My bookmarksSign up free

Commission Decision (EU) 2020/969 CHAPTER 2 — DATA PROTECTION OFFICER AND DATA PROTECTION COORDINATOR

Article 4–Article 7 · 4 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Designation and position

Article 4

The DPO shall be selected from the staff of the Commission on the basis of his or her professional qualities, including a sound knowledge of the Commission Services, their structure, and their administrative rules and procedures.

Tasks and duties

Article 5

1.   The DPO shall contribute to creating a culture of protection of personal data within the Commission based on risk assessment and accountability. 2.   The DPO shall monitor implementation of Regulation (EU) 2018/1725 in the Commission by, inter alia, annually establishing and carrying out a work programme on inspections and audits. 3.   The DPO shall organise and chair regular meetings of DPCs. 4.   The DPO shall keep the Commission’s records of processing activities in a central register and shall make it publicly accessible. The DPO shall also keep an internal Commission register of personal data breaches within the meaning of Article 3(16) of Regulation (EU) 2018/1725. 5.   In the discharge of his or her functions, the DPO shall cooperate with the data protection officers designated by the other Union institutions and bodies. 6.   The DPO shall be considered to be the delegated controller for the purpose of individual decisions concerning the rights of data subjects under Regulation (EU) 2018/1725 in relation to processing operations of the DPO.

Powers

Article 6

In performing the DPO tasks, the DPO: (a) shall, where necessary for his or her tasks have access to the data forming the subject matter of processing operations on personal data and to all offices, data processing installations and data carriers; (b) may request legal opinions from the Legal Service of the Commission; (c) may, in the event of conflict between the DPO and the delegated controller, operational controller or processor relating to the interpretation or implementation of Regulation (EU) 2018/1725, inform the competent delegated controller and the Secretary-General; (d) may assign files to the Commission’s Directorates-General or Services concerned for appropriate follow-up; (e) may perform investigations on request, or upon the DPO’s own initiative, into matters and occurrences directly relating to the DPO tasks in accordance with the procedure set out in Article 11; (f) may, when making recommendations and rendering advice: (i) call upon the delegated controller or the processor to comply with a data subject’s request for the exercise of his or her rights pursuant to Regulation (EU) 2018/1725; (ii) issue warnings to the delegated controller or the processor when a processing operation infringes provisions of Regulation (EU) 2018/1725, and call upon them to bring processing operations into compliance, where appropriate, in a specified manner and within a specified period; (iii) call upon the delegated controller or the processor to suspend data flows to a recipient in a Member State, to a third country or to an international organisation; (iv) request the delegated controller or the processor to report within a set deadline to the DPO on the follow-up given to the DPO’s recommendation or advice; (g) may bring to the attention of the Secretary-General any failure of a delegated controller, an operational controller or a processor to comply with the measures taken pursuant to Article 6(f); (h) shall be responsible for initial decisions on requests for access to documents held by his or her office under Regulation (EC) No 1049/2001 of the European Parliament and of the Council  ( 5 ) .

Data Protection Coordinators

Article 7

1.   The delegated controller shall appoint a DPC and, where appropriate one or more assistant DPCs in the Directorate-General or Service under his or her responsibility. Two or more delegated controllers may, for reasons of coherence or efficiency, decide to appoint a common DPC or assistant DPC or share the services of an already appointed DPC or assistant DPC. The delegated controllers concerned shall record their agreement to do so in writing. 2.   The DPC appointed by a Directorate-General or Service shall also be competent for the Cabinet responsible for that Directorate-General or Service. The DPC appointed for the Secretariat-General shall be competent for the President’s Cabinet as well as for Cabinets for which the Secretariat-General is the only supporting Service. Where a Cabinet is responsible for several Directorates-General or Services, the delegated controllers shall decide which of their respective DPCs are to be competent for that Cabinet. 3.   The DPO, the staff of the relevant Directorate-General or Service and the relevant Cabinet shall be informed whenever a new DPC is appointed. Newly appointed DPCs shall complete training to acquire the necessary competences for the role of DPC within six months of appointment. A DPC who has previously held a DPC post in another Directorate-General or Service or has been a staff member of the DPO within two years prior to appointment as DPC shall be exempt from that training requirement. 4.   Delegated controllers shall put appropriate arrangements in place in order to ensure that the DPC is involved properly and in a timely manner in all issues which relate to data protection in their Directorate-General or Service and that opinions delivered by the DPC are promptly brought to the attention of the delegated controller at the request of the DPC. 5.   DPCs shall be chosen on the basis of their knowledge and experience of the functioning of the respective Directorate-General or Service, motivation for the function, competences relating to data protection, understanding of information systems principles, and communication skills. 6.   The function of DPC may be combined with other functions. The delegated controller shall ensure that those functions are compatible with the function of DPC. 7.   The DPC function shall be part of the job description of each member of staff appointed as DPC. Reference to their responsibilities and achievements shall be made in the annual appraisal report. 8.   The DPC shall act as a contact point between the delegated controller, the operational controller and the processor, and the DPO. 9.   DPCs shall have the right to obtain any information in their Directorate-General or Service to the extent that this is necessary for the performance of the tasks of DPC. DPCs shall access personal data, only if it is necessary for the performance of their tasks. 10.   The DPC shall keep records and provide anonymised statistics of requests from data subjects to the Directorate-General, Service or Cabinet, specifying the numbers of requests and the number of requests rejected fully or in part. The DPO shall specify the categories of requests of which statistics shall be kept. The DPO may specify which further details are to be provided. The DPC shall keep anonymised statistics of personal data breaches managed by the Directorate-General, Service or Cabinet, specifying the total number of personal data breaches, the number of personal data breaches notified to the EDPS and the number of personal data breaches communicated to data subjects. 11.   The DPC shall raise awareness on data protection matters within his or her DG or Service and shall advice and assist the delegated controllers and operational controllers in complying with their obligations, especially as regards: (a) implementation of the general principles of Regulation (EU) 2018/1725; (b) documentation of the processing operations; (c) submission of the records of delegated controllers’ processing operations to the DPO pursuant to Article 10; (d) the preparation of privacy statements. 12.   DPCs shall participate in the meetings and, where necessary, in working groups of the DPCs. 13.   The DPO shall issue additional guidance on the responsibilities and the functions of the DPC.

Back to Commission Decision (EU) 2020/969 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next