In connection with the effectiveness of the GDPR regulation and the newly established institute of the personal data protection officer, a "fight" for this profession can be observed on the relevant market. The GDPR does not specify a legal education as a condition for the performance of this function, and so many other subjects from various fields (IT technicians, auditors, compliance managers, or graduates of various crash courses promoting themselves with a certificate from any institution, which are not even half a year old) are grinding their teeth to perform this position since the effective date of the GDPR, it has already been around like a mushroom).
In addition, the practices applied by individual candidates for this position are beginning to be predatory, which is somewhat surprising considering the fact that trustees are still rather a scarce commodity. A popular practice in particular is the so-called negative comparative advertising in the style of citing reasons why someone else cannot perform this profession (the controversy as to whether in a specific case such comparative advertising is not deceptive and does not border on anti-competitive behavior can be left for another time). Lawyers are a popular target for negative comparisons, perhaps because the appointment of a lawyer to the position of trustee is a natural and first choice for many administrators in view of the GDPR's basic requirement that the trustee has expert knowledge of law and practice in the field of data protection. So what have we read about lawyers as "unsuitable" candidates for the position of commissioner [1] did they listen? Here's a quick outline:
- A lawyer, or a lawyer in general, is never independent and cannot meet the GDPR requirement of no conflict of interest.
- Some law firms or lawyers will try to nominate to the position of commissioner with the intention of increasing the billing volume of services outside their area of competence.
- Most law firms or lawyers, with regard to the various specializations, will not be sufficiently familiar with the legal regulation and application practice regarding the protection of personal data.
- Even if a few law firms or lawyers will be real experts in personal data protection, will that be enough to be GDPR mandated?
- Unlike lawyers, a professional trustee must understand what the law requires and how to implement it in an operational sense. Thus, the appointee must be able to identify risks of breach of regulations, determine and carry out controls, ensure that instructions are in accordance with all operational and legal requirements, provide advice in relation to process changes to ensure their compliance with regulations, oversee relationships with processors, while allegedly none of these activities are the work of lawyers.
- In addition to legal knowledge, the trustee also needs to understand IT, information security, communication and marketing.
- The role and responsibilities of a trustee are so broad and require so much practical experience with the running of an organization that the narrow focus of a lawyer is insufficient.
- The trustee does not only need to know what the law says, but what it means and how it applies to trustees' activities. You don't need to be a lawyer to understand the law.
Nice collection, what do you say? According to the EU Working Party on Data Protection (WP29), the data controller should also have a certain standard of moral integrity and ethics [2].However, at least these qualities can be doubted in the case of the promoters of the advertisement outlined above.
Before we make further conclusions in relation to the above statements, let us recall what the GDPR stipulates in relation to the trustee, the prerequisites for the performance of this profession and his basic tasks.
Article 37 paragraph 5 of the GDPR states that the data protection officer must be appointed on the basis of his professional qualities, in particular his expertise in data protection law and practice and his ability to perform the tasks set out in Article 39 of the GDPR. Among the duties of the commissioner set out in Article 39, paragraph 1 of the GDPR, are:
a) providing information and advice to administrators in accordance with the GDPR and other regulations of the Union or member states in the field of data protection;
b) monitoring compliance with this regulation, other regulations of the Union or Member States in the field of data protection and with the concepts of the administrator or processor in the field of personal data protection, including the division of responsibility, awareness raising and professional training of workers involved in processing operations and related audits;
c) providing advice on request regarding personal data protection impact assessment and monitoring its application;
d) cooperation with the supervisory authority;
e) acting as a point of contact for the supervisory authority in matters relating to processing, including prior consultation pursuant to Article 36 of the GDPR, and possibly leading consultations in any other matter.
It is clear from the above that the trustee does not necessarily have a legal education. However, most of his tasks are related to the interpretation, application, legal advice and monitoring of the development and compliance of the entire range of regulations, not only in the area of personal data protection. Good luck to those brave enough to take a course of several days to perform this activity. It could also be disputed whether or not the activities of the trustee are or are not the provision of legal services and whether, in the case of these persons, it is not a matter of accounting (even if, according to the official statements of the Czech Bar Association (ČAK), the performance of the trustee's activities is not the provision of legal services in the sense of the Act on Advocacy, but it is a different activity of a lawyer within the meaning of § 56 of the Act on Advocacy) [3].
There is no doubt that a suitable candidate for the position of commissioner is a lawyer, even the international organization IAPP (International Association of Privacy Professionals) recommends that the position of commissioner be held by an experienced lawyer or an information systems auditor who is oriented to the protection of personal data or technological law [4] . However, in order not to lower ourselves to the level of our "competitors" in the proxy market, we will not categorically claim that only lawyers are the only suitable candidates for this position and all the criticisms outlined above against them are ridiculous, but we will constructively evaluate their validity.
