求,使其变成可选性,并留给各国法律来将其确定为法定义务。
DPO对应到《个保法》中叫个人信息保护负责人,规定依然没有GDPR详细。《个保法》一条两款,GDPR则是用了整整三条,分别说了DPO的任命、职位和任务。之前转载过一期:GDPR框架下的数据保护官(DPO)八问八答。
再谈谈自己的体会吧:
1.GDPR下是否需要任命的判断因素是数据处理行为的危险性。《个保法》项下是否需要任命个人信息保护负责人的依据则是个人信息处理数量。以数据处理行为的风险程度判断则更加合理一些。
2.一个集团下多个法人可以任命一个DPO,只要能轻易触达各公司。
3.GDPR对DPO的数据保护相关专业知识也有进一步的要求。
4.DPO履职需完全独立,且不会因履职受罚。(这很难,拿人手短呀)
GDPR:
Art. 37 Designation of the data protection officer
第37条数据保护专员的任命
1.The controller and the processor shall designate a data protection officer in any case where:
1.在以下情形中,数据控制者和数据处理者应当指定一名数据保护专员:
a.the processing is carried out by a public authority or body, except for courts acting in their judicial capacity;
当数据处理是由行政机关或公共团体实施时,除了法院在其司法职能内的行为;
b.the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or
数据控制者和数据处理者的核心业务由数据处理组成,该处理因其自身的性质、范围和 或目的等需要对数据主体进行定期的、系统化的大规模监控;或者
c.the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 or personal data relating to criminal convictions and offences referred to in Article 10.
数据控制者和处理者的核心业务由处理第9 条规定的大规模特殊类型的数据和第10 条规定的与犯罪记录和违法行为有关的数据组成。
2.A group of undertakings may appoint a single data protection officer provided that a data protection officer is easily accessible from each establishment.
2.若该专员能够轻易接触到每个部门,一个企业集团可以只任命一个数据保护专员。
3.Where the controller or the processor is a public authority or body, a single data protection officer may be designated for several such authorities or bodies, taking account of their organisational structure and size.
3.当数据控制者或处理者是行政机关或公共团体时,考虑到他们的组织机构和规模,可以为多个机关和团体指定一名数据保护专员。
4.In cases other than those referred to in paragraph 1, the controller or processor or associations and other bodies representing categories of controllers or processors may or, where required by Union or Member State law shall, designate a data protection officer. The data protection officer may act for such associations and other bodies representing controllers or processors.
4.除了本条第1 款所列情形外,数据控制者和数据处理者以及其他代表各类数据控制者和处理者的团体和机构( associations an d other bodies )也可以按照欧盟或者成员国法律的要求,指定一名数据保护专员。该专员可以代表上述团体和机构履行职责。
5.The data protection officer shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39.
5.数据保护专员的任命应当建立在专业素养,尤其是对数据保护法律的专业知识和实践,以及履行第39 条规定的任务的能力基础上。
6.The data protection officer may be a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract.
6.数据保护专员可以是数据控制者或处理者的员工,也可以按照服务合同来完成任务。
7.The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority.
7.数据控制者或处理者应当公开数据保护专员的联系方式,并且告知监管机构。
Art. 38 Position of the data protection officer
第38条数据保护专员的职位
1.The controller and the processor shall ensure that the data protection officer is involved, properly and in a timely manner, in all issues which relate to the protection of personal data.
1.数据控制者或数据处理者应当确保数据保护专员恰当、及时地参与所有有关个人数据保护的事务。
2.The controller and processor shall support the data protection officer in performing the tasks referred to in Article 39 by providing resources necessary to carry out those tasks and access to personal data and processing operations, and to maintain his or her expert knowledge.
2.数据控制者和处理者应当通过提供执行这些任务所必要的资源,个人数据和处理行为的访问途径,以及维持他或她的专业知识等途径,支持数据保护专员执行第39 条规定的任务。
3.The controller and processor shall ensure that the data protection officer does not receive any instructions regarding the exercise of those tasks. 2He or she shall not be dismissed or penalised by the controller or the processor for performing his tasks. 3The data protection officer shall directly report to the highest management level of the controller or the processor.
3.数据控制者和处理者应当确保数据保护专员不会收到任何有关执行其工作任务的指示。他或她不能因执行自身的任务而被解雇或处罚。数据保护专员应当直接向数据控制者或处理者的最高管理层报告。
4.Data subjects may contact the data protection officer with regard to all issues related to processing of their personal data and to the exercise of their rights under this Regulation.
4.数据主体可以就有关处理其个人数据和行使本条例规定的权利的所有问题联系数据保护专员。
5.The data protection officer shall be bound by secrecy or confidentiality concerning the performance of his or her tasks, in accordance with Union or Member State law.
5.依据欧盟或成员国的法律,数据保护专员对其工作任务的执行有保密义务。
6.The data protection officer may fulfil other tasks and duties. The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests.
6.数据保护专员可以履行其他任务和职务,数据控制者或处理者应当确保任何这样的任务和职务都不能导致利益冲突。
Art. 39 Tasks of the data protection officer
第三十九条数据保护专员的任务
1.The data protection officer shall have at least the following tasks:
1.数据保护专员至少应当有以下任务:
a.to inform and advise the controller or the processor and the employees who carry out processing of their obligations pursuant to this Regulation and to other Union or Member State data protection provisions;
向数据控制者或处理者和有义务按照本条例或者其他欧盟或成员国数据保护条款实施处理行为的雇员发出通知或建议;
b.to monitor compliance with this Regulation, with other Union or Member State data protection provisions and with the policies of the controller or processor in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits;
监督本条例的遵守情况,和其他欧盟或成员国数据保护条款以 及控制者或处理者有关个人数据保护的政策的遵守情况,包括责任的分配、意识的提升、参与处理行为的员工的培训以及相关的审计;
c.to provide advice where requested as regards the data protection impact assessment and monitor its performance pursuant to Article 35;
应要求提供有关数据保护影响评估的建议并根据第35 条的规定监督评估工作的实施;
d.to cooperate with the supervisory authority;
与监管机构保持协作;
e.to act as the contact point for the supervisory authority on issues relating to processing, including the prior consultation referred to in Article 36, and to consult, where appropriate, with regard to any other matter.
在有关数据处理的问题中充当监管机构的联络点,包括第36 条规定的事先咨询和有关任何其他事务的咨询(如有)。
2.The data protection officer shall in the performance of his or her tasks have due regard to the risk associated with processing operations, taking into account the nature, scope, context and purposes of processing.
2.数据保护专员应当在履行他或她的职责时 从处理行为的性质、范围、环境以及处理目的的角度合理关注数据处理行为中伴随的风险。
《个保法》:第52条处理个人信息达到国家网信部门规定数量的个人信息处理者应当指定个人信息保护负责人,负责对个人信息处理活动以及采取的保护措施等进行监督。
个人信息处理者应当公开个人信息保护负责人的联系方式,并将个人信息保护负责人的姓名、联系方式等报送履行个人信息保护职责的部门。
GDPR评注学习笔记(11)--条文变迁(DPO)
作者:何琛没有以来源:数据何规

1.数据保护专员(DPO) GDPR Proposal规定所有公共机构和所有拥有超250名永久职工公司的公司均需要任命DPO。集团公司可以仅在集团层面任命一名DPO。