Skip to main content
  • Personal
  • Business
  • Foundation
    Close
  • Select Region
    • Global
    • India
    • MENA
  • mySHRM Login
  • MySHRM
    • Dashboard
    • Account
    • Logout
SHRM
  • Membership
    • Membership

      As a SHRM Member®, you’ll pave the path of your success with invaluable resources, world-class educational opportunities and premier events.

      Membership Benefits
  • Certification
    • SHRM Certification

      Demonstrate your ability to apply HR principles to real-life situations.

      • How to Get Certified
      • Eligibility Criteria
      • Exam Fees & Options
      • SHRM-CP
      • SHRM-SCP
      • Which Certification is Best for Me?
      • Recertification
      Prepare for the Exam
      • Exam Preparation
      • SHRM BASK
      • SHRM Learning System
      • Instructor-Led Learning
      • Self-Study
      Specialty Credentials

      Demonstrate targeted competence and enhance your HR credibility.

      PMQ

      Gain a deeper understanding and develop critical skills.

  • Events & Education
    • India Events

      Demonstrate your ability to apply HR principles to real-life situations.

      • Talent Leadership Summit
      • Tech Conference
      • India Annual Conference
      MENA Events
      • MENA Annual Conference
      Global Events
      • US Annual Conference
      Webinars
  • Resources
    • Resources

      Stay up to date with news and leverage our vast library of resources.

      • Compliance
      • HR Research
      • Legal & Compliance
      • Latest News & Trends
      • Tools & Guides
      HR Topics
      • AI in the Workplace
      • Civility at Work
      • Compensation & Benefits
      • Inclusion & Diversity
      • Talent Acquisition
      • Workplace Technology
      • Workplace Violence Prevention
  • SHRM Connect
  • Shop
    • SHRM Store

      Shop for HR certifications, credentials, learning, events, merchandise and more.

      Workplace Essentials
      • SHRM Memberships
      • SHRM Certification
      • Specialty Credentials
      • HR Tools & Tech
      Education
      • Seminars
      • eLearning
      • Books
      Merchandise
      • Accessories
      • Apparel
      • Office & Home
Become a Member
Renew
Rejoin Now
Renew
Close
  • Personal
  • Business
  • Foundation
  • Membership
    back
    Membership
    • Membership

      As a SHRM Member®, you’ll pave the path of your success with invaluable resources, world-class educational opportunities and premier events.

      Membership Benefits
  • Certification
    back
    Certification
    • SHRM Certification

      Demonstrate your ability to apply HR principles to real-life situations.

      • How to Get Certified
      • Eligibility Criteria
      • Exam Fees & Options
      • SHRM-CP
      • SHRM-SCP
      • Which Certification is Best for Me?
      • Recertification
      Prepare for the Exam
      • Exam Preparation
      • SHRM BASK
      • SHRM Learning System
      • Instructor-Led Learning
      • Self-Study
      Specialty Credentials

      Demonstrate targeted competence and enhance your HR credibility.

      PMQ

      Gain a deeper understanding and develop critical skills.

  • Events & Education
    back
    Events & Education
    • India Events

      Demonstrate your ability to apply HR principles to real-life situations.

      • Talent Leadership Summit
      • Tech Conference
      • India Annual Conference
      MENA Events
      • MENA Annual Conference
      Global Events
      • US Annual Conference
      Webinars
  • Resources
    back
    Resources
    • Resources

      Stay up to date with news and leverage our vast library of resources.

      • Compliance
      • HR Research
      • Legal & Compliance
      • Latest News & Trends
      • Tools & Guides
      HR Topics
      • AI in the Workplace
      • Civility at Work
      • Compensation & Benefits
      • Inclusion & Diversity
      • Talent Acquisition
      • Workplace Technology
      • Workplace Violence Prevention
  • SHRM Connect
  • Shop
    back
    Shop
    • SHRM Store

      Shop for HR certifications, credentials, learning, events, merchandise and more.

