Article 37
Designation of the data protection officer
(49) Whereas, in order to avoid unsuitable administrative formalities, exemptions from the obligation to notify and simplification of the notification required may be provided for by Member States in cases where processing is unlikely adversely to affect the rights and freedoms of data subjects, provided that it is in accordance with a measure taken by a Member State specifying its limits; whereas exemption or simplification may similarly be provided for by Member States where a person appointed by the controller ensures that the processing carried out is not likely adversely to affect the rights and freedoms of data subjects; whereas such a data protection official, whether or not an employee of the controller, must be in a position to exercise his functions in complete independence;
(54) Whereas with regard to all the processing undertaken in society, the amount posing such specific risks should be very limited; whereas Member States must provide that the supervisory authority, or the data protection official in cooperation with the authority, check such processing prior to it being carried out; whereas following this prior check, the supervisory authority may, according to its national law, give an opinion or an authorization regarding the processing; whereas such checking may equally take place in the course of the preparation either of a measure of the national parliament or of a measure based on such a legislative measure, which defines the nature of the processing and lays down appropriate safeguards;
|
Regulation
Art. 37 1. The controller and the processor shall designate a data protection officer in any case where: a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; b) the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or c) the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 and personal data relating to criminal convictions and offences referred to in Article 10. 2. A group of undertakings may appoint a single data protection officer provided that a data protection officer is easily accessible from each establishment. 3. Where the controller or the processor is a public authority or body, a single data protection officer may be designated for several such authorities or bodies, taking account of their organisational structure and size. 4. In cases other than those referred to in paragraph 1, the controller or processor or associations and other bodies representing categories of controllers or processors may or, where required by Union or Member State law shall, designate a data protection officer. The data protection officer may act for such associations and other bodies representing controllers or processors. 5. The data protection officer shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39. 6. The data protection officer may be a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract. 7. The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority.
|
Directive
Art. 18 (...) 2. Member States may provide for the simplification of or exemption from notification only in the following cases and under the following conditions: - where, for categories of processing operations which are unlikely, taking account of the data to be processed, to affect adversely the rights and freedoms of data subjects, they specify the purposes of the processing, the data or categories of data undergoing processing, the category or categories of data subject, the recipients or categories of recipient to whom the data are to be disclosed and the length of time the data are to be stored, and/or - where the controller, in compliance with the national law which governs him, appoints a personal data protection official, responsible in particular: - for ensuring in an independent manner the internal application of the national provisions taken pursuant to this Directive - for keeping the register of processing operations carried out by the controller, containing the items of information referred to in Article 21 (2), thereby ensuring that the rights and freedoms of the data subjects are unlikely to be adversely affected by the processing operations. |
Ireland
|
Spain
Artículo 34. Designación de un delegado de protección de datos. 1. Los responsables y encargados del tratamiento deberán designar un delegado de protección de datos en los supuestos previstos en el artículo 37.1 del Reglamento (UE) 2016/679 y, en todo caso, cuando se trate de las siguientes entidades: a) Los colegios profesionales y sus consejos generales. b) Los centros docentes que ofrezcan enseñanzas en cualquiera de los niveles establecidos en la legislación reguladora del derecho a la educación, así como las Universidades públicas y privadas. c) Las entidades que exploten redes y presten servicios de comunicaciones electrónicas conforme a lo dispuesto en su legislación específica, cuando traten habitual y sistemáticamente datos personales a gran escala. d) Los prestadores de servicios de la sociedad de la información cuando elaboren a gran escala perfiles de los usuarios del servicio. e) Las entidades incluidas en el artículo 1 de la Ley 10/2014, de 26 de junio, de ordenación, supervisión y solvencia de entidades de crédito. f) Los establecimientos financieros de crédito. g) Las entidades aseguradoras y reaseguradoras. h) Las empresas de servicios de inversión, reguladas por la legislación del Mercado de Valores. i) Los distribuidores y comercializadores de energía eléctrica y los distribuidores y comercializadores de gas natural. j) Las entidades responsables de ficheros comunes para la evaluación de la solvencia patrimonial y crédito o de los ficheros comunes para la gestión y prevención del fraude, incluyendo a los responsables de los ficheros regulados por la legislación de prevención del blanqueo de capitales y de la financiación del terrorismo. k) Las entidades que desarrollen actividades de publicidad y prospección comercial, incluyendo las de investigación comercial y de mercados, cuando lleven a cabo tratamientos basados en las preferencias de los afectados o realicen actividades que impliquen la elaboración de perfiles de los mismos. l) Los centros sanitarios legalmente obligados al mantenimiento de las historias clínicas de los pacientes. Se exceptúan los profesionales de la salud que, aun estando legalmente obligados al mantenimiento de las historias clínicas de los pacientes, ejerzan su actividad a título individual. m) Las entidades que tengan como uno de sus objetos la emisión de informes comerciales que puedan referirse a personas físicas. n) Los operadores que desarrollen la actividad de juego a través de canales electrónicos, informáticos, telemáticos e interactivos, conforme a la normativa de regulación del juego. ñ) Las empresas de seguridad privada. o) Las federaciones deportivas cuando traten datos de menores de edad. 2. Los responsables o encargados del tratamiento no incluidos en el párrafo anterior podrán designar de manera voluntaria un delegado de protección de datos, que quedará sometido al régimen establecido en el Reglamento (UE) 2016/679 y en la presente ley orgánica. 