2012-07-13
Added · Updated
The General Board of the European Systemic Risk Board establishes implementing rules for data protection, defining the appointment, status, tasks, and powers of the Data Protection Officer (DPO). Controllers and data protection coordinators are assigned specific duties, including a requirement to provide information and respond to requests within 20 working days. The decision sets a three-calendar-month deadline for controllers to grant data subjects access to their personal data and outlines procedures for exercising rights, investigations, and exemptions. These rules enter into force on the 20th day following publication in the Official Journal of the European Union.