{"title":"Post-GDPR survey of data protection officers in research and non-research institutions in Croatia: a cross-sectional study.","authors":"Anamarija Mladinić, Livia Puljak, Zvonimir Koporc","doi":"10.11613/BM.2021.030703","DOIUrl":null,"url":null,"abstract":"<p><strong>Introduction: </strong>General Data Protection Regulation (GDPR) focuses on important elements of data ethics, including protecting people's privacy, accountability and transparency. According to the GDPR, certain public institutions are obliged to appoint a Data Protection Officer (DPO). However, there is little publicly available data from national EU surveys on DPOs. This study aimed to examine the scope of work, type of work, and education of DPOs in institutions in Croatia.</p><p><strong>Materials and methods: </strong>During 2020-2021, this cross-sectional study surveyed DPOs appointed in Croatia. The survey had 35 items. The questions referred to their appointment, work methods, number and type of cases handled by DPOs, the sources of information they use, their experience and education, level of work independence, contacts with ethics committees, problems experienced, knowledge, suggestions for improvement of their work, changes caused by the GDPR, and sociodemographic information.</p><p><strong>Results: </strong>Out of 5671 invited DPOs, 732 (13%) participated in the study. The majority (91%) indicated that they could perform their job independently; they did not have prior experience in data protection before being appointed as DPOs (54%) and that they need additional education in data protection (82%).</p><p><strong>Conclusions: </strong>Most DPOs indicated that they had none or minimal prior experience in data protection when they were appointed as DPO, that they would benefit from further education on data protection, and exhibited insufficient knowledge on basic concepts of personal data protection. Requirements for DPO appointments should be clarified; mandatory education and certification of DPOs could be introduced and DPOs encouraged to engage in continuous education.</p>","PeriodicalId":9021,"journal":{"name":"Biochemia Medica","volume":"31 3","pages":"030703"},"PeriodicalIF":3.8000,"publicationDate":"2021-10-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8495615/pdf/","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Biochemia Medica","FirstCategoryId":"3","ListUrlMain":"https://doi.org/10.11613/BM.2021.030703","RegionNum":3,"RegionCategory":"医学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"MEDICAL LABORATORY TECHNOLOGY","Score":null,"Total":0}
引用次数: 2
Abstract
Introduction: General Data Protection Regulation (GDPR) focuses on important elements of data ethics, including protecting people's privacy, accountability and transparency. According to the GDPR, certain public institutions are obliged to appoint a Data Protection Officer (DPO). However, there is little publicly available data from national EU surveys on DPOs. This study aimed to examine the scope of work, type of work, and education of DPOs in institutions in Croatia.
Materials and methods: During 2020-2021, this cross-sectional study surveyed DPOs appointed in Croatia. The survey had 35 items. The questions referred to their appointment, work methods, number and type of cases handled by DPOs, the sources of information they use, their experience and education, level of work independence, contacts with ethics committees, problems experienced, knowledge, suggestions for improvement of their work, changes caused by the GDPR, and sociodemographic information.
Results: Out of 5671 invited DPOs, 732 (13%) participated in the study. The majority (91%) indicated that they could perform their job independently; they did not have prior experience in data protection before being appointed as DPOs (54%) and that they need additional education in data protection (82%).
Conclusions: Most DPOs indicated that they had none or minimal prior experience in data protection when they were appointed as DPO, that they would benefit from further education on data protection, and exhibited insufficient knowledge on basic concepts of personal data protection. Requirements for DPO appointments should be clarified; mandatory education and certification of DPOs could be introduced and DPOs encouraged to engage in continuous education.
期刊介绍:
Biochemia Medica is the official peer-reviewed journal of the Croatian Society of Medical Biochemistry and Laboratory Medicine. Journal provides a wide coverage of research in all aspects of clinical chemistry and laboratory medicine. Following categories fit into the scope of the Journal: general clinical chemistry, haematology and haemostasis, molecular diagnostics and endocrinology. Development, validation and verification of analytical techniques and methods applicable to clinical chemistry and laboratory medicine are welcome as well as studies dealing with laboratory organization, automation and quality control. Journal publishes on a regular basis educative preanalytical case reports (Preanalytical mysteries), articles dealing with applied biostatistics (Lessons in biostatistics) and research integrity (Research integrity corner).