Skip to main content

Compliance

What is a DPO (Data Protection Officer)?

A DPO is the company's data protection officer, the independent watchdog for GDPR. See when you need one, and whether it should be internal or external.

In short

A DPO (Data Protection Officer) is an independent adviser who monitors an organisation's compliance with GDPR, advises management and acts as the point of contact for the Danish Data Protection Agency (Datatilsynet) and the data subjects.

Public authorities must always have a DPO, while private companies are only obliged to if their core activity consists of large-scale systematic monitoring of individuals or large-scale processing of sensitive data. Most Danish SMBs are therefore not obliged, but many still choose to engage a DPO or a permanent data protection adviser, because the role consolidates responsibility for an area that otherwise falls between the cracks.

The DPO can be an internal employee or an external provider; what matters is independence, competence and real access to management. MI Support IT advises Danish businesses on data protection and the practical GDPR work in the IT environment.

Back to the glossary

What is a DPO?

A DPO (Data Protection Officer) is GDPR's built-in watchdog: a person with independent status who monitors that the organisation complies with the rules, advises on impact assessments and is the point of contact for both Datatilsynet (the Danish Data Protection Agency) and the people whose data you process. The DPO must not be instructed in how the tasks are carried out, and must not be dismissed for doing their job: independence is the whole point of the role.

When MUST you have a DPO?

GDPR requires a DPO in three situations:

  1. Public authorities: always.
  2. Core activity is systematic monitoring of data subjects on a large scale, e.g. tracking, profiling or surveillance services.
  3. Core activity is large-scale processing of sensitive data, e.g. health data, biometrics or criminal records.

The key words are core activity and large scale. An ordinary manufacturing, trading or consulting business that processes employee and customer data in support of the business is typically not obliged. If you are in doubt, document the assessment: being able to justify the choice is itself a GDPR requirement.

Internal or external DPO?

Both are lawful, and the choice is a practical one:

  • An internal DPO knows the organisation, but it can be hard to find a person with both legal and technical insight, and the role must not conflict with other interests. The IT manager, for example, cannot be the DPO, as they would be supervising themselves.
  • An external DPO is bought as a service from a law firm or an adviser. That provides specialist competence and independence from day one and is often the realistic model for SMBs, where the role cannot fill a full-time position.

Many choose a middle way: an external data protection adviser on an hourly basis, even though they are not formally required to appoint a DPO.

What does a DPO do in practice?

The everyday work of a DPO is less about legal clauses and more about processes: supervising the record of processing activities, reviewing data processing agreements, advising on new systems and projects, training employees, handling requests for access and erasure, and assisting with personal data breaches, where the 72-hour deadline to the Danish Data Protection Agency starts running. A good DPO works closely with IT, because the vast majority of GDPR requirements end up as technical measures in the IT environment.

How MI Support IT can help

MI Support IT is not a law firm, but we are the ones who turn the DPO's recommendations into reality: access control, encryption, logging, backup and documentation. With IT advisory we help you clarify where you stand and what needs to be put in place first. Contact us for a no-obligation chat.

Shall we talk about your business and your needs?

Real people talking to real people. We get back to you the same day.