Kada Data Protection (KDP) is formally designated as your organisation’s External Data Protection Officer in accordance with Articles 37 to 39 of the General Data Protection Regulation. This designation is contractually defined and, where applicable, notified to the competent Supervisory Authority. It ensures that the DPO function is clearly identified, legally recognised, and fully compliant with regulatory requirements, providing the organisation with a stable and accountable data protection reference point.
The DPO function exercised by KDP is strictly independent and free from any conflict of interest. KDP does not participate in operational decision-making related to data processing activities, allowing the DPO role to be performed with full impartiality and professional objectivity. This independence guarantees that advice and oversight are provided exclusively in the interest of regulatory compliance and the protection of individuals’ rights.
KDP is integrated into the organisation’s governance framework, ensuring that data protection considerations are embedded into decision-making processes at the appropriate level. The External DPO function operates in coordination with internal stakeholders while remaining autonomous, enabling effective alignment between regulatory obligations and organisational structures.
As External DPO, KDP maintains direct and unhindered access to senior management. This enables timely and informed advice on GDPR obligations, regulatory risks, and strategic initiatives involving personal data. Such access ensures that data protection is addressed at executive level and effectively supports informed governance and accountability.
KDP provides continuous oversight of GDPR compliance, monitoring processing activities, organisational changes, and regulatory developments on an ongoing basis. This approach ensures that compliance is sustained over time and adapted to evolving operational, legal, and strategic contexts, rather than treated as a one-off exercise.