Data protection

Data protection officer (DPO) and GDPR compliance

Public bodies, and companies whose core activities involve large-scale monitoring of people or large-scale processing of sensitive data such as health data, must appoint a data protection officer under the GDPR. We take on that role or support the person you appoint, and we put your core GDPR documents in order.

What we deliver

  • An external data protection officer (DPO), or support for the one you appoint.
  • A data protection policy.
  • The record of processing activities the GDPR requires.
  • Acting as the contact point for the Hellenic Data Protection Authority, one of the DPO's duties under the GDPR.

Public bodies

Every public authority must have a data protection officer. We have provided GDPR and DPO services to a regional public health authority, and we understand how the rules apply to the everyday work of a public service.

Who leads the work

Data protection work is led by Michalis G. Pouspourikas, CFE, CICA, CCS, MSc, Head of Corporate Governance Services.

Frequently asked questions

Who must appoint a DPO?

Under Article 37 of the GDPR: every public authority, and any organisation whose core activities involve regular and systematic monitoring of people on a large scale, or large-scale processing of special categories of data, such as health data.

Can the DPO be external?

Yes. The GDPR allows the DPO to be a member of staff or to work on the basis of a service contract.

What is the record of processing activities?

A document that lists what personal data you process, why, about whom, who receives it and how long you keep it. Article 30 of the GDPR requires it, and it is one of the first documents the authority asks for in an inspection.

Not sure whether you need a DPO?

Tell us what data you handle. We will give you a straight answer.

Book a free consultation