Data Protection Officer is the independent advisor a controller or processor must appoint under GDPR Article 37 in defined circumstances, responsible for monitoring data-protection compliance.
The Data Protection Officer (DPO) is a statutory role under Articles 37 to 39 of the GDPR.
The controller or processor must designate a DPO when the processing is carried out by a public authority, when the core activities require regular and systematic monitoring of data subjects on a large scale, or when the core activities involve large-scale processing of special-category data under Article 9 or data on criminal convictions under Article 10.
The DPO's tasks under Article 39 include informing and advising the organisation, monitoring GDPR compliance, advising on Data Protection Impact Assessments, cooperating with the supervisory authority, and acting as the contact point for data subjects.
The role must be independent: the DPO reports to the highest level of management, cannot be dismissed or penalised for performing their duties, and cannot hold a conflicting role such as head of marketing or head of HR.
A DPO can be an employee or an external service provider, and a group of undertakings can share a single DPO if they remain easily accessible from each establishment. Some non-EU jurisdictions have adopted equivalent or analogous roles: the UK GDPR mirrors Articles 37-39, and Brazil's LGPD requires an encarregado.
You will encounter DPO obligations when designing the privacy programme of any organisation processing health data, biometrics, behavioural advertising data at scale, employee monitoring data, or operating as a public authority. The DPO's contact details must be published, typically in the privacy notice, and notified to the supervisory authority.
See what a company actually costs in year one, and how the jurisdictions compare on tax, capital and timeline.