Personal Data Protection Law

Article 10 — Article (10) Appointing Data Protection Officer

1. The Controller and Processor shall appoint a Data Protection Officer, who has sufficient skills and knowledge of the Personal Data Protection Law, in any of the following cases: a. If processing would cause a high-level risk to the confidentiality and privacy of the Personal Data of the Data Subject as a result of adopting new technologies or with regard to the volume of data. b. If processing would involve a systematic and comprehensive assessment of Sensitive Personal Data, including Profiling and Automated Processing. c. If processing would be carried out on a large volume of Sensitive Personal Data. 2. The Data Protection Officer may be an employer of the Controller or the Processor or authorized by them, whether inside or outside the State. 3. The Controller or the Processor shall specify the contact details of the Data Protection Officer and notify the Bureau of the same. 4. The Executive Regulations of this Decree by Law shall specify the types of technologies and criteria for determining the volume of data required in accordance with this Article.

WAWhatsAppTGTelegram