Art. 38 GDPR – Position of the data protection officer
- The controller and the processor shall ensure that the data protection officer is involved, properly and in a timely manner, in all issues which relate to the protection of personal data.
- The controller and processor shall support the data protection officer in performing the tasks referred to in Article 39 by providing resources necessary to carry out those tasks and access to personal data and processing operations, and to maintain his or her expert knowledge.
- 1The controller and processor shall ensure that the data protection officer does not receive any instructions regarding the exercise of those tasks. 2He or she shall not be dismissed or penalised by the controller or the processor for performing his tasks. 3The data protection officer shall directly report to the highest management level of the controller or the processor.
- Data subjects may contact the data protection officer with regard to all issues related to processing of their personal data and to the exercise of their rights under this Regulation.
- The data protection officer shall be bound by secrecy or confidentiality concerning the performance of his or her tasks, in accordance with Union or Member State law.
- 1The data protection officer may fulfil other tasks and duties. 2The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests.
Related Recitals
Frequently Asked Questions about Article 38
+ What is the role of a DPO within an organisation?
Article 38 requires that the DPO is involved properly and in a timely way in all data protection matters, has adequate resources, and reports to the highest level of management.
+Must a DPO be independent under the GDPR?
Yes. The DPO must perform their duties independently, cannot be dismissed or penalised for doing so, and must not receive instructions on how to carry out their tasks.
+ Can a DPO have other duties in the company?
A DPO may carry out other tasks, but the organisation must ensure those duties do not create a conflict of interest with their data protection responsibilities.