Extended definition
The person responsible for GDPR compliance in an organization. Mandatory for companies over 250 employees or processing sensitive data at scale.
Context and application
DPO mandatory under GDPR Art. 37 for: 1) Public authorities, 2) Organizations doing “regular and systematic monitoring of data subjects on a large scale” (e.g., advertising tracking at scale), 3) Organizations processing sensitive data (health, criminology) at scale. For smaller companies, DPO is optional but recommended. Role: monitors compliance, internal training, communication with authorities (ANSPDCP in RO), DPIA (Data Protection Impact Assessment) on new processes. DPO can be internal or external (DPO-as-a-service is a growing market in EU).
Related terms
GDPR.