DPO · NIS2 · GDPR

Data Protection Officer & NIS2 Lead Implementer

Data Protection Officer & NIS2 Lead Implementer

Gecertificeerd DPO en NIS2 Lead Implementer, actief als freelance consultant. Deze combinatie is schaars: de meeste DPO's adviseren vanaf de zijlijn, de meeste NIS2-implementatoren komen uit een pure IT-hoek. Ik doe beide, en ik voer het ook zelf uit.

Certified DPO and NIS2 Lead Implementer, working as a freelance consultant. That combination is rare: most DPOs advise from the sidelines, most NIS2 implementers come from a pure IT background. I do both, and I execute it myself.

Wat doet een DPO?

What does a DPO do?

Een Data Protection Officer (functionaris gegevensbescherming) waakt over hoe een organisatie omgaat met persoonsgegevens - van klanten, personeel of andere betrokkenen. De DPO is wettelijk voorzien in de AVG/GDPR (Verordening (EU) 2016/679, artikelen 37-39) en controleert of de organisatie de regels correct volgt, adviseert het management, en is het aanspreekpunt voor zowel de toezichthouder als voor mensen die vragen hebben over hun gegevens.

A Data Protection Officer safeguards how an organisation handles personal data - of customers, staff or other data subjects. The DPO role is set out in the GDPR (Regulation (EU) 2016/679, Articles 37-39) and involves checking that the organisation follows the rules correctly, advising management, and acting as the point of contact for both the supervisory authority and individuals with questions about their data.

  1. Toezicht houden - controleren of verwerkingen van persoonsgegevens aan de AVG voldoen.
  2. Adviseren - het management begeleiden bij nieuwe projecten, tools en risicoanalyses (DPIA's).
  3. Aanspreekpunt zijn - voor de Gegevensbeschermingsautoriteit én voor betrokkenen met vragen of klachten.
  4. Opleiden & sensibiliseren - medewerkers bewust maken van hun verantwoordelijkheden.
  5. Incidenten begeleiden - datalekken correct en tijdig laten melden en afhandelen.
  1. Monitoring compliance - checking that personal data processing complies with the GDPR.
  2. Advising - guiding management on new projects, tools and risk assessments (DPIAs).
  3. Acting as point of contact - for the Data Protection Authority and for individuals with questions or complaints.
  4. Training & awareness - making staff aware of their responsibilities.
  5. Handling incidents - ensuring data breaches are reported and handled correctly and on time.
ToepasselijkheidApplicability Wie valt hieronderWho this covers
Verplicht (Art. 37 AVG)Mandatory (Art. 37 GDPR) Overheidsinstanties en -organen; organisaties waarvan de kerntaak bestaat uit grootschalige, regelmatige en stelselmatige monitoring van personen (bv. profiling, tracking, verzekeraars, banken, telecom); organisaties die op grote schaal gevoelige gegevens verwerken (gezondheid, biometrie, strafrechtelijke gegevens) - bv. ziekenhuizen, labo's, verzekeraars. Public authorities and bodies; organisations whose core activity involves large-scale, regular and systematic monitoring of individuals (e.g. profiling, tracking, insurers, banks, telecom); organisations processing sensitive data at scale (health, biometric, criminal records) - e.g. hospitals, labs, insurers.
Niet verplicht, wel sterk aan te radenNot mandatory, but strongly advisable KMO's en scale-ups die persoonsgegevens van klanten en personeel verwerken op kleinere schaal, of onder NIS2 vallen. Geen wettelijke DPO-plicht, maar wél volledig aansprakelijk bij inbreuken - een vast aanspreekpunt beperkt dat risico. SMEs and scale-ups processing customer and staff personal data on a smaller scale, or subject to NIS2. No legal DPO obligation, but still fully liable in case of breaches - a fixed point of contact limits that risk.
Geen aparte DPO nodigNo dedicated DPO needed Zeer kleine ondernemingen of zelfstandigen zonder systematische, grootschalige gegevensverwerking. Let op: de AVG zelf blijft wél gelden voor iedereen - enkel de verplichting om een aparte DPO aan te stellen vervalt. Very small businesses or self-employed individuals without systematic, large-scale data processing. Note: the GDPR itself still applies to everyone - only the obligation to appoint a dedicated DPO falls away.

Bron: Algemene Verordening Gegevensbescherming (AVG/GDPR), artikel 37. Dit is algemene informatie, geen juridisch advies - de exacte verplichting voor jouw organisatie wordt best individueel getoetst.

Source: General Data Protection Regulation (GDPR), Article 37. This is general information, not legal advice - your organisation's exact obligation is best assessed individually.

Wat ik lever

What I deliver

  • Verwerkingsregisters & DPIA's
  • Betrokkenenrechten-procedures
  • Disaster recovery planning
  • NIS2-complianceprogramma's
  • Informatiebarrières & CSI-compliance
  • ISO 27001-trajecten
  • Processing registers & DPIAs
  • Data subject rights procedures
  • Disaster recovery planning
  • NIS2 compliance programmes
  • Information barriers & CSI compliance
  • ISO 27001 tracks

Certificeringen

Certifications

  • Data Protection Officer - Data Protection Institute (2026)
  • NIS2 Lead Implementer België - Data Protection Institute (2025)
  • DORA-certificering - in opleiding, te behalen in 2026
  • ISO 27001 (2026)
  • Sustainability Management - Vlerick College
  • Data Protection Officer - Data Protection Institute (2026)
  • NIS2 Lead Implementer Belgium - Data Protection Institute (2025)
  • DORA certification - in training, to be obtained in 2026
  • ISO 27001 (2026)
  • Sustainability Management - Vlerick College
01

Nulmeting

Baseline assessment

Gap-analyse t.o.v. GDPR/NIS2-verplichtingen en bestaande processen.

Gap analysis against GDPR/NIS2 obligations and existing processes.

02

Registers & DPIA's

Registers & DPIAs

Verwerkingsregisters, risicoanalyses en betrokkenenrechten uitwerken.

Building processing registers, risk assessments and data subject rights.

03

Implementatie

Implementation

Procedures, informatiebarrières en beleid effectief uitrollen in de organisatie.

Rolling out procedures, information barriers and policy across the organisation.

04

Audit-ready

Audit-ready

Dossier en bewijslast op orde, klaar voor de auditor.

Documentation and evidence in order, ready for the auditor.

Bij een grootstedelijke overheidsorganisatie bouwde ik een NIS2-traject op: verwerkingsregisters, DPIA's, betrokkenenrechten-procedures, disaster recovery planning. Bij een telecom-wholesale speler leidde ik informatiebarrières, CSI-compliance en ISO27001-trajecten binnen een complexe regelgevende omgeving.

At a large city government organisation, I built out a full NIS2 track: processing registers, DPIAs, data subject rights procedures, disaster recovery planning. At a telecom wholesale player, I led information barriers, CSI compliance and ISO 27001 tracks within a complex regulatory environment.

Actief voor: grote corporates, overheid/publieke sector en scale-ups - zowel voor NIS2-/GDPR-compliancetrajecten als voor projectmanagement binnen complexe, technische omgevingen.

Active for: large corporates, government/public sector and scale-ups - both for NIS2/GDPR compliance tracks and for project management within complex, technical environments.

Search