
{"id":14544,"date":"2024-04-10T14:57:46","date_gmt":"2024-04-10T12:57:46","guid":{"rendered":"https:\/\/www.dp-institute.eu\/?p=14544"},"modified":"2024-05-08T13:57:43","modified_gmt":"2024-05-08T11:57:43","slug":"dpo-in-the-spotlight-frieke-verniest","status":"publish","type":"post","link":"https:\/\/www.dp-institute.eu\/en\/dpo-in-the-spotlight-frieke-verniest\/","title":{"rendered":"DPO in the spotlight: Frieke Verniest"},"content":{"rendered":"<h4>In this article we want to spotlight a data protection officer based on 10 questions they were asked by DPI.<\/h4>\n<h4>Frieke Verniest , Data Protection Officer\u00a0 at AZ Sint-Jan in Bruges , is this months DPO.<\/h4>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-14536\" src=\"https:\/\/www.dp-institute.eu\/wp-content\/uploads\/2024\/04\/DPO-in-de-kijker-Frieke-Verniest-foto-300x200.jpg\" alt=\"\" width=\"300\" height=\"200\" srcset=\"https:\/\/www.dp-institute.eu\/wp-content\/uploads\/2024\/04\/DPO-in-de-kijker-Frieke-Verniest-foto-300x200.jpg 300w, https:\/\/www.dp-institute.eu\/wp-content\/uploads\/2024\/04\/DPO-in-de-kijker-Frieke-Verniest-foto-1024x683.jpg 1024w, https:\/\/www.dp-institute.eu\/wp-content\/uploads\/2024\/04\/DPO-in-de-kijker-Frieke-Verniest-foto-768x512.jpg 768w, https:\/\/www.dp-institute.eu\/wp-content\/uploads\/2024\/04\/DPO-in-de-kijker-Frieke-Verniest-foto-1536x1024.jpg 1536w, https:\/\/www.dp-institute.eu\/wp-content\/uploads\/2024\/04\/DPO-in-de-kijker-Frieke-Verniest-foto-2048x1365.jpg 2048w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<p><b><span data-contrast=\"none\">How did you end up in the role of DPO?<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\"><strong>Frieke:<\/strong> In 2016, I started as a staff officer in the ICT department at AZ Sint-Jan. The former information security consultant had just retired. I was asked if I was interested in anything to do with privacy and security. A training course quickly followed, very quickly followed by many information sessions on the upcoming GDPR, networking moments with colleagues from other hospitals and we started a process to get the hospital as ready as possible when the AVG came into force. <\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">This included the official appointment of a DPO. This gave me a new interpretation of my role in the hospital. To this day I have no regrets about that, on the contrary.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"none\">Which part of the tasks of a DPO do you prefer?<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\"><strong>Frieke<\/strong>: I get the most satisfaction from contacts with the various departments and stakeholders in the hospital. The role of DPO ensures that I may and must gain knowledge of all processes and functions in the hospital.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">I still enjoy setting up and giving awareness sessions the most. Turning dry subject matter into a recognizable story with the aim of conveying something that sticks with colleagues who are in the field, that&#8217;s where I get satisfaction.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"none\">Which event in the privacy landscape has affected you the most to date?<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\"><strong>Frieke: <\/strong>The cyberattack and thus the major data breach at Limburg.net made me frown. That a data leak with such a large impact is possible is no secret to anyone. What did make me frown was the apparent calm and resignation among the victims. Few involved seem to be very concerned about their data being on the street. Very few see any danger in certain information being shared or leaked. This indicates that we still have a long way to go in terms of awareness.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">I do see a nice positive evolution at VRT NWS, for example. Technology, privacy and security are getting more and more specific attention and appear as separate items in the news and in news programs.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"none\">\u00a0How would you describe the role of DPO in your company?<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\"><strong>Frieke: <\/strong>The role of DPO within our hospital consists of rigorous advising, being accessible for any question, setting up awareness from top to bottom of the organization. As a DPO, I also try to think along where possible.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"none\">What do you think is the biggest challenge for a DPO?<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\"><strong>Frieke: <\/strong>The ever-growing connection between privacy and technology. How can you, as a DPO, keep up with legislation and case law on the one hand and have sufficient up-to-date knowledge of technology and technical possibilities in terms of privacy and security on the other?<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">Everything is becoming digital, everything has a security aspect and every project has a privacy section and a security section. AI is a great example of this. As a DPO, how much do you need to understand what is coming in-house and what is being used in-house? How should you as a DPO correctly oversee and advise without thwarting innovation? Is that the role of the DPO alone?<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">Fortunately, in our organization we can count on a very close collaboration with the IT security team. We almost sit next to each other and consult weekly. We benefit from each other&#8217;s knowledge and passion about privacy and technology.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"none\">\u00a0Which technological evolution do you think has the most impact on data protection (positive\/negative)?<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\"><strong>Frieke: <\/strong>AI without a doubt. This sounds like kicking in an open door. AI is rushing at us. Where technology is starkly improving ease of use, there you see that people are more likely to give up their privacy. That&#8217;s perfectly understandable. I get a lot back, so why not give up some of my privacy?