Duties of the Data Protection Commissioner
The duties of the official data protection commisioner are described in Art. 25, Par. 4 of the BayDSG as follows: "The official data protection commissioners are responsible for enforcing the rules of regulations that apply to data protection in public offices. In supervising the implementation of the rules and regulations, the commissioners have the right to search data and files in their domain, insofar as they do not conflict with other legal regulations. In order to search files concerning personal data that are subject to doctor's confidentiality or files concerning security checks that contain additional personal information, the commissioners need the permission of the concerned party. They are bound to secrecy concerning facts and information they acquire through their function as official data protechtion commissioners unless they have received permission from the said party."
Their responsibilities are as follows:
- to follow follow the procedures as outlined in Ar. 27 BayDSG, in the absence of other regulations,
- to give clearance approval according to Art. 26 BayDSG,
- to provide citizens with information concerning data protection,
- to coordinate a response to information-seekers accroding to Art. 10 BayDSG,
- to assist in the production of forms, especially concerning the formulation of consent according to Art. 15 BayDSG and information contained in Art. 16, Par. 3 and 4 BayDSG,
- to provide information on data protection.
Other duties include
- controlling for the maintenance of data protection regulations and instructions on data protection and data security
- supervision of the use of data processing systems in regard to personal data (assisting in the production and control of such systems),
- assisting in the inspection of files for their admissibility,
- assisting in the training of those who work with personal data, especially in regard to data protection,
- cooperation in the preparation of user instructions,
- authorization of users' access,
- cooperation in the production of a risk analysis and the resulting security concept for data processing,
- inspection of data processing of mandates in regard to the creation of contracts and maintenance of given data protection measures.
Source:
Bayerischer Landesbeauftragter für den Datenschutz