Governance and the privacy officer (RPRP)
The person in charge of protecting personal information (RPRP)
Every enterprise must designate a person in charge of protecting personal information (s. 3.1). By default, this is the person with the highest authority (for example the CEO); they may delegate the role in writing to a staff member. It is not tied to organization size: a five-person SMB is covered like a large company.
The RPRP's title and contact details must be published on the organization's website.
What the RPRP does
- oversees application of the law and internal policies;
- approves governance policies and practices (s. 3.2);
- receives requests and complaints from individuals;
- takes part in privacy impact assessments (PIAs);
- keeps the confidentiality incident register.
When to contact them
| Situation | Contact the RPRP |
|---|---|
| Suspected leak, loss or unauthorized access | Immediately |
| New system, new supplier, new API | Before go-live |
| Access or deletion request from an individual | As soon as received |
| Doubt about consent or data sharing | Before acting |
Example (SaaS). A developer wants to add a third-party analytics tool: they talk to the RPRP before integrating it.
Example (school). A teacher wants to use an online app with students' names: they consult the principal and the person in charge first.
In your organization: insert the RPRP's name and email here (to be configured by the organization).
Detailed legal framework: see the reference guide — The person in charge of the protection of personal information.