HubBroker & Data Protection Officers

1. Appointed Data Protection Officer(s)
In accordance with GDPR Article 37, HubBroker ApS has appointed a Data Protection Officer (DPO) responsible for monitoring compliance with data protection law and serving as the point of contact for data subjects and supervisory authorities.
Primary Data Protection Officer
Name: Upendra Verma
Title: Country Manager
Email: upen@hubroker.com
Phone: +91 9727794030
Postal Address:
HubBroker ApS,
D-1010, The First, B/H ITC Narmada, Ahmedabad, Gujarat, 380015, India.
Business Hours: [Monday-Friday, 10:00 AM-07:00 PM IST]
Response Time SLA: [24 hours for email inquiries]
Deputy/Backup Data Protection Officer
Name: Kishan Mehta
Title: Cloud System Administrator
Email: kime@hubbroker.com
Phone: +91 7621900625
Backup DPO provides continuity during primary DPO absence (vacation, leave, etc.)
How to Contact Our DPO?
For data subjects: Send your inquiry to upen@hubbroker.com with subject line "GDPR Data Subject Request" or "Data Protection Matter"
For supervisory authorities: Contact primary DPO first; if unresponsive, escalate to backup DPO
Response guarantee: All inquiries acknowledged within 24 hours; substantive response within 10 business days
2. Tasks and Responsibilities of the Data Protection Officer
Our Data Protection Officer is responsible for the following tasks as mandated by GDPR Article 39:
2.1 Monitoring Compliance (Article 39(1)(a))
The DPO monitors HubBroker ApS's compliance with:
- GDPR (Regulation 2016/679) and all applicable data protection laws
- UK GDPR (Data Protection Act 2018, as amended)
- ePrivacy Directive (2002/58/EC) and national implementations
- EDPB Guidelines (including Guidelines 05/2020 on SCCs, 01/2018 on DPIA, etc.)
- Internal data protection policies, procedures, and standards
- Contractual obligations (Data Processing Agreements, Privacy Notices, etc.)
- Sub-processor management and due diligence
- Data Protection Impact Assessments (DPIA)
- International data transfer safeguards (Schrems II compliance)
- Personal data security measures and incident response procedures
Monitoring Activities:
- Quarterly compliance assessments
- Annual audit of data protection policies and procedures
- Review of processing activities and data inventory
- Oversight of sub-processor agreements (minimum annual)
- Monitoring of security certifications and audit reports
- Tracking of data protection incident patterns
- Assessment of third-party risk
2.2 Awareness and Training (Article 39(1)(b))
The DPO is responsible for:
- Designing and delivering mandatory data protection training for all employees with access to personal data (minimum annually)
- Creating tailored training for specific roles:
- Technical staff (security, infrastructure)
- Customer-facing teams (support, sales)
- Management and decision-makers
- New employees (onboarding)
- Developing training materials and resources
- Measuring training effectiveness through assessments
- Keeping staff informed of regulatory changes and best practices
- Promoting a "privacy by design" culture within the organization
Training Schedule:
- Mandatory: All employees - minimum 1 session per year
- Role-specific: Technical/Data-heavy roles - 2+ sessions per year
- New hires: Within first month of employment
- Senior management: Minimum twice per year
- Ad hoc: Following security incidents or regulatory changes
2.3 Cooperation with Supervisory Authorities (Article 39(1)(c))
The DPO shall:
- Serve as the primary point of contact with data protection authorities (e.g., Danish Data Protection Authority, EU regulators)
- Respond to supervisory authority inquiries within 5 business days or as legally required)
- Cooperate fully with data protection inspections and investigations
- Provide supervisory authorities with requested documentation and access
- Report serious compliance breaches to supervisory authorities when required
- Participate in any regulatory investigations without penalization
- Maintain confidentiality of supervisory authority communications unless legally prohibited
Escalation Process:
- Minor inquiries: DPO responds directly
- Complex matters: DPO escalates to Legal/Compliance team
- Strategic matters: DPO escalates to Executive Management
- Serious breaches: Escalate to supervisory authority within 72 hours (per Article 33)
2.4 Data Subject Rights Support
The DPO assists in:
- Fulfilling data subject access requests (Article 15)
- Implementing rectification and erasure requests (Articles 16-17)
- Providing data portability (Article 20)
- Managing restrictions on processing (Article 18)
- Handling objections and withdrawal of consent (Articles 21, 7)
- Explaining processing activities and rights to data subjects
- Processing complaints from data subjects
Support includes:
- Coordinating across departments for information gathering
- Drafting responses to data subject communications
- Ensuring response timelines met (typically 30 days)
- Advising on data subject rights implications
2.5 Data Protection Impact Assessments (DPIA)
The DPO shall:
- Be consulted when a Data Protection Impact Assessment is required (Article 35(2))
- Review DPIA results for high-risk processing
- Monitor implementation of DPIA recommendations
- Advise on whether supervisory authority prior consultation is needed (Article 36)
DPIA Scope:
- Processing of special categories of data (Article 9)
- Large-scale processing of personal data
- Processing using new technologies
- Processing likely to restrict data subject rights
- Systematic monitoring or profiling (if applicable)
2.6 International Data Transfer Oversight
The DPO monitors:
- Transfers to third countries requiring SCCs or other mechanisms (Schrems II)
- Adequacy decisions and their ongoing validity
- Data Transfer Impact Assessments (DTIA) compliance
- Sub-processor international transfer safeguards
- Supplementary measures effectiveness (encryption, access controls, etc.)
At minimum, annually:
- Review transfer mechanisms in place
- Assess whether supplementary measures remain adequate
- Review any new data transfer regulations or court decisions
- Update DTIAs if circumstances change
2.7 Security and Incident Response
The DPO monitors:
- Implementation of security measures (Article 32)
- Sub-processor security compliance (Article 28)
- Data breach detection and response procedures
- Incident notification timeline compliance (Article 33: 72 hours to authority)
- Post-incident reviews and corrective actions
- Penetration testing and vulnerability management
Responsibilities:
- Review all security incident reports
- Advise on breach notification decisions
- Support supervisory authority cooperation in breach investigations
- Recommend security improvements
2.8 Data Processing Instruction Review
The DPO ensures:
- All processing is done in accordance with customer instructions (as a processor)
- Customer Data Processing Agreements (DPAs) comply with Article 28
- Processing only occurs within documented scope
- Unauthorized processing is identified and escalated
- Sub-processor changes comply with notification requirements
2.9 Record Keeping and Documentation
The DPO maintains:
- Records of processing activities (Article 30)
- Data Protection Impact Assessments (when conducted)
- Training records and completion certifications
- Audit reports and findings
- Compliance assessment results
- Supervisory authority communications
- Data breach logs and incident reports
Record Retention: Minimum 3 years (or as legally required)
2.10 Policy Development and Updates
The DPO assists in:
- Developing and updating data protection policies
- Creating Privacy Notices (Article 13-14 compliant)
- Establishing data processing procedures
- Creating data retention and deletion schedules
- Developing incident response procedures
- Documenting processing activities
- Updating DPAs with customers
Review Schedule:
- Annual review of all policies (minimum)
- Updates following regulatory guidance changes
- Updates following security incidents
- Updates following organizational changes
Category: GDPR
Last date of update: 24.08.2026