All Bavarian authorities and other Bavarian public bodies (e.g. municipalities, district offices, governments, district hospitals) that process personal data must appoint an official data protection officer. It is possible for several public bodies to appoint a joint data protection officer, who does not have to be an employee of the responsible bodies and can also be represented and supported by other persons. The contact details of the data protection officer must be published in an easily accessible manner; the name of the data protection officer does not have to be included in the publication.
The data protection officer has the following statutory duties:
- Informing and advising
The data protection officer shall inform and advise the controller and the employees who carry out processing operations with regard to their obligations under data protection law and shall be involved in all matters relating to the protection of personal data - Monitoring
The data protection officer monitors the controller's compliance with data protection regulations and strategies for the protection of personal data - Advice on data protection impact assessment
The data protection officer advises the controller on request in connection with a data protection impact assessment and monitors its implementation - Cooperation with the supervisory authority
The data protection officer cooperates with the data protection supervisory authority and is its point of contact for data protection issues - Support for data subjects
Data subjects can consult the data protection officer on all issues relating to the processing of their data and the exercise of their rights under the General Data Protection Regulation - Opinion prior to the use of automated procedures
The data protection officer must be given the opportunity to comment prior to the use of or a significant change to an automated procedure with which personal data is processed - Opinionon planned video surveillance
Public bodies must inform the data protection officer in good time before the use of video surveillance and give him or her the opportunity to comment
Assignment of further tasks
The following tasks of the controller under the GDPR may be transferred to the data protection officer
- Implementing the notification of data breaches to the supervisory authority
- Coordination in the implementation of the rights of data subjects pursuant to Art. 12 et seq. of the GDPR.