Skip to content
RGPD

Article 39

Tasks of the data protection officer

1.   The data protection officer shall have at least the following tasks:

(a)

to inform and advise the controller or the processor and the employees who carry out processing of their obligations pursuant to this Regulation and to other Union or Member State data protection provisions;

(b)

to monitor compliance with this Regulation, with other Union or Member State data protection provisions and with the policies of the controller or processor in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits;

(c)

to provide advice where requested as regards the data protection impact assessment and monitor its performance pursuant to Article 35;

(d)

to cooperate with the supervisory authority;

(e)

to act as the contact point for the supervisory authority on issues relating to processing, including the prior consultation referred to in Article 36, and to consult, where appropriate, with regard to any other matter.

2.   The data protection officer shall in the performance of his or her tasks have due regard to the risk associated with processing operations, taking into account the nature, scope, context and purposes of processing.

Common Questions

Frequently Asked Questions

What tasks does Article 39 assign to the data protection officer?

Article 39 sets out a minimum list, so an organisation can give its data protection officer additional tasks but not fewer. The tasks are:

  • informing and advising the controller or the processor and the employees who carry out processing of their obligations under this Regulation and other Union or Member State data protection provisions
  • monitoring compliance with the Regulation, other data protection provisions and the organisation's own policies on the protection of personal data, including the assignment of responsibilities, awareness-raising, training of staff involved in processing operations and the related audits
  • providing advice where requested on the data protection impact assessment and monitoring its performance
  • cooperating with the supervisory authority
  • acting as the contact point for the supervisory authority on issues relating to processing
What role does the data protection officer play in data protection impact assessments?

The officer provides advice where requested as regards the data protection impact assessment and monitors its performance pursuant to Article 35.

The wording matters: the officer advises and monitors, the article does not say the officer carries out the assessment. The text frames the role as advisory and supervisory, not as doing the assessment itself.

How does the data protection officer work with the supervisory authority?
Article 39 gives the officer two connected tasks: to cooperate with the supervisory authority, and to act as the contact point for the supervisory authority on issues relating to processing. That contact-point role expressly includes the prior consultation referred to in Article 36, and the officer may also consult, where appropriate, with regard to any other matter.
Does the data protection officer have to treat every processing operation the same way?

No. Article 39(2) says the officer shall in the performance of his or her tasks have due regard to the risk associated with processing operations, taking into account the nature, scope, context and purposes of processing.

In practice this allows the officer to set priorities: higher-risk processing operations get more attention than routine, low-risk ones.