GDPR
Chapter IV - Controller and Processor

GDPR GDPR-Art.37: Designation of the data protection officer

Designate a data protection officer where the processing is carried out by a public authority or body, except for courts acting in their judicial capacity, where the core activities consist of processing operations which by their nature, scope or purposes require regular and systematic monitoring of data subjects on a large scale, or where the core activities consist of processing on a large scale of special category data or of personal data relating to criminal convictions and offences. A group of undertakings may appoint a single data protection officer provided that officer is easily accessible from each establishment. Designate on the basis of professional qualities, in particular expert knowledge of data protection law and practice and the ability to fulfil the Article 39 tasks. The officer may be a staff member or fulfil the tasks under a service contract. Publish the officer's contact details and communicate them to the supervisory authority.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 24 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 3 controls

  • 5.3.3 Organizational roles, responsibilities and authorities
  • 5.5.2 Competence
  • 6.3.1 Internal organization
  • s38 s 38 Private bodies designate a data protection officer at 20 persons, or regardless of size for high-risk processing
  • s5 s 5 Public bodies designate a qualified data protection officer and publish the contact details

Bahrain PDPL · 1 control

  • BB-DPA-21 Sections 61-69 - Data Privacy Officer
  • PIPL-Art52 Designation of a DPO
  • EGY-PDPL-Art.8 Appointment of the Data Protection Officer
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • GOV-PO Privacy officer and accountability
  • RO-LAW190-006 Designation and Notification of the Data Protection Officer
  • CIA-OFF-03 Credit information management and protection officer
  • ZDPA-03 Appointment of Data Protection Officer

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter IV - Controller and Processor

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.37 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 24 it maps to, and the evidence behind each claim, over MCP and REST.