GDPR
Chapter IV - Controller and Processor

GDPR GDPR-Art.39: Tasks of the data protection officer

The data protection officer must at least inform and advise the controller or processor and the employees who carry out processing of their obligations under the Regulation and other Union or Member State data protection provisions; monitor compliance with those provisions and with the controller's or processor's own data protection policies, including the assignment of responsibilities, awareness raising, the training of staff involved in processing operations, and the related audits; provide advice where requested on the data protection impact assessment and monitor its performance under Article 35; cooperate with the supervisory authority; and act as the contact point for the supervisory authority on processing issues including the Article 36 prior consultation, consulting on any other matter where appropriate. In performing these tasks the officer must have due regard to the risk associated with the processing operations, taking account of their nature, scope, context and purposes.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 17 controls across 13 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 3 controls

ISO 27701:2019 · 2 controls

  • AUCDR-IS-6 Information security training and awareness program
  • PIPL-Art52 Designation of a DPO
  • CCM-HRS-12 Personal and Sensitive Data Awareness and Training
  • EGY-PDPL-Art.9 Data Protection Officer obligations
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • s7 s 7 Give the data protection officer at least the statutory tasks and avoid conflicts
  • 5.9 5.9 Train those who process personal data
  • CIA-EDU-19 Training of employees and officers
  • ZDPA-19 Awareness and Training

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter IV - Controller and Processor

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.39 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 17 it maps to, and the evidence behind each claim, over MCP and REST.