Article 39 GDPR: Duties of the Data Protection Officer (DPO)

Article 39 GDPR: Duties of the Data Protection Officer (DPO)

Article 39 of the GDPR Explained

The DPO is responsible for:

  • Informing and advising the data controller and employees on GDPR obligations;
  • Monitoring compliance with the regulation and internal policies;
  • Advising on the conduct of data protection impact assessments (DPIAs);
  • Cooperating with the French supervisory authority (or other supervisory authority);
  • Acting as the point of contact for the French supervisory authority and for data subjects.

They must act with independence and objectivity, while taking into account the company's activities.

Why This Article Matters for Your GDPR Compliance

The DPO is a key player in GDPR compliance. Through their defined responsibilities, they ensure the implementation of best practices and the legal security of the organisation. Their role is both operational, strategic, and educational.

How to comply with Article 39 of the GDPR?

  • Clarify the DPO's duties in their engagement letter or contract;
  • Provide them with the means to carry out their duties (time, budget, autonomy);
  • Facilitate cooperation with internal departments and with the French supervisory authority;
  • Document the actions taken as part of their duties.

Examples of Application of GDPR Article 39

  • A DPO regularly trains employees on data protection;
  • They monitor the record of processing activities and internal procedures;
  • They assist an HR department with a data protection impact assessment related to employee monitoring.

Related Resources

Accelerate Your Compliance in a Few Clicks

With our all-in-one solution, you can easily accelerate and ensure your compliance:

  • Automate your compliance with our GDPR software
  • Supported or outsourced by our DPO experts
  • Raise your teams' awareness with our GDPR training e-learning

Request a demo with an expert

Assess your situation in 15 minutes with our free, no-obligation GDPR self-assessment.

GDPR: Self-assess now