
In the second of a series of articles, Rollits LLP consider the role of data protection officers & the issues surrounding obtaining valid consent
- What the appointment of a data protection officer means in practice.
- When is it appropriate to rely on consent as a lawful basis for processing personal data?
In the first part in this series on the General Data Protection Regulation (GDPR), we considered why current data protection legislation needed updating and provided an overview of the key provisions under the GDPR (see ‘Mind the GDPR’, NLJ , 22 September 2017, p 8). Our focus now turns to two key action points organisations will need to consider early on in their preparations for the GDPR: (1) the appointment of a Data Protection Officer (DPO) and what that means in practice; and (2) when it is appropriate to rely on consent as a lawful basis for processing personal data.
Appointment of a DPO
Under the GDPR, both controllers and processors are under an obligation to appoint a DPO where:
- the processing is carried