Certix

Data Protection Officer (DPO):
what it is, functions and how to appoint one

The DPO is the figure responsible for supervising your company's regulatory compliance in privacy matters. Certix provides you with an expert external Data Protection Officer (DPO) available from day one.

Art. 37

GDPR — legal basis for the DPO

24 h

personalised proposal

Art. 38

GDPR — DPO independence

0€

free initial consultation

Definition

What is the Data Protection Officer (DPO)?

The Data Protection Officer —also known as DPO— is the professional figure responsible for supervising an organisation's compliance with the General Data Protection Regulation (GDPR) and national data protection legislation.

Introduced by art. 37 of the GDPR as an independent figure, the DPO acts as a bridge between the company, data subjects (customers, employees) and the supervisory authority (in Spain, the Spanish Data Protection Agency, AEPD).

Contrary to common belief, the DPO is not legally liable for the company's infringements: their role is advisory, supervisory and liaison-based. Legal liability always rests with the data controller, i.e. the organisation itself.

The DPO may be an employee of the organisation (internal DPO) or an external professional (external DPO). In practice, most SMEs opt for the external DPO for reasons of cost and specialisation.

Legal and technical profile

With specialist knowledge of data protection legislation and an understanding of the organisation's activities.

Structural independence

Does not receive instructions regarding the performance of their functions (art. 38.3 GDPR).

AEPD point of contact

Official liaison with the supervisory authority during inspections and consultations.

Internal or external

May be an employee of the company or engaged as an external specialist service.

Responsibilities

What are the DPO's functions under the GDPR?

Art. 39 GDPR establishes a minimum catalogue of functions that the DPO must perform in any organisation.

Information and advisory

Informs and advises the data controller, processors and employees on their obligations under the GDPR and other data protection legislation.

Compliance monitoring

Monitors the company's compliance with the GDPR and LOPDGDD, including the assignment of responsibilities, staff awareness and training, and relevant audits.

Data Protection Impact Assessments (DPIAs)

Advises on carrying out Data Protection Impact Assessments (art. 35 GDPR) where processing activities are likely to result in a high risk to the rights of data subjects.

Cooperation with the AEPD

Acts as the point of contact with the Spanish Data Protection Agency, cooperates with it and responds to queries from the supervisory authority on any matter related to processing activities.

Handling data subject requests

May be contacted by any individual to exercise their rights of access, rectification, erasure, objection or portability. The DPO facilitates the handling and recording of these requests.

Policy compliance supervision

Monitors compliance with the GDPR and the controller's internal data protection policies, including the assignment of responsibilities and staff awareness.

Data breach management

Advises on the detection, classification and notification of data breaches to the AEPD (within 72 hours) and to affected individuals where appropriate, minimising reputational and sanction risk.

Prior consultations

Participates in the prior consultation process with the AEPD (art. 36 GDPR) where a DPIA determines that a processing activity presents a residual high risk that the controller cannot mitigate.

Training and awareness

Informs and advises the controller and staff on their data protection obligations, and monitors that staff receive appropriate training on the subject.

Mandatory requirement

When is a DPO mandatory?

Art. 37 GDPR establishes three cases in which the designation of a DPO is mandatory:

  • Public authorities and bodies, with the exception of courts acting in their judicial capacity.
  • Organisations whose core activities consist of processing operations that require regular and systematic monitoring of data subjects on a large scale (e.g. digital marketing companies, tracking platforms, insurance companies).
  • Organisations that process special categories of data on a large scale (health, biometric, genetic data, ideology, religion, trade union membership, sexual orientation) or data relating to criminal convictions and offences.

In addition, the Spanish LOPDGDD significantly extends the cases of possible mandatory designation under its art. 34, including private hospitals and clinics, schools and educational centres, private security companies, financial institutions, insurers, telecommunications operators, among others. The precise applicability to each organisation depends on the type and scale of the processing.

Even where it is not mandatory, appointing an external DPO is highly recommended as a demonstration of proactive accountability to the AEPD.

