Skip to content
McCullochRegulatory Compliance
All practices

Data Protection Officer (DPO)

McCulloch Regulatory Compliance acts as outsourced Data Protection Officer for controllers and processors under the UK GDPR and EU GDPR, providing the independent monitoring, advice, and supervisory-authority liaison the role requires, from data protection impact assessments to breach notification and international transfers, with a dedicated specialism in clinical trials.

Advising underEuropean Union EU GDPRUnited Kingdom UK GDPR

DPO Requirement

Under Article 37 of the UK GDPR and the EU GDPR, the appointment of a Data Protection Officer is mandatory where an organisation's core activities consist of the large-scale processing of special category data, including health data, or the regular and systematic monitoring of individuals on a large scale, and for all public authorities. The Regulation permits the role to be fulfilled by an external service provider, which enables an organisation to meet its statutory obligation without appointing a full-time member of staff. For organisations in life sciences and health technology, appointment is frequently required.

Article 37UK & EU GDPRRead the article

Services

  • Records of processing

    Art 30

    Maintaining the record of processing activities required by Article 30, kept accurate against operational practice.

  • Data protection impact assessments

    Art 35

    Advising whether an assessment is required under Article 35, and reviewing the assessment of high-risk processing.

  • Advice and monitoring

    Art 39

    Advising the organisation and its personnel on their obligations, and monitoring compliance with the UK and EU GDPR.

  • Vendor and processor oversight

    Art 28

    Reviewing processors and sub-processors, together with the data processing terms that bind them.

  • International transfers

    Chapter V

    Governing transfers from the UK and EEA under Chapter V, using the Standard Contractual Clauses, the UK International Data Transfer Agreement, and transfer risk assessments.

  • Training and awareness

    Art 39

    Raising awareness and training the personnel who handle personal data.

    Delivered in person, remotely, or asynchronously through the MRC Learning Portal.

  • Breach response

    Arts 33 to 34

    Assessing personal data breaches, meeting the 72-hour notification requirement, and communicating with data subjects where required.

  • Authority and data-subject liaison

    Arts 37 to 39

    Acting as the published point of contact for the supervisory authority and for data subjects.

Delivery

McCulloch Regulatory Compliance is appointed as the organisation's external Data Protection Officer and named as its point of contact for supervisory authorities and data subjects. The role is performed by a named senior privacy lead who maintains current knowledge of the organisation's processing, operates independently of its business functions, and remains accessible to the organisation, its data subjects, and the relevant authority.

Engagements are scaled to the organisation's circumstances, from an initial appointment to a mature multi-jurisdiction programme, and adjusted as processing activities change. The appointment provides the independence, resources, and reporting lines required by Articles 38 and 39, without the expense of a permanent hire.

A data protection professional at work
Abstract network of connected data points

Data privacy in AI

Artificial intelligence systems process personal data and produce decisions affecting individuals, which brings them within the scope of data protection law. The GDPR applies to the personal data used to train, refine, and operate a model, and applies in parallel with the EU Artificial Intelligence Act rather than being displaced by it. The Data Protection Officer has a central role in assessing and documenting compliance across both regimes.

Artificial Intelligence practice
  • Lawful basis and training data

    Establishing a lawful basis for the personal data used to train and refine models, and observing purpose limitation and data minimisation.

  • Automated decisions and profiling

    Article 22 applies where decisions concerning individuals are taken without meaningful human involvement, and imposes specific safeguards and a right to an explanation.

  • Impact assessments for AI

    High-risk processing by an artificial intelligence system ordinarily requires a data protection impact assessment before deployment, documenting the risks and the controls applied.

  • Transparency

    Informing individuals, clearly and accessibly, when their personal data is processed by an automated system and to what effect.

  • GDPR and the EU AI Act

    Identifying the areas in which the two regimes overlap, in order that a system satisfies both rather than one at the expense of the other.

  • Data subject rights

    Managing access, rectification, and erasure where personal data is embedded in models, prompts, and processing pipelines.

Researchers reviewing data in a clinical research laboratory

Clinical Trials DPO

Clinical trials involve the large-scale processing of health data, which renders the appointment of a Data Protection Officer mandatory in most cases. The role in this context is distinct, comprising data protection impact assessments for the trial data flows, review of informed consent and participant information, review of the trial website and privacy notice, and assessment of CRO and vendor compliance.

Clinical Trials DPO

Contacts

Scott McCulloch

Scott McCulloch

Principal Advisor