GlossaryCompliance operations

DPO

Short answer

A DPO (Data Protection Officer) is the person who advises an organisation on its data protection obligations and monitors its compliance with the GDPR. Appointing one is mandatory for public bodies and for companies whose core activities involve large scale monitoring of people or large scale processing of sensitive data.

When a DPO is mandatory

Article 37 of the GDPR requires a DPO for public authorities, for organisations whose core activities involve regular and systematic monitoring of people on a large scale, and for those that process special categories of data or criminal records on a large scale. In Spain, Article 34 of the LOPDGDD adds a list of sectors that must appoint one, including schools and universities, credit institutions, insurers, energy suppliers and private security companies. The appointment must be notified to the AEPD.

What the DPO does

Informs and advises management and staff, monitors compliance with the GDPR and internal policies, advises on data protection impact assessments, trains staff, and acts as the contact point for the supervisory authority and for people who want to exercise their rights.

Independence

The DPO must have expert knowledge of data protection law and practice, report to the highest level of management, receive no instructions on how to carry out their tasks and have no conflict of interest. That is why the role is usually not combined with heads of IT, marketing or HR. It can be an employee or an external service.

DPO and security

The DPO is not the person responsible for security, but works closely with the CISO on data breaches, supplier assessments and security measures for personal data.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub