Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: EN

Article 38 Position of the data protection officer


Summary What does Article 38 of the GDPR regulation say?

This article sets out the conditions under which a Data Protection Officer (DPO) must operate once appointed — building directly on Article 37, which establishes when a DPO must be designated.

The focus here is on protecting the DPO's independence and effectiveness: controllers and processors must involve the DPO in all relevant matters, give them the resources they need, and crucially, shield them from instructions or penalties that could compromise their role.

The article also addresses the DPO's relationship with data subjects, their obligation of secrecy, and the management of potential conflicts of interest if they hold additional duties.

Important points:

  • Ensure your DPO is involved in all personal data protection matters in a timely manner, is properly resourced, and reports directly to the highest management level.
  • The DPO must not receive instructions on how to perform their tasks and cannot be dismissed or penalised for carrying them out.
  • If the DPO holds other roles or duties, controllers and processors must ensure no conflict of interests arises.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. The controller and the processor shall ensure that the data protection officer is involved, properly and in a timely manner, in all issues which relate to the protection of personal data.

    1. The controller and processor shall support the data protection officer in performing the tasks referred to in Article 39 by providing resources necessary to carry out those tasks and access to personal data and processing operations, and to maintain his or her expert knowledge.

    1. The controller and processor shall ensure that the data protection officer does not receive any instructions regarding the exercise of those tasks. He or she shall not be dismissed or penalised by the controller or the processor for performing his tasks. The data protection officer shall directly report to the highest management level of the controller or the processor.

    1. Data subjects may contact the data protection officer with regard to all issues related to processing of their personal data and to the exercise of their rights under this Regulation.

    1. The data protection officer shall be bound by secrecy or confidentiality concerning the performance of his or her tasks, in accordance with Union or Member State law.

    1. The data protection officer may fulfil other tasks and duties. The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod