Data protection and the data protection officer
We take on the data protection officer role, or help yours get the work under control, from records of processing to answering data subject requests.
Two regulations, largely the same evidence
Data protection and cyber security ask for much of the same evidence. We produce it once.
The overlap with the Cybersecurity Act is large and deliberate. The asset inventory and the record of processing describe the same system from two sides. Access control is proved by the same records. Incident handling differs only in who is notified and within what deadline.
That is why we do not run these two separately. Where an incident also involves a personal data breach, one and the same procedure has to branch in the first hour, towards the data protection authority and towards the competent CSIRT. These are two procedures and neither replaces the other, so they are written as one document with two branches rather than as two that drift apart in practice.
We take on the data protection officer role under contract, where it is mandatory or where the organisation wants one. The role is independent and does not decide on the purposes of processing, and that must be stated expressly in the contract.
This page is about the work. The provisions themselves, the deadlines, the fines and the powers of the supervisory authority are set out on the page on the General Data Protection Regulation, so we do not repeat them here.
What we do
Seven pieces of work that make up the role, whether we take it on or support your own person.
The data protection officer role under contract
We take on the role or support your appointed person. The appointment is notified to the supervisory authority, and the contract secures independence and the fact that the role does not decide on purposes of processing.
Records of processing activities
We list the processing operations, purposes, categories of data and data subjects, recipients, retention periods and security measures. The record is the first thing a supervisory authority asks for, and the fastest route to a list of systems that need protecting.
Data protection impact assessment
Carried out where processing is likely to be high risk, for instance large-scale processing of special categories of data, systematic monitoring or new technology. In healthcare that is the rule, not the exception.
Handling data subject requests
We set up a procedure with a deadline, forms and a rule on who answers. A request may be refused only if it is manifestly unfounded or excessive, and the burden of proof is on you, so a refusal is always justified in writing.
Access logs and answering a request
We check whether your systems record who looked at a file, when and why, and whether they do it in a form that can later be searched. Alongside that we set the rule on what is disclosed in an answer and what is not, and a template that applies it. How far the right of access reaches is set out on the page on the GDPR.
Breach notification and the dual track
We set up a procedure that branches in the first hour: the data protection authority within 72 hours and the competent CSIRT within 24 hours where the incident is also a cyber one. Alongside it runs a breach register, which must be kept even for breaches that are not notified.
Contracts with processors
Every supplier processing data on your behalf needs a contract with the prescribed content. The same supplier list serves the supply chain measure in Annex II of the Cybersecurity Regulation, so the work is done once.
Frequently asked questions
The questions we are asked most often before we start.
Can the data protection officer be external?
Yes, the role may be contracted out. What matters is that the appointment is notified to the supervisory authority, that the person does not decide on the purposes and means of processing, and that their independence is secured, under Articles 37 to 39 of the GDPR. That is settled in the contract, so we draft that part before the role is taken on.Do you also act when a breach actually happens?
We do. Alongside the procedure and the forms we go through the event itself: we help judge whether a breach occurred at all, whether it has to be notified, whether the data subjects have to be told and how that is recorded. For institutions also covered by the Cybersecurity Act we run it as one event with two notifications.How long do we keep the data?
As long as the purpose of processing and the relevant sectoral legislation require. For medical records the retention periods are set by healthcare legislation and differ by type of record, so we always verify them for your institution rather than assuming.What do we need to have ready to start?
A list of the systems holding personal data, the record of processing if one exists, the contracts with suppliers processing data on your behalf, and the names of the people who actually keep those systems running. If there is no record yet we start from the list of systems, because the record is built from it anyway.Do you run this separately from alignment with the Cybersecurity Act?
We do not, and that is deliberate. Run in parallel, the asset inventory, access control and the incident procedure are produced once and serve both. Run separately, the same records get written twice and drift apart over time.Where to go next
Work that shares the same records with data protection.
Let us check whether your records hold up.
Half an hour, no obligation. We look at your record of processing and your request procedure and tell you what would trip first.
