ERM approach argued for Data Protection Officers

FERMA has called for an ERM approach to be included in the Guidelines on Data Protection Officers (DPOs) in its comments to the Article 29 Working Party considering this aspect of the EU General Data Protection Regulation (GDPR).

FERMA comments on DPO guidelinesIn its submission to the working party, FERMA sees parallels between the roles of the data protection officer and risk managers and says that an ERM methodology will help ensure a professional approach to the assessment of data protection risks. It further argues that “three lines of defence model” is likely to be relevant in this process and could be updated to the latest cyber law requirements, including the GDPR and notably the new function of data protection officer.

FERMA also believes that the role of DPO does not necessarily need to be a newly created function. It could be exercised by existing positions in the organisation, notably the risk manager, with some adjustments, thus avoiding an extra cost layer.

FERMA has consistently stated that cyber/information security is an enterprise-wide risk and compliance with the GPDR cannot be the sole responsibility of the IT department. FERMA’s working party with the European Confederation of Institutes of Internal Auditing (ECIIA) is developing a set of recommendations on corporate governance processes that will support organisations in managing cyber risks across their operations.

Share with others

Subscribe to our newsletter

* indicates required
Interests

By subscribing to our newsletter, you agree that we may process your information in accordance with our Privacy policy.

You can change your mind at any time by clicking the unsubscribe link in the footer of any email you receive from us, or by contacting us at enquiries@ferma.eu.

We use MailChimp as our marketing platform. By subscribing to our newsletter, you acknowledge that your information will be transferred to MailChimp for processing. Learn more about MailChimp’s privacy practices here.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

If you disable this cookie, we will not be able to save your preferences. This means that every time you visit this website you will need to enable or disable cookies again.

3rd Party Cookies

This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping this cookie enabled helps us to improve our website.