{"id":2438,"date":"2019-04-26T06:27:10","date_gmt":"2019-04-26T06:27:10","guid":{"rendered":"https:\/\/www.bizlegal.eu\/?page_id=2438"},"modified":"2019-04-30T05:48:59","modified_gmt":"2019-04-30T05:48:59","slug":"government-body-ignoring-privacy-rules-2","status":"publish","type":"page","link":"https:\/\/www.bizlegal.eu\/?page_id=2438","title":{"rendered":"Government Body Ignoring Privacy Rules"},"content":{"rendered":"\n<p>The Article 29\nWorking Group, the predecessor of the European Data Protection Board (which is\na body consisting of all the data protection regulators in the EU) has issued\nguidelines <a href=\"http:\/\/ec.europa.eu\/newsroom\/document.cfm?doc_id=44100\">http:\/\/ec.europa.eu\/newsroom\/document.cfm?doc_id=44100<\/a>\n&nbsp;quite some time ago confirming that a\nData Protection Officer must be independent in the carrying out of their\nfunctions.&nbsp; They must not take direction\nfrom senior management as the carrying out of their functions, nor may they be\nalso fulfilling another role which might conflict with their role as Data\nProtection Officer.&nbsp; The Article 29 Group\ngive a list of roles which it indicated would conflict with the independence of\nthe Data Protection Officer.&nbsp; <\/p>\n\n\n\n<p>These are senior\nmanagement positions (such as chief executive, chief operating officer, chief\nfinancial officer, chief medical officer, head of marketing, head of Human\nResources or head of IT) but also other roles lower down in the organisational structure<strong> if such positions or roles lead to the\ndetermination of purposes and means of processing<\/strong>.&nbsp; <\/p>\n\n\n\n<p>The Department of Social Protection became the\nsubject of criticism when it emerged in July 2018 that in the absence of the\nthen Data Protection Officer who was on leave, changes were made to the Privacy\nPolicy of the Department.&nbsp; These were\nauthorised by the Secretary General of the Department.&nbsp; Strictly speaking, the Data Protection\nOfficer does not have to authorise the Privacy Policy, but they are obliged to\nmonitor compliance with the GDPR.<\/p>\n\n\n\n<p>More recently, the Department of Social\nProtection has now been subject to further criticism because the previous Data\nProtection Officer was removed from that role by the Department, and replaced with\na colleague who also heads its Business Information Security Unit (BISU), which\nhas been designated as the data controller for the Department.&nbsp; Clearly, the head of the controller cannot\nalso be its Data Protection Officer.<\/p>\n\n\n\n<p>We would suggest, with respect, that the\ncurrent situation is untenable, and is likely to fall at the first\nchallenge.&nbsp; It seems a clear example of\nthe State misunderstanding its obligations under the GDPR.<\/p>\n\n\n\n<p>We have seen this on many occasions, with\nState bodies appointing heads of IT, and heads of other business units to be\nthe data protection officer.&nbsp; It is\nclearly still not understood within the State sector that the Data Protection\nOfficer is more in the nature of an independent auditor, than an operational\nrole on behalf of the controller.<\/p>\n\n\n\n<p>It seems likely that the present stance of\nthe State sector will lead to litigation.&nbsp;\nThe Data Protection Commission has already taken an interest in this\nmatter, but previous investigations by that body would not suggest that there\nwill be an outcome from that investigation any time soon.&nbsp; However, this is not likely to be the\nDepartment\u2019s main problem.&nbsp; Under the new\nprinciples set out in the GDPR that data subjects may sue for \u201cnon\u2014material\ndamage\u201d, it is likely that any person who has concerns over the processing of\nthe personal data in circumstances where the protection of the Data Protection\nOfficer may be less than envisaged in the GDPR, could sue the Department.<\/p>\n\n\n\n<p>Any claimant would not have to prove\nmaterial damage of any kind.&nbsp; They would\nlikely simply need to show that there had been a breach of their statutory\nrights in this regard and that this caused them some discernible level of\ndistress.<\/p>\n\n\n<p><!--EndFragment--><\/p>\n<p><\/p>","protected":false},"excerpt":{"rendered":"<p>The Article 29 Working Group, the predecessor of the European Data Protection Board (which is a body consisting of all the data protection regulators in the EU) has issued guidelines http:\/\/ec.europa.eu\/newsroom\/document.cfm?doc_id=44100 &nbsp;quite some time ago confirming that a Data Protection Officer must be independent in the carrying out of their functions.&nbsp; They must not take &hellip;<\/p>\n<p class=\"read-more\"> <a class=\"\" href=\"https:\/\/www.bizlegal.eu\/?page_id=2438\"> <span class=\"screen-reader-text\">Government Body Ignoring Privacy Rules<\/span> Read More &raquo;<\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"advgb_blocks_editor_width":"","advgb_blocks_columns_visual_guide":""},"coauthors":[],"author_meta":{"author_link":"https:\/\/www.bizlegal.eu\/?author=3","display_name":"Sharon McGauley"},"relative_dates":{"created":"Posted 7 years ago","modified":"Updated 7 years ago"},"absolute_dates":{"created":"Posted on 26\/04\/2019","modified":"Updated on 30\/04\/2019"},"absolute_dates_time":{"created":"Posted on 26\/04\/2019 6:27 am","modified":"Updated on 30\/04\/2019 5:48 am"},"featured_img_caption":"","featured_img":false,"series_order":"","_links":{"self":[{"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/pages\/2438"}],"collection":[{"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2438"}],"version-history":[{"count":2,"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/pages\/2438\/revisions"}],"predecessor-version":[{"id":2447,"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/pages\/2438\/revisions\/2447"}],"wp:attachment":[{"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2438"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}