Data Protection Officer (DPO):
what it is, functions and how to appoint one
The DPO is the figure responsible for supervising your company's regulatory compliance in privacy matters. Certix provides you with an expert external Data Protection Officer (DPO) available from day one.
Art. 37
GDPR — legal basis for the DPO
24 h
personalised proposal
Art. 38
GDPR — DPO independence
0€
free initial consultation
Definition
What is the Data Protection Officer (DPO)?
The Data Protection Officer —also known as DPO— is the professional figure responsible for supervising an organisation's compliance with the General Data Protection Regulation (GDPR) and national data protection legislation.
Introduced by art. 37 of the GDPR as an independent figure, the DPO acts as a bridge between the company, data subjects (customers, employees) and the supervisory authority (in Spain, the Spanish Data Protection Agency, AEPD).
Contrary to common belief, the DPO is not legally liable for the company's infringements: their role is advisory, supervisory and liaison-based. Legal liability always rests with the data controller, i.e. the organisation itself.
The DPO may be an employee of the organisation (internal DPO) or an external professional (external DPO). In practice, most SMEs opt for the external DPO for reasons of cost and specialisation.
Legal and technical profile
With specialist knowledge of data protection legislation and an understanding of the organisation's activities.
Structural independence
Does not receive instructions regarding the performance of their functions (art. 38.3 GDPR).
AEPD point of contact
Official liaison with the supervisory authority during inspections and consultations.
Internal or external
May be an employee of the company or engaged as an external specialist service.
Responsibilities
What are the DPO's functions under the GDPR?
Art. 39 GDPR establishes a minimum catalogue of functions that the DPO must perform in any organisation.
Information and advisory
Informs and advises the data controller, processors and employees on their obligations under the GDPR and other data protection legislation.
Compliance monitoring
Monitors the company's compliance with the GDPR and LOPDGDD, including the assignment of responsibilities, staff awareness and training, and relevant audits.
Data Protection Impact Assessments (DPIAs)
Advises on carrying out Data Protection Impact Assessments (art. 35 GDPR) where processing activities are likely to result in a high risk to the rights of data subjects.
Cooperation with the AEPD
Acts as the point of contact with the Spanish Data Protection Agency, cooperates with it and responds to queries from the supervisory authority on any matter related to processing activities.
Handling data subject requests
May be contacted by any individual to exercise their rights of access, rectification, erasure, objection or portability. The DPO facilitates the handling and recording of these requests.
Policy compliance supervision
Monitors compliance with the GDPR and the controller's internal data protection policies, including the assignment of responsibilities and staff awareness.
Data breach management
Advises on the detection, classification and notification of data breaches to the AEPD (within 72 hours) and to affected individuals where appropriate, minimising reputational and sanction risk.
Prior consultations
Participates in the prior consultation process with the AEPD (art. 36 GDPR) where a DPIA determines that a processing activity presents a residual high risk that the controller cannot mitigate.
Training and awareness
Informs and advises the controller and staff on their data protection obligations, and monitors that staff receive appropriate training on the subject.
Mandatory requirement
When is a DPO mandatory?
Art. 37 GDPR establishes three cases in which the designation of a DPO is mandatory:
- Public authorities and bodies, with the exception of courts acting in their judicial capacity.
- Organisations whose core activities consist of processing operations that require regular and systematic monitoring of data subjects on a large scale (e.g. digital marketing companies, tracking platforms, insurance companies).
- Organisations that process special categories of data on a large scale (health, biometric, genetic data, ideology, religion, trade union membership, sexual orientation) or data relating to criminal convictions and offences.
In addition, the Spanish LOPDGDD significantly extends the cases of possible mandatory designation under its art. 34, including private hospitals and clinics, schools and educational centres, private security companies, financial institutions, insurers, telecommunications operators, among others. The precise applicability to each organisation depends on the type and scale of the processing.
Even where it is not mandatory, appointing an external DPO is highly recommended as a demonstration of proactive accountability to the AEPD.
Sectors with a possible DPO requirement under the LOPDGDD
Professional profile
Who can be a Data Protection Officer?
The GDPR does not require a specific qualification or a mandatory official certification, but does require the DPO to possess specialist knowledge of data protection law and practice (art. 37.5 GDPR), as well as the ability to perform the functions referred to in art. 39.
In practice, the typical DPO profile combines:
- Legal (Law, Political Science) or technical (Computer Science, Telecommunications) background.
- In-depth knowledge of the GDPR, LOPDGDD, EDPB Guidelines and AEPD doctrine.
- Practical experience in compliance projects.
- Communication skills with management, employees and data subjects.
Although not mandatory, data protection certification (such as the IAPP's CIPP/E or the AEPD/ENAC CDPO) is a recognised quality indicator in the sector.
The DPO may be an employee or an external provider. The organisation may not dismiss or penalise them for the performance of their duties, a protection expressly established in art. 38.3 GDPR to preserve their independence.
Key requirements of the DPO (art. 37.5 GDPR)
Incompatibilities to bear in mind
The DPO may not simultaneously hold positions that involve a conflict of interests, such as IT Director, HR Director, Marketing Director or Chief Executive, as these roles involve taking decisions about the very processing activities they would then be required to supervise.
