What is the Data Protection Officer
The Data Protection Officer (DPO) is the independent person responsible for supervising compliance with privacy regulations within an organisation. They act as a bridge between the entity processing personal data, the individuals concerned, and supervisory authorities such as the AEPD.
The role carries significant autonomy: the DPO cannot receive instructions on how to carry out their functions and is protected against sanctions or dismissal for the proper performance of their duties.
DPO in English and Spanish: is it the same thing?
Yes. Both acronyms refer to the same role: "Delegado de Protección de Datos" in