Académie / DPO — Data Protection

DPO Annex · GDPR · Cours

Data protection: legal bases, sensitive data, DPIA, roles

The GDPR in its own right — legal bases, sensitive data, impact assessment, controller/processor, DPO independence. The world of DPO certification.

3 sections

1Legal bases and impact assessment

Every processing activity needs a legal basis art. 6: consent, contract, legal obligation, vital interest, public interest task, or legitimate interest (weighed against individuals' rights — but not available to public authorities for the performance of their tasks).

When processing is likely to result in a high risk (new technologies, large-scale profiling, sensitive data…), a DPIA (Data Protection Impact Assessment, art. 35) is mandatory — a high-risk AI system triggers it almost every time.

The bridge with art. 10. Measuring bias requires processing art. 9 data (sensitive). The GDPR prohibits this in principle; art. 10(5) of the AI Act opens the door, under strict necessity and with safeguards (minimization, restricted access and retention, security/pseudonymization, no transfer, deletion after use). The DPO knows how to reconcile these two texts — while the signing expert under art. 10 attests to the compliance of the data (representativeness, bias, quality). Beware of a conflict of interest if the same person designs the processing and attests to it.

2Roles and DPO independence

Controller (determines purposes and means) vs processor (acts on behalf of, and under the instructions of, the controller) art. 28. This qualification determines who is accountable for what.

The DPO advises, monitors compliance, is the point of contact for the authority and for individuals, and raises awareness. They carry out their duties in full independence, free of conflicts of interest, report to the highest level of management, and cannot be penalized for performing their functions. They advise and monitor — they do not decide on processing activities: responsibility for compliance remains with the controller (accountability). Their appointment is mandatory in certain cases art. 37: public authority or body, large-scale systematic monitoring, or large-scale processing of sensitive data.

3Practical obligations and individuals' rights

Consent and rights

When used as the basis, consent must be freely given, specific, informed and unambiguous (and revocable). Individuals have rights: access, rectification, erasure (under conditions), objection, portability — but not a "right to demand a perfect model."

The building blocks of accountability

  • Register of processing activities art. 30: lists the processing activities — a key tool for demonstrating compliance.
  • DPIA art. 35: description of the processing, risk assessment for individuals, mitigation measures — mandatory in case of high risk.
  • Breach notification: to the authority within 72 hours of becoming aware, if the breach presents a risk.
Protection by design. Privacy by design & by default art. 25 requires integrating data protection upfront and setting it as the default configuration — not as a last-minute patch.