First of all, it must be admitted that the requirement to prohibit conflicts of interest limits the performance of the position of trustee both by lawyers and by the in-house lawyers of individual administrators. The Office for the Protection of Personal Data (ÚOOÚ) concluded that a conflict of interest may constitute a special law if the trustees could at certain moments make it impossible for them to act (e.g. special confidentiality of lawyers) [5] . The Council of European Bar Associations (CCBE) warns [6] , that the assimilation of the two functions (lawyer vs. trustee) and the risk of confusion between these functions is a key concern for any attorney who might be appointed as a trustee at the request of a client. It may happen that the lawyer will have to alternate between the function of an attorney and the function of a lawyer performing a regulated profession. A lawyer in the position of trustee must ensure independence and prevent conflicts of interest, especially conflicts that may result from the fact that, from the position of trustee, he will also have to act against the interests of the administrator (e.g. reporting obligation to the ÚOOÚ), while he is also obliged to represent the interests of the client to the full extent permitted by law. In this context, the CAK recommends its members to clearly define in the contract with the client the activities that cannot be performed in order to avoid a conflict of interest (e.g. that the lawyer will not represent the client in court in a case related to the protection of personal data) [7]. According to the ČAK, a lawyer in the role of a trustee should first and foremost consistently exclude all forms of legal representation and legal advice both in the area of processing and protection of personal data, and in areas to which the processing of such data necessarily relates (e.g. labor law issues, e-commerce and marketing etc.). In connection with the performance of the function of trustee for several clients, there have also been arguments about the conflict of interests between these individual clients, who may be in a competitive position. In particular, the ÚOOÚ is of the opinion that it is appropriate to consider the competitive point of view, when one representative can provide services for a competitor, and there is a risk of disclosure of know-how [8]. In this context, however, one can agree with the authors of the comment on the GDPR that the commissioner, within the scope of his prescribed role, is not a person who should advise on business relations and procedures between competitors, so they should not even be able to influence him (prescribed by the regulation) ) activity. Therefore, only the conflict of interests in the area of personal data protection should be decisive [9]. Indeed, the opposite conclusion could significantly limit the availability of this service, which would have the greatest impact on small and medium-sized enterprises, for which, for example, internal provision of the function of the trustee often will not make economic sense. However, as the authors of the comments on the GDPR aptly note, the correctness of this opinion will eventually be confirmed only by the relevant decision-making practice.
Even in-house lawyers in the role of trustees cannot avoid the risk of conflict of interests. Thus, for example, according to established German practice (where special entities for the protection of personal data have existed for many years), the position of commissioner should probably not be held by an in-house lawyer responsible for ensuring the protection of personal data. It is true that an in-house attorney has a great advantage in knowing the administrator's internal processes and security measures better than an outside attorney. According to the WP29 working group, however, it is necessary to ensure that the person in charge is never in a position to determine or bindingly approve the purposes or means of processing - in such a case, he could end up in a situation where, from the position of the person in charge, he controls his own (other) activity [10]. In this context, it is also possible to mention the conflict of interest between the data subject, whose rights the trustee is obliged to protect and enforce, and the administrator, who, on the other hand, employs the trustee and in whose interest the trustee should act in accordance with labor law regulations.
The other criticisms mentioned above in relation to the performance of the function of attorney by lawyers can be thrown into the same bag, as they all point to the lawyers' lack of professional knowledge and experience, especially in the field of IT security and related processes, incl. carrying out risk analyses, audits, controls, etc. The stated argument is also justified to a certain extent. After all, it is impossible to competently supervise the practical security and protection of personal data without any orientation in this area. However, this aspect is remembered by the GDPR itself, which, in Article 38, paragraph 1 and paragraph 2, stipulates for administrators and processors the obligation for the person in charge to be properly and timely involved in all matters related to the protection of personal data. Furthermore, the administrator and the processor have the obligation to support the trustee in the performance of his tasks by providing him with the resources necessary to perform these tasks, to access personal data and processing operations and to maintain his expertise.
The trustee should thus have the support of individual relevant departments of the administrator, such as IT, internal audit, compliance, human resources, security, etc. He should be able to obtain from these departments not only the information necessary to fulfill his tasks, but also secondary support. With the support of the given components, the lawyer should be able to competently fulfill the function of a trustee. After all, such cooperation between a lawyer and experts (experts, expert staff of clients, etc.), on the basis of which the lawyer builds his outputs in practice, is a common and often inevitable practice in the work of lawyers. In the light of the above, the above-mentioned complaints are still unfounded.