3. Los responsables y encargados del tratamiento comunicarán en el plazo de diez días a la Agencia Española de Protección de Datos o, en su caso, a las autoridades autonómicas de protección de datos, las designaciones, nombramientos y ceses de los delegados de protección de datos tanto en los supuestos en que se encuentren obligadas a su designación como en el caso en que sea voluntaria. 4. La Agencia Española de Protección de Datos y las autoridades autonómicas de protección de datos mantendrán, en el ámbito de sus respectivas competencias, una lista actualizada de delegados de protección de datos que será accesible por medios electrónicos. 5. En el cumplimiento de las obligaciones de este artículo los responsables y encargados del tratamiento podrán establecer la dedicación completa o a tiempo parcial del delegado, entre otros criterios, en función del volumen de los tratamientos, la categoría especial de los datos tratados o de los riesgos para los derechos o libertades de los interesados. Artículo 35. Cualificación del delegado de protección de datos. El cumplimiento de los requisitos establecidos en el artículo 37.5 del Reglamento (UE) 2016/679 para la designación del delegado de protección de datos, sea persona física o jurídica, podrá demostrarse, entre otros medios, a través de mecanismos voluntarios de certificación que tendrán particularmente en cuenta la obtención de una titulación universitaria que acredite conocimientos especializados en el derecho y la práctica en materia de protección de datos. --- Article 34.- Appointment of a data protection officer. 1. Controllers and processors shall appoint a data protection officer in the cases provided for in Article 37.1 of Regulation (EU) 2016/679 and, in any case, in the case of the following entities: a) Professional associations and their general councils. b) Schools offering education at any of the levels established in the legislation regulating the right to education, as well as public and private universities. c) Entities operating electronic communications networks and providing electronic communications services in accordance with the provisions of their specific legislation, when they routinely and systematically process personal data on a large scale. d) Providers of information society services when they elaborate large-scale profiles of service users. e) The entities included in Article 1 of Law 10/2014, of June 26, on the regulation, supervision and solvency of credit institutions. f) Financial credit institutions. g) Insurance and reinsurance companies. h) Investment services companies, regulated by the Securities Market legislation. i) Electric power distributors and marketers and natural gas distributors and marketers. j) The entities responsible for common files for the evaluation of solvency and creditworthiness or common files for the management and prevention of fraud, including those responsible for the files regulated by the legislation for the prevention of money laundering and the financing of terrorism. k) Entities that carry out advertising and commercial prospecting activities, including commercial and market research activities, when they conduct processing based on the preferences of the data subjects or perform activities involving profiling of the data subjects. I) Health centers legally obliged to keep patients' medical records. Exceptions are health professionals who, although legally obliged to keep patients' medical records, carry out their activity on an individual basis. m) The entities that have as one of their objects the issuance of commercial reports that may refer to natural persons. n) Operators that develop the gaming activity through electronic, computerized, telematic and interactive channels, in accordance with the gaming regulation regulations. ñ) Private security companies. o) Sports federations when processing data of minors. 2. Data controllers or processors not included in the preceding paragraph may voluntarily appoint a data protection officer, who shall be subject to the regime established in Regulation (EU) 2016/679 and in this Organic Law. 3. Data controllers and data processors shall communicate within ten days to the Spanish Data Protection Agency or, as the case may be, to the regional data protection authorities, the designations, appointments and dismissals of the data protection officers both in the cases in which they are obliged to designate them and in the case in which their designation is voluntary. 4. The Spanish Data Protection Agency and the regional data protection authorities will maintain, within the scope of their respective competences, an updated list of data protection officers, which will be accessible by electronic means. 5. In fulfilling the obligations of this article, controllers and processors may establish the full or part-time dedication of the delegate, among other criteria, depending on the volume of processing, the special category of data processed or the risks to the rights or freedoms of data subjects. Article 35. Qualification of the data protection officer. Compliance with the requirements set forth in Article 37.5 of Regulation (EU) 2016/679 for the appointment of the data protection officer, whether a natural or legal person, may be demonstrated, among other means, through voluntary certification mechanisms that shall take particular account of obtaining a university degree attesting to specialized knowledge in data protection law and practice. |
