northdan.
Vezi pagina în română

IT Glossary

What is a DPO?

The Data Protection Officer is the person an organisation designates to oversee compliance with personal data rules — a role defined and, in some cases, required by GDPR.

GDPR names very few roles explicitly, and the Data Protection Officer is one of them. That tells you how the regulation expects accountability to work: not spread evenly across everyone until it belongs to nobody, but attached to a named person with defined duties and protection from being dismissed for performing them. The DPO informs and advises the organisation on its obligations, monitors how personal data is actually handled, advises on impact assessments for risky processing, trains the people who touch that data, and acts as the contact point both for individuals exercising their rights and for the supervisory authority. Crucially the role is advisory and independent — the DPO does not decide what the business does with data, and cannot be instructed which conclusion to reach. Appointment is mandatory for public authorities, for organisations whose core activity involves large-scale systematic monitoring, and for those processing sensitive categories at scale. Plenty of companies below that threshold appoint one anyway, because a single accountable name is cheaper than the alternative: a regulator asking who was responsible and receiving a shrug.

Let’s talk about your project

Message us on WhatsApp or send an email — you talk directly to a developer.

office@northdan.com · +40 752 070 247

Why it matters for your business

One accountable name, not diffuse blame

Requests, incidents and authority correspondence land with someone whose job it is, instead of circulating until a deadline passes.

Risks found before the fine

Routine review of new processing, vendors and marketing practices catches the expensive problems while they are still cheap to fix.

Demonstrable trust for partners

Enterprise buyers and public tenders ask for the data protection contact by name, and an empty field slows the deal.

Frequently asked questions

Is my company obliged to appoint a DPO?

Mandatory in three cases: you are a public authority; your core activity requires regular, systematic monitoring of people on a large scale; or your core activity is large-scale processing of special categories such as health, biometric or criminal data. A distributor with a customer list and a payroll usually falls outside. If your product tracks users or handles health data, assume you are inside and document the assessment either way.

Must the DPO be an employee, or can the role be outsourced?

Either is permitted. An external DPO under a service contract is common for small and mid-sized organisations because the role demands legal and technical knowledge that is expensive to keep in-house part-time. The requirements stay the same in both cases: genuine expertise, no conflict of interest with roles that decide processing purposes, and published contact details.

What is the exposure for a company that should have appointed a DPO and did not?

Failure to designate is itself an infringement, in the tier reaching up to ten million euros or two per cent of global annual turnover. In practice the omission rarely arrives alone — it surfaces during an investigation into a breach or a complaint, and it signals to the authority that governance was absent, which colours the assessment of everything else they find.