CIPP-E · Question #38
Which of the following would require designating a data protection officer?
The correct answer is D. The core activities of the controller or processor consist of processing operations that require. According to Article 37 of the GDPR, the designation of a data protection officer (DPO) is mandatory for controllers and processors in three cases1: When the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; When the…
Question
Which of the following would require designating a data protection officer?
Options
- AProcessing is carried out by an organization employing 250 persons or more.
- BProcessing is carried out for the purpose of providing for-profit goods or services to individuals in
- CThe core activities of the controller or processor consist of processing operations of financial
- DThe core activities of the controller or processor consist of processing operations that require
How the community answered
(34 responses)- A3% (1)
- B3% (1)
- C9% (3)
- D85% (29)
Explanation
According to Article 37 of the GDPR, the designation of a data protection officer (DPO) is mandatory for controllers and processors in three cases1: When the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; When the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or When the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 and personal data relating to criminal convictions and offences referred to in Article 10. The GDPR does not define what constitutes "regular and systematic monitoring" or "large scale", but the Article 29 Working Party (now replaced by the European Data Protection Board) has provided some guidance on these concepts. According to the guidance, "regular and systematic monitoring" includes all forms of tracking and profiling on the internet, including for the purposes of behavioural advertising, but also offline activities such as CCTV or health data monitoring. The guidance also suggests some criteria to assess whether the processing is carried out on a large scale, such as the number of data subjects concerned, the volume of data or the range of data items processed, the duration or permanence of the processing activity, and the geographical extent of the processing. In the given scenario, option D is the only one that clearly falls under the second case of mandatory DPO designation, as it implies that the controller or processor is engaged in regular and systematic monitoring of data subjects on a large scale as part of their core activities. This could include, for example, online behavioural advertising, location tracking, loyalty programs, or health data analytics.
Topics
Community Discussion
No community discussion yet for this question.