Sectors with a possible DPO requirement under the LOPDGDD

Private hospitals, clinics and healthcare centres
Educational centres, schools and universities
Private security companies
Financial and credit institutions
Insurers and reinsurers
Telecommunications operators
Advertising and digital marketing companies
Occupational health and safety services
Credit reference file managers
Large-scale e-commerce operators
Investment services firms and funds
Electricity distributors and retailers

Professional profile

Who can be a Data Protection Officer?

The GDPR does not require a specific qualification or a mandatory official certification, but does require the DPO to possess specialist knowledge of data protection law and practice (art. 37.5 GDPR), as well as the ability to perform the functions referred to in art. 39.

In practice, the typical DPO profile combines:

  • Legal (Law, Political Science) or technical (Computer Science, Telecommunications) background.
  • In-depth knowledge of the GDPR, LOPDGDD, EDPB Guidelines and AEPD doctrine.
  • Practical experience in compliance projects.
  • Communication skills with management, employees and data subjects.

Although not mandatory, data protection certification (such as the IAPP's CIPP/E or the AEPD/ENAC CDPO) is a recognised quality indicator in the sector.

The DPO may be an employee or an external provider. The organisation may not dismiss or penalise them for the performance of their duties, a protection expressly established in art. 38.3 GDPR to preserve their independence.

Key requirements of the DPO (art. 37.5 GDPR)

Specialist knowledge of data protection law and practice
Ability to perform the functions set out in art. 39 GDPR
Independence in the performance of their functions
Access to the resources necessary to carry out their tasks
Ability to report directly to the highest level of management

Incompatibilities to bear in mind

The DPO may not simultaneously hold positions that involve a conflict of interests, such as IT Director, HR Director, Marketing Director or Chief Executive, as these roles involve taking decisions about the very processing activities they would then be required to supervise.

Modalities

Internal DPO vs external DPO: differences and advantages

Internal DPO

In-depth knowledge of the organisation
Immediate day-to-day availability
High cost (salary + continuous training)
Risk of conflicts of interest with other roles
Real independence compromised by role conflicts
Knowledge limited to one sector
Vulnerable to absences, holidays or staff turnover

Recommended for large companies with a high volume of processing activities and the resources to dedicate an exclusive profile.

External DPO

Recommended for SMEs
Significantly lower cost than a dedicated employee
Structural independence (art. 38.3 GDPR)
Access to a multidisciplinary specialist team
Experience across multiple sectors and scenarios
No risk of gaps due to holidays or absences
Automatic and continuous regulatory updates
Requires an initial onboarding phase
Appoint an external DPO with Certix

Supervisory authority

The Data Protection Officer and the AEPD

The Spanish Data Protection Agency (AEPD) is the supervisory authority responsible for overseeing the application of the GDPR and LOPDGDD in Spain. The DPO is the company's official liaison with the AEPD.

Art. 37.7 GDPR requires organisations that must designate a DPO to communicate the DPO's contact details to the supervisory authority. In Spain, the AEPD maintains a Register of Data Protection Officers in which organisations must register their DPO.

This register is public and allows any data subject to identify an organisation's DPO in order to exercise their rights. Failure to register when required may be considered an infringement of art. 37.7 GDPR.

When the AEPD initiates an inspection or receives a complaint against a company, the first point of contact is the registered DPO. Having a registered and accredited DPO is an unequivocal signal of compliance to the supervisory authority.

At Certix we handle registration with the AEPD's DPO Register as part of the service, at no additional cost.

AEPD DPO Register

The AEPD maintains a public register where organisations communicate the contact details of their DPO. Registration is mandatory where the DPO is required by law, and recommended in all cases.

Consult the official DPO register →

AEPD consultation channel for DPOs

The AEPD provides a dedicated channel for DPOs to submit queries on regulatory interpretation. At Certix we manage these queries proactively so your company always operates with up-to-date guidance.

DPO protection from the organisation

Art. 38.3 GDPR expressly prohibits the data controller from penalising or dismissing the DPO for the performance of their functions. This protection is one of the reasons why the external DPO is preferable: their independence is structurally assured.

