Q&As
If a multinational company with entities in a number of EU states has registered a data protection officer (DPO) with the Information Commissioner’s Office (ICO), does it need to register a DPO in the other EU states where it has entities or is registration in one country sufficient?
Under Article 37 of the General data protection Regulation, Regulation (EU) 2016/679 (the GDPR), companies have to appoint a data protection officer (DPO) if certain conditions are met. The information commissioner’s Office (ICO) offers a simple questionnaire to determine if a mandatory DPO is required. Even if a DPO is not required, a voluntary appointment of a formal DPO is possible.
A group of companies may appoint a single DPO provided that the DPO is easily accessible from each establishment (Article 37(2) of the GDPR). According to the Article 29 Data Protection Working Party Guidelines on Data Protection Officers (the DPO guidelines), ‘easily accessible’ refers to being available internally within the organisation as well as externally to data subjects and supervisory authorities.
The GDPR requires the details of the DPO to be published
To view the latest version of this document and thousands of others like it,
sign-in with LexisNexis or register for a free trial.