More Posts

Following its investigation of a personal data breach, the Belgian Data Protection Authority (DPA) issued a ruling on April 28, 2020, imposing a €50,000 fine on an organization for negligence in having appointed the company’s head of compliance, risk and audit as its data protection officer (DPO). This decision should cause entities to reconsider appointing a DPO who holds another senior role in the organization.

Article 38.6 of the EU’s General Data Protection Regulation (GDPR) allows that a DPO may fulfill other tasks and duties assigned by an organization, provided such duties do not result in a conflict of interest. Since the GDPR came into effect in May 2018, we have seen limited regulatory enforcement focused on the DPO’s role. The Belgian DPA’s fine complicates this landscape and highlights key considerations for organizations with respect to the appointment of a DPO.