{"id":2388,"date":"2017-05-18T10:16:28","date_gmt":"2017-05-18T09:16:28","guid":{"rendered":"http:\/\/mouillere.com\/universconvergents\/?p=2388"},"modified":"2017-05-18T10:24:08","modified_gmt":"2017-05-18T09:24:08","slug":"le-nouveau-data-protection-officer-dpo","status":"publish","type":"post","link":"https:\/\/mouillere.com\/universconvergents\/2017\/05\/18\/le-nouveau-data-protection-officer-dpo\/","title":{"rendered":"Le nouveau Data Protection Officer (DPO)"},"content":{"rendered":"<p>Le\u00a0R\u00e8glement du 27 avril 2016 relatif \u00e0 la protection des personnes physiques \u00e0 l\u2019\u00e9gard du traitement des donn\u00e9es \u00e0 caract\u00e8re personnel et \u00e0 la libre circulation de ces donn\u00e9es (\u00ab RGDP \u00bb) a cr\u00e9\u00e9 le DPO charg\u00e9\u00a0d&#8217;assurer un r\u00f4le d\u2019interm\u00e9diaire entre\u00a0les\u00a0entreprises et la CNIL.<\/p>\n<p><!--more--><\/p>\n<p>Le DPO va devenir obligatoire d&#8217;ici un an pour :<\/p>\n<ul>\n<li><strong>les traitements qui exigent un suivi r\u00e9gulier et syst\u00e9matique \u00e0 grande \u00e9chelle<\/strong>;<\/li>\n<li><strong>les traitements \u00e0 grande \u00e9chelle des donn\u00e9es particuli\u00e8res<\/strong> (ex. : sant\u00e9)<\/li>\n<li><strong>les traitement des donn\u00e9es personnelles effectu\u00e9s par les autorit\u00e9s et organismes publiques.<\/strong><\/li>\n<\/ul>\n<p>Le\u00a0DPO peut \u00eatre un membre du personnel du responsable de traitement ou du sous-traitant, mais \u00e9galement \u00eatre externe \u00e0 l\u2019entreprise et accomplir ses missions sur la base d\u2019un contrat de services (ex. : avocat).<\/p>\n<p>Le DPO aura pour missions :<\/p>\n<ul>\n<li>d&#8217;aviser et de conseiller l\u2019entreprise notamment dans le cadre analyses d\u2019impact pr\u00e9vues \u00e0 l\u2019article 35 du RGDP afin d&#8217;\u00e9valuer\u00a0les risques que pr\u00e9sente un projet de traitement de donn\u00e9es personnelles ;<\/li>\n<li>de contr\u00f4ler le respect du RGDP;<\/li>\n<li>d&#8217;\u00eatre\u00a0le point de contact de la CNIL;<\/li>\n<li>de tenir le registre d\u2019activit\u00e9 qui remplace les d\u00e9clarations CNIL.<\/li>\n<\/ul>\n<p>Il devra donc :<\/p>\n<ul>\n<li>\u00eatre nomm\u00e9 par le biais d\u2019une communication interne au sein de l\u2019entreprise;<\/li>\n<li>disposer de supports, de temps, de ressources financi\u00e8res, d\u2019infrastructures;<\/li>\n<li>\u00eatre mis en relation avec les autres directions de l\u2019entreprise;<\/li>\n<li>\u00eatre invit\u00e9 aux r\u00e9unions importantes en mati\u00e8re de\u00a0donn\u00e9es personnelles;<\/li>\n<li>\u00eatre consult\u00e9 pour tout incident impactant les donn\u00e9es personnelles;<\/li>\n<li>exercer ses missions dans le respect du secret professionnel ou d\u2019une obligation de confidentialit\u00e9<\/li>\n<\/ul>\n<p>Le responsable de traitement et le sous-traitant doivent veiller \u00e0 ce que le DPO ne re\u00e7oive aucune instruction en ce qui concerne l\u2019exercice de ses missions. Le DPO ne peut \u00eatre relev\u00e9 de ses fonctions ou p\u00e9nalis\u00e9 du fait de l\u2019exercice de ses missions\u00a0(sanction disciplinaire, absence ou de retard dans l\u2019octroi de promotion, absence de prime).<\/p>\n<p>Le DPO n\u2019est pas personnellement responsable des manquements du responsable de traitement ou du sous-traitant.<\/p>\n<iframe src=\"\/\/docs.google.com\/viewer?url=https%3A%2F%2Fmouillere.com%2Funiversconvergents%2Fwp-content%2Fuploads%2F2017%2F05%2FD%C3%89L%C3%89GU%C3%89-%C3%80-LA-PROTECTION-DES-DONN%C3%89ES.pdf&hl=fr&embedded=true\" class=\"gde-frame\" style=\"width:100%; height:500px; border: none;\" scrolling=\"no\"><\/iframe>\n<p class=\"gde-text\"><a href=\"https:\/\/mouillere.com\/universconvergents\/wp-content\/uploads\/2017\/05\/D\u00c9L\u00c9GU\u00c9-\u00c0-LA-PROTECTION-DES-DONN\u00c9ES.pdf\" class=\"gde-link\">T\u00e9l\u00e9charger (PDF, 1.08Mo)<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Le\u00a0R\u00e8glement du 27 avril 2016 relatif \u00e0 la protection des personnes physiques \u00e0 l\u2019\u00e9gard du traitement des donn\u00e9es \u00e0 caract\u00e8re personnel et \u00e0 la libre circulation de ces donn\u00e9es (\u00ab&hellip; <\/p>\n","protected":false},"author":1,"featured_media":2389,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[16],"tags":[48],"class_list":["post-2388","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-donnees-personnelles","tag-cnil"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2017\/05\/GDPR-en.png?fit=1101%2C560&ssl=1","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p6jw1p-Cw","jetpack-related-posts":[{"id":2529,"url":"https:\/\/mouillere.com\/universconvergents\/2017\/06\/10\/data-privacy-officer-dpo\/","url_meta":{"origin":2388,"position":0},"title":"Data Privacy Officer (DPO)","author":"Fred","date":"10 juin 2017","format":false,"excerpt":"L\u2019article 37 du r\u00e8glement europ\u00e9en 2016\/679 du 27 avril 2016 (RGDP) contraint certains responsables de traitement de d\u00e9signer un D\u00e9l\u00e9gu\u00e9 \u00e0 la protection des donn\u00e9es (DPO) aupr\u00e8s des autorit\u00e9s de contr\u00f4le (la CNIL en France).