Source: OJ L 119, 4.5.2016, pp. 1–88 · Consolidated textCurrent language: SV
- General data protection
Basic legislative acts
- GDPR regulation
Artikel 39 Dataskyddsombudets uppgifter
Summary What does Article 39 of the GDPR regulation say?
This article sets out the minimum tasks assigned to the data protection officer (DPO), a role established under Article 37.
It covers the full range of the DPO's responsibilities, from internal advisory and compliance monitoring functions to external engagement with supervisory authorities.
The article also establishes a risk-based approach to how the DPO must carry out these duties, requiring them to factor in the nature, scope, context, and purposes of processing operations.
Important points:
- The DPO is required to inform and advise the controller, processor, and relevant employees of their obligations under the GDPR and other applicable data protection provisions.
- The DPO must monitor compliance, including through awareness-raising, staff training, and audits, and act as the contact point for the supervisory authority.
- The DPO must perform all tasks with due regard to the risk associated with processing operations.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
Dataskyddsombudet ska ha minst följande uppgifter:
Att informera och ge råd till den personuppgiftsansvarige eller personuppgiftsbiträdet och de anställda som behandlar om deras skyldigheter enligt denna förordning och andra av unionens eller medlemsstaternas dataskyddsbestämmelser.
Att övervaka efterlevnaden av denna förordning, av andra av unionens eller medlemsstaternas dataskyddsbestämmelser och av den personuppgiftsansvariges eller personuppgiftsbiträdets strategi för skydd av personuppgifter, inbegripet ansvarstilldelning, information till och utbildning av personal som deltar i behandling och tillhörande granskning.
Att på begäran ge råd vad gäller konsekvensbedömningen avseende dataskydd och övervaka genomförandet av den enligt artikel 35.
Att samarbeta med tillsynsmyndigheten.
Att fungera som kontaktpunkt för tillsynsmyndigheten i frågor som rör behandling, inbegripet det förhandssamråd som avses i artikel 36, och vid behov samråda i alla andra frågor.
Dataskyddsombudet ska vid utförandet av sina uppgifter ta vederbörlig hänsyn till de risker som är förknippade med behandling, med beaktande av behandlingens art, omfattning, sammanhang och syften.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
tillsynsmyndighet
(En. supervisory authority)
Definition
personuppgifter
(En. personal data)
Definition
behandling
(En. processing)