Fiche 44/54
Part 5 — Operational Obligations & Sanctions
Intermediate
Reviewed 2026-08-23
Data Protection Officer (DPO) (Art. 37–39)
Data Protection Officer (DPO) (Art. 37–39)
⚡ In 30 seconds
Under Article 37(1), designating a DPO is mandatory where: (a) Processing is carried out by a public authority, (b) Core activities require regular and systematic monitoring of individuals on a large scale, or (c) Core activities consist of processing on a large scale of sensitive data (Art. 9) or criminal data (Art. 10).
| Statutory Dimension | Legal Requirement | Operational Reality |
|---|---|---|
| Status & Position (Art. 38) | Reports directly to highest management; protected against dismissal for performing tasks. | Direct board access; no instructions on how to interpret law; zero conflict of interest. |
| Core Tasks (Art. 39) | Inform, advise, monitor compliance, oversee DPIAs, act as contact point for DPA. | Reviewing vendor DPAs; organizing staff training; auditing RoPA records. |
| Legal Liability | The DPO is personally not liable for corporate GDPR non-compliance. | The controller alone bears legal responsibility and risk of administrative fines. |