Designation and status of the DPO
1. The Secretary-General of the Council shall designate the DPO from the staff of the GSC and register him or her with the European Data Protection Supervisor (‘EDPS’), in accordance with Article 43 of Regulation (EU) 2018/1725.
2. The DPO shall be selected on the basis of his or her professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 45 of Regulation (EU) 2018/1725. The DPO shall also have a sound knowledge of the GSC, its structure and its administrative rules and procedures. For the purposes of performing his or her tasks, the DPO shall be relieved of any other task within the GSC.
3. The DPO is designated for a term of five years and shall be eligible for reappointment.
4. The DPO and his or her staff are directly attached to the Secretary-General of the Council and report directly to him or her.
5. In performing his or her tasks, the DPO shall act in an independent manner and shall not receive any instruction from the Secretary-General of the Council, from the delegated controllers or the operational controllers or from anyone else regarding the internal application of the provisions of Regulation (EU) 2018/1725 or his or her cooperation with the EDPS.
6. The Council and the GSC shall support the DPO in performing the tasks referred to in Article 45 of Regulation (EU) 2018/1725 by providing the resources necessary to carry out those tasks and provide access to personal data and processing operations, and to maintain his or her expert knowledge.
7. The DPO shall not be dismissed or penalised for performing his or her tasks. The DPO may only be dismissed in accordance with Article 44(8) of Regulation (EU) 2018/1725. For the purpose of obtaining the consent of the EDPS to such a dismissal pursuant to that Article, the EDPS shall be consulted in writing. A copy of that consent shall be sent to the DPO.
8. The GSC, in particular the delegated controllers and the operational controllers, shall ensure that the DPO is involved properly and in a timely manner in all issues which relate to the protection of personal data.
Tasks and duties
1. The DPO shall exercise all the tasks foreseen in Article 45 of Regulation (EU) 2018/1725. In particular, the DPO shall:
(a)
ensure the application and implementation of Regulation (EU) 2018/1725 by the Council and the GSC, and monitor compliance with that Regulation and the applicable legal framework on the protection of personal data;
(b)
advise the Secretary-General of the Council, the delegated controllers and the operational controllers on matters concerning the application of data protection provisions;
(c)
advise and assist the delegated controllers and the operational controllers when carrying out a data protection impact assessment in accordance with Articles 39 and 40 of Regulation (EU) 2018/1725;
(d)
ensure that the rights and freedoms of data subjects are not adversely affected by processing operations;
(e)
raise awareness on the applicable legal framework on the protection of personal data and contribute to creating a culture of protection of personal data within the GSC.
The DPO may be consulted by the Secretary-General of the Council, the controllers concerned, the Staff Committee and by any individual, without going through the official channels, on any matter concerning the application or implementation of Regulation (EU) 2018/1725.
2. The DPO shall keep a register of records of processing activities and shall make it publicly available, in accordance with Article 12.
3. The DPO shall keep an internal register of personal data breaches within the meaning of Article 3, point (16), of Regulation (EU) 2018/1725.
4. The DPO shall advise the delegated controller, where requested, on the application of a restriction of the application of Articles 14 to 22, 35 and 36, as well as Article 4 of Regulation (EU) 2018/1725.
5. The DPO shall organise and chair regular meetings of data protection coordinators.
6. The DPO shall submit an annual report on his or her activities to the Secretary-General of the Council and make it available to GSC staff.
7. The DPO shall cooperate with the data protection officers designated by the other Union institutions and bodies and shall regularly attend meetings convened by the EDPS or the data protection officers of the other Union institutions and bodies with a view to facilitating good cooperation, in particular by exchanging experience and best practices.
8. The DPO shall be considered the delegated controller for the processing operations carried out in the exercise of his or her tasks.
Powers
In performing his or her tasks and duties, the DPO:
(a)
shall have access at all times to the data forming the subject-matter of processing operations and to all offices, data-processing installations and data carriers;
(b)
may request legal opinions from the Council Legal Service;
(c)
may request other support from the relevant of the GSC directorates-general and services;
(d)
may assign files to the GSC directorates-general and services concerned for appropriate follow-up;
(e)
may perform investigations on request, or on his or her own initiative, into matters and occurrences directly relating to the DPO tasks in accordance with the procedure set out in Article 14;
(f)
may propose administrative measures to the Secretary-General of the Council and issue general recommendations on the appropriate application of Regulation (EU) 2018/1725;
(g)
may make recommendations for the practical improvement of the application of Regulation (EU) 2018/1725 to the GSC, the delegated controllers and operational controllers, including:
(i)
calling upon the delegated controller or the processor to comply with a data subject’s request for the exercise of his or her rights pursuant to Regulation (EU) 2018/1725;
(ii)
issuing warnings to the delegated controller or the processor where a processing operation infringes provisions of Regulation (EU) 2018/1725, and calling upon them to bring processing operations into compliance, where appropriate, in a specified manner and within a specified period;
(iii)
calling upon the delegated controller or the processor to suspend data flows to a recipient in a Member State, to a third country or to an international organisation;
(iv)
requesting the delegated controller or the processor to report within a set deadline to the DPO on the follow-up given to the DPO’s recommendation or advice;
(h)
may request the services of external information and communication technologies experts upon prior agreement of the authorising officer in compliance with Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council ( 9 ) ;
(i)
shall be invited to the relevant management boards and committees of the GSC whenever issues relating to the processing of personal data are discussed and may propose relevant points on the agenda of those boards and committees;
(j)
may bring to the attention of the Appointing Authority of the GSC any failure of a GSC staff member to comply with the obligations under Regulation (EU) 2018/1725 and suggest that an administrative investigation be launched with a view to the possible application of the sanctions provided for in Article 69 of that Regulation;
(k)
shall be responsible for initial decisions on requests for access to documents held by his or her office under Regulation (EC) No 1049/2001, in consultation with the relevant services of the GSC.
Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.