Three letters that show up more and more in the GDPR and in job ads. Let's clear up, without the jargon, what a DPO actually is and what the role involves.
"Do you have a DPO?" It's a question companies hear more and more often — from large clients, from partners, sometimes from the authority itself. And it's often followed by an awkward pause, because not everyone knows what those three letters actually mean.
So let's clear it up. No dry quotes from the law, no jargon.
DPO stands for Data Protection Officer. It is the person (or, when outsourced, the firm) who makes sure an organisation treats people's data correctly: the data of customers, of employees, of anyone who leaves a piece of personal information behind.
The role isn't a marketing invention. It is written, in black and white, into the GDPR — in Articles 37, 38 and 39. That's where you find when a DPO is needed, what position they must hold inside the organisation, and what they have to do.
The simplest way to picture it: the DPO is like a trusted advisor on the data side. They don't run the company, but they tell you early where you're stepping wrong and how to avoid a fine or a loss of trust.
Article 39 of the GDPR lists, briefly, what a DPO does. Here it is in everyday language.
One more important detail: the DPO works with a sense of risk. They don't put the same pressure on a newsletter list as on a medical database. Where the stakes for people are high, their attention goes up.
Not every company is required to have a DPO. The law calls for one in three cases (Art. 37):
Otherwise, you can appoint a DPO voluntarily. Many do, because a serious partner asks for it, or simply for the peace of mind of knowing someone keeps an eye on this side of things.
The DPO can be an employee of the company or an outside person or firm hired for the job. The law accepts both. For small and medium businesses, the outsourced option is often more practical: you get up-to-date expertise without paying a full salary, and without the risk that your "GDPR person" is actually busy with something else. You'll find the details on our Outsourced DPO page.
Whichever you choose, two conditions stay the same: the DPO must be independent (no one dictates their conclusions) and free of any conflict of interest (they can't be, say, the head of IT who decides everything they would then have to check).
This is where most of the confusion comes from, so it's worth saying clearly:
A good DPO isn't a compliance checkbox. They're the person who turns the rules into simple steps, warns you before the problem shows up, and speaks to the authority on your behalf when needed. And when the role is taken seriously — in-house or outsourced — it shows: fewer surprises, more trust from clients and partners.
DPO stands for Data Protection Officer. It is the person who makes sure an organisation uses people's data correctly and in line with the GDPR. The role is set out in Articles 37-39 of the GDPR.
Informing and advising management and staff about their obligations, checking that the rules are followed, helping with risk assessments (DPIA), acting as the contact point for people and for the authority, and cooperating with it. In short: guide, check and keep in touch.
When you are a public authority or body, when you monitor people's behaviour systematically and on a large scale, or when you process special-category data (health, criminal records and so on) on a large scale. Otherwise, you may appoint one voluntarily.
No. Legal responsibility stays with the organisation (the data controller). The DPO advises and checks, but does not decide how data is used and is not fined in the company's place.
We provide an outsourced Data Protection Officer: guidance, regular checks, a contact point with the authority and the peace of mind that someone is actually on it — without the cost of an extra employee.