100% found this document useful (1 vote)
207 views8 pages

DPO Requirements Across Countries

The document provides information on data protection officer requirements by country. It catalogs requirements for Bermuda, Brazil, Canada, China, Colombia, and Egypt. The requirements include terminology used for the role, scope of organizations covered, tasks of the officer, structure and support for the role, required training or expertise, and whether registration with the local data protection authority is necessary. For example, in Brazil the role is called a DPO and has responsibilities like receiving complaints, communicating with the data protection authority, and educating staff on data protection practices. In most countries covered, the officer reports to senior management and requires relevant expertise.

Uploaded by

Chandrashekar M
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
100% found this document useful (1 vote)
207 views8 pages

DPO Requirements Across Countries

The document provides information on data protection officer requirements by country. It catalogs requirements for Bermuda, Brazil, Canada, China, Colombia, and Egypt. The requirements include terminology used for the role, scope of organizations covered, tasks of the officer, structure and support for the role, required training or expertise, and whether registration with the local data protection authority is necessary. For example, in Brazil the role is called a DPO and has responsibilities like receiving complaints, communicating with the data protection authority, and educating staff on data protection practices. In most countries covered, the officer reports to senior management and requires relevant expertise.

Uploaded by

Chandrashekar M
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
  • Bermuda
  • Data Protection Officer Requirements Overview
  • Colombia
  • China
  • EU Member States
  • Egypt
  • Mexico
  • New Zealand
  • Nigeria
  • Mauritius
  • Singapore
  • Russia
  • Philippines
  • Thailand
  • South Korea
  • South Africa
  • Ukraine
  • Uganda
  • United Kingdom
  • United States
  • Uruguay

Data Protection Officer

Requirements by Country

Increasingly, privacy and data protection laws around the world require organizations to designate a data protection officer to
translate legal protections into practical reality. This chart catalogues those requirements but does not include the many additional
instances in which a DPO is recommended but not required. If you are aware of additional material that should be included here,
please email the Westin Research Center at research@[Link].

Legal Training/ Registration/


instrument Terminology Scope Tasks Structure expertise notification
Bermuda Personal • Designate a • All organizations. • Take responsibility for compliance • Publish name of
Information representative with the act. privacy officer in
Protection Act (“privacy • Communicate with the commissioner. privacy notice.
officer”).
Part 2, Section 5
Brazil General Data • Appoint a DPO. • Controllers • Receive and respond to complaints. • Publish identity
Protection Law (could be • Communicate with the DPA. and contact
circumscribed by information.
Article 41 • Educate staff and contractors on
data protection
personal data protection practices.
authority rules).
• Conduct other duties as prescribed by
controller or set forth in DPA rules.
Canada Personal • Designate an • Covered entities. • Account for the organization’s
Information individual or compliance with act’s principles.
Protection individuals who • Handle complaints or inquiries from
and Electronic are account- individuals.
Documents Act able for the
organization’s
Schedule 1, 4.1
compliance.
Principle 1

International Association of Privacy Professionals  •  [Link] 1


Legal Training/ Registration/
instrument Terminology Scope Tasks Structure expertise notification
China Personal • Appoint a • Controllers. • Take responsibility for data • Report to the • Relevant
Information person and a protection. principal of management
Security department • Participate in important decisions on organization. experience.
Specification responsible data processing. • Resourced as • Data protection
for personal necessary. expertise.
11.1(b)(d–e) • Coordinate data security efforts.
information
protection. • Develop data protection plan.
• Develop/maintain data protection
policies and procedures.
• Maintain list of personal data
processed and access rights.
• Conduct data security assessment.
• Organize data security trainings.
• Conduct product testing to avoid
unknown personal data collection,
use, sharing and other processing.
• Handle complaints.
• Conduct security audits.
• Liaise with management and report
personal data incident handling.
Colombia Law 1581/2012 • Designate one • Controllers and • Assume the role of personal data • Include desig-
person or area processors. protection. nated person or
Decree 1377
to assume the • Handle data subjects’ requests. area responsible
Articles 13(4) role of personal for data protec-
& 23 data protection. Non-binding SIC guidance lays out tion in privacy
additional tasks: notice.
• Assist organizations implementing
policies and procedures to comply
with the data protection regulation.
• Monitor compliance and the data
protection program.
• Train staff and conduct internal audits.
• Serve as contact point for DPA.
• Submit information related to
processing operations to the
National Registry of Databases of the
Colombian DPA.

