One of the guiding principles of data protection regulations is proactive responsibility, also known as accountability. Let’s explore what it entails.
This concept originally referred to the responsibility of public officials to comply with the law and their obligation to be accountable for their governmental actions before the citizens. During the 19th and 20th centuries, the concept extended to the private sector through corporations, where it became associated with the accountability of managers to shareholders and investors.
The General Data Protection Regulation (GDPR) of the European Union adopted this concept and established it as a fundamental principle in data protection. In this context, it refers to the preventive approach that both public and private organizations must take to ensure the privacy and security of the personal data they handle. Moreover, they must be able to demonstrate their compliance efforts through proper documentation.
This principle implies anticipating potential risks and taking preventive measures in advance. It contrasts with a reactive policy, which focuses on responding to damages and repairing them after they occur. Proactive responsibility means acting ahead of time to prevent harm from happening in the first place. Consequently, organizations may be exempt from liability for damages caused, or their liability may be significantly reduced, if they have taken all reasonable measures to prevent such damage.
To comply with this guiding principle, organizations must continuously implement control actions to guarantee the security and legality of the data processing activities they carry out. The measures adopted by organizations must be demonstrable, specific, useful, relevant, effective, and proportional to the nature and purpose of the data processing involved.
Within the framework of this principle, the GDPR requires organizations to apply data protection by design and by default, conduct risk and impact assessments, and, where necessary, appoint a Data Protection Officer (DPO) to oversee regulatory compliance.
If a complaint arises, the competent authority will require documentation supporting the actions taken by the organization to comply with the law. If such documentation is missing or inadequate, the organization will face a sanction. The severity of the sanction may vary depending on how much effort the organization has made to comply with the regulations, provided they can demonstrate it.
