1. The Management Board shall appoint a Data Protection Officer, who shall be a member of the staff. In the performance of his or her duties, he or she shall act independently.
2. The Data Protection Officer shall be selected on the basis of his or her personal and professional qualities and, in particular, the expert knowledge of data protection.
It shall be ensured in the selection of the Data Protection Officer that no conflict of interest may result from the performance of his or her duty in that capacity and from any other official duties, in particular those relating to the application of this Regulation.
3. The Data Protection Officer shall be appointed for a term of four years. He or she shall be eligible for reappointment up to a maximum total term of eight years. He or she may be dismissed from his or her function as Data Protection Officer by the Management Board only with the consent of the EDPS, if he or she no longer meets the conditions required for the performance of his or her duties.
4. After his or her appointment, the Data Protection Officer shall be registered with the EDPS by the Management Board.
5. With respect to the performance of his or her duties, the Data Protection Officer shall not receive any instructions.
6. The Data Protection Officer shall, in particular, have the following tasks with regard to personal data, with the exception of administrative personal data:
(a)
ensuring, in an independent manner, the internal application of this Regulation concerning the processing of personal data;
(b)
ensuring that a record of the transfer and receipt of personal data is kept in accordance with this Regulation;
(c)
ensuring that data subjects are informed of their rights under this Regulation at their request;
(d)
cooperating with Europol staff responsible for procedures, training and advice on data processing;
(e)
cooperating with the EDPS;
(f)
preparing an annual report and communicating that report to the Management Board and to the EDPS;
(g)
keeping a register of personal data breaches.
7. The Data Protection Officer shall also carry out the functions provided for by Regulation (EC) No 45/2001 with regard to administrative personal data.
8. In the performance of his or her tasks, the Data Protection Officer shall have access to all the data processed by Europol and to all Europol premises.
9. If the Data Protection Officer considers that the provisions of this Regulation concerning the processing of personal data have not been complied with, he or she shall inform the Executive Director and shall require him or her to resolve the non-compliance within a specified time.
If the Executive Director does not resolve the non-compliance of the processing within the time specified, the Data Protection Officer shall inform the Management Board. The Data Protection Officer and the Management Board shall agree a specified time for a response by the latter. If the Management Board does not resolve the non-compliance within the time specified, the Data Protection Officer shall refer the matter to the EDPS.
10. The Management Board shall adopt implementing rules concerning the Data Protection Officer. Those implementing rules shall, in particular, concern the selection procedure for the position of the Data Protection Officer and his or her dismissal, tasks, duties and powers, and safeguards ensuring the independence of the Data Protection Officer.
11. Europol shall provide the Data Protection Officer with the staff and resources needed in order for him or her to be able to carry out his or her duties. Those staff members shall have access to all the data processed at Europol and to Europol premises only to the extent necessary for the performance of their tasks.
12. The Data Protection Officer and his or her staff shall be bound by the obligation of confidentiality in accordance with Article 67(1).
Home› Justice & Home Affairs› Europol Regulation
Chapter VI · DATA PROTECTION SAFEGUARDS › Article 41
Data Protection Officer
←→ also move between articles