International Association of Privacy Professionals  •  [Link] 2


Legal Training/ Registration/
instrument Terminology Scope Tasks Structure expertise notification
Egypt Personal Data • Appoint a • Controllers and • Take charge of application of the law. • Competent • Register with
Protection Law competent processors. • Monitor compliance. employee of DPA.
employee to be entity.
Articles 8–9 • Receive and respond to data subject
responsible for
requests.
the protection
of personal data. • Evaluate personal data protection
systems, document results and issue
recommendations.
• Maintain personal data records.
• Take corrective actions for violations.
• Train staff.
• Implement security procedures.
• Liaise with DPA, notify DPA of infringe-
ments and implement decisions.
EU General Data • Designate a • Public authority • Inform and advise on data protection • Staff member or • Professional • Publish contact
member Protection DPO. or body process- requirements. contractor. qualities. information and
states (27) Regulation ing data, except communicate
• Monitor compliance. • Resourced to • Expert knowl-
courts. carry out tasks edge of data it to DPA (see
Articles 37–39 • Advise organization on data protec-
• Controllers or and maintain protection law how to do so by
tion impact assessments.
processors whose expertise. and practices. country).
• Cooperate with DPA.
core activities • Report to high- • Ability to fulfill
require regular • Serve as contact for individuals
est management legally man-
and systematic and DPA.
level. dated tasks.
monitoring of
• No instructions
data subjects on
or dismissal with
a large scale.
regard to tasks.
• Controllers or
• Bound by
processors whose
confidentiality.
core activities
include processing
on a large scale of
special categories
of data.
• Where required
by EU member
state law.

International Association of Privacy Professionals  •  [Link] 3


Legal Training/ Registration/
instrument Terminology Scope Tasks Structure expertise notification
Mauritius Data Protection • Designate • Controllers. • Take responsibility for data protection • Inform data
Act an officer compliance. subject of DPO
responsible for identity at time
Section 22(2)(e)
data protection of collection.
compliance. • Maintain DPO
contact details
in record of
processing.
Mexico Federal Law on • Designate a • Controllers. • Process requests from data subjects.
Protection of personal data • Promote data protection within the
Personal Data person or organization.
Held by Private department.
Parties
Article 30
New Privacy Act • Appoint as • Covered entities. • Handle individual requests. • Staff member or
Zealand privacy officers • Liaise with DPA on investigations. contractor.
Part 9 Section 201
for the agency
• Ensure compliance with the act.
one or more
individuals.
Nigeria Data Protection • Designate a • Controllers. • Ensure adherence to the regulation. • Staff member or • Requires • Provide contact
Regulation DPO. • Follow the controller’s data protec- contracted firm continuous information
tion directives. or individual. capacity building to data sub-
Section 3.1.2
for DPOs and jects prior to
personnel collection.
involved in data
processing.
Philippines Data Privacy Act • Designate an • Controllers. • Account for the organization’s • One or more • Make identity
individual or compliance with the act. individuals. of designated
Section 21(b)
individuals who individual(s)
are account- available to data
able for the subject upon
organization’s request.
compliance. • Register with
DPA.

International Association of Privacy Professionals  •  [Link] 4


Legal Training/ Registration/
instrument Terminology Scope Tasks Structure expertise notification
Russia Data Protection • Appoint • Operator, which • Organize the processing of • Accountable
Act a person is a legal entity. personal data. to operator’s
responsible for • Exercise internal control over com- executive body.
Section 22.1.1
organizing the pliance with personal data-related
processing of legislation.
personal data.
• Educate the operator and employees
regarding personal data-related
requirements.
• Handle data subject requests.
Singapore Personal Data • Designate • Covered entities. • Ensure compliance with the act. • Person or team. • PDPC DPO • Publish contact
Protection Act one or more Competency information.
individuals to Framework
Section 11(3)
be responsible and Training
for ensuring the Roadmap.
organization
complies.
South Protection • Designate an • Public and private • Encourage lawful processing of • Register with
Africa of Personal information bodies. personal information. regulator.
Information Act officer. • Handle individual requests.
Chapter 5, Part B • Liaise with regulator on
investigations.
• Ensure compliance with the act.
• Other duties, as prescribed.

