Cluster
Guides
The register, worked through
Four long-form entries on the Data Protection Officer under Articles 37 to 39: whether you need one, whether to appoint internally or externally, where the conflict-of-interest line falls, and how the Baltic and Nordic authorities want the designation filed.
Index
All entries
Every guide in this register
-
Do you need a Data Protection Officer?
Three cases, no headcount threshold, and two words that decide almost every borderline call. The Article 37(1) test worked through with the Working Party's own examples.
Open entry -
Internal or external DPO: what the service contract has to carry
Article 37(6) permits an outsourced officer in fourteen words. The other thirty provisions of Section 4 decide whether the arrangement actually works.
Open entry -
DPO conflict of interest: where the line actually falls
The Court of Justice has given the test, the Working Party has named the positions, and supervisory authorities have found the failure modes. Including the ones that only appear when the officer is external.
Open entry -
Notifying your DPO to the supervisory authority
One sentence of European law, four completely different national filings. Latvia runs an examination, Estonia uses the business register, Finland publishes a warning, and Lithuania wants the employer named.
Open entry