The issue of personal data protection is acute for Belarusian business. Only recently, three high-profile cases of leakage of customer data of large companies in Belarus have become known. Since November 2021, when the law “On Personal Data Protection” came into force, every company has an obligation to appoint a structural unit or a person who controls the processing of this data. Such a profession is an analogue of the sought-after position of data protection officer (DPO), which has long existed in European and other countries. This responsible person plays a key role in the organisation’s processing of personal data. The purpose of the DPO is to prevent possible violations of personal data protection legislation by the company.
We emphasise: a responsible person is appointed in every organisation, including public bodies.
There are no exemptions today – for example, for organisations with a small number of employees or organisations that do not do large-scale processing.
These requirements do not apply only to natural persons, sole proprietors, lawyers, notaries, craftsmen, tutors and mediators.
Depending on the scale of personal data processing, companies have several options to address the issue.
Suitable for: large organisations that process large amounts of personal data and where such processing involves significant risks to the data subjects.
It is recommended that such a unit include not only legal advisors, but also persons with technical backgrounds to analyse processes in a comprehensive manner. The number of such staff depends on the scale of data processing.
Suitable for: organisations that process personal data on a large scale, but on the condition that one person can still control all processing.
Such a specialist should report directly to the Director of the company. This will ensure the independence of the employee and allow him/her to fulfil his/her duties effectively.
Suitable for: those who work with a small amount of personal data.
However, such an employee cannot be any person in the company.
Here are the requirements that need to be met:
For example, control over the implementation of organisational and legal measures for the processing of personal data is best entrusted to a lawyer. But control over the implementation of technical and cryptographic protection measures for personal data is better entrusted to an information security specialist. He or she will be responsible for developing and implementing technical security measures, controlling access to data, and detecting and responding to possible threats and breaches.
Or you can hire a contracted data protection specialist.
The National Centre for Personal Data Protection, during inspections in 2022, often detected violations such as the absence of a responsible person in the enterprise or the formal assignment of duties to some employee who cannot perform them.
Such violations are punishable by a fine of up to 50 basic units (part 4 of article 23.7 of the Code of Administrative Offences).
In addition, we would like to draw attention to an important point: the appointment of a data protection officer does not exempt a company from liability in the event of a breach of the Personal Data Protection Act. Simply put: this responsibility lies with the company as a whole, and the person in charge is responsible for fulfilling his or her duties.
Dear journalists, use of material from the REVERA website in publications is only possible with our written permission.
To approve material, please contact i.antonova@revera.legal or Telegram: https://t.me/PR_revera