International Association of Privacy Professionals  •  [Link] 5


Legal Training/ Registration/
instrument Terminology Scope Tasks Structure expertise notification
South Personal • Designate a • Covered entities. • Manage data processing. • May not be
Korea Information privacy officer. • Establish data protection plan. disadvantaged
Protection Act without justifi-
• Survey and improve data processing.
able grounds.
Article 31(1)
• Address grievances with data
Enforcement processing.
Decree • Build controls to prevent misuse of
personal data.
• Educate staff about data protection.
• Protect, control and manage data files.
• Implement corrective measures for
violations and report them to head of
organization.
• Establish and implement a privacy
policy.
• Maintain materials related to data
protection.
• Destroy personal data once process-
ing purpose is complete or retention
period expires.
Thailand Personal Data • Designate a • Data controllers • Give advice with respect to compli- • Affiliated • Regulator may • Designate in
Protection Act DPO. and processors ance with the act. controllers and prescribe quali- writing.
which are (1) • Investigate data processing for processors can fications related • Provide contact
Sections 41 & 42
public authorities; compliance with the act. designate a to knowledge or details to data
(2) engaged in single DPO. expertise. subjects and
• Cooperate with the regulator.
regular monitor- • Staff member or regulator.
ing of individuals • Maintain confidentiality of personal
contractor.
on a large scale; data.
• Must be pro-
(3) processing • Other duties as assigned that do not
vided adequate
sensitive data as conflict with duties under the act.
tools, equipment
a core activity.
and data access.
• Report to chief
executive and
protected from
dismissal for
performing
tasks.

International Association of Privacy Professionals  •  [Link] 6


Legal Training/ Registration/
instrument Terminology Scope Tasks Structure expertise notification
Uganda Data Protection • Designate a • Institutions (i.e., • Ensure compliance with the act.
and Privacy Act person as the covered entities
DPO. other than indi-
Article 6
viduals or public
bodies).
Ukraine Data Protection • Appoint a unit • State and local • Organize the work related to personal • Notify the
Law or responsible governments; data protection. Ukrainian
person to controllers and • Inform and advise the controller Parliament
Article 24(2)
organize the processors or processor on observance of the Commissioner
work related to processing data legislation. for Human
personal data of particular risk Rights of
• Cooperate with the Ukrainian
protection. to the rights and responsible
Parliament Commissioner for Human
freedoms of data person, who will
Rights and appointed officials on
subjects. then publish the
compliance.
• Excludes sole information.
traders, including
doctors, attorneys
and notaries,
which are person-
ally responsible.
United U.K. General • Designate a • Processing by • Inform and advise on data protection • Staff member or • Professional • Publish contact
Kingdom Data Protection DPO. public authority requirements. contractor. qualities. information and
Regulation or body, except • Monitor compliance. • Resourced to • Expert knowl- communicate it
courts. carry out tasks edge of data to ICO.
Articles 37–39 • Advise organization on data protec-
• Data controllers tion impact assessments. and maintain protection law
or processors expertise. and practices.
• Cooperate with the Information
whose core activ- • Reports to high- • Ability to fulfill
Commissioner’s Office.
ities require regu- est management legally mandated
lar and systematic • Serve as contact for individuals and
level. tasks.
monitoring of ICO.
• No instructions
data subjects on a
or dismissal
large scale.
regarding tasks.
• Data controllers or
• Bound by
processors whose
confidentiality.
core activities
include processing
on a large scale of
special categories
of data.

International Association of Privacy Professionals  •  [Link] 7


Legal Training/ Registration/
instrument Terminology Scope Tasks Structure expertise notification
United Health Insurance • Designate a • HIPAA-covered • Develop and implement the policies • Maintain written
States Portability and privacy official. entities. and procedures of the entity. or electronic
Accountability record of
Act designation.
Section
164.530(a)(1)
Uruguay Law 19670 • Appoint a DPO. • Public entities. • Advise on the formulation, design • Must have tech- • Possess neces- • Communicate
Article 40 • Fully or partially and application of data protection nical autonomy sary qualifica- appointment to
Decree 65/020 state-owned policies. and receive no tions to perform regulator within
private entities. • Supervise compliance with regulations. instructions on tasks. 90 days.
performance of • Knowledge in
• Private entities • Propose measures to conform to the
DPO function. law, specialized
that process sen- regulations and international stan-
sitive data as their dards on data protection. • Can be staff or in the protection
main business and • Liaise with the regulator. contractor. of personal data,
those that process • Must have full which must be
• Other tasks as assigned, which do not accredited.
large volumes of access to per-
conflict with mandated duties.
data (concerning sonal databases
more than 35,000 and processing
people). operations.

International Association of Privacy Professionals  •  [Link] 8

Common questions

Powered by AI

In Egypt, the Personal Data Protection Law requires DPOs to apply the law, monitor compliance, manage data subject requests, evaluate and document data protection systems, and train staff. They must also liaise with the Data Protection Authority (DPA) for legal compliance and notify DPA of infringements . In Thailand, under the Personal Data Protection Act, DPOs advise on compliance, investigate data processing activities, maintain confidentiality, and cooperate with the regulator. They are also protected from dismissal when performing their duties . Egypt's law emphasizes systemic evaluation and staff training, while Thailand's law focuses on regulatory cooperation and confidentiality.

