For a Significant Data Fiduciary, the DPO occupies a distinct statutory position. The organisation should provide an official channel that reaches the DPO or DPO function. A general customer-service address will not be adequate where the support team cannot explain processing or coordinate the exercise of rights.
For other Data Fiduciaries, the authorised person could be a privacy officer, compliance officer, legal representative, grievance officer or another trained function. The Rule does not demand a particular designation.
However, merely naming an employee does not establish compliance. The designated person must be able to obtain reliable information concerning:
-
personal data collected or generated;
-
purposes of processing;
-
consent and other grounds relied upon;
-
relevant systems;
-
disclosures and Data Processors;
-
retention and erasure;
-
withdrawal of consent;
-
correction and access procedures;
-
grievances;
-
and breach-related questions.
The person does not need to know every technical detail immediately. The organisation must nevertheless give the contact sufficient authority, internal access and escalation support to obtain the answer and communicate it accurately.
Illustration
A customer asks an online retailer why her mobile number has been supplied to a delivery provider and whether the provider may send promotional messages.
The privacy contact should be able to determine:
-
why the number was originally shared;
-
whether the delivery provider acts as a Data Processor;
-
what contractual restrictions govern its use;
-
whether promotional use was authorised;
-
whether consent was obtained for marketing;
-
and what corrective step is required.
Telling the customer simply to contact the delivery provider would be inadequate if the retailer determined the original purpose and shared the data for processing on its behalf.