What is the role of a DPO?

Linkedin logo
Publié le 15/03/2024  |  Actualisé le 20/08/2024

In the digital age, where personal data has become the new black gold, a new figure is emerging within companies: the Data Protection Officer (DPO ).

In this article, delve into the heart of the DPO’s job, a role as strategic as it is indispensable, and discover how it orchestrates the security of personal data.

The Data Protection Officer (Délégué à la Protection des Données ) is a recent profession which covers several activities and has a transversal role within a company. Its role is to have a complete overview of personal data processing within a company. The challenge, of course, is to control the risks associated with such processing, and to educate everyone involved (project managers, consultants, etc.) in good data protection and confidentiality practices.

But what does the DPO actually do?

It all starts with an understanding of the company’s organization and the specifics of each business line. HR and finance departments do not handle the same data. As for IT services, they are essential to the smooth running of our teams, manage a considerable amount of data.

Mapping personal data processing

To obtain an exhaustive overview of processing operations, the DPO draws up a map of personal data processing operations.


As I regularly remind you, all you need to process personal data is a first and last name, or just an e-mail address.


For a company like SQORUS, personal data processing is identified for all cross-functional functions (HR, Marketing, Administrative…), but also within each consultant division. Personal data is processed as part of fixed-price projects and Application Management. But it is also essential to identify the personal data processing operations carried out by third-party consultants on behalf of their customers.

    Risk control and crisis management

    This mapping is important for several reasons:

    Firstly, it identifies the risk associated with each treatment. For example, the risk is rather low when processing is carried out directly on a customer’s computer, within its own secure systems, with no possibility of transferring data to a third-party system.

    However, when sensitive data is processed, or when it is necessary to transfer data to a third-party system for processing, it is crucial to secure the processing of sensitive data. An action plan must then be put in place to secure all stages, both organizationally and technically. It’s at times like these that the interweaving of personal data processing and cybersecurity comes into sharp focus. The DPO is the CISO ‘s partner in securing information and data.

    Secondly, this mapping is very important for crisis management, in the event of a cyber attack or data breach. As we can see, solid, certified companies are under attack. If, during an attack, we identify a vulnerability that has corrupted one of our personal data processing operations, we must contact the data controller as soon as possible.

    In the mapping, we therefore also need to include the crisis contact for each processing operation, and keep in mind the contractual and regulatory deadlines for declaring the data breach to the CNIL and/or filing a complaint.

    Impact analysis and risk management

    As the company evolves and so do its tools, we process personal data in our internal projects. GDPR compliance is an integral part of benchmarking when choosing a new application or partner.

    Upstream, it is important to carry out an impact analysis, or AIPD. During this analysis, we need to check the security of the software (authentication, data retention, etc.), the tool’s certifications, the purpose of each processing operation we wish to implement, etc. The depth of the analysis obviously depends on the complexity of the internal project.

    Training and support for GDPR compliance

    Another role of the DPO is to ensure that all employees are trained in the issues surrounding the processing of personal data. This training is provided in a number of ways: through access to mandatory e-learning training, and through one-off training sessions on compliance news, to explain the latest CNIL sanctions and the impact of new regulations on day-to-day work.

    On the contractual side, the role of the DPO is to support the company in rereading the GDPR aspects, but also to provide support so that each player completes the annexes dedicated to the subject. The Data Protection Officer has a good overview of the contractual, regulatory and operational aspects. It’s a key element in risk management in three ways.

    Cyber security awareness

    Finally, the role of the DPO is to emphasize the importance of good cybersecurity practices.
    Indeed, effective protection of personal data cannot be dissociated from a global security policy.

    Cybersecurity rests on three fundamental pillars: people, software and hardware.
    At the heart of this triad, the human element is the first line of defense.

    It’s crucial to adopt a cautious attitude, especially to thwart phishing and phishing attempts, which represent the most common threats.
    It is also imperative to install software protections such as virtual private networks (VPNs) and antivirus software, not forgetting to carry out the necessary updates on a regular basis.
    Finally, vigilance regarding hardware is essential: it should be secured when not in use, and reliable, secure Wi-Fi connections should be preferred.
    It is important to stress that these measures, while essential, do not constitute an exhaustive list of actions to be taken to guarantee optimum IT security.

    How do you become a DPO?

    According to the latest AFCDP barometer, 53% of DPOs come from a legal or IT background. The remaining 47% come from administrative and financial functions, quality or compliance-audit.
    Rigor is essential in this role. Nevertheless, it’s essential to recognize that every career path is unique and has its own strengths to build on.

    Conclusion on the role of a DPO

    As you can see, the Data Protection Officer must have a good knowledge of the company’s various departments.
    He or she must understand the challenges and processes of each department, and be able to work closely with the company’s senior management. Its recommendations will have an impact on the organization’s overall strategy.

    The DPO ‘s versatility doesn’t stop there.
    He or she must also have a thorough knowledge of data protection legislation, and be able to understand and interpret laws and regulations and apply them to the company.

    Finally, the DPO must have project management skills. He or she must be able to plan and manage the company’s data protection initiatives, monitor their progress and ensure that they are carried out successfully.
    He or she must also be able to manage data security incidents and coordinate the company’s response.
    .

    All about IT project governance

    Discover the roles and responsibilities of key profiles, as well as best practices in governance and technological development, to ensure the success of your digital transformation projects.

    Also in our “IT project governance” issue

     

    Contact

    A project? A request?A question?

    Contact us today and find out how we can work together to make your company’s digital future a reality.

    Consultant expert IT SQORUS

    Consultant expert IT SQORUS

    Articles complémentaires

    Parcours - Onboarding SQORUS

    Pour ne rien rater, inscrivez-vous à notre newsletter !

    Notre mission

    Découvrez les forces de la stratégie SQORUS

    Nous avons su nous adapter aux nouveaux enjeux digitaux, à l’arrivée du Cloud et aux évolutions des modes de travail. Nous avons réussi à tisser des partenariats forts avec les principaux éditeurs du marché et à attirer des experts métiers et techniques.

    Notre force : nos plus de 350 talents dédiés à la réussite de vos projets et partageant des valeurs fortes : la diversité, l’engagement et la solidarité, qui constituent une réelle valeur pour l’entreprise et ses clients.

    Great Place to Work depuis 11 années consécutives, SQORUS est sensible à l’épanouissement de ses Sqorusien.ne.s, à leur évolution de carrière et à leur formation sur des solutions d’avenir.

    SQORUS est un cabinet spécialisé dans la transformation digitale et métiers des fonctions RH, Finance et IT. Nos consultants interviennent depuis plus de 35 ans auprès de grandes entreprises sur des projets stratégiques, à dimension internationale, autour des systèmes d’information : stratégie d’évolution, aide au choix, intégration, Business Intelligence, Data Management, support et conduite du changement, mais également sur des enjeux autour du Cloud et de l’Intelligence Artificielle.