In the UK, the DPO must publish contact information and report to the highest management level, serving as a contact point for individuals and the Information Commissioner's Office (ICO). They must not be given instructions that affect the performance of their DPO tasks and are bound by confidentiality . Conversely, in Mauritius, the DPO's identity is informed to data subjects at the time of collection and maintained in records of processing, but there is less emphasis on direct interaction with the Examiner equivalent to the ICO . This highlights a more structured and public-facing role for UK DPOs compared to Mauritius.

Privacy Officers in New Zealand, under the Privacy Act, are responsible for handling individual requests, liaising with the Data Protection Authority (DPA) on investigations, and ensuring compliance with the act. They must act as the primary interface between their agency and the DPA and aid in regulatory investigations, thus playing a crucial role in maintaining transparency and ensuring adherence to privacy laws .

Nigeria mandates continuous capacity building for Data Protection Officers and personnel involved in data processing as part of its Data Protection Regulation. This is ingrained in the regulation to ensure that DPOs remain updated with evolving data protection practices and are able to lead compliance efforts effectively within their organizations .

The GDPR mandates that a Data Protection Officer (DPO) must inform and advise the organization on GDPR obligations, monitor compliance with these obligations, advise on data protection impact assessments, cooperate with the supervisory authority, and act as a contact point for data subjects and the authority. Additionally, the DPO must carry out their tasks independently without being dismissed or penalized for performing their duties. They are expected to possess expert knowledge of data protection law and practices to effectively guide the organization .

Under HIPAA, a designated privacy official must develop and implement the entity's privacy policies and procedures. The DPO is responsible for maintaining either written or electronic records of this designation, ensuring compliance with HIPAA's privacy rule requirements, and overseeing the implementation of privacy measures .

In Singapore, the Personal Data Protection Act mandates that a DPO ensures compliance by being responsible for the organization's data protection measures. They must adhere to the PDPC DPO Competency Framework and Training Roadmap, which provides guidelines and professional frameworks for compliance. The DPO must also publish their contact information to facilitate communication and transparency with data subjects and the regulator .

In Brazil, the DPO's tasks under the General Data Protection Law include receiving complaints and communications from data subjects and the national data protection authority, educating staff on personal data protection practices, and responding to data protection-related inquiries . In contrast, China's Personal Information Security Specification requires the appointment of a person and department to take responsibility for data protection, coordinate security efforts, develop data protection plans, conduct security assessments, and handle data security incidents . China's approach is broader, emphasizing organizational security strategy and technical assessments, while Brazil focuses more on communication and educational responsibilities.

The South Korean Personal Information Protection Act outlines that a Privacy Officer is responsible for managing data processing, establishing a data protection plan, and carrying out data management improvements. They must address grievances related to data processing, implement controls to prevent personal data misuse, and educate staff about data protection. The role is comprehensive, blending compliance, operational oversight, and staff training to enforce robust data protection measures .

Under Uruguay's Law 19670, a DPO must have technical autonomy, meaning they should act independently without instructions on their performance of DPO functions. They are required to have necessary qualifications in law, with specialization in data protection, which should be accredited. Uruguay mandates full access to the organization's databases and processing operations for the DPO. Furthermore, the DPO's appointment must be communicated to the regulator within 90 days . These qualifications and protections ensure that the DPO can perform their duties effectively and impartially.

International Association of Privacy Professionals  •  iapp.org	
1
Data Protection Officer 
Requirements by Country
Legal 
in
International Association of Privacy Professionals  •  iapp.org	
2
Legal 
instrument
Terminology
Scope
Tasks
Structure
Traini
International Association of Privacy Professionals  •  iapp.org	
3
Legal 
instrument
Terminology
Scope
Tasks
Structure
Traini
International Association of Privacy Professionals  •  iapp.org	
4
Legal 
instrument
Terminology
Scope
Tasks
Structure
Traini
International Association of Privacy Professionals  •  iapp.org	
5
Legal 
instrument
Terminology
Scope
Tasks
Structure
Traini
International Association of Privacy Professionals  •  iapp.org	
6
Legal 
instrument
Terminology
Scope
Tasks
Structure
Traini
International Association of Privacy Professionals  •  iapp.org	
7
Legal 
instrument
Terminology
Scope
Tasks
Structure
Traini
International Association of Privacy Professionals  •  iapp.org	
8
Legal 
instrument
Terminology
Scope
Tasks
Structure
Traini

You might also like