A valuable asset or a tick-box appointment?

The role of a Data Protection Officer has long been established in law, but across healthtech it is appointed and utilised in different ways, quite different to that of other roles such as Clinical Safety Officers (CSOs). So, what is a DPO, do healthtech companies need one, and what should organisations look out for when appointing one?

The starting point.

The first thing to note is that the DPO is a statutory role. This means the individual undertaking the role has statutory tasks they must undertake. These are primarily to:

  1. Provide advice and guidance on data protection law

  2. Monitor the organisation's compliance with data protection law

  3. Act as the point of contact with the data protection regulator

The position of the DPO is also set out in law. A DPO must:

  1. Not receive instruction on how to exercise their tasks

  2. Have no conflict in exercising their tasks. This means a C-suite executive (CEO, CTO, CDO etc.) is unable to be the Data Protection Officer.

  3. Be involved in a timely manner in all issues relating to data protection.

  4. Be able to report to the highest level of management

  5. Be appointed on the basis of their 'professional qualities and, in particular, expert knowledge of data protection law and practices' [UK GDPR Article 37(5)].

In some instances, a DPO is mandated by data protection law, including where the core activities of the organisation involve large-scale processing of special category data (including health data).

Both controllers and processors may be required to appoint a DPO, depending on their processing activities.

What this means in practice.

As a statutory role, if a DPO is appointed, the individual undertaking that role, and the organisation appointing the role, must ensure that the DPO is involved in all aspects. It cannot be a 'lip-service' role.

What your DPO will be doing:

  1. Providing advice and guidance to any new or changing product features.

  2. Monitoring your organisation's compliance with UK/EU data protection laws.

  3. Keeping you up to date with changes in law and guidance and providing proactive advice and recommended changes based on this.

  4. Reviewing Data Protection Impact Assessments.

  5. Having routine calls with relevant teams/groups in the organisation.

  6. Supporting data breach management, qualification and communication.

  7. Supporting advice and guidance in relation to individual rights.

  8. Advising on the set-up and management of personal data involved in any clinical investigation or study in relation to your product.

  9. Supporting conversations with commercial partners and NHS IG teams.

  10. Advising on implementation of data strategy.

  11. Supporting due diligence of potential suppliers.

A good DPO can be far more than a compliance function, acting as a strategic advisor when properly integrated into the organisation and involved in decision-making.

Practical steps to a DPO in HealthTech.

The first question is whether your organisation is legally required to appoint a DPO.

If the answer is yes, a DPO must be appointed. If no, then you need to decide whether you want to appoint one voluntarily, or whether you want to appoint a data protection lead in a non-statutory position.

Note: Although the Digital Technology Assessment Criteria (DTAC) Version 2 removed the question regarding DPO appointment, this has not changed anything in law and you are still required to appoint a DPO in the circumstances noted above.

If appointing a DPO, this can be done internally or externally.

If appointing internally it is recommended that you:

  • Assure yourself there is no conflict of interest, where the individual also makes decisions in the organisation about using personal data. This means that the individual should not be a CEO, CTO, CDO or Head of Marketing, for example.

  • Assure yourself they have the relevant experience and knowledge to advise on data protection law.

If appointing externally it is recommended that you:

  • Understand the experience of your named DPO

  • Understand whether your named DPO has experience in health

  • Understand the inclusions of the service: how do they undertake all the statutory tasks?

  • Understand the flexibility of their services. Some limit contact by hours, or pre-assigned days.

Takeaway

A DPO is a statutory role in law with the tasks they must undertake also set out in law. If appointing a DPO, either internally or externally, they can be of immense value.

Whether you are looking to undertake an innovative project utilising data, looking to gain approval from local NHS Information Governance Teams for your product or have an overview of your information risk exposure, the DPO should be a key part of your team.

Whether you are looking for a statutory Data Protection Officer, reviewing your current supplier or looking for strategic support for a growing organisation, learn more about Iniver's Outsourced DPO service here or contact us to discuss your requirements. See more on Iniver's wider support for health and healthtech organisations.