Role of the DPO Banner

Under the GDPR, certain organisations are required to appoint a designated Data Protection Officer (DPO). University of Galway, as an organisation that undertakes its processing as a public body is required to have a DPO. The University of Galway DPO can be contacted at:

dataprotection@universityofgalway.ie

The DPO is a statutory independent role that facilitates data subjects in exercising their rights under the GDPR and the Irish Data protection Act 2018.

The DPO assists their organisation (controller or processor) in all issues relating to the protection of personal data. Tasks of the DPO include:

    • Inform and advise the controller or processor, as well as their employees, of their obligations under data protection law
    • Monitor compliance of the organisation with all legislation in relation to data protection, including in audits, awareness-raising activities as well as training of staff involved in processing operations
    • Provide advice on Data Protection Impact Assessments (DPIAs)
    • Act as a contact point for requests from individuals regarding the processing of their personal data and the exercising of their rights
    • Cooperate with the Data Protection Commission (DPC) and act as their organisation’s contact point for the DPC on issues relating to processing.

The organisation must involve the DPO in a timely manner. The DPO must not receive any instructions from their organisation (controller or processor) for the exercise of their tasks. The DPO reports directly to the highest level of management of the organisation.

DPOs are not personally responsible for non-compliance with data protection requirements. It is the controller or the processor who is required to ensure and to be able to demonstrate that processing.

See further information at:

Regulation - 2016/679 - EN - gdpr - EUR-Lex

Data Protection Act 2018 - Irish Statute Book

Guidelines on Data Protection Officers ('DPOs'), wp243rev.01_en