GDPR
Chapter IV - Controller and Processor

GDPR GDPR-Art.39: Tasks of the data protection officer

The data protection officer must at least inform and advise the controller or processor and the employees who carry out processing of their obligations under the Regulation and other Union or Member State data protection provisions; monitor compliance with those provisions and with the controller's or processor's own data protection policies, including the assignment of responsibilities, awareness raising, the training of staff involved in processing operations, and the related audits; provide advice where requested on the data protection impact assessment and monitor its performance under Article 35; cooperate with the supervisory authority; and act as the contact point for the supervisory authority on processing issues including the Article 36 prior consultation, consulting on any other matter where appropriate. In performing these tasks the officer must have due regard to the risk associated with the processing operations, taking account of their nature, scope, context and purposes.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 15 controls across 11 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 3 controls

  • NIST800-AT-3 Role-based training
  • NIST800-PM-14 Testing, Training, and Monitoring. Implement a process for ensuring that organizational plans for conducting security and privacy testing, training, and monitoring activities associated with organizational systems: Are developed and maintained; and Continue to be
  • NIST800-PM-18 Privacy Program Plan. Develop and disseminate an organization-wide privacy program plan that provides an overview of the agency's privacy program, and: Includes a description of the structure of the privacy program and the resources

ISO 27701:2019 · 2 controls

  • AUCDR-IS-6 Information security training and awareness program
  • CCM-HRS-12 Personal and Sensitive Data Awareness and Training

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter IV - Controller and Processor

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.39 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 40 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 15 it maps to, and the evidence behind each claim, over MCP and REST.