      Workplace Essentials
      • SHRM Memberships
      • SHRM Certification
      • Specialty Credentials
      • HR Tools & Tech
      Education
      • Seminars
      • eLearning
      • Books
      Merchandise
      • Accessories
      • Apparel
      • Office & Home
Become a Member
Renew
Rejoin Now
Renew
  • Select Region
    • Global
    • India
    • MENA
SHRM
mySHRM Login
  • MySHRM
    • Dashboard
    • Account
    • Logout
Close

  1. Topics & Tools
  2. Employment Law & Compliance
  3. GDPR Says Companies Must Have a Data Privacy Officer. Who Should That Be?
Share
  • Linked In
  • Facebook
  • Twitter
  • Email

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Vivamus convallis sem tellus, vitae egestas felis vestibule ut.


Error message details.

Copy button
Reuse Permissions

Request permission to republish or redistribute SHRM content and materials.


Learn More
News

GDPR Says Companies Must Have a Data Privacy Officer. Who Should That Be?

May 23, 2018 | Allen Smith, J.D.

The word gdpr is shown on a computer screen.


​Employers in the U.S. that must comply with the European Union (EU) General Data Protection Regulation (GDPR), which takes effect May 25, are struggling with the requirement to appoint a data protection officer. They also face grappling with the GDPR's 72-hour notification requirement upon discovery of a qualifying breach.

Data Protection Officer

The requirement to hire or appoint a data protection officer applies if a business is engaged in large-scale data processing, but there is no real guidance on what that means, according to Philip Yannella, an attorney with Ballard Spahr in Philadelphia.

If a business decides it will hire a data protection officer, it needs to decide if:

  • The officer will work internally or externally.
  • The company will hire a full-time officer or use someone on staff.
  • The business will appoint an officer in Europe or the United States.

According to an Association of Corporate Counsel (ACC) Foundation report, The State of Cybersecurity Report: An In-House Perspective 2018, released in May, most (62 percent) of the surveyed 617 in-house lawyers at more than 412 companies in 33 countries are using current staff to function as data protection officers. Fourteen percent of survey respondents didn't know how the company was addressing the GDPR requirement to hire a data protection officer. Eight percent are hiring a full-time data privacy officer, while 5 percent are hiring an outside privacy officer, and 5 percent are using an independent company.

[SHRM members-only toolkit: Introduction to the Global Human Resources Discipline]

A data protection officer can't be fired because of the decisions he or she makes in that role, Yannella said. That spooks some U.S. companies, which are used to employment at will, he noted.

If a data protection officer is someone within an organization, he or she should be an expert on GDPR and data privacy. Yannella said the person most likely to have the requisite expertise is a chief privacy officer.


However, a data protection officer must act independently of the company. Consequently, it's tricky for an employee to be a chief privacy officer, who is constantly making decisions on behalf of the company, and a data protection officer, he observed. While the employer could not fire the chief privacy officer because of what he or she decides as a data protection officer, it could fire him or her for subpar performance in other job responsibilities.

Hiring a data protection officer internally in Europe has its advantages. Someone in Europe is more likely to have a greater familiarity with EU privacy law, he said. In addition, it's easier for someone in Europe to liaise with privacy regulators, he noted.

Breach Notification

The GDPR will require that notifications of data breaches are made within 72 hours of discovery. This requirement is much quicker than under U.S. state laws, said Amar Sarwal, ACC's chief legal officer and senior vice president of advocacy and legal services.

States typically require breach notification generally without undue delay or in a reasonable time—30 days is the quickest time period of any state, Yannella observed. Florida has the 30-day requirement.

When asked in the ACC report if respondent companies had determined how they would meet the 72-hour notification requirement, 37 percent said no, while only 34 percent said yes. Large companies were more likely to know how to respond to this requirement than smaller ones.

Yannella said companies that are technically covered by GDPR but don't have many contacts in Europe are struggling the most and aren't sure why they have to comply, particularly when the law is so broad and its penalties are so onerous.

ACC survey respondents said that the primary point of contact for a breach was the:

  • Chief information officer (18 percent).
  • IT department (17 percent).
  • General counsel/chief legal officer (17 percent).
  • Chief information security officer (13 percent).
  • President/chief executive officer (10 percent).
  • Chief privacy officer (4 percent).
  • Chief risk officer (3 percent).
  • Vice president (3 percent).

