When a DPO is mandatory
Article 37 of the GDPR requires a DPO for public authorities, for organisations whose core activities involve regular and systematic monitoring of people on a large scale, and for those that process special categories of data or criminal records on a large scale. In Spain, Article 34 of the LOPDGDD adds a list of sectors that must appoint one, including schools and universities, credit institutions, insurers, energy suppliers and private security companies. The appointment must be notified to the AEPD.
What the DPO does
Informs and advises management and staff, monitors compliance with the GDPR and internal policies, advises on data protection impact assessments, trains staff, and acts as the contact point for the supervisory authority and for people who want to exercise their rights.
Independence
The DPO must have expert knowledge of data protection law and practice, report to the highest level of management, receive no instructions on how to carry out their tasks and have no conflict of interest. That is why the role is usually not combined with heads of IT, marketing or HR. It can be an employee or an external service.
DPO and security
The DPO is not the person responsible for security, but works closely with the CISO on data breaches, supplier assessments and security measures for personal data.




