FOI Request - Data Protection Officer
Request 101002575834
1. Could you let me know?
a. What position in the Council is designated as Senior Information Risk Owner (SIRO)?
b. The name of your Data Protection Officer (DPO)?
c. Job title of the DPO, if not just DPO?
d. If the DPO also has other duties, approximately how much of their time is spent on DPO work?
e. If the DPO has other responsibilities, has a risk assessment been carried out to ensure that any potential conflicts of interest as identified in the GDPR and the guidance from the European Data Protection Board are managed? If so, has this been reviewed in light of the recent decision of the Belgium Data Protection Authority (28 April 2020): https://edpo.com/news/dpo-and-conflict-of-interest-50-000e-fine-by-the-belgian-dpa/
f. The line manager of the DPO – i.e. the post that the post holder reports to. Is it the SIRO?
g. Who the DPO reports to in their role as DPO if that differs from the line manager? Is it the SIRO?
h. At what spinal point is the DPO paid?
i. Key relevant qualifications that the DPO and SIRO hold or relevant training completed.
2. And could you provide the relevant extract of the Council’s Organisational Chart that shows the DPO, the DPO’s line manager, the post holder that the DPO reports to, the SIRO and Chief Executive?
Response 15-09-2020
1. Information for A-C is published on the Council website and is therefore exempt under section 25 of the Freedom of Information (Scotland) Act 2002, information otherwise accessible. For ease of reference please find links to the web page here and see Elements 1 and 2.
d. Specific amounts of time are not allotted to different duties as tasks are fulfilled according to evolving priorities and needs.
e. No specific Risk Assessment has been undertaken, however there is currently some internal analysis of the post being undertaken.
Information for F-I is published on the Council website and is therefore exempt under section 25 of the Freedom of Information (Scotland) Act 2002, information otherwise accessible. For ease of reference please find links to the web page here and see Element 2.
2. In accordance with section 17 of the Freedom of Information (Scotland) Act 2002 please be advised that a structure chart is not held. We can, however, list the relevant posts below:
Records and Heritage Manager > Principal Librarian > Head of Education Resources & Communities > Depute Chief Executive for Education, Communities & Organisational Development > Chief Executive