The Data Protection Officer, also referred to by the abbreviation DPO, oversees compliance with personal data protection rules within the company, advises management, trains employees, and is the point of contact for both the supervisory authority and data subjects. It must be appointed by public authorities, as well as by organisations whose core activity consists of large-scale regular monitoring of individuals or the processing of special categories of data, for example health data. An ordinary e-shop or manufacturing company generally has no such obligation, but voluntary appointment is possible. The Data Protection Officer must be independent, must not receive instructions on how to carry out their tasks, and cannot be someone who at the same time decides on the purposes of processing – so typically not a managing director or head of marketing. The role is commonly filled externally.
See also: Privacy policy, Data subject rights, Records of processing activities.