Source: OJ L 119, 4.5.2016, pp. 1–88 · Consolidated textCurrent language: SV
- General data protection
Basic legislative acts
- GDPR regulation
Artikel 38 Dataskyddsombudets ställning
Summary What does Article 38 of the GDPR regulation say?
This article sets out the conditions under which a Data Protection Officer (DPO) must operate once appointed — building directly on Article 37, which establishes when a DPO must be designated.
The focus here is on protecting the DPO's independence and effectiveness: controllers and processors must involve the DPO in all relevant matters, give them the resources they need, and crucially, shield them from instructions or penalties that could compromise their role.
The article also addresses the DPO's relationship with data subjects, their obligation of secrecy, and the management of potential conflicts of interest if they hold additional duties.
Important points:
- Ensure your DPO is involved in all personal data protection matters in a timely manner, is properly resourced, and reports directly to the highest management level.
- The DPO must not receive instructions on how to perform their tasks and cannot be dismissed or penalised for carrying them out.
- If the DPO holds other roles or duties, controllers and processors must ensure no conflict of interests arises.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
Den personuppgiftsansvarige och personuppgiftsbiträdet ska säkerställa att dataskyddsombudet på ett korrekt sätt och i god tid deltar i alla frågor som rör skyddet av personuppgifter.
Den personuppgiftsansvarige och personuppgiftsbiträdet ska stödja dataskyddsombudet i utförandet av de uppgifter som avses i artikel 39 genom att tillhandahålla de resurser som krävs för att fullgöra dessa uppgifter samt tillgång till personuppgifter och behandlingsförfaranden, samt i upprätthållandet av dennes sakkunskap.
- ▼C1ModificationCorrectedParagraph 3 corrected by a corrigendum to Regulation (EU) 2016/679. Published in the Official Journal 23 May 2018.
Den personuppgiftsansvarige och personuppgiftsbiträdet ska säkerställa att dataskyddsombudet inte tar emot instruktioner som gäller utförandet av dessa uppgifter. Han eller hon får inte avsättas eller bli föremål för sanktioner av den personuppgiftsansvarige eller personuppgiftsbiträdet för att ha utfört sina uppgifter. Dataskyddsombudet ska rapportera direkt till den personuppgiftsansvariges eller personuppgiftsbiträdets högsta förvaltningsnivå.
Den registrerade får kontakta dataskyddsombudet med avseende på alla frågor som rör behandlingen av dennes personuppgifter och utövandet av dennes rättigheter enligt denna förordning.
Dataskyddsombudet ska, när det gäller dennes genomförande av sina uppgifter, vara bundet av sekretess eller konfidentialitet i enlighet med unionsrätten eller medlemsstaternas nationella rätt.
Dataskyddsombudet får fullgöra andra uppgifter och uppdrag. Den personuppgiftsansvarige eller personuppgiftsbiträdet ska se till att sådana uppgifter och uppdrag inte leder till en intressekonflikt.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
personuppgifter
(En. personal data)
Definition
behandling
(En. processing)