2.5 Put in place a Data Protection Governance
To comply with Article 24(1) and (2) of the GDPR and deal with the protection of personal data and its complex regulatory environment effectively and efficiently, an appropriate organisation structure with clearly defined roles and responsibilities as well as clear guidance on what needs to be achieved at each level should be implemented.
Therefore, TPOmap is based on a Data Protection Governance structure along the following lines to increase ownership of the business and support an efficient implementation of the Privacy Management Program:

Such governance structure is the basis for defining staff members’ access rights to the TPOmap Documentation Depository which are granted in accordance with the following roles.