| Literature DB >> 34658644 |
Anamarija Mladinić1, Livia Puljak2, Zvonimir Koporc2.
Abstract
INTRODUCTION: General Data Protection Regulation (GDPR) focuses on important elements of data ethics, including protecting people's privacy, accountability and transparency. According to the GDPR, certain public institutions are obliged to appoint a Data Protection Officer (DPO). However, there is little publicly available data from national EU surveys on DPOs. This study aimed to examine the scope of work, type of work, and education of DPOs in institutions in Croatia.Entities:
Keywords: data science; ethics; questionnaire; research; surveys
Mesh:
Year: 2021 PMID: 34658644 PMCID: PMC8495615 DOI: 10.11613/BM.2021.030703
Source DB: PubMed Journal: Biochem Med (Zagreb) ISSN: 1330-0962 Impact factor: 2.313
Participants’ characteristics*
|
|
|
|---|---|
| Age, years | 42 (23-65)* |
| Sex | |
| Man | 171 (23) |
| Woman | 542 (74) |
| No answer | 19 (2.7) |
| Level of education | |
| High school | 65 (8.9) |
| Bachelor’s degree | 117 (16) |
| Master’s degree | 414 (57) |
| Specialist study | 104 (14) |
| Scientific postgraduate study – master of science | 21 (2.9) |
| Scientific postgraduate study – PhD | 5 (0.7) |
| No answer | 6 (0.8) |
| Total lifetime employment, years* | 15 (0-43) |
| Number of months serving as a data protection officer* | 18 (1-156) |
| Institutional affiliation | |
| Research institution | 16 (2.2) |
| Educational institution | 256 (35) |
| Government body | 99 (14) |
| Public body | 252 (34) |
| Private sector | 88 (12) |
| No answer | 21 (2.9) |
| How were you selected for the position of Data Protection Officer | |
| A call for recruitment of a new employee | 13 (1.8) |
| Appointment of an existing employee to the position of DPO | 674 (92) |
| External contractor | 29 (3.9) |
| No answer | 16 (2.2) |
| *Data presented as median (range). | |
Workload and work environment of data protection officers
|
|
|
|---|---|
|
| |
| None | 431 (59) |
|
| |
| None | 609 (83) |
|
| |
| Yes | 668 (91) |
|
| |
| Yes | 597 (82) |
Frequency of seeking help or response from various information sources
|
|
|
| ||||
|---|---|---|---|---|---|---|
|
|
|
|
|
| ||
| AZOP – Croatian Personal Data Protection Agency | 190 (31) | 56 (9.1) | 98 (16) | 68 (11) | 202 (33) | 614 |
| Professional literature | 93 (16) | 75 (13) | 113 (19) | 128 (22) | 178 (30) | 587 |
| Colleagues who are not data protection officers | 245 (56) | 65 (15) | 67 (15) | 32 (7.3) | 28 (6.4) | 437 |
| Other data protection officers | 186 (35) | 74 (14) | 100 (19) | 81 (15) | 84 (16) | 525 |
| Internet | 68 (11) | 62 (9.8) | 115 (18) | 128 (20) | 261 (41) | 634 |
| Institution’s legal department | 166 (34) | 48 (16) | 66 (13) | 67 (14) | 143 (29) | 490 |
| Sources are ranked from 1 to 5, where 1 indicates the highest frequency and 5 the lowest frequency. *Total number of participants in the study was 732; the number of respondents for each item is shown in the table | ||||||
Answers to knowledge questions about personal data protection
|
|
|
|---|---|
|
| |
| Correct answer | 365 (60) |
|
| |
| Identity and contact details of the data controller/ the controller’s representative | 498 (72) |
| Information on whether the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, as well as whether the data subject is obliged to provide the personal data and of the possible consequences of failure to provide such data | 410 (60) |
| The existence of automated decision-making/development and meaningful information about the logic in question, as well as the importance and anticipated consequences of such processing for the respondent | 242 (35) |
| Information on whether the data is transferred to third countries and the existence or non-existence of a European Commission adequacy decision, and if applicable, information on appropriate safeguards | 411 (60) |
| Participants that chose all 10 items (as all must be included in the privacy policy) | 162 (23) |
Data protection officers’ compliance with legal regulations regarding personal data protection
|
|
|
|---|---|
|
| |
| Yes | 264 (36) |
|
| |
| Yes | 205 (28) |
|
| |
| Yes | 379 (52) |
|
| |
| Yes | 123 (17) |
|
| |
| Yes | 120 (16) |
|
| |
| Yes | 441 (60) |
|
| |
| Yes | 419 (57) |
|
| |
| Technical data protection measures | 317 (43) |
|
| |
| Yes, for data controllers/processors | 219 (30) |
Data protection officers and ethics committees
|
|
|
|---|---|
|
| |
| Yes | 263 (36) |
|
| |
| Yes | 45 (6.2) |
|
| |
| Yes, often | 24 (3.3) |
|
| |
| Yes | 86 (12) |
|
| |
| Yes | 100 (14) |