← back to the act's dossier

GDPR — Article 39

The article's text

Article 39 Tasks of the data protection officer 1. The data protection officer shall have at least the following tasks: (a) to inform and advise the controller or the processor and the employees who carry out processing of their obligations pursuant to this Regulation and to other Union or Member State data protection provisions; (b) to monitor compliance with this Regulation, with other Union or Member State data protection provisions and with the policies of the controller or processor in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits; (c) to provide advice where requested as regards the data protection impact assessment and monitor its performance pursuant to Article 35; (d) to cooperate with the supervisory authority; (e) to act as the contact point for the supervisory authority on issues relating to processing, including the prior consultation referred to in Article 36, and to consult, where appropriate, with regard to any other matter. 2. The data protection officer shall in the performance of his or her tasks have due regard to th
full text
e risk associated with processing operations, taking into account the nature, scope, context and purposes of processing. Section 5 Codes of conduct and certification

Who wrote about this article in the consultations

Filers who named this exact article number in their own text. It is their sentence, not our reading — and not a causal claim.

4
NGO
1
other
1
business association
1
EU citizen
1
ACADEMIC_RESEARCH_INSTITTUTION
WhoCountryWhat they wrote
Gesellschaft für Datenschutz und Datensicherheit (GDD) e.V.DEGVO bei. Für die konkrete Aufga- benerfüllung durch Datenschutzbeauftragte erscheint eine Präzisierung der Aufgabe Überwa- chung (Art. 39 Abs. 1 lit. b) DS-GVO) wünschenswert, um diesen Terminus von der damit na- heliegenden Aufgabe der Kontrolle abzugrenzen.
EuroISPA (European Internet Services Providers Association)BEy due to limited guidance from DPAs as well as a role played inconsistently across the industry. b. The statutory requirements in Article 39 are quite broad, leading to difficulties in finding the individual with the appropriate skills. c. Resources dedicated
Bitkom e.V.DEstantial resources. 14 b. Are there enough skilled individuals to recruit as DPOs? Due to the variety of legal requirements under Article 39 of the GDPR, it is difficult to find one individual with all the necessary skills. Instead, teams could be set up (e.g.
ANITEC-ASSINFORMITgh skilled individuals to recruit as DPOs? 7b) Answer: High Level & Detailed The wide variety of statutory requirements on GDPR’s Article 39 make it difficult to find one individual with all the necessary skills. In particular, the GDPR provides re
Délégué à la Protection des Données (ancien et formateur)FR: Lorsqu'il n'est pas rendu à l'expiration de ces délais, l'avis demandé à l’autorité de contrôle est réputé favorable. 16) Article 39 RGPD : introduire l’obligation, pour le Délégué à la Protection des Données, de présenter son rapport annuel à son responsabl
FR. On y parle aussi des « pratiques en matière de protection des données » et de la « capacité à accomplir les missions visées à l'article 39 ».
CEDPO - European Confederation of Data Protection Organisations.BEto information for controllers and processors subject, and a fair process. CEDPO would like to emphasize that as stipulated under Art 39.1(e) of the GDPR, data protection officers (DPO), as appointed by controllers and processors, are the primary point of cont
Czech Data Protection AssociationCZh to the investigation of (cross-border) cases. On the one hand, DPOs are supposed to cooperate with the supervisory authorities (Article 39(1)(d) and (e) GDPR), but at the same time they are bound by a duty of loyalty towards the controllers or processors con
David BARNARD-WILLSGBante thinking. The GDPR makes explicit requirements upon DPAs to encourage and support data protection certification mechanisms (Article 39) and sets out a role for DPAs in determining when DPIAs are required in certain contexts, and for consulting with data
Universiteit van Amsterdam (IViR), Vrije Universiteit Brussel (LSTS) and KU Leuven (CiTiP)BEMaar (21) The Data Protection Officer (DPO) is another important actor in the governance structure of the GDPR. According to Article 39(1)(b) GDPR, one of the tasks of the data protection officer is to monitor whether the data controller is compliant with the

Source: public consultation submissions and position papers. n = 10 mentions; counted as a literal reference to the article number.

Ask about this article →