DPO and AIO Services
GDPR and AI Act Compliance Services
Outsource your DPO Services
With the advent of GDPR many organisations now find they have to have a Data Protection Officer (DPO). This role is defined in legislation and should not be treated lightly as:
- Article 37(5) provides that the DPO ‘shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices' including the following Article 39 tasks:
- Advising controllers, processors and employees who carry out data processing of their obligations.
- Monitoring compliance in relation to the protection of personal data, assign responsibilities, deliver staff awareness-training.
- Providing advice and monitor DPIA exercises.
- Cooperating with regulators.
- Acting as the contact point for regulators and consult with them when necessary.
- Article 38(6) allows DPOs to ‘fulfil other tasks and duties’. It also requires organisation to ensure that ‘any such tasks and duties do not result in a conflict of interests’. As a rule of thumb, conflicting positions within the organisation may include senior management positions (such as chief executives; chief operating, financial and medical officers; heads of marketing departments, human resources or IT departments) as well as subordinate roles if these lead to the determination of purposes and means of processing.
- In summary, DPO's key role is to oversee GDPR compliance, secure and protect the personal data that it holds in its care, safeguard the rights of data subjects including handling of subject rights requests, undertake DPIAs, manage the organisation's Record of Processing Activities (ROPA), notifying regulators and communicating with data subjects in the event of a data breach.
If your organisation requires a DPO please talk to us about outsourcing the function or training your staff.
Outsource your AIO Services
The AI Act states that providers of high-risk AI are responsible for ensuring that their product is fully compliant with legislation and having fit-for-purpose infrastructure in place, i.e. the people, processes and tooling necessary to build trustworthy and responsible AI systems.
While not a legal obligation, the role is framed as a best-practice for companies that build, integrate or deploy AI systems. The role itself is very broad in scope and requires the application of regulatory, technical and ethical due-diligence. As such, organisations are free to outsource certain tasks to an AIO partner to help build momentum and accelerate go-to-market plans.
- The AIO role mirrors that of the DPO in that independence and direct access to the Board is essential to ensure that a clear and sponsored AI strategy exists and has been communicated to all staff; supporting AI policy artefacts are developed; tools put in place and teams are adequately resourced.
- The AIO is responsible for establishing and operating an AI Management System (AIMS) and the AI Act Quality Management Standard, prEN 18286 which serves the complete AI lifecycle from model development, training, testing and post-sales monitoring.
- The operation of the AIMS requires that risk assessments are undertaken at various stages. The AIO's is responsible for ensuring that these are completed in full and any flagged risks are mitigated. Such assessments include - amongst others - the Fundamental Rights Impact Assessment (FRIA) necessary when the AI is classified as high risk to begin with, the AI Impact Assessment to identify and mitigate personal and systemic harms and the AI Conformity Assessment (AICA) requisite to obtaining a CE mark before AI market launch.
- The AIO is responsible for promoting general AI literacy acrss the organisation and providing training as needed.
- The AIO will liaise with the DPO to ensure that the training of Machine Learning models using datasets containing personal data are ethically and consentually procured and de-identified if necessary.
- The AIO is responsible for ensuring that the ethical principles of fairness and transparency are reflected in the production of technical documentation, information notices, the operation of the AI itself and in post-launch AI monitoring programmes.
- The AIO also acts as an organisation's point of contact with regulators and standards bodies.
If your organisation requires AIO services, please talk to us about outsourcing the function in whole or in part as well as providing awareness training for staff.