Many courses promise a "mandatory DPO certificate". It sounds official — but it isn't. Let's look, without the myth and the marketing, at what the law actually requires to act as a data protection officer.
It's one of the most widespread misconceptions in the GDPR world: "To be a DPO, you need a mandatory certificate." On course websites, in ads, sometimes even in tender specifications, it shows up as if it were a requirement of the law. It isn't.
Let's separate the myth from the text. The short answer: the law requires competence, not a certificate. And the difference matters — both for companies that appoint a DPO and for people who want to become one.
The conditions for designating a data protection officer are set out in Article 37 of the GDPR. Paragraph (5) is the relevant one here, and it says plainly: the DPO is designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices, as well as the ability to fulfil the tasks referred to in Article 39.
Notice what it does not say: it does not call for a particular diploma, a state exam, an accreditation or a "DPO certificate". The text speaks about the level of knowledge and the ability to do the job, in proportion to the complexity and sensitivity of the organisation's processing. The riskier the processing, the higher the expertise expected — but not in the form of a piece of paper.
This is confirmed by the official DPO guidance of the European Data Protection Board (EDPB), carried over from the former Article 29 Working Party: professional certification is not a legal requirement to be a DPO. It is a possible good practice, not an obligation.
A second common misconception: the idea that the supervisory authority hands you a kind of "DPO attestation". That is not the case. ANSPDCP does not issue and does not make the designation of a data protection officer conditional on obtaining any certificate from it. What happens instead is a notification of the DPO's contact details to the authority (Art. 37(7)) — an administrative step, not an exam.
In other words, there is no public authority in Romania that "authorises" individuals as DPOs. The responsibility for appointing a genuinely competent person stays with the organisation (the data controller).
Here we need to be precise, so we don't swing to the opposite extreme. In Romania there is a recognised occupation — "Data protection officer" — with an occupational standard and a place in the national classification of occupations. On that basis, training providers run courses that, at the end, issue a certificate of professional competence.
What does such a certificate prove? That you attended and passed structured training. That's it — and that's not nothing. It is useful, it is credible to a partner or an employer, and it can speed up your entry into the role. But it must be said just as clearly: it is not a statutory condition to be designated DPO. The GDPR does not impose it and ANSPDCP does not impose it. Anyone presenting it as "mandatory by law" is overstating it.
Phrases such as "mandatory DPO certification", "the only certificate the law accepts" or "you can't practise without this attestation" are red flags. None of them has any basis in the GDPR. Often they turn useful training into a false obligation, to justify the price.
What you should look for instead, in a person or a firm about to act as DPO:
Beyond any paper, a serious data protection officer needs a concrete set of competences:
If you want to dig into the role itself, we've written at length about what a DPO is and about who can be the GDPR data protection officer. For small and medium businesses, an outsourced DPO brings up-to-date competence without the cost of an extra employee.
None of this means training is pointless — quite the opposite. A good course is the fastest way to build or refresh the competence required by Art. 37(5). The key is to treat it correctly: as an investment in what you can do, not as "the mandatory certificate" without which you're not allowed to exist.
In that spirit, we offer training courses for data protection officers and for the teams that work with personal data every day — to build real competence and keep it current.
The question "Is the DPO certificate mandatory?" has a short answer: no. The law requires competence — expert knowledge and the ability to do the job — not a piece of paper. A certificate can prove you've learned and has its value, but it doesn't make you a DPO on its own and is not imposed by the GDPR or by ANSPDCP. Choose people and partners by what they know and have demonstrated, not by a promise of "mandatory accreditation".
No. The GDPR does not require any specific certificate or diploma. Art. 37(5) requires expert knowledge of data protection law and practices and the ability to fulfil the tasks set out in Art. 39 — that is, competence, not a piece of paper. The EDPB guidance (former Article 29 Working Party) confirms that certification is not a legal requirement.
No. The supervisory authority (in Romania, ANSPDCP) does not issue and does not require a "DPO certificate" as a precondition for appointing or designating a data protection officer. The appointment is notified to the authority, but there is no mandatory exam or accreditation issued by it.
Real value: a serious course builds and refreshes competence, and a certificate of completion (for example, based on the occupational standard and the recognised occupation) proves you attended and passed structured training. It is useful and credible — but it is not a statutory condition to be appointed DPO. What matters is what you know and can do, not just the paper.
Knowledge of the GDPR and national law (in Romania, Law 190/2018), a concrete understanding of the organisation's processing, information security literacy, independence and the absence of a conflict of interest, plus practical experience and ongoing learning. A certificate helps, but it does not replace real competence.
We provide an outsourced Data Protection Officer: up-to-date legal and security expertise, regular checks, a contact point with the authority and the peace of mind that someone is actually on it — with competence, not a token certificate.