The Economic Benefits of Having a DPO

  • Panel
  • Class Room
  • Thursday 22.05 — 17:20 - 18:40

Organising Institution

CNIL

France

French data protection authority
  • Academic 1
  • Business 3
  • Policy 2
Sometimes required by GDPR, sometimes voluntary, the setting up of a Data Protection Officer is often seen by firms as a compliance duty and as a source of costs. But firm sometimes underestimate the economic interest and the business benefits for them to have a DPO. Such economic benefits actually overlap the benefits of GDPR compliance itself. Based on novel results of a statistical investigation in France, as well as interviews, the panel will identify the main types of economic gains associated with the presence of a DPO, set up a typology of controllers concerned and come back to the condition of success of such an approach. Controllers need a new perspective on their DPOs, considering them as an asset generating economic value added, and to organise its role in conjunction with this investment.

Questions to be answered

  1. What are the economic gains associated with a DPO ?
  2. Should a DPO be considered as an investment and an asset for a firm ?
  3. Which controllers can benefit from this ?
  4. How to reap these benefits in practice ?

Moderator

Aymeric Pontvianne

CNIL - France

Head of the Economic analysis team at CNIL, the French data protection authority, for two years, Aymeric created the CNIL sandbox program for innovators and prepared the CNIL White Paper on means of payment and payment data. He and is also co-coordinator of the EDPB subgroup on cross-regulatory interplay and cooperation. Graduate of the Ecole nationale d’administration, he holds a Master 2 degree in Economics and occupied various positions within the French Treasury, dealing with european economic and financial matters.

Speaker

Ricardo Catalan

Autoriteit Persoonsgegevens - Netherlands

Ricardo worked as a consultant in data protection before being appointed as the DPO of the Leiden University in the Netherlands. Subsequently, Ricardo started working for the Dutch Data Protection Authority in 2022 and he continues to work there to this day. Ricardo is a senior inspector and leads the DPO team at the Dutch DPA. The DPO team is primarily focused on assisting DPO's in the Netherlands with technical and enforcement support. Furthermore, Ricardo also leads the drafting team of the EDPB that is tasked with updating the EDPB Guidelines on DPO's.

Speaker

Nadia Arnaboldi

AssoDPO - Italy

Nadia Arnaboldi is an international data protection professional and lecturer with over 20 years of experience in the field. She is Vice President of the Confederation of European Data Protection Organisations (CEDPO) and of the Italian Association of Data Protection Officers (ASSO DPO). She holds a master’s degree in economics and corporate Law from the University of Pavia and a certificate in AI implications for Business Strategies from MIT Sloan School of Management. She is a Court-appointed technical expert in data protection, is a certified public auditor, and a certified DPO according to rule UNI 11697:2017. She also holds the CIPP/E, CIPP/US, CIPM and FIP certifications. She is an Auditor and Lead Auditor for ISO/IEC 27001:2013 and an Auditor ISO 17065:2012. She is the author of numerous specialized publications (articles and books), a regular speaker on data protection, and lecturer in technology and data protection at the second-level University Master’s Course at University of Salento.

Speaker

Thomas van Gremberghe

Agoria - Belgium

Thomas Van Gremberghe is a senior company lawyer with specific expertise in personal data protection. Thomas provides advice to the members of Agoria, the Belgian federation for the technology sector. He holds a Master’s degree in Law from the Free University of Brussels (VUB) and obtained a certificate as DPO. Thomas is a regular speaker on data protection matters and provides also in depth trainings on GDPR implementation. Furthermore, he publishes articles with regard to privacy and personal data protection matters.

Speaker

Gerard Buckley

University College London - United Kingdom

Dr Buckley was awarded a PhD in Cybersecurity by University College London (UCL) earlier this year. His areas of expertise are privacy, data protection, and AI at the intersection of technology, business strategy, and regulation. His research has included investigating the benefits to business (if any) from GDPR, measuring the indefinable effectiveness of data protection regulators and scenario planning the future shape of the GDPR. He has 35 years of experience in the information services industry as CIO, CMO and CEO before returning to university six years ago. Previous employers included Westinghouse, British Telecom, Reuters, London Metal Exchange, Dun & Bradstreet and Thomson Financial. He was part of the executive team that floated Garban plc on the London Stock Exchange and has led a series of technology start-ups as CEO in Cambridge and London.