Governance and the privacy officer (RPRP)

The person in charge of protecting personal information (RPRP)

Every enterprise must designate a person in charge of protecting personal information (s. 3.1). By default, this is the person with the highest authority (for example the CEO); they may delegate the role in writing to a staff member. It is not tied to organization size: a five-person SMB is covered like a large company.

The RPRP's title and contact details must be published on the organization's website.

What the RPRP does

  • oversees application of the law and internal policies;
  • approves governance policies and practices (s. 3.2);
  • receives requests and complaints from individuals;
  • takes part in privacy impact assessments (PIAs);
  • keeps the confidentiality incident register.

When to contact them

Situation Contact the RPRP
Suspected leak, loss or unauthorized access Immediately
New system, new supplier, new API Before go-live
Access or deletion request from an individual As soon as received
Doubt about consent or data sharing Before acting

Example (SaaS). A developer wants to add a third-party analytics tool: they talk to the RPRP before integrating it.

Example (school). A teacher wants to use an online app with students' names: they consult the principal and the person in charge first.

In your organization: insert the RPRP's name and email here (to be configured by the organization).

Detailed legal framework: see the reference guide — The person in charge of the protection of personal information.