\u00a0Les responsables de traitement et les sous-traitants devront d\u00e9signer un DPO s\u2019ils appartiennent au secteur public,\u2026","rel":"","context":"Dans &quot;Donn\u00e9es personnelles&quot;","block_context":{"text":"Donn\u00e9es personnelles","link":"https:\/\/mouillere.com\/universconvergents\/category\/it\/donnees-personnelles\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2017\/06\/role-of-the-data-protection-officer-18-638.jpg?fit=638%2C479&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2017\/06\/role-of-the-data-protection-officer-18-638.jpg?fit=638%2C479&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2017\/06\/role-of-the-data-protection-officer-18-638.jpg?fit=638%2C479&ssl=1&resize=525%2C300 1.5x"},"classes":[]},{"id":3544,"url":"https:\/\/mouillere.com\/universconvergents\/2020\/01\/14\/rgpd-laccountability-concretement-cest-quoi\/","url_meta":{"origin":2388,"position":1},"title":"RGPD : l&#8217;accountability, concr\u00e8tement, c&#8217;est quoi ?","author":"Fred","date":"14 janvier 2020","format":false,"excerpt":"Le Village de la Justice consacre un article listant les documents devant composer le dossier de conformit\u00e9\u00a0 selon le principe d'accountability de l\u2019article 5 du RGPD qui impose aux entreprises de mettre en \u0153uvre des m\u00e9canismes et des proc\u00e9dures internes permettant de d\u00e9montrer \u00e0 tout moment le respect des r\u00e8gles\u2026","rel":"","context":"Dans &quot;Donn\u00e9es personnelles&quot;","block_context":{"text":"Donn\u00e9es personnelles","link":"https:\/\/mouillere.com\/universconvergents\/category\/it\/donnees-personnelles\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2020\/01\/accountability.png?fit=670%2C395&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2020\/01\/accountability.png?fit=670%2C395&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2020\/01\/accountability.png?fit=670%2C395&ssl=1&resize=525%2C300 1.5x"},"classes":[]},{"id":6213,"url":"https:\/\/mouillere.com\/universconvergents\/2024\/09\/09\/kourou-sans-dpo-sanctionnee-par-la-cnil\/","url_meta":{"origin":2388,"position":2},"title":"Kourou sans DPO sanctionn\u00e9e par la CNIL","author":"Fred","date":"9 septembre 2024","format":false,"excerpt":"Kourou, port de l'espace europ\u00e9en aux finances d\u00e9j\u00e0 fragiles, a \u00e9t\u00e9 sanctionn\u00e9e par la Cnil pour ne s\u2019\u00eatre toujours pas conform\u00e9e \u00e0 son obligation de d\u00e9signer un D\u00e9l\u00e9gu\u00e9 \u00e0 la Protection des Donn\u00e9es (DPO). La commune de Kourou, en tant qu\u2019autorit\u00e9 publique, a pour obligation de d\u00e9signer un d\u00e9l\u00e9gu\u00e9 \u00e0\u2026","rel":"","context":"Dans &quot;Donn\u00e9es personnelles&quot;","block_context":{"text":"Donn\u00e9es personnelles","link":"https:\/\/mouillere.com\/universconvergents\/category\/it\/donnees-personnelles\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2024\/09\/procedures_sanctions_kourou-scaled.jpg?fit=1200%2C471&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2024\/09\/procedures_sanctions_kourou-scaled.jpg?fit=1200%2C471&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2024\/09\/procedures_sanctions_kourou-scaled.jpg?fit=1200%2C471&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2024\/09\/procedures_sanctions_kourou-scaled.jpg?fit=1200%2C471&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2024\/09\/procedures_sanctions_kourou-scaled.jpg?fit=1200%2C471&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":2717,"url":"https:\/\/mouillere.com\/universconvergents\/2017\/11\/04\/privacy-on-track\/","url_meta":{"origin":2388,"position":3},"title":"Privacy On Track","author":"Fred","date":"4 novembre 2017","format":false,"excerpt":"Afin d\u2019accompagner les entreprises dans leur mise en conformit\u00e9 au R\u00e8glement europ\u00e9en