With 2020 days counting down, we are surely approaching 30 months since GDPR implementation, which did not reveal all its mysteries yet. As a toddler of the same age, it is only understandable to others 50% of the time…
Indeed, there is a lot of confusion between the DPO and DPR roles.
MyData-TRUST received many questions during the last Webinar “What is the GDPR and How to operationalize It”. The aim of this article is to clarify the situation.
By February 2021, about two and a half years had passed since the General Data Protection Regulation (GDPR) came into force, yet it still had complexities to be fully understood. This is particularly evident when distinguishing between the roles of the Data Protection Officer (DPO) and the Data Protection Representative (DPR).
During our last webinar, “What is the GDPR and How to Operationalize It,” MyData-TRUST received many questions on this topic. In this article, we aim to clarify the differences between these roles, outlining both the legal requirements and practical considerations.
DPO & DPR
Among repeatedly explained, yet poorly understood obligations, the appointment of a Data Protection Officer (DPO) and a Data Protection Representative (DPR) regularly hit the top of our clients’ frequently asked questions. Indeed, appointment of either or both DPO and DPR is still not systematically complied with none of them being invented by GDPR.
Among the obligations that are often explained but still poorly understood, the appointment of a DPO and DPR consistently hit the top of our clients’ frequently asked questions. Indeed, the requirement to appoint one or both roles is still not systematically fulfilled, despite neither role being newly created by the GDPR.
The old, poorly implemented directive 95/46/EC, refers to the data protection official, a DPO ancestor and mandates data controller not established in the Union to name a representative. So, why with none of these notions coming out of the blue, DPO and DPR remain such a mystery?
Let’s try to dissipate at least some bits of the mist and hopefully dispel some misconceptions.
The previous Directive 95/46/EC, which was replaced by the GDPR in 2018, referred to the data protection official—an early form of the DPO—and required data controllers not established within the Union to appoint a representative. So, why, given that none of these notions came out of the blue, do the DPO and DPR roles remain such a mystery?
Although DPO and DPR roles may appear similar, they have significant differences and should not be confused.
Essentially, the DPO serves as a facilitator, helping controllers/processors –both within and outside EEA– implement GDPR while maintaining independence and cooperating with data protection authorities.
In contrast, the DPR acts under instructions of non-EEA controllers/processors and may be contacted by data protection authorities, either instead of or alongside those controllers/processors, to ensure compliance with the regulation.