Conflicts of interest among data protection officers can lead to fines

Last updated:
07.12.2022
Appointing a data protection officer is essential for any company. However, it is crucial to mitigate the risk of a conflict of interest when making this decision. Read on to find out what you need to consider.
Conflicts of interest among data protection officers can lead to fines
Key Takeaways
  • Conflicts of interest involving data protection officers can lead to heavy fines.
  • Data protection officers must be neutral and independent.
  • Executives and members of the works council are often unsuitable for the role of DPO.
  • External data protection officers help to avoid conflicts of interest.
  • Supervisory authorities monitor conflicts of interest and impose fines.

Corporate data protection officers have a significant responsibility: they do not just advise your company on all data protection obligations; they also monitor compliance with data protection regulations. Specific requirements are in place to ensure this role is performed reliably. Failure to meet these can quickly lead to a conflict of interest for a data protection officer, which is contrary to GDPR provisions. Such a conflict of interest can prove very costly for companies, as demonstrated by a recent case involving a Berlin-based retail group. In this instance, a fine of 525,000 euros was imposed on a corporate data protection officer. Read on to learn more about the situation and how an external DPO can help prevent conflicts of interest.

Involve an external data protection officer now

The 525,000 euro fine shows that conflicts involving data protection officers can occur and, in the worst-case scenario, violate GDPR provisions. We advise companies as external data protection officers, ensuring that you and your company remain on the safe side.

When does a conflict of interest arise for data protection officers?

A data protection officer should maintain a neutral perspective on all data protection matters within the company. This requires that the individual in question has no influence over the purposes for which personal data is processed within the company. Furthermore, the means used for such processing must not fall within the DPO's scope of duties and responsibilities.

There are three different types of conflicts of interest that make it impossible for a data protection officer to perform their duties:

  • When interests unrelated to data protection influence the advice provided to the company.
  • When the conscientious and comprehensive monitoring and oversight of data protection are jeopardized by personal interests.
  • When neutrality in dealings with supervisory authorities cannot be guaranteed, as the proper representation of data protection matters can only be ensured by a neutral data protection officer.

Consequently, individuals in senior or upper-middle management are not suitable for the role of data protection officer. Employees in leadership positions make key decisions regarding the processing of personal data within their company; in the role of DPO, they would essentially be monitoring themselves. Conflicts of interest for data protection officers also frequently occur with members of the works council, where different areas of responsibility regarding the handling of personal data collide.

Commentary by Prof. Dr. Boris Paal

"To avoid data protection violations, it is essential to examine any dual roles held by data protection officers for potential conflicts of interest in the interest of data protection compliance. Determining whether a 'genuine' conflict of interest exists under the GDPR requires an assessment of the specific individual case. In general, conflicts of interest can be avoided by separating operational and supervisory tasks."

Conflicts of interest are also monitored by supervisory authorities

A corporate data protection officer can quickly find themselves in a conflict of interest. This puts SMEs in a particularly difficult position, as smaller companies often face the problem of having no staff below the management level who possess the professional qualifications and expertise required for the role. Yet, consistent compliance with regulations is absolutely essential. Data protection officers not only work closely with supervisory authorities but are also monitored by them. While supervisory authorities assess individual cases on their own merits, they are in agreement on the overarching principles: a member of the management board cannot simultaneously fulfill the role of DPO without risking a conflict of interest. The urgency of this is highlighted by a recent example: despite repeated warnings from supervisory authorities, a Berlin-based company failed to address allegations of a conflict of interest and is now facing heavy fines.

This fine is causing a stir

In the view of the supervisory authorities, this case represents a classic conflict of interest: the subsidiary of a Berlin-based e-commerce group appointed a data protection officer who was also the managing director of two of the company's service providers. These entities were also part of the group, handling customer service and order fulfillment. The companies were processing personal data on a large scale, and the DPO was tasked with monitoring the practices of companies in whose management he himself was involved. The Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) viewed this as a clear case of a conflict of interest and, therefore, a violation of the GDPR. The supervisory authority initially issued a warning to the company in 2021. After the violation was not rectified, it imposed a fine of 525,000 euros, which, as of today, is not yet legally binding. The fine is based on the company's triple-digit million-euro turnover from the previous year and takes into account, among other things, the significant role of the DPO given the high number of employees and customers.

Responsible implementation of data protection and GDPR compliance can only be achieved by a data protection officer who is free from conflicts of interest. Neutrality is an absolute must here. This precludes the DPO from determining the purposes and means of personal data processing in any other capacity for their company, as they would effectively be monitoring themselves. This poses a particular challenge for SMEs, which often lack sufficient staff who meet all the necessary requirements. Appointing an external data protection officer mitigates the risk of a conflict of interest. They should have no ties to the company and hold no other roles that could trigger a conflict. Our team of data protection experts is happy to advise you on all matters of data protection law. Simply get in touch with us and book an appointment today!

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
60+ Expertinnen und Experten
Book a consultation
Topics
Editorial
Alexander Ingelheim
Co-Founder & CEO
Alexander Ingelheim is Co-founder and CEO of Proliance. His driving force from day one has been to support companies with the hurdles and challenges of data protection and GDPR. He brings extensive experience from his work in international consulting, including positions at Bregal Unternehmerkapital GmbH and McKinsey & Company. He is also a certified Data Protection Officer (TÜV & DEKRA).
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in