DATA PROTECTION OFFICER
We assign a DPO (Data protection officer) who is responsible for overseeing data protection strategies and ensuring that the organization complies with data protection laws and regulations.
The work of this legal figure is essential since it helps prevent risks and sanctions, and creates new business opportunities.
For some companies it is mandatory to have a DPO. This depends on the regulations you work under but it is usually the case for companies that handle personal data on a big scale.
IMPORTANT INFORMATION TO HAVE IN MIND
Europe’s G.D.P.R. establishes that private companies that have to name a DPO are those which perform:
Large-Scale
Systematic
Monitoring
Organizations whose core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale must appoint a DPO. This includes activities like tracking and profiling individuals for behavior-based advertising.
Large-Scale
Processing of Special
Categories of Data
Organizations whose core activities consist of processing on a large scale special categories of data or personal data relating to criminal convictions and offenses must appoint a DPO. Special categories of data include information about racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person’s sex life or sexual orientation.
PONDER´S DPO WORK MODEL
Having an external DPO provides several advantages. It reduces costs and it ensures you count with a specialized professional who is up to date with the latest privacy regulations.
Depending on your company’s needs regarding data protection we have the following work models:
DPO´S
MAIN
OBJECTIVES:
Design your company’s privacy strategies.
Analyze the data flow, identify both risks and opportunities.
Suggest measures to ensure compliance with privacy regulations.
Accompany you on the execution of those measures.
Inform and train your staff to improve privacy practices.
Be the bond with users and solve their doubts and concerns about their personal data.
Direct to data privacy authorities when needed.


