You've appointed a data protection officer. Good. But the job doesn't end there: their contact details must be published and communicated to the supervisory authority. Here's what that means, without the unnecessary steps.
Many controllers stop halfway: they appoint a DPO, sign a contract or an internal decision, and consider the obligation ticked off. In reality, designation is only the first step. The GDPR explicitly requires that, after the appointment, the officer's contact details reach two places: the public and the supervisory authority.
Let's look at exactly what the law says, what you submit, and how it's done in Romania.
The obligation comes straight from Article 37(7) of the GDPR. The text sets out two things that go together: the controller or processor publishes the contact details of the data protection officer and communicates them to the supervisory authority.
In Romania, the supervisory authority is ANSPDCP — the National Supervisory Authority for Personal Data Processing (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal). At national level, the GDPR framework is supplemented by Law no. 190/2018, the national implementing law. In other words: the core rule sits in the GDPR, while the national, institutional context is handled by ANSPDCP and Law 190/2018.
Worth remembering: this obligation applies to anyone who has designated a DPO — whether because they were required to (Art. 37(1)) or because they appointed one voluntarily. Once you have a DPO, the publish-and-communicate rule kicks in.
This is where confusion often arises. The GDPR talks about the officer's contact details, not the public exposure of their full identity.
The distinction matters in practice: publishing on the website serves data subjects, while communicating to the authority serves the institutional relationship. They are not the same thing and one does not replace the other — both must be done.
The communication to ANSPDCP is made through the authority's official channel. The ANSPDCP website (dataprotection.ro) provides the dedicated form and the electronic means for notifying the contact details of the data protection officer.
In practical terms, the steps generally look like this:
A note of caution: always work with the current form and instructions on the authority's website, because the procedure and the fields may be updated over time. Don't rely on old screenshots or on instructions copied from other sources.
The rule is simple: without undue delay after designating the DPO. The GDPR does not fix an exact number of days, but the logic is one of promptness — once you have an officer, the authority and the public must know who to contact.
And, very importantly, the communication is not a one-time task. You must update the details whenever:
In practice, we see the same handful of slip-ups, year after year:
If you first want to understand the role itself — what a DPO is and what its tasks are — or if you're considering the option of an outsourced DPO, you'll find the full context there. Registering with ANSPDCP is, in fact, the final piece that makes the role visible to the outside world.
The DPO's contact details are not an administrative formality: they are the channel through which the authority and data subjects reach the organisation when something goes wrong. In a security incident, ANSPDCP will look at who the officer is and how they can be contacted.
That's why correctly registering the DPO and your incident-handling process go hand in hand. If you want to see the other side of the relationship with the authority, read about breach notification to ANSPDCP — when you do it, how, and what to expect. A DPO who is easy to reach and a well-kept incident register are the two things that make the difference in the first hours of a breach.
Designating a DPO is the visible step; communicating their contact details to ANSPDCP and publishing them for the public are the steps that actually have effect. Treat them as an ongoing obligation, not a checkbox: communicate promptly, publish on the website, update on every change, and keep proof. That's how you avoid the surprisingly common situation of having an officer on paper whom no one on the outside can find.
Yes. Under Art. 37(7) GDPR, once you designate a data protection officer you have two obligations: to publish their contact details and to communicate them to the supervisory authority. In Romania, that authority is ANSPDCP, and the communication is made through the dedicated form on the authority's website.
You submit the DPO's contact details — typically a dedicated email and phone, possibly a role address (for example [email protected]), not necessarily the full identity of the person to the public. The distinction matters: to the public you publish a contact channel, while to ANSPDCP you communicate the details needed to identify the DPO and the controller.
Without undue delay after designation. The GDPR does not set a fixed number of days, but the communication must be prompt, and the details must be updated whenever the DPO or their contact details change. It is not a one-time, tick-the-box task.
You remain non-compliant with Art. 37(7) GDPR, even though you have actually appointed a DPO. In practice, the authority and data subjects don't know who to contact, and in an investigation or a breach the missing notification signals that governance obligations were not handled seriously. The risk is a non-compliance finding and, where appropriate, corrective measures.
We check the designation, the publication of contact details and the communication to the authority, keep the details current, and tie it all to a working incident register — so the DPO role is visible and valid, not just on paper.