Pricing

Cost of the Data Protection Officer service

Certix's external DPO service is an independent contract, separate from the base consultancy service. The cost varies according to the size of the organisation, the complexity of its processing activities and the sector.

We send a personalised proposal within 24 hours following an initial analysis of your case. The contract includes:

  • Formal designation as DPO of your organisation.
  • Registration with the AEPD DPO Register.
  • Continuous monitoring of regulatory compliance.
  • Point of contact for data subjects and the AEPD.
  • Advisory in the event of complaints and inspections.
  • Advisory on Data Protection Impact Assessments (DPIAs) when the client carries these out.
  • Updates in response to regulatory changes and new EDPB Guidelines.

External DPO Service · Certix

Bespoke pricing based on the organisation's activities and processing complexity. Response within 24 hours.

Request a personalised quote

Independent contract

The DPO service is formalised through a standalone contract, independent of the consultancy service.

Full transparency

The quote covers all DPO functions. Only services such as DPIAs or training are quoted separately.

Does your company need a DPO?

Tell us your case and within 24 hours we will advise you on whether the DPO applies to your situation and what the cost would be.

Free consultation

Response within 24 h · +34 611 030 124

FAQ

Frequently asked questions about the DPO

What is the Data Protection Officer?

The Data Protection Officer (DPO) is the professional figure responsible for supervising an organisation's compliance with the GDPR and data protection legislation. The DPO acts as the point of contact between the company, data subjects and the supervisory authority (AEPD in Spain), advises on regulatory obligations and monitors that processing activities are carried out in accordance with the law.

When is a DPO mandatory?

The GDPR requires a DPO for public authorities, companies whose core activities involve large-scale systematic monitoring of individuals, and organisations that process special-category data (health, biometric, etc.) on a large scale. The Spanish LOPDGDD extends these cases under art. 34 to sectors such as private healthcare, education, security companies, financial institutions, telecommunications operators and several others, although the precise obligation for each organisation depends on an individualised analysis. If in doubt, contact us and we will analyse your case free of charge.

Who can be a DPO?

The GDPR does not require a specific official qualification, but does require specialist knowledge of data protection law and practice. In practice, the profile typically combines legal or technical training with demonstrable experience in compliance projects. Sector certifications (CIPP/E, CDPO) are a recognised quality indicator. The DPO may be an internal employee or an external specialist service.

How much does an external Data Protection Officer cost?

The cost of an external DPO varies depending on the complexity of the processing activities and the sector. At Certix we prepare a personalised quote that includes formal designation, registration with the AEPD, continuous compliance monitoring and support in the event of incidents. The initial consultation is free.

What does the GDPR say about the DPO?

The GDPR regulates the DPO figure in arts. 37 to 39. Art. 37 establishes when designation is mandatory, art. 38 governs the DPO's position (independence, resources, access to management, professional secrecy) and art. 39 defines the minimum catalogue of functions: informing and advising, monitoring compliance, advising on DPIAs, cooperating with the supervisory authority and acting as point of contact.

Is the DPO legally liable if my company breaches the GDPR?

No. The DPO has advisory and supervisory functions, but legal liability always rests with the data controller (the company). The DPO may incur personal liability only if they act negligently in the performance of their functions. This is why it is important to choose a DPO with the appropriate qualifications and resources.

Your expert DPO,
from day one.

No salespeople, no bureaucracy. A data protection expert analyses your case and proposes the most appropriate solution.

INFORMACIÓN BÁSICA DE PROTECCIÓN DE DATOS: De conformidad con las normativas de Protección de Datos, le facilitamos la siguiente información del tratamiento: Responsable: Certificación y Gestión Normativa S.L.U. Finalidad: atender su solicitud y contactarle para ofrecerle la información solicitada. Derechos: acceso, rectificación, portabilidad, supresión, limitación y oposición, así como otros derechos detallados en la información adicional. + info: Puedes encontrar información más detallada en nuestra Política de privacidad.

Or tell us your full case →

Proposal within 24 h · info@certix.es