For Organisation AdminsAdding & Managing DPOs

Adding & Managing DPOs

Invite a Data Protection Officer, activate their account, and connect the systems they will search.

Every person who runs SARs needs their own DPO account.

During onboarding, Fisar assigns your initial DPOs for you - you do not need an administrator in place first. See Onboarding. This page covers adding further DPOs yourself once you have an organisation administrator account.

Watch it done

A DPO can only be created from the organisation dashboard. This cannot be done from a DPO account.

Adding a DPO

Click New DPO

Use the New DPO button at the top of the left-hand menu.

Enter their details

Provide the person's name, company name and email address. The email address is where their invitation is sent.

Save

The account is created and shows as Inactive until they accept.

They accept the invitation

They receive a "You're invited to join Fisar" email. Following the link lets them set a password and configure multi-factor authentication.

Connect their systems

Once active, connect the available connectors for them from the organisation account.

New DPO dialog with fields for name, company name and email address
New DPO dialog with fields for name, company name and email address

If the invitation email has not arrived, check the recipient's Other or junk folder. You can also copy the invitation link directly from the platform and send it another way.

Managing existing DPOs

DPO Management lists everyone on the account with their request volumes, SLA performance and last sign-in.

DPO Management screen listing Data Protection Officers with their status and activity
DPO Management screen listing Data Protection Officers with their status and activity

From here you can resend an invitation, suspend an account, or review activity.

Connectors and DPOs

You can connect several systems at once to a DPO from the organisation account - Microsoft 365, Google, Bromcom and others can all be attached to the same person.

There is an important limitation. When a DPO runs a request from their own login, they can only search one connector at a time. To search a different system they must disconnect the current one and reconnect the other.

This means a request covering both Microsoft 365 and Google is run as two passes, not one.