However, this "tussle" of lawyers and experts from other relevant fields to perform the position of trustee is natural in view of the requirements of the GDPR for the performance of this profession. As mentioned above, the commissioner should have expert knowledge not only of law but also of practice in the field of data protection, as he will have to analyze and evaluate the effectiveness of data protection security measures. However, such a combination of legal and IT education is quite rare. For administrators who are responsible for selecting a high-quality trustee, the most ideal and uncertain solution appears to be the appointment of a "collective" trustee, i.e. a team that includes both a lawyer and an IT security expert. The introduction of such a department internally within the administrator's organizational structure may not pose a problem, but this solution may not be problematic in the case of external trustees either. In this context, the ÚOOÚ expressed that the service of a trustee can also be provided by a legal entity, referring to the provisions of the GDPR, which enables the functioning of a trustee even on the basis of a contract for the provision of services [11]. However, according to the ÚOOÚ, in the event that the service is provided by a legal entity, a specific natural person who will perform the service must always be designated. The ČAK also gave a positive opinion on the given concept, which confirmed that a lawyer can establish a separate company to carry out the activities of a trustee [12]. Such companies, whose members are both lawyers and IT and privacy security experts, already exist in our practice.
The specific choice of a trustee as an expert in which area and the modalities of performing his function depends on the specific administrator, his circumstances and needs. WP29 confirms that the level of expertise required is not well defined, but must be appropriate to the sensitivity, complexity and amount of data that the organization processes [13]. For example, if the data processing activity is particularly complex or involves a large amount of sensitive data, the data controller may need a higher level of expertise and support. There is also a difference depending on whether the organization systematically transfers personal data outside the EU or whether such transfers are occasional. In the case of systematic transfer, a lawyer will be necessary at least as a member of the commissioner's team, as it will be necessary to assess the legal systems of the countries to which the data will be transferred, whether they provide sufficient data protection guarantees.
In general, the person in charge should have sufficient skills to fulfill their tasks according to the GDPR. However, this does not mean that he must necessarily be an expert in IT, security, law and human resources, the combination of such a complex qualification is almost unrealistic in practice. From the point of view of the GDPR, it is sufficient if the person in charge has sufficient knowledge of these areas [14]. The administrator should then provide the trustee with access to experts in these areas within other departments of the organization or externally or, if necessary, directly within his team. From this point of view, it seems undecided whether the trustee will be a lawyer with the support of other departments or an expert with the support of a lawyer. So it seems that there is no clear winner in the competition for trustees and that the key to success will be the ability to rein in the ego and recognize the qualities of the other, including the necessity of mutual cooperation.
Source: epravo Magazine 4/2018

Mgr. Zuzana Gajdošová,
Attorney
[1] Compare eg the verbal exchange between Thomas Shaw and Emma Butler (both trustees) on the IAPP platform, available here: https://iapp.org/news/a/two-pros-square-off-must-the-dpo-be-a-lawyer/ or an article entitled "Why a lawyer shouldn't be a DPO" on the blog of a leading UK proxy services company: https://blog.dpo-experts.com/blank/why-a-lawyer-shouldnt-be-a-dpo
[2] See WP29 Guidance on Data Protection Officers
[3] Compare ČAK website, GDPR section, FAQ: https://www.cak.cz/scripts/detail.php?id=18807
[4] Compare ČAK website, GDPR section, FAQ: https://www.cak.cz/scripts/detail.php?id=18807
[5] Compare ÚOOÚ website, GDPR section, Basic Guide to GDPR, Commissioner for Personal Data Protection: https://www.uoou.cz/9-poverenec-pro-nbsp-ochranu-osobnich-udaju/d-27280/p1=4744
[6] See CCBE guidance on key measures for lawyers to comply with the GDPR, available here: http://www.bulletin-advokacie.cz/doporuceni-ccbe-ohledne-klicovych-opatreni
[7] Compare ČAK website, GDPR section, FAQ: https://www.cak.cz/scripts/detail.php?id=18807
[8] Compare ÚOOÚ website, GDPR section, Basic Guide to GDPR, Commissioner for Personal Data Protection: https://www.uoou.cz/9-poverenec-pro-nbsp-ochranu-osobnich-udaju/d-27280/p1=4744
[9] Nulíček, Donát, Nonnemann, Lichnovský, Tomíšek, GDPR. General Regulation on the Protection of Personal Data. Practical commentary. Prague: Wolters Kluwer CR, 2017. 544 p.
[10] Nulíček, Donát, Nonnemann, Lichnovský, Tomíšek, GDPR. General Regulation on the Protection of Personal Data. Practical commentary. Prague: Wolters Kluwer CR, 2017. 544 p.
[11] According to Article 37, paragraph 6 of the GDPR, the personal data protection officer may be an employee of the administrator or processor, or may perform tasks on the basis of a contract for the provision of services.
[12] Compare ČAK website, GDPR section, FAQ: https://www.cak.cz/scripts/detail.php?id=18807
[13] See WP29 Guidance on Data Protection Officers.
[14] Nulíček, Donát, Nonnemann, Lichnovský, Tomíšek, GDPR. General Regulation on the Protection of Personal Data. Practical commentary. Prague: Wolters Kluwer CR, 2017. 544 p.