<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Advise on designating a Data Protection Officer (DPO) for a US company having EU customers in Privacy</title>
    <link>https://community.isc2.org/t5/Privacy/Advise-on-designating-a-Data-Protection-Officer-DPO-for-a-US/m-p/10464#M474</link>
    <description>&lt;P&gt;Dear Newcomer,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;since I am not a lawyer, I can't tell you if it is legally rquired for that business. But from my practical experiance (in Germany) apointing a DPO is seen very positive by customers and their DPOs here. It is common practice that these DPO's are very often external Consultants in many cases from organistions with good reputation such as the TÜV. They have a good knowöedge of what companies and governments expect in their country (and there are some differences as I had to learn in the past). Their charges are reasonable, mostly based on effort.&lt;/P&gt;&lt;P&gt;Especially in a phase where customers come up with all sort of questions and contract templates they obtained from the web, some advise can only be an advantage. When this type of issues decreases, you can always reduce the consultany.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope that helps, if practical information from Germany is needed, drop a line.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;oms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 20 May 2018 15:40:12 GMT</pubDate>
    <dc:creator>oms</dc:creator>
    <dc:date>2018-05-20T15:40:12Z</dc:date>
    <item>
      <title>Advise on designating a Data Protection Officer (DPO) for a US company having EU customers</title>
      <link>https://community.isc2.org/t5/Privacy/Advise-on-designating-a-Data-Protection-Officer-DPO-for-a-US/m-p/7382#M304</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Would appreciate if those who are familiar&amp;nbsp;with&amp;nbsp; DPO aspects could provide some guidance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GDPR states the following regarding DPO requirement.:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;"Virtually all public sector bodies will be required to designate a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="il"&gt;DPO&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;under the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="il"&gt;GDPR&lt;/SPAN&gt;.&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;When it comes to the private sector, the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="il"&gt;GDPR&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;introduces a limited mandatory&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="il"&gt;DPO&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;requirement.&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Controllers and processors will only be required to designate a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="il"&gt;DPO&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;if their core activities consist of:&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;i. processing operations which, by virtue of their nature, scope and/or purposes, require regular and&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;systematic monitoring of data subjects on a large scale; or&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;ii. processing on a large scale of special categories of data or data relating to criminal convictions and offences. "&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;A SaaS provider offering solutions to end users in the EU (through their orgs) will not be coming under the two core activities mentioned above. If the PII collected is minimal without any payment instrument data or health-related information, would appointing a DPO be useful to demonstrate further compliance to GDPR?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Additionally, if it would be better to have a DPO in a member state where the provider conducts most business (i.e., the state where the supervisory authority for GDPR will be), can a consultant in that state would do? If the DPO is a person in the US, not sure how that will fly with different member states.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Thanks in advance.&lt;/DIV&gt;</description>
      <pubDate>Thu, 15 Feb 2018 03:44:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Advise-on-designating-a-Data-Protection-Officer-DPO-for-a-US/m-p/7382#M304</guid>
      <dc:creator>2012</dc:creator>
      <dc:date>2018-02-15T03:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: Advise on designating a Data Protection Officer (DPO) for a US company having EU customers</title>
      <link>https://community.isc2.org/t5/Privacy/Advise-on-designating-a-Data-Protection-Officer-DPO-for-a-US/m-p/7390#M305</link>
      <description>&lt;P&gt;The Article 29 working party group has guidance on appointing a DPO but it's mostly focused on the role:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A title="Article 29 WP advice" href="http://ec.europa.eu/newsroom/document.cfm?doc_id=44100" target="_blank"&gt;http://ec.europa.eu/newsroom/document.cfm?doc_id=44100&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It does express a preference for EU based DPOs but it's not mandatory.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's very difficult to comment further without more clarity on the data you are storing - the "large scale and systematic" part of the storage will be the key issue. If you're storing for example name, address, email, phone number for 1000s of data subjects in the EU for your customers, you'd almost certainly be seen as needing a DPO.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2018 11:12:05 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Advise-on-designating-a-Data-Protection-Officer-DPO-for-a-US/m-p/7390#M305</guid>
