Data Protection Officer (DPO)
The data protection officer monitors compliance with data protection law within an organization and is regularly required to be appointed by insurers due to their extensive processing of sensitive data.
Concept
The data protection officer is a person with particular expertise, required under the GDPR, who monitors an organization’s compliance with data protection law and serves as a point of contact for data protection matters for both management and the data subjects and the supervisory authority.
Appointment Obligation for Insurers
Due to their extensive processing of special categories of personal data, particularly health data in the course of underwriting and claims assessment, insurers are regularly required under the GDPR to appoint a data protection officer, regardless of company size.
Responsibilities and Independence
The data protection officer’s responsibilities include monitoring compliance with the GDPR and other data protection rules, advising management, conducting and supporting data protection impact assessments, and cooperating with the competent supervisory authority; the data protection officer must perform their tasks independently and free of conflicts of interest, and may not be dismissed or penalized for performing their duties.