Art.39 Tasks of the data protection officer
The data protection officer must at least inform and advise the controller or processor and the employees who carry out processing of their obligations under the Regulation and other Union or Member State data protection
5
artefacts
1
held by a system
1
at each review
hard
to go live
Document repository
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Evidence the monitoring effort is weighted by processing risk rather than spread evenly across the organisation · SIEM / log platform
periodic reviewEvidence produced at each review
- The officer's record of contacts as supervisory authority contact point, and of impact assessment advice given under Article 35(2) · Document repository
governing documentDocuments that govern the control
- The officer's monitoring plan and its output, such as a review or audit programme with findings and their closure · Policy repository / GRC workspace
- Advice given, recorded with its date and outcome including where it was not followed and by whose decision · Document repository
- Training and awareness activity delivered or overseen, with coverage figures for the staff involved in processing operations · HR system / LMS
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your SIEM / log platform on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- The officer acting as the compliance delivery function, writing and running the very controls they are meant to independently monitor
- Advice given verbally and never recorded, so there is no evidence of what was recommended when a decision is later questioned
- Monitoring reduced to a policy review cycle, with no testing of whether the processing actually follows the policy
- No record kept of advice that was overridden, which is the evidence that most protects both the officer and the organisation
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetArt.38 Position of the data protection officer · Art.44 General principle for transfers