The main function of a data protection officer is to monitor how the GDPR requirements are being met, and to give recommendations and advice on it.
As your external data protection officer, we will:
- carry out a data protection audit to establish whether your existing data protection documentation is sufficient and matches your data processing practices;
- on the basis of the audit results, make the necessary changes to the documents you use and, if you do not yet have any, prepare them;
- inform you of the processing operations you carry out that pose a risk, and propose solutions to reduce that risk;
- act as the contact person in dealings with the State Data Protection Inspectorate (VDAI) and with third parties or company employees (interns) who submit data protection requests;
- advise on day-to-day data protection questions;
- take part in decisions relating to the protection of personal data;
- keep your records of processing activities and help you manage other documentation;
- where needed, advise on carrying out a data protection impact assessment;
- once a year, deliver staff training on topics agreed in advance, taking into account the company’s existing documentation and the audit results;
- provide a dedicated telephone number and email address that you can publish on your website together with the data protection officer’s details;
- keep you informed of changes and news in the legal regulation of personal data protection;
- perform the other functions of a data protection officer laid down by law.
To receive a detailed description of our external data protection officer services, including our fees, fill in the form on the right-hand side of this page.
Contact us
Check it yourself
You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).
Frequently asked questions
When must a company or institution appoint a data protection officer?
A data protection officer is mandatory in three cases. First, where the processing is carried out by a public authority or body. Second, where the core activities require regular and systematic monitoring of people on a large scale. Third, where the core activities consist of processing special categories of data (for example, health data) on a large scale. If none of these criteria applies, you are not required to appoint an officer, but this should be recorded in writing, because both clients and the supervisory authority ask about it.
Can the data protection officer be an external service provider rather than one of our employees?
Yes. The Regulation expressly allows it: the officer may be a member of staff or fulfil the tasks on the basis of a service contract. In practice, for small and medium-sized organisations an external service is often the only realistic option, since it is rare to find someone in-house who both knows data protection law and has no conflict of interest.
Can the chief executive, the head of IT or the head of HR act as data protection officer?
Usually not. The Regulation requires that the officer’s other tasks and duties do not result in a conflict of interest. The chief executive, or the head of IT, HR or marketing, decide themselves on the purposes and means of processing, so they cannot impartially monitor their own decisions. In that case the function exists on paper but not in reality.
What happens if a data protection officer is appointed on paper but does not actually perform the tasks?
The criteria remain unmet, and the position is worse than having no officer at all. Clients and the supervisory authority both believe the function is working, so nobody checks it, while requests and notifications go unanswered. The Regulation requires genuine expert knowledge, not a job title.
Do the data protection officer’s contact details have to be published and notified to the supervisory authority?
Yes, both are mandatory. The contact details are published (usually in the privacy policy and in the contacts section of the website) and are notified to VDAI. An appointment without a public contact and without notifying the authority does not meet the requirement.
What does a data protection officer actually do each month?
The Regulation lists five minimum tasks: to inform and advise; to monitor compliance (including staff training and audits); to advise on data protection impact assessments; to cooperate with the supervisory authority; and to act as its contact point. In practice this means reviewing and updating documents, keeping records of processing activities, answering data subjects’ requests and running annual staff training.
Can one data protection officer serve several companies in a group or several institutions?
Yes. A group of undertakings may appoint a single officer, provided the officer is easily accessible from each establishment. A separate rule applies to public authorities and bodies: a single officer may be designated for several of them, taking account of their organisational structure and size. A group usually receives one proposal, but each legal entity formalises the appointment separately.
Is the data protection officer liable for data protection breaches committed by the company?
No. Responsibility remains with the data controller, which must implement the measures and be able to demonstrate that data is processed lawfully. The officer monitors, advises and warns, but does not take over the controller’s responsibility. That is why it matters that the officer’s recommendations and the organisation’s decisions are recorded in writing.
Can we tell the data protection officer how to perform their tasks, and can we dismiss them?
No. The officer may not receive any instructions regarding the performance of these tasks, may not be dismissed or penalised for performing them, and reports directly to the highest level of management. The organisation must also involve the officer in good time in all issues relating to data protection and provide real resources.
How does a data protection officer differ from a representative in the European Union?
These are two different roles and one cannot replace the other. A representative in the Union is designated in writing where an organisation is not established in the EU but offers goods or services to people in the EU or monitors their behaviour; the representative must be established in the Member State where the data subjects are. A data protection officer is appointed on entirely different criteria and performs a monitoring and advisory function. The same organisation may have both.
Does the data protection officer have to be reachable by employees and customers?
Yes. Data subjects have the right to contact the officer on all issues relating to the processing of their data and the exercise of their rights. That is why, when an external officer is appointed, a separate telephone number and email address are provided, which the organisation publishes on its website.
Is it worth appointing a data protection officer voluntarily when we are not required to?
You may. The Regulation allows an officer to be appointed in cases that do not fall within the mandatory ones. However, a voluntarily appointed officer is subject to the same requirements: independence, no conflict of interest, resources and a public contact. If you cannot meet them, it is more honest not to appoint an officer and to name a contact person for data protection matters instead.
Can the data protection officer’s email address be a generic one, or must it name a specific person?
A generic address is fine. The published contact details must make it easy to get in touch (a postal address, a dedicated telephone number and/or an email address), but the officer’s name is not required to be included. A functional address is even more convenient: when the person changes, the address does not have to. The name and surname must, however, be given to the supervisory authority. It is also worth publishing the name and contact details within the organisation, for example on the intranet.
Do we need to sign a separate data processing agreement with an external data protection officer?
Usually not. A data processing agreement is concluded with whoever processes data on your behalf and on your instructions. The officer works the other way round: the Regulation prohibits giving the officer instructions regarding the performance of their tasks, so the officer is not your processor. A service contract is enough. It is worth using it to allocate tasks clearly among the team members and to appoint one lead contact person, which is exactly what the WP29 guidelines recommend.
Does the external officer service include an unlimited number of hours?
No. The scope is usually defined in the contract as an annual number of hours or a package, and additional hours are agreed separately. The first year is almost always more intensive than later ones, as the documentation is put in order, records of processing activities are started and the first training sessions are held, so it is worth agreeing from the outset what happens when the scope is exceeded. The Regulation requires the organisation to provide the officer with the necessary resources, and the agreed number of hours is exactly that.
Which supervisory authority applies to us if we are registered in Lithuania but provide services to residents of other EU countries?
The “one-stop shop” principle applies. The lead supervisory authority is the one where the main establishment is located; for a company registered in Lithuania, that is VDAI. The authority of another Member State is a supervisory authority concerned: it is competent to handle a complaint if the subject matter relates only to an establishment in its Member State or substantially affects data subjects only in its Member State. In that case it informs the lead authority without delay, and the lead authority decides within three weeks whether to handle the case itself.
What do we need to provide to receive a proposal for an external data protection officer?
It is enough to fill in a short GDPR readiness questionnaire about what data you process and for what purposes. On that basis, we prepare a specific proposal setting out the scope and the price. If you prefer, the same can be discussed by telephone. The questionnaire also shows whether you are required to have an officer at all.
How long does the appointment take?
Usually a few days from signing the agreement to the contact details being published.