sur la protection des donn\u00e9es personnelles (RGPD ou GDPR) qui entrera en vigueur le 25 mai 2018, Staub & Associ\u00e9s propose une solution permettant notamment de\u00a0cartographier le traitement de donn\u00e9es personnelles, mettre en oeuvre une gouvernance de la\u2026","rel":"","context":"Dans &quot;Donn\u00e9es personnelles&quot;","block_context":{"text":"Donn\u00e9es personnelles","link":"https:\/\/mouillere.com\/universconvergents\/category\/it\/donnees-personnelles\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2017\/11\/privacy-on-track-schema.jpg?fit=800%2C424&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2017\/11\/privacy-on-track-schema.jpg?fit=800%2C424&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2017\/11\/privacy-on-track-schema.jpg?fit=800%2C424&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2017\/11\/privacy-on-track-schema.jpg?fit=800%2C424&ssl=1&resize=700%2C400 2x"},"classes":[]},{"id":2806,"url":"https:\/\/mouillere.com\/universconvergents\/2018\/09\/25\/bilan-des-4-mois-de-rgpd-en-france\/","url_meta":{"origin":2388,"position":4},"title":"Bilan des 4 mois de RGPD en France","author":"Fred","date":"25 septembre 2018","format":false,"excerpt":"La CNIL vient de publier son bilan apr\u00e8s 4 mois de RGPD en France. Parmi ces chiffres, nous pouvons souligner que: 24 500 organismes ont d\u00e9sign\u00e9 un DPO ce qui repr\u00e9sente 13 000 DPO contre 5 000 CIL (correspondants informatique et libert\u00e9s) avant le RGPD ; \u00a0 Plus de 600\u2026","rel":"","context":"Dans &quot;Donn\u00e9es personnelles&quot;","block_context":{"text":"Donn\u00e9es personnelles","link":"https:\/\/mouillere.com\/universconvergents\/category\/it\/donnees-personnelles\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2018\/09\/visuel_actu_11.jpg?fit=975%2C500&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2018\/09\/visuel_actu_11.jpg?fit=975%2C500&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2018\/09\/visuel_actu_11.jpg?fit=975%2C500&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2018\/09\/visuel_actu_11.jpg?fit=975%2C500&ssl=1&resize=700%2C400 2x"},"classes":[]},{"id":2475,"url":"https:\/\/mouillere.com\/universconvergents\/2017\/06\/05\/les-entreprises-seront-elles-en-conformite-avec-le-rgdp-en-mai-2018\/","url_meta":{"origin":2388,"position":5},"title":"Les entreprises seront-elles en conformit\u00e9 avec le RGDP en mai 2018 ?","author":"Fred","date":"5 juin 2017","format":false,"excerpt":"Le 25 mai 2018, les entreprises europ\u00e9ennes devront appliquer le RGDP et s\u2019assurer de la s\u00e9curisation des donn\u00e9es. Elles seront enti\u00e8rement responsables de la cha\u00eene de traitement des donn\u00e9es et devront s\u2019assurer des garanties apport\u00e9es par les sous-traitants et fournisseurs. Les entreprises de plus de 250 salari\u00e9s devront tenir un\u2026","rel":"","context":"Dans &quot;Donn\u00e9es personnelles&quot;","block_context":{"text":"Donn\u00e9es personnelles","link":"https:\/\/mouillere.com\/universconvergents\/category\/it\/donnees-personnelles\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2017\/06\/34042190.jpg?fit=354%2C397&ssl=1&resize=350%2C200","width":350,"height":200},"classes":[]}],"_links":{"self":[{"href":"https:\/\/mouillere.com\/universconvergents\/wp-json\/wp\/v2\/posts\/2388","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mouillere.com\/universconvergents\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mouillere.com\/universconvergents\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mouillere.com\/universconvergents\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mouillere.com\/universconvergents\/wp-json\/wp\/v2\/comments?post=2388"}],"version-history":[{"count":2,"href":"https:\/\/mouillere.com\/universconvergents\/wp-json\/wp\/v2\/posts\/2388\/revisions"}],"predecessor-version":[{"id":2391,"href":"https:\/\/mouillere.com\/universconvergents\/wp-json\/wp\/v2\/posts\/2388\/revisions\/2391"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mouillere.com\/universconvergents\/wp-json\/wp\/v2\/media\/2389"}],"wp:attachment":[{"href":"https:\/\/mouillere.com\/universconvergents\/wp-json\/wp\/v2\/media?parent=2388"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mouillere.com\/universconvergents\/wp-json\/wp\/v2\/categories?post=2388"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mouillere.com\/universconvergents\/wp-json\/wp\/v2\/tags?post=2388"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}