Who can be Data Controller and Data Protection Officer in the small organisation?

Lanacosmo

Free Member
Aug 25, 2015
59
2
Hello everyone,

I am in the process of registering our company (less than 250 employees) with ICO under GDPR and would like to clarify who should be a data controller? HR Manager or a directors owners of the business

Data protection officer can be someone from HR ?

Thank you very much
 

fisicx

Moderator
Sep 12, 2006
46,680
8
15,376
Aldershot
www.aerin.co.uk
  • Like
Reactions: Lanacosmo
Upvote 0

Alan

Free Member
  • Aug 16, 2011
    7,089
    1,974
    The DPO generally is only required where personal data is systematically processed in a 'large scale'. Large scale is not defined, but there is some guidance which an example of large scale is all the patients handled by a hospital - and not large is all the patients of a single physician.

    I guess if you are in between, like a surgery of 4 doctors, you are in that GDPR unproven grey area :) and judgement calls are required.
     
    Upvote 0

    Ozzy

    Founder of UKBF
    UKBF Staff
  • Feb 9, 2003
    8,322
    11
    3,439
    Northampton, UK
    bdgroup.co.uk
    Something that also gets missed is that you must appoint a senior member of staff, or director, who is responsible for Data Protection but the role of "Data Protection Officer" is a defined role in the legislation that has specific legal responsibility. You do not always need to appoint a DPO, so as a small business if you don't process large scale data then you don't need to appoint that specific role and a Data Protection Manager will be sufficient.

    A lot of hype as been created over GDPR and in reality it just boils down to be diligence and sensible, nothing has really changed that much since the original data protection act other than accountability. Just be sensible and accountable.
     
    Upvote 0

    Latest Articles