Identifying and Managing Conflicts of Interest Related to the Role of Data Protection Officer

The National Commission on Informatics and Liberty (CNIL) has published recommendations aimed at identifying and managing conflicts of interest that may arise when the Data Protection Officer (DPO) performs other tasks.

The GDPR allows a DPO to perform tasks other than those provided for in Article 39, provided that these do not create a conflict of interest. Such a conflict arises if the DPO determines the purposes and means of processing within the scope of their other functions, placing them in a "judge and party" situation. The CNIL recommends a case-by-case analysis before appointment, notably examining whether the DPO holds a senior management position, has decision-making power over processing, or holds a staff representative mandate. For an external DPO, the risk may come from a past representation of the organization in a dispute or an appointment by entities with opposing interests, such as a controller and its processor.

When a conflict of interest is identified, the organization must put an end to it, either by replacing the DPO, removing the conflicting tasks, or through remediation measures. One solution is to organize the DPO's recusal from the scope of the conflict and to appoint a "deputy DPO" who is not subordinate and who will benefit from the guarantees of Articles 37 to 39 of the GDPR without being declared to the CNIL. For an external legal entity DPO, the conflict can be managed by assigning tasks to distinct collaborators. Any solution must be effective and documented, specifying the distribution of responsibilities.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire