Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: SV

Artikel 39 Dataskyddsombudets uppgifter


Summary What does Article 39 of the GDPR regulation say?

This article sets out the minimum tasks assigned to the data protection officer (DPO), a role established under Article 37.

It covers the full range of the DPO's responsibilities, from internal advisory and compliance monitoring functions to external engagement with supervisory authorities.

The article also establishes a risk-based approach to how the DPO must carry out these duties, requiring them to factor in the nature, scope, context, and purposes of processing operations.

Important points:

  • The DPO is required to inform and advise the controller, processor, and relevant employees of their obligations under the GDPR and other applicable data protection provisions.
  • The DPO must monitor compliance, including through awareness-raising, staff training, and audits, and act as the contact point for the supervisory authority.
  • The DPO must perform all tasks with due regard to the risk associated with processing operations.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Dataskyddsombudet ska ha minst följande uppgifter:

      1. Att informera och ge råd till den personuppgiftsansvarige eller personuppgiftsbiträdet och de anställda som behandlar om deras skyldigheter enligt denna förordning och andra av unionens eller medlemsstaternas dataskyddsbestämmelser.

      2. Att övervaka efterlevnaden av denna förordning, av andra av unionens eller medlemsstaternas dataskyddsbestämmelser och av den personuppgiftsansvariges eller personuppgiftsbiträdets strategi för skydd av personuppgifter, inbegripet ansvarstilldelning, information till och utbildning av personal som deltar i behandling och tillhörande granskning.

      3. Att på begäran ge råd vad gäller konsekvensbedömningen avseende dataskydd och övervaka genomförandet av den enligt artikel 35.

      4. Att samarbeta med tillsynsmyndigheten.

      5. Att fungera som kontaktpunkt för tillsynsmyndigheten i frågor som rör behandling, inbegripet det förhandssamråd som avses i artikel 36, och vid behov samråda i alla andra frågor.

    1. Dataskyddsombudet ska vid utförandet av sina uppgifter ta vederbörlig hänsyn till de risker som är förknippade med behandling, med beaktande av behandlingens art, omfattning, sammanhang och syften.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod