Data Protection Compliance Organizations (DPCO) Under the NDPR, and Monitoring Bodies Under the GDPR: Two Sides of the Same Compliance Coin?

Olumide Babalola
{"title":"Data Protection Compliance Organizations (DPCO) Under the NDPR, and Monitoring Bodies Under the GDPR: Two Sides of the Same Compliance Coin?","authors":"Olumide Babalola","doi":"10.54648/gplr2022010","DOIUrl":null,"url":null,"abstract":"The European Union (EU) Data Protection Directive (DPD) was repealed for its failure to achieve the anticipated level of regulatory compliance thereby paving the way for General Data Protection Regulation (GDPR) which came with a number of novelties including the introduction of monitoring bodies (MBs) as another layer of compliance enforcement with provisions of the GDPR through sector-specific codes of conduct (CoC). While the DPD also had a provision on CoC, it was bereft of its enforcement mechanism, success indicators and workability, hence the introduction of MBs as an additional player in the GDPR-enforcement ecosystem to ensure compliance with the CoC on the one hand and sanction violations on the other. Conversely, on the other side of the Mediterranean Sea, Nigeria issued its own version of the GDPR as ‘Nigeria Data Protection Regulation’ (NDPR) and introduced its own peculiar MB styled ‘Data Protection Compliance Organization’ (DPCO) to, interestingly, on behalf of the National Information Technology Development Agency (NITDA) ensure and monitor compliance with the NDPR and at the same time forge a fiduciary relationship with the controllers as their paid auditors. This article places the European concept of MBs and Nigerian novelty of DPCOs side by side while examining the relationship between the two similar yet asymmetric concepts. The article analyses the varying issues surrounding the nature, appointment or creation, powers, and functionalities of MBs and DPCOs under the European and Nigerian regulations.\nNigeria, Nigeria Data Protection Regulation, NDPR, National Information Technology Development Agency, NITDA, Data Protection Compliance Organization, DPCO","PeriodicalId":127582,"journal":{"name":"Global Privacy Law Review","volume":"42 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-05-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Global Privacy Law Review","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.54648/gplr2022010","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

The European Union (EU) Data Protection Directive (DPD) was repealed for its failure to achieve the anticipated level of regulatory compliance thereby paving the way for General Data Protection Regulation (GDPR) which came with a number of novelties including the introduction of monitoring bodies (MBs) as another layer of compliance enforcement with provisions of the GDPR through sector-specific codes of conduct (CoC). While the DPD also had a provision on CoC, it was bereft of its enforcement mechanism, success indicators and workability, hence the introduction of MBs as an additional player in the GDPR-enforcement ecosystem to ensure compliance with the CoC on the one hand and sanction violations on the other. Conversely, on the other side of the Mediterranean Sea, Nigeria issued its own version of the GDPR as ‘Nigeria Data Protection Regulation’ (NDPR) and introduced its own peculiar MB styled ‘Data Protection Compliance Organization’ (DPCO) to, interestingly, on behalf of the National Information Technology Development Agency (NITDA) ensure and monitor compliance with the NDPR and at the same time forge a fiduciary relationship with the controllers as their paid auditors. This article places the European concept of MBs and Nigerian novelty of DPCOs side by side while examining the relationship between the two similar yet asymmetric concepts. The article analyses the varying issues surrounding the nature, appointment or creation, powers, and functionalities of MBs and DPCOs under the European and Nigerian regulations. Nigeria, Nigeria Data Protection Regulation, NDPR, National Information Technology Development Agency, NITDA, Data Protection Compliance Organization, DPCO
NDPR下的数据保护合规组织(DPCO)和GDPR下的监管机构:同一枚合规硬币的两面?
欧盟(EU)数据保护指令(DPD)因未能达到预期的监管合规水平而被废除,从而为通用数据保护条例(GDPR)铺平了道路,该条例带来了许多新颖之处,包括引入监测机构(mb)作为GDPR规定的另一层合规执行,通过特定部门的行为准则(CoC)。虽然DPD也有关于“准则”的规定,但它缺乏其执行机制、成功指标和可操作性,因此在gdpr执法生态系统中引入了MBs作为额外的参与者,以确保一方面遵守“准则”,另一方面制裁违规行为。相反,在地中海的另一边,尼日利亚发布了自己的GDPR版本,即“尼日利亚数据保护条例”(NDPR),并引入了自己独特的MB风格的“数据保护合规组织”(DPCO),有趣的是,它代表国家信息技术发展局(NITDA)确保和监督NDPR的遵守情况,同时与控制者建立信托关系,作为他们的付费审计师。本文将欧洲的MBs概念和尼日利亚的dpco概念放在一起,同时研究这两个相似但不对称的概念之间的关系。本文分析了欧洲和尼日利亚法规下MBs和dpco的性质、任命或创建、权力和职能等不同问题。尼日利亚,尼日利亚数据保护条例,NDPR,国家信息技术发展局,NITDA,数据保护合规组织,DPCO
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信