CNIL sets a decision making test for when a second role disqualifies the DPO
The CNIL has published guidance on when a second job inside the organisation stops someone acting as data protection officer. Its test is decision making power: a DPO who decides the purposes or the means of a processing activity in another role cannot then review it, and would be judge and party at once. Where that happens the organisation must bring the conflict to an end.
The guidance treats senior management posts, naming chief executive and head of human resources, as generally incompatible with the DPO function, and says a role lower down the structure is caught on the same reasoning if it leads the DPO to determine the purposes and means of processing. It works the point through an information security manager who also holds the DPO role, asking whether that person sets the retention period for connection and activity logs, proposes the security measures, and decides on requests for access to staff data. Further questions cover a DPO who sits on an ethics committee, holds a staff representative or trade union mandate, or is designated by a processor, joint controller or recipient of the same data. The list is expressly not exhaustive and each situation is assessed case by case.
On remediation the guidance is firmer than the usual advice to document and monitor. Once a conflict is identified the designating organisation has an obligation to end it, by replacing the DPO, by withdrawing the third party duties that create the conflict, or by another effective measure. The measure developed in most detail is recusal, where a deputy DPO covers the affected scope. That deputy must receive the Article 37 to 39 guarantees and must have no relationship of subordination to the designated DPO for that scope, and a countersignature with no real decision making power is called out as purely formal. The deputy is not registered with the CNIL, since the designated DPO remains the single point of contact, but must be informed when the regulator raises processing inside the recused scope.
The question keeps returning because the person who understands a processing activity well enough to run it is usually the person an organisation wants reviewing it, and the CJEU in X-FAB Dresden left the compatibility test to be worked out case by case.
Original title: Délégué à la protection des données : identifier et gérer les conflits d’intérêts liés à la fonction de DPO
GDPR Articles 37 to 39, in particular Article 38(6)
- Who this binds
- Any organisation in France that has designated a DPO, internal, external or shared, and in particular those where the DPO also holds an operational or management role.
- What changed
- The CNIL now states that where a DPO holds decision making power over the purposes or means of processing in another role, the designating organisation is under an obligation to end the conflict rather than simply record it.
- What to check
- Check whether your DPO also sets retention periods, chooses security measures or rules on access to staff data in a second role, and whether any recusal arrangement gives a deputy real decision making power rather than a countersignature.
- What this does not mean
- This does not mean a part time or shared DPO is prohibited. The CNIL confirms other duties are permitted, and only bars those that undermine the DPO function or the independence attached to it.
Send this to your team
The CNIL has published guidance saying a DPO who decides the purposes or means of processing in another role is in a conflict of interest, and that the organisation must end that conflict by replacement, withdrawal of the other duties, or an effective recusal to a deputy DPO.