RISKORIA ADVISING & PROFESSIONAL SERVICES D.O.O. · ZAGREB+385 97 737 1345INFO@RISKORIA.EU

Data protection and the data protection officer

We take on the data protection officer role, or help yours get the work under control, from records of processing to answering data subject requests.

LEGAL FRAMEWORKGDPR EU 2016/679IMPLEMENTATION ACT NN 42/2018ZKS NN 14/2024

Two regulations, largely the same evidence

Data protection and cyber security ask for much of the same evidence. We produce it once.

The overlap with the Cybersecurity Act is large and deliberate. The asset inventory and the record of processing describe the same system from two sides. Access control is proved by the same records. Incident handling differs only in who is notified and within what deadline.

That is why we do not run these two separately. Where an incident also involves a personal data breach, one and the same procedure has to branch in the first hour, towards the data protection authority and towards the competent CSIRT. These are two procedures and neither replaces the other, so they are written as one document with two branches rather than as two that drift apart in practice.

We take on the data protection officer role under contract, where it is mandatory or where the organisation wants one. The role is independent and does not decide on the purposes of processing, and that must be stated expressly in the contract.

This page is about the work. The provisions themselves, the deadlines, the fines and the powers of the supervisory authority are set out on the page on the General Data Protection Regulation, so we do not repeat them here.

What we do

Seven pieces of work that make up the role, whether we take it on or support your own person.

01

The data protection officer role under contract

We take on the role or support your appointed person. The appointment is notified to the supervisory authority, and the contract secures independence and the fact that the role does not decide on purposes of processing.

CONTRACT AND APPOINTMENTNOTIFICATION TO THE AUTHORITYDESCRIPTION OF TASKS
02

Records of processing activities

We list the processing operations, purposes, categories of data and data subjects, recipients, retention periods and security measures. The record is the first thing a supervisory authority asks for, and the fastest route to a list of systems that need protecting.

RECORDS OF PROCESSINGRETENTION PERIODSLEGAL BASES
03

Data protection impact assessment

Carried out where processing is likely to be high risk, for instance large-scale processing of special categories of data, systematic monitoring or new technology. In healthcare that is the rule, not the exception.

IMPACT ASSESSMENTLIST OF MEASURESCONSULTATION RECORD
04

Handling data subject requests

We set up a procedure with a deadline, forms and a rule on who answers. A request may be refused only if it is manifestly unfounded or excessive, and the burden of proof is on you, so a refusal is always justified in writing.

REQUEST PROCEDURERESPONSE TEMPLATESREQUEST REGISTER
05

Access logs and answering a request

We check whether your systems record who looked at a file, when and why, and whether they do it in a form that can later be searched. Alongside that we set the rule on what is disclosed in an answer and what is not, and a template that applies it. How far the right of access reaches is set out on the page on the GDPR.

ACCESS LOGSDISCLOSURE RULERESPONSE TEMPLATE
06

Breach notification and the dual track

We set up a procedure that branches in the first hour: the data protection authority within 72 hours and the competent CSIRT within 24 hours where the incident is also a cyber one. Alongside it runs a breach register, which must be kept even for breaches that are not notified.

BREACH PROCEDUREFORMSBREACH REGISTER
07

Contracts with processors

Every supplier processing data on your behalf needs a contract with the prescribed content. The same supplier list serves the supply chain measure in Annex II of the Cybersecurity Regulation, so the work is done once.

LIST OF PROCESSORSCONTRACT CLAUSESSUB-PROCESSOR CHECKS

Frequently asked questions

The questions we are asked most often before we start.

Can the data protection officer be external?

Yes, the role may be contracted out. What matters is that the appointment is notified to the supervisory authority, that the person does not decide on the purposes and means of processing, and that their independence is secured, under Articles 37 to 39 of the GDPR. That is settled in the contract, so we draft that part before the role is taken on.

Do you also act when a breach actually happens?

We do. Alongside the procedure and the forms we go through the event itself: we help judge whether a breach occurred at all, whether it has to be notified, whether the data subjects have to be told and how that is recorded. For institutions also covered by the Cybersecurity Act we run it as one event with two notifications.

How long do we keep the data?

As long as the purpose of processing and the relevant sectoral legislation require. For medical records the retention periods are set by healthcare legislation and differ by type of record, so we always verify them for your institution rather than assuming.

What do we need to have ready to start?

A list of the systems holding personal data, the record of processing if one exists, the contracts with suppliers processing data on your behalf, and the names of the people who actually keep those systems running. If there is no record yet we start from the list of systems, because the record is built from it anyway.

Do you run this separately from alignment with the Cybersecurity Act?

We do not, and that is deliberate. Run in parallel, the asset inventory, access control and the incident procedure are produced once and serve both. Run separately, the same records get written twice and drift apart over time.

Where to go next

Work that shares the same records with data protection.

Let us check whether your records hold up.

Half an hour, no obligation. We look at your record of processing and your request procedure and tell you what would trip first.

Book a callINFO@RISKORIA.EU · +385 97 737 1345