General Data Protection Regulation (GDPR) ambiguity, national diversity and data protection officer certification: Implementing Art. 39(1) GDPR in France, Italy, Luxembourg and Spain
Jacob Kornbeck — Journal of Data Protection Privacy
How it connects
Related across sources
Full text
The General Data Protection Regulation (GDPR) of the European Union (EU) does not always make legally binding provisions with unambiguous implications. The implementation of Art. 39(1) GDPR regarding the certification of Data Protection Officers (DPOs) is left to the discretion of Member States. This paper will show what action has been taken by the national data protection authorities (DPAs) of France, Italy, Luxembourg and Spain. Insights gained from examining the four national frameworks, which are quite dissimilar in many ways, will be compared and contrasted. This will lead to a systematic and teleological interpretation, as well as to a more general discussion of GDPR ambiguity and the prospect of fragmentation through national implementation diversity. The paper will conclude with some thoughts on the need for controllers to invest in qualified staff to perform DPO roles, as well as some reflection on the human resources (HR) policies of DPAs.