Imagine your organization processes personal data falling under the PDA. This might be because your organization employs enforcement officers who perform law enforcement tasks such as municipal enforcement, parking attendants, truancy officers, forest rangers, and environmental officers. In such cases, you’re obliged under the PDA to appoint a DPO. If you’ve already appointed a DPO for personal data processing under the GDPR, you don’t need a separate DPO specifically for the PDA, as the GDPR-DPO is also responsible for personal data processing under the PDA.
Note: The appointed DPO must be knowledgeable about both legislations, the GDPR and the PDA. If not, you might choose to appoint an additional PDA-DPO (ensure that the original DPO notification is supplemented, retaining a single DPO number for both roles).
The PDA stipulates this requirement more stringently than the GDPR. According to Article 36(4) of the PDA, the PDA-DPO must annually submit a written report of their findings regarding PDA compliance. While a similar written report isn’t mandatory under the GDPR, it’s commonly observed in practice that the DPO delivers an annual report.
Under the GDPR, the DPO has job protection, meaning they “shall not be dismissed or penalized for performing their tasks” (Article 38 of the GDPR). The PDA-DPO doesn’t enjoy this job protection, as the PDA doesn’t address it.
However, this doesn’t mean the GDPR-DPO can’t be dismissed altogether, as this is possible if other reasons exist beyond performing their tasks as a DPO. Examples might include theft, harassment, or similar serious misconduct.
Under the GDPR, organizations sometimes have an obligation to conduct Data Protection Impact Assessments (DPIAs). This process assesses the privacy risks of planned data processing and determines measures to mitigate those risks. The GDPR-DPO has an advisory function in this process (Article 39 of the GDPR).
The PDA often involves processing special (leaning towards criminal) personal data. In such cases, a DPIA is almost always required. Similarly, the PDA-DPO has an advisory role in this process, as stated in Article 36 of the PDA.
All organizations with enforcement officers must conduct a mandatory external PDA audit every four years. Additionally, these organizations must carry out a mandatory internal PDA audit annually. However, the GDPR or PDA-DPO cannot conduct this internal audit. The DPO oversees PDA compliance within their organization. They also supervise compliance with the audit obligation and the quality of the audits as part of their responsibilities. Conducting audits themselves would conflict with this role.
The NOREA guideline for the PDA (in norm 31) specifies the precise areas the PDA-DPO should oversee, as stipulated by the supervisory authority. This can serve as a helpful guideline for the PDA-DPO. According to the guideline, the DPO should oversee:
The PDA often involves processing special (leaning towards criminal) personal data. In such cases, a DPIA is almost always required. Similarly, the PDA-DPO has an advisory role in this process, as stated in Article 36 of the PDA.
Get in touch with Steven Kant.
Senior Consultant