One in 10 respondents said that the company did not have a single point of contact, and 5 percent didn't know who that person was.

When asked whether they had cybersecurity insurance coverage, only 56 percent of respondents said they did. Yannella said this response surprised him, as it was only slightly higher than when the survey was conducted two years ago. He cautioned that it's risky to not be insured.

ESG, Ethics & Compliance
HR Function Strategy
Skills Training

Was this resource helpful?

Leave Feedback

SHRM-CP Promo Image
Validate your HR expertise

Earning your SHRM-CP credential makes you a recognized expert and leader in the HR field.

Get Certified


Related Content

(opens in a new tab)
News
How One Company Uses Digital Tools to Boost Employee Well-Being

Learn how Marsh McLennan successfully boosts staff well-being with digital tools, improving productivity and work satisfaction for more than 20,000 employees.

(opens in a new tab)
News
A 4-Day Workweek? AI-Fueled Efficiencies Could Make It Happen

The proliferation of artificial intelligence in the workplace, and the ensuing expected increase in productivity and efficiency, could help usher in the four-day workweek, some experts predict.

(opens in a new tab)
News
Rising Demand for Workforce AI Skills Leads to Calls for Upskilling

As artificial intelligence technology continues to develop, the demand for workers with the ability to work alongside and manage AI systems will increase. This means that workers who are not able to adapt and learn these new skills will be left behind in the job market.

Workplace Compliance Newsletter

Keep abreast of employment law and compliance developments and their wide-reaching impacts.

Success title

Success caption

Manage Subscriptions
Our Brands

SHRM Foundation Logo
SHRM Executive Network Logo
CEO Circle Logo
SHRM Business Logo
SHRM Linkage Logo
SHRM Labs
Overview


  • About SHRM
  • SHRM India Advisory Council
  • Careers at SHRM
  • Press Room
  • Contact SHRM India
  • Book a SHRM Executive Speaker
  • Ask an Advisor
  • SHRM Newsletter
  • Post a Job
  • Find an HR Job
  • Advertise with us
  • Copyright & Permission
Contact Us


Email: shrmindia@shrm.org
Phone: (1)800.103.2198
WhatsApp: +919810503727

SHRM India Corporate Information

© 2026 SHRM. All Rights Reserved
SHRM provides content as a service to its readers and members. It does not offer legal advice, and cannot guarantee the accuracy or suitability of its content for a particular purpose. Disclaimer

Follow Us

  • LinkedIn
  • Facebook
  • Twitter
  • Instagram
  • YouTube

  1. Your Privacy Choices

  2. Terms of Use

  3. Accessibility

Join SHRM for Exclusive Access to Professional Content

SHRM Members enjoy unlimited access to articles and exclusive member resources.

Already a member? Login
Free Article

Login to unlock unlimited access or join SHRM today to get unlimited access to articles and member-exclusive resources.

Already a member? Login
Limit Reached

You've reached the limit of 1 free article this month. Join to access unlimited articles and member-only resources.

Already a member? Login
Free Article

Login to unlock unlimited access or join SHRM today to get unlimited access to articles and member-exclusive resources.

Already a member? Login
Exclusive Executive-Level Content

You've reached the limit of 1 free article this month. Join the Executive Network and enjoy unlimited content.

Already a member? Login
Unlock Your Career with SHRM Membership

Please enjoy this free resource! Join SHRM for unlimited access to exclusive articles and tools.

Already a member? Login
Join SHRM for Exclusive Access to Professional Premium Content

SHRM Members enjoy unlimited access to articles and exclusive member resources.

Already a member? Login
Join SHRM for Exclusive Access to Student Content

SHRM Members enjoy unlimited access to articles and exclusive member resources.

Already a member? Login
Join SHRM for Exclusive Access to Executive Network Content

SHRM member enjoys unlimited access to articles and exclusive member resources.

Already a member? Login

Your membership is almost expired! Renew today for unlimited access to member content.

Renew now

Your membership has expired. Renew today for unlimited access to member content.

Renew Now

Your Executive Network membership is nearing its expiration. Renew now to maintain access.

Renew Now

Your membership has expired. Renew your Executive Network benefits today.

Renew Now