Modalities
Internal DPO vs external DPO: differences and advantages
Internal DPO
Recommended for large companies with a high volume of processing activities and the resources to dedicate an exclusive profile.
External DPO
Recommended for SMEsSupervisory authority
The Data Protection Officer and the AEPD
The Spanish Data Protection Agency (AEPD) is the supervisory authority responsible for overseeing the application of the GDPR and LOPDGDD in Spain. The DPO is the company's official liaison with the AEPD.
Art. 37.7 GDPR requires organisations that must designate a DPO to communicate the DPO's contact details to the supervisory authority. In Spain, the AEPD maintains a Register of Data Protection Officers in which organisations must register their DPO.
This register is public and allows any data subject to identify an organisation's DPO in order to exercise their rights. Failure to register when required may be considered an infringement of art. 37.7 GDPR.
When the AEPD initiates an inspection or receives a complaint against a company, the first point of contact is the registered DPO. Having a registered and accredited DPO is an unequivocal signal of compliance to the supervisory authority.
At Certix we handle registration with the AEPD's DPO Register as part of the service, at no additional cost.
AEPD DPO Register
The AEPD maintains a public register where organisations communicate the contact details of their DPO. Registration is mandatory where the DPO is required by law, and recommended in all cases.
Consult the official DPO register →AEPD consultation channel for DPOs
The AEPD provides a dedicated channel for DPOs to submit queries on regulatory interpretation. At Certix we manage these queries proactively so your company always operates with up-to-date guidance.
DPO protection from the organisation
Art. 38.3 GDPR expressly prohibits the data controller from penalising or dismissing the DPO for the performance of their functions. This protection is one of the reasons why the external DPO is preferable: their independence is structurally assured.
Pricing
Cost of the Data Protection Officer service
Certix's external DPO service is an independent contract, separate from the base consultancy service. The cost varies according to the size of the organisation, the complexity of its processing activities and the sector.
We send a personalised proposal within 24 hours following an initial analysis of your case. The contract includes:
- Formal designation as DPO of your organisation.
- Registration with the AEPD DPO Register.
- Continuous monitoring of regulatory compliance.
- Point of contact for data subjects and the AEPD.
- Advisory in the event of complaints and inspections.
- Advisory on Data Protection Impact Assessments (DPIAs) when the client carries these out.
- Updates in response to regulatory changes and new EDPB Guidelines.
External DPO Service · Certix
Bespoke pricing based on the organisation's activities and processing complexity. Response within 24 hours.
Request a personalised quoteIndependent contract
The DPO service is formalised through a standalone contract, independent of the consultancy service.
Full transparency
The quote covers all DPO functions. Only services such as DPIAs or training are quoted separately.
Does your company need a DPO?
Tell us your case and within 24 hours we will advise you on whether the DPO applies to your situation and what the cost would be.
Free consultationResponse within 24 h · +34 611 030 124
FAQ
Frequently asked questions about the DPO
What is the Data Protection Officer?
The Data Protection Officer (DPO) is the professional figure responsible for supervising an organisation's compliance with the GDPR and data protection legislation. The DPO acts as the point of contact between the company, data subjects and the supervisory authority (AEPD in Spain), advises on regulatory obligations and monitors that processing activities are carried out in accordance with the law.
When is a DPO mandatory?
The GDPR requires a DPO for public authorities, companies whose core activities involve large-scale systematic monitoring of individuals, and organisations that process special-category data (health, biometric, etc.) on a large scale. The Spanish LOPDGDD extends these cases under art. 34 to sectors such as private healthcare, education, security companies, financial institutions, telecommunications operators and several others, although the precise obligation for each organisation depends on an individualised analysis. If in doubt, contact us and we will analyse your case free of charge.
Who can be a DPO?
The GDPR does not require a specific official qualification, but does require specialist knowledge of data protection law and practice. In practice, the profile typically combines legal or technical training with demonstrable experience in compliance projects. Sector certifications (CIPP/E, CDPO) are a recognised quality indicator. The DPO may be an internal employee or an external specialist service.
How much does an external Data Protection Officer cost?
The cost of an external DPO varies depending on the complexity of the processing activities and the sector. At Certix we prepare a personalised quote that includes formal designation, registration with the AEPD, continuous compliance monitoring and support in the event of incidents. The initial consultation is free.
What does the GDPR say about the DPO?
The GDPR regulates the DPO figure in arts. 37 to 39. Art. 37 establishes when designation is mandatory, art. 38 governs the DPO's position (independence, resources, access to management, professional secrecy) and art. 39 defines the minimum catalogue of functions: informing and advising, monitoring compliance, advising on DPIAs, cooperating with the supervisory authority and acting as point of contact.
Is the DPO legally liable if my company breaches the GDPR?
No. The DPO has advisory and supervisory functions, but legal liability always rests with the data controller (the company). The DPO may incur personal liability only if they act negligently in the performance of their functions. This is why it is important to choose a DPO with the appropriate qualifications and resources.
Your expert DPO,
from day one.
No salespeople, no bureaucracy. A data protection expert analyses your case and proposes the most appropriate solution.
Proposal within 24 h · info@certix.es