Nine questions, about three minutes. The answer is worked out in your browser, following the European guidance WP 243 rev.01, Article 37 GDPR and the Romanian laws that add cases of their own.
Enable JavaScript to use the questionnaire. Or write to us and we will check together whether the obligation applies.
The questionnaire applies the three cases in Article 37(1) GDPR, read with the WP29 Guidelines WP 243 rev.01 on Data Protection Officers, adopted on 13 December 2016 and revised on 5 April 2017, endorsed by the European Data Protection Board.
On top of them it adds two cases from Romanian law that the European guidance does not cover:
Article 10 of Law no. 190/2018 creates no new designation cases: it refers to Articles 37-39 GDPR and only adds the option of a single officer shared by several public authorities or bodies, a useful solution for small town halls, schools and services under the same authority.
In section 2.1 the guidance recommends that controllers and processors document the internal analysis by which they established whether designation is required, except where it is obvious that no obligation exists. That analysis is part of the documentation required by the accountability principle and may be requested by the supervisory authority. The result of this questionnaire, printed or downloaded, is exactly that documented analysis.
If the result shows an obligation, the questions the questionnaire does not cover come next: who holds the role, how a conflict of interests is avoided, what resources and access to management they receive, how the contact details are communicated to the Romanian DPA. Our outsourced DPO service covers all of them.