9.2.1—9.2.1
>Control Description
+ A data protection officer is appointed, if required by Art. 37 GDPR
- Determination of whether the appointment of a data protection officer is voluntary or mandatory
- otherwise determination of a data protection function or comparable
+ Publication of contact details (e.g. on the Internet)
+ Integration into the organization's structure
+ Exercise of the control obligations as defined in Art. 39 (1) (b) GDPR and corresponding documentation
+ Documentation of the data protection status and report to organization's top management
+ Equipped with sufficient capacities and resources
- Determination of whether the data protection function is full-time or part-time
- adequate professional qualification
- regular professional training
- access to specialist literature
- support of the data protection officer by data protection coordinators in the companies organizational units, depending on the company size (e.g. marketing, sales, personnel, logistics, development, etc.)
>Cross-Framework Mappings
Ask AI
Configure your API key to use AI features.