Data protection officer

The data protection officer is the internal supervisor of compliance with data protection rules. They advise, monitor, cooperate with the regulator and act as the contact point for data subjects.

Legal basis

Article 37 GDPR sets out when appointment is compulsory: for public authorities, for organisations whose core activities involve regular and systematic monitoring of individuals on a large scale, and for those whose core activities involve large-scale processing of special category or criminal data. Article 38 safeguards the position: the officer must be involved in good time, be given the necessary resources, receive no instructions on the exercise of their tasks, and not be dismissed or penalised for performing them. They report to the highest level of management. Article 39 lists the tasks, including monitoring compliance, advising on impact assessments and cooperating with the supervisory authority. The appointment must be notified to the Dutch Data Protection Authority.

How it works in practice

The role can be filled internally or externally, part-time, and may be combined with other duties provided there is no conflict of interest. Such a conflict arises with roles that themselves determine purposes and means, such as head of IT, head of HR or a director. Many organisations appoint an officer voluntarily; the same safeguards then apply.

Where it goes wrong

The role is given to the head of IT, creating a conflict of interest on which European regulators have already enforced repeatedly. A second error is an officer with no time, budget or access to the board. Third, the officer is consulted only once a system has been purchased, whereas the law requires timely involvement.

Related terms

The officer has a role in the data protection impact assessment, in the personal data breach and in data subject rights.

Unsure whether appointment is compulsory? Our IT lawyers test the criteria and the independence requirement.