Responsibilities of a Voluntary Data Protection Officer

Thinking of becoming a voluntary Data Protection Officer (DPO) in addition to your current role? This post explains the risks and responsibilities volunteers and organisations recruiting them should understand.

I often see voluntary Data Protection Officer (DPO) jobs on LinkedIn. They are for great causes and at interesting organisations (usually charities), but taking a voluntary DPO role, especially if you’re already a DPO elsewhere, comes with personal and organisational risks. There is more to being a “hobby DPO” and it’s not just a question of whether or not there will be time for the job.

Voluntary Doesn’t Mean Lighter Touch or Less Serious

Only because the role is unpaid or for a few hours here and there does not mean the DPO’s responsibilities in Article 39 of the UK GDPR apply any less.

If you’re the organisation, please read Article 39. This is the core of the DPO’s job, which is already substantial, so think twice about expanding this just because it’s "voluntary”. You have to let the person do their “job”.

If you’re the volunteer, please read Article 39. Can you honestly say you will find the time to fulfil the requirements in a meaningful way? Can you demonstrate the organisation is complying with the law with your help?

Also, if you’re the volunteer, don’t just jump to do a voluntary DPO role because you like the sector or the organisation. Consider the context of the data use and if you actually have the expert knowledge to give practical advice.

@slelham on Unsplash

The Organisation Remains Accountable for Compliance

As the organisation recruiting a voluntary DPO, you should keep in mind that the ultimate compliance check will be done on you, not on your DPO. You’re the controller and responsible for demonstrating compliance.*

So while the DPO role may be voluntary, if your DPO is:

  • under-supported because you can’t get them a team, or

  • only works the occasional hours in the evening,

your organisation’s data use may not get the needed data protection attention. This means you could fall foul of some UK GDPR requirement, which is riskier if the context of personal data processing is more sensitive (e.g. an NHS trust with health data and thousands of patients).

DPO Conflict of Interests

If an organisations gets a voluntary DPO, it is likely that this person will already have the same paid role elsewhere. There are several different conflict of interests for both sides to be aware of:

  • Paid DPO role for a controller and voluntary DPO role for its processor (or vice versa).

    This is a problem for independence under the UK GDPR because the parties will have different interests.

  • The DPO as an employee will have a duty to not tarnish their employer’s reputation.

    This may be a problem if the voluntary DPO position is with an organisation that campaigns against what the employer as a type of company does (e.g. the employer is a cosmetics company but the charity’s goal is to stop animal testing including for cosmetics).

  • If the DPO knows someone at the charity and is doing them a favour.

    If the DPO agrees to do the job just so the charity has a named DPO for the record, it will be nominal more than anything else.

A Voluntary DPO is Still a Professional Adviser

While the organisation is responsible for compliance, it’s prudent that the volunteering DPO takes out professional indemnity insurance as a professional adviser (albeit unpaid).

Insurance can be expensive and the money will have to come out of the person’s own pocket because the job is outside employment. It is not a stretch to think that perhaps the volunteer is more likely to prioritise their paid job, where they feel more secure (in different ways).

It’s also worth remembering that while insurance might cover claims for bad advice, their professional reputation may suffer and there is no magic fix for that.

Next Steps

For the organisation

If you still want to recruit a volunteer to manage your data protection framework, you could just not call the role “DPO”. This is a statutory role with defined expectations for both the person assuming the position and the organisation creating it.

Also, if you are concerned about your data or reputation, investing in a qualified data protection professional is forwarding thinking and showing respect for clients and customers.

  • You don’t have to have a full-time person (but consider the sensitivity of the data you hold).

  • You can outsource it and keep it flexible (“DPO as a service”).

  • You can get a consultant to shape your framework and have them train your staff to maintain it before they leave.

For the volunteer

  • Tell your employer about your voluntary role to clear or declare any conflict of interests.

  • Arrange for professional indemnity insurance.

  • Separate the volunteer DPO role with different emails and working hours.

  • Keep records of advice you have given for both roles.

  • Sign an agreement with clear tasks and working expectations.

Having a voluntary DPO is, on balance, better than having none. In the long run, however, it makes business more complicated for both parties.

A DPO is a trusted friend and adviser. Don’t shy away from hiring one if you need them.

If you are the DPO, you’re a trusted friend and adviser, so do your very best.

*UK GDPR, Article 5(2)

Previous
Previous

How to Become a UK Data Protection Officer

Next
Next

Women’s Privacy Online: Data Dangers