Data Protection Officer (DPO)
McCulloch Regulatory Compliance acts as outsourced Data Protection Officer for controllers and processors under the UK GDPR and EU GDPR, providing the independent monitoring, advice, and supervisory-authority liaison the role requires, from data protection impact assessments to breach notification and international transfers, with a dedicated specialism in clinical trials.
DPO Requirement
Under Article 37 of the UK GDPR and the EU GDPR, the appointment of a Data Protection Officer is mandatory where an organisation's core activities consist of the large-scale processing of special category data, including health data, or the regular and systematic monitoring of individuals on a large scale, and for all public authorities. The Regulation permits the role to be fulfilled by an external service provider, which enables an organisation to meet its statutory obligation without appointing a full-time member of staff. For organisations in life sciences and health technology, appointment is frequently required.
Services
Records of processing
Art 30Maintaining the record of processing activities required by Article 30, kept accurate against operational practice.
Data protection impact assessments
Art 35Advising whether an assessment is required under Article 35, and reviewing the assessment of high-risk processing.
Advice and monitoring
Art 39Advising the organisation and its personnel on their obligations, and monitoring compliance with the UK and EU GDPR.
Vendor and processor oversight
Art 28Reviewing processors and sub-processors, together with the data processing terms that bind them.
International transfers
Chapter VGoverning transfers from the UK and EEA under Chapter V, using the Standard Contractual Clauses, the UK International Data Transfer Agreement, and transfer risk assessments.
Training and awareness
Art 39Raising awareness and training the personnel who handle personal data.
Delivered in person, remotely, or asynchronously through the MRC Learning Portal.
Breach response
Arts 33 to 34Assessing personal data breaches, meeting the 72-hour notification requirement, and communicating with data subjects where required.
Authority and data-subject liaison
Arts 37 to 39Acting as the published point of contact for the supervisory authority and for data subjects.
Delivery
McCulloch Regulatory Compliance is appointed as the organisation's external Data Protection Officer and named as its point of contact for supervisory authorities and data subjects. The role is performed by a named senior privacy lead who maintains current knowledge of the organisation's processing, operates independently of its business functions, and remains accessible to the organisation, its data subjects, and the relevant authority.
Engagements are scaled to the organisation's circumstances, from an initial appointment to a mature multi-jurisdiction programme, and adjusted as processing activities change. The appointment provides the independence, resources, and reporting lines required by Articles 38 and 39, without the expense of a permanent hire.
Data privacy in AI
Artificial intelligence systems process personal data and produce decisions affecting individuals, which brings them within the scope of data protection law. The GDPR applies to the personal data used to train, refine, and operate a model, and applies in parallel with the EU Artificial Intelligence Act rather than being displaced by it. The Data Protection Officer has a central role in assessing and documenting compliance across both regimes.
Artificial Intelligence practiceLawful basis and training data
Establishing a lawful basis for the personal data used to train and refine models, and observing purpose limitation and data minimisation.
Automated decisions and profiling
Article 22 applies where decisions concerning individuals are taken without meaningful human involvement, and imposes specific safeguards and a right to an explanation.
Impact assessments for AI
High-risk processing by an artificial intelligence system ordinarily requires a data protection impact assessment before deployment, documenting the risks and the controls applied.
Transparency
Informing individuals, clearly and accessibly, when their personal data is processed by an automated system and to what effect.
GDPR and the EU AI Act
Identifying the areas in which the two regimes overlap, in order that a system satisfies both rather than one at the expense of the other.
Data subject rights
Managing access, rectification, and erasure where personal data is embedded in models, prompts, and processing pipelines.
Clinical Trials DPO
Clinical trials involve the large-scale processing of health data, which renders the appointment of a Data Protection Officer mandatory in most cases. The role in this context is distinct, comprising data protection impact assessments for the trial data flows, review of informed consent and participant information, review of the trial website and privacy notice, and assessment of CRO and vendor compliance.
Clinical Trials DPOContacts
