What is a DPO?
A DPO (Data Protection Officer) is GDPR's built-in watchdog: a person with independent status who monitors that the organisation complies with the rules, advises on impact assessments and is the point of contact for both Datatilsynet (the Danish Data Protection Agency) and the people whose data you process. The DPO must not be instructed in how the tasks are carried out, and must not be dismissed for doing their job: independence is the whole point of the role.
When MUST you have a DPO?
GDPR requires a DPO in three situations:
- Public authorities: always.
- Core activity is systematic monitoring of data subjects on a large scale, e.g. tracking, profiling or surveillance services.
- Core activity is large-scale processing of sensitive data, e.g. health data, biometrics or criminal records.
The key words are core activity and large scale. An ordinary manufacturing, trading or consulting business that processes employee and customer data in support of the business is typically not obliged. If you are in doubt, document the assessment: being able to justify the choice is itself a GDPR requirement.
Internal or external DPO?
Both are lawful, and the choice is a practical one:
- An internal DPO knows the organisation, but it can be hard to find a person with both legal and technical insight, and the role must not conflict with other interests. The IT manager, for example, cannot be the DPO, as they would be supervising themselves.
- An external DPO is bought as a service from a law firm or an adviser. That provides specialist competence and independence from day one and is often the realistic model for SMBs, where the role cannot fill a full-time position.
Many choose a middle way: an external data protection adviser on an hourly basis, even though they are not formally required to appoint a DPO.
What does a DPO do in practice?
The everyday work of a DPO is less about legal clauses and more about processes: supervising the record of processing activities, reviewing data processing agreements, advising on new systems and projects, training employees, handling requests for access and erasure, and assisting with personal data breaches, where the 72-hour deadline to the Danish Data Protection Agency starts running. A good DPO works closely with IT, because the vast majority of GDPR requirements end up as technical measures in the IT environment.
How MI Support IT can help
MI Support IT is not a law firm, but we are the ones who turn the DPO's recommendations into reality: access control, encryption, logging, backup and documentation. With IT advisory we help you clarify where you stand and what needs to be put in place first. Contact us for a no-obligation chat.