CIPP-E · Question #162
A multinational company is appointing a mandatory data protection officer. In addition to considering the rules set out in Article 37 (1) of the GDPR, which of the following actions must the company…
The correct answer is A. Consult national derogations to evaluate if there are additional cases to be considered in relation. A multinational company that is appointing a mandatory data protection officer (DPO) must also consult national derogations to evaluate if there are additional cases to be considered in relation to the matter. According to Article 37 (1) of the GDPR, a DPO must be designated by…
Question
A multinational company is appointing a mandatory data protection officer. In addition to considering the rules set out in Article 37 (1) of the GDPR, which of the following actions must the company also undertake to ensure compliance in all EU jurisdictions in which it operates?
Options
- AConsult national derogations to evaluate if there are additional cases to be considered in relation
- BConduct a Data Protection Privacy Assessment on the processing operations of the company in
- CAssess whether the company has more than 250 employees in each of the EU member-states in
- DRevise the data processing activities of the company that affect more than one jurisdiction to
How the community answered
(53 responses)- A79% (42)
- B4% (2)
- C6% (3)
- D11% (6)
Explanation
A multinational company that is appointing a mandatory data protection officer (DPO) must also consult national derogations to evaluate if there are additional cases to be considered in relation to the matter. According to Article 37 (1) of the GDPR, a DPO must be designated by the controller or the processor in any case where: (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; (b) the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or ?the core activities of the controller or the processor consist of processing on a large scale of special categories of data or personal data relating to criminal convictions and offences. However, Article 37 (4) of the GDPR also allows Member States to provide for additional cases where a DPO must be designated by law. Therefore, a multinational company must consult the national laws of the EU jurisdictions in which it operates to ensure that it complies with any additional requirements for appointing a DPO.
Topics
Community Discussion
No community discussion yet for this question.