S2 Ep31: What Happens When Your DPO Is OOO?

Hosted by Caine Glancy and Oluwagbenga Onojobi

What happens to data protection compliance when your DPO is unavailable? Caine Glancy and Gbenga Onojobi discuss continuity planning, accountability, urgent requests and suitable cover.

What Happens When Your DPO Is OOO_

S2 Ep31: What Happens When Your DPO Is OOO?

The hidden liability gap: what happens when your DPO leaves?

Your organisation’s data protection responsibilities do not pause when its Data Protection Officer is unavailable.

In this episode of the Data Protection Made Easy podcast, Caine Glancy and Gbenga Onojobi discuss how organisations can maintain accountability when their DPO is on annual leave, absent unexpectedly or has left the organisation.

The Latest Data Protection News

Before exploring the main topic, Caine and Gbenga discuss several recent stories from across data protection and technology.

  • The proposed use of live facial recognition at Scottish football matches
  • The importance of human review when automated systems identify people
  • Concerns about addictive features on social media platforms
  • Unauthorised access to patient records by a former NHS employee

The discussion highlights a recurring concern. Technology may support decision-making, but organisations still need appropriate oversight, accountability and safeguards.

Does Accountability Leave With the DPO?

A DPO may take annual leave, become unwell, resign or retire. An outsourced DPO arrangement may also come to an end. However, the organisation remains responsible for its data protection compliance.

“The DPO leaving or being out of office does not remove the organisation’s responsibility. Accountability does not leave with them.”

Gbenga compares the DPO to a navigator on a ship. The navigator advises on the route and watches for danger, but the captain and the organisation remain responsible for the journey.

Why Organisations Need a Continuity Plan

Organisations need to plan for temporary and permanent DPO absences. Staff should know who can provide advice, receive an escalation and take ownership of urgent work.

This is particularly important for matters with strict deadlines, including personal data breaches, subject access requests and other individual rights requests.

“Being able to have another trusted individual who helps you, whether that is upwards or downwards, is really quite vital.”

Policies and procedures should explain what happens when the usual DPO contact is unavailable. The plan may involve a deputy, trained managers, data champions or access to external data protection support.

Data Protection Is Not One Person’s Responsibility

Caine and Gbenga discuss the risks of allowing every data protection matter to sit with the DPO.

Senior leaders remain accountable. Managers and staff also need to understand how data protection applies to their work and when an issue must be escalated.

Training should reflect each person’s responsibilities. Board members, managers, data champions and frontline staff do not need identical training. They need practical knowledge that helps them recognise and manage the situations they may face.

Independence and Conflicts of Interest

When a DPO leaves, appointing the nearest senior employee may appear to solve the immediate problem. However, organisations must consider whether that person has the necessary expertise, time and independence.

A person should not be expected to make decisions about how personal data is used and then independently monitor their own decisions.

“Organisations should not solve a vacancy by creating an additional conflict. A rushed appointment may fill the box while leaving the organisation with a DPO who cannot properly perform the role.”

Protecting Time-Sensitive Work

A subject access request can arrive anywhere in an organisation. It may be sent to HR, reception, a manager or through social media. It may also be made verbally.

The individual does not need to use the words “subject access request” for the request to be valid. This means staff need to recognise a possible request and know where to send it, even when the DPO is unavailable.

Clear ownership and an appropriate quality assurance process can reduce the risk of missed deadlines, inappropriate disclosures or information being withheld incorrectly.

Questions to Ask Your Organisation

  • Who provides cover when the DPO is unavailable?
  • Do staff know where to send urgent data protection matters?
  • Who monitors subject access request and breach deadlines?
  • Are key decisions, risks and responsibilities properly recorded?
  • Does any temporary replacement have suitable expertise and independence?
  • Can the organisation access additional support when internal capacity is limited?

The Final Takeaway

“A DPO leaving an organisation should not create a compliance vacuum. The organisation itself remains accountable.”

Good continuity means recording important knowledge, clearly allocating responsibilities and making sure somebody suitable is ready to step in.

Meet Your Hosts

Caine Glancy

Caine is the Data Protection Support Desk Manager at Data Protection People. He brings practical insight from helping organisations manage everyday data protection questions, breaches and individual rights requests.

Gbenga Onojobi

Gbenga is a Data Protection Consultant at Data Protection People. He supports organisations with practical compliance, governance and data protection risk management.

Watch or Listen

📺 Watch on YouTube: https://youtu.be/hqokBvSh-Ho

🎧 Listen on Spotify: https://open.spotify.com/episode/7ukmE70eDsPsMYQG39O8kf