      <dc:creator>Steve_D</dc:creator>
      <dc:date>2018-02-15T11:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: Advise on designating a Data Protection Officer (DPO) for a US company having EU customers</title>
      <link>https://community.isc2.org/t5/Privacy/Advise-on-designating-a-Data-Protection-Officer-DPO-for-a-US/m-p/7446#M307</link>
      <description>&lt;P&gt;Thank you for your response.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2018 16:25:47 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Advise-on-designating-a-Data-Protection-Officer-DPO-for-a-US/m-p/7446#M307</guid>
      <dc:creator>2012</dc:creator>
      <dc:date>2018-02-16T16:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: Advise on designating a Data Protection Officer (DPO) for a US company having EU customers</title>
      <link>https://community.isc2.org/t5/Privacy/Advise-on-designating-a-Data-Protection-Officer-DPO-for-a-US/m-p/10368#M467</link>
      <description>&lt;P&gt;See WP29 WP243 opinion and the related FAQs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is considered good practice by the WP29 to appoint a DPO on a voluntary basis even if the 3 conditions in article 37 are not met.&amp;nbsp; I'd suggest as SaaS supply may be processing personal data of many client therefore needs to carefully consider documenting any decision not to appoint a DPO.&amp;nbsp; If the EEA country is Germany you will have to appoint a DPO as national legislation requires it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A consultant on a service contract in the relevant country would be acceptable under GDPR.&amp;nbsp; It will be more difficult to argue that a DPO in the US has the relevant experience of EU jurisdictions, is fluent in the relevant languages and is easily contactable given time zone differences etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2018 13:57:44 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Advise-on-designating-a-Data-Protection-Officer-DPO-for-a-US/m-p/10368#M467</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2018-05-16T13:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: Advise on designating a Data Protection Officer (DPO) for a US company having EU customers</title>
      <link>https://community.isc2.org/t5/Privacy/Advise-on-designating-a-Data-Protection-Officer-DPO-for-a-US/m-p/10464#M474</link>
      <description>&lt;P&gt;Dear Newcomer,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;since I am not a lawyer, I can't tell you if it is legally rquired for that business. But from my practical experiance (in Germany) apointing a DPO is seen very positive by customers and their DPOs here. It is common practice that these DPO's are very often external Consultants in many cases from organistions with good reputation such as the TÜV. They have a good knowöedge of what companies and governments expect in their country (and there are some differences as I had to learn in the past). Their charges are reasonable, mostly based on effort.&lt;/P&gt;&lt;P&gt;Especially in a phase where customers come up with all sort of questions and contract templates they obtained from the web, some advise can only be an advantage. When this type of issues decreases, you can always reduce the consultany.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope that helps, if practical information from Germany is needed, drop a line.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;oms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 20 May 2018 15:40:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Advise-on-designating-a-Data-Protection-Officer-DPO-for-a-US/m-p/10464#M474</guid>
      <dc:creator>oms</dc:creator>
      <dc:date>2018-05-20T15:40:12Z</dc:date>
    </item>
    <item>
      <title>Sorry</title>
      <link>https://community.isc2.org/t5/Privacy/Advise-on-designating-a-Data-Protection-Officer-DPO-for-a-US/m-p/10465#M475</link>
      <description>&lt;P&gt;Dear 2012,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am sorry, that was my first post here. I just realized that "Newcomer" is just the "level".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;oms&lt;/P&gt;</description>
      <pubDate>Sun, 20 May 2018 15:57:08 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Advise-on-designating-a-Data-Protection-Officer-DPO-for-a-US/m-p/10465#M475</guid>
      <dc:creator>oms</dc:creator>
      <dc:date>2018-05-20T15:57:08Z</dc:date>
    </item>
    <item>
      <title>Re: Sorry</title>
      <link>https://community.isc2.org/t5/Privacy/Advise-on-designating-a-Data-Protection-Officer-DPO-for-a-US/m-p/10494#M477</link>
      <description>&lt;P&gt;No problem, the tags newcomer, contributor etc are a bit strange.&amp;nbsp; Thanks for the feedback though.&amp;nbsp; I was aware that in a German context the role of the DPO was long accepted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 06:59:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Advise-on-designating-a-Data-Protection-Officer-DPO-for-a-US/m-p/10494#M477</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2018-05-21T06:59:18Z</dc:date>
    </item>
  </channel>
</rss>