\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">The impact on data protection here can be negative, although I don&#8217;t want to sound pessimistic here. Negative in terms of sharing personal data too easily to a black box that needs to be trained or that can give us a smart answer back. What guarantees are there here in terms of data protection?<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">I also see a lot of projects emerging that are really committed to privacy and security by design. In the world of blockchain, some players are betting rock hard on privacy. I am eagerly waiting to see if they will make a go-ahead with a positive impact on data protection.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">Another positive story, is that of data vaults, such as the Solid project. Wondering if that will become a standard and how this evolves and if it will really be a true transformation as people suggest.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"none\">What are your experiences in the contact between the DPO and the data subject\/supervisor?<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\"><strong>Frieke: <\/strong>Contacts with stakeholders are often a positive story. People have questions and get answers or get a better understanding of what is possible, allowed and who ever accessed their file. Sometimes there is a less positive experience with a data subject, that can be if there was another negative experience before the question or complaint to the DPO.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">Often a lesser experience also comes from a lack of understanding. I have found that calling people and not limiting yourself to email can be a big help here. In 1 extreme case, we even once went up to a patient&#8217;s room to show together how to manage eHealth-level access to your file.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">Contact with the VTC is often positive. They are accessible if you have questions. If you report a data breach, you always get a response (with some delay). We&#8217;ll take the reprimand at that point.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"none\">What is your golden tip for getting data protection and information security higher on management&#8217;s agenda?<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\"><strong>Frieke: <\/strong>A data breach or a cyber incident are the quickest way to get this on their agenda. No, we&#8217;re not going to wait for that and you don&#8217;t wish that on any organization.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">Facts, figures and an understandable story. Link the organization&#8217;s strategic goals with how privacy and cybersecurity can help with that. Make that tangible, show them figures on how easily we still fall for phishing emails. Make them aware of their responsibilities as outlined in the law (GDPR and NIS2).<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">But the golden tip? Get to know your management and find out if they are sensitive to dry numbers or rather to a story of responsibilities or maybe they are very keen to get certified and compliancy is important? For every type of manager, there is certainly a way to make them understand that privacy and security are important.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"none\">What is your Swiss army knife as a DPO?<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\"><strong>Frieke: <\/strong>An app with the legislation. That way I always have it handy.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">Colleagues and collaboration with colleagues from other hospitals. That is so important. Sharing knowledge, sharing frustrations, sharing tools and thinking together how to do things better.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"none\">\u00a0How do you keep up with new trends in GDPR technology and legislation?<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\"><strong>Frieke: <\/strong>On the one hand through knowledge-sharing platforms and on the other through the Stay Tuned sessions that Data Protection Institute sets up.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">To skim the website of the GBA, EDPB and VTC myself sometimes lacks the time. So I am very grateful that these knowledge-sharing opportunities and Stay Tuned sessions are there.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this article we want to spotlight a data protection officer based on 10 questions they were asked by DPI. Frieke Verniest , Data Protection Officer\u00a0 at AZ Sint-Jan in Bruges , is this months DPO. How did you end up in the role of DPO?\u00a0 Frieke: In 2016, I started as a staff officer [&hellip;]<\/p>\n","protected":false},"author":30,"featured_media":14536,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[611,625],"tags":[],"class_list":["post-14544","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-dpo","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.dp-institute.eu\/en\/wp-json\/wp\/v2\/posts\/14544","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.dp-institute.eu\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.dp-institute.eu\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.dp-institute.eu\/en\/wp-json\/wp\/v2\/users\/30"}],"replies":[{"embeddable":true,"href":"https:\/\/www.dp-institute.eu\/en\/wp-json\/wp\/v2\/comments?post=14544"}],"version-history":[{"count":2,"href":"https:\/\/www.dp-institute.eu\/en\/wp-json\/wp\/v2\/posts\/14544\/revisions"}],"predecessor-version":[{"id":14548,"href":"https:\/\/www.dp-institute.eu\/en\/wp-json\/wp\/v2\/posts\/14544\/revisions\/14548"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.dp-institute.eu\/en\/wp-json\/wp\/v2\/media\/14536"}],"wp:attachment":[{"href":"https:\/\/www.dp-institute.eu\/en\/wp-json\/wp\/v2\/media?parent=14544"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.dp-institute.eu\/en\/wp-json\/wp\/v2\/categories?post=14544"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.dp-institute.eu\/en\/wp-json\/wp\/v2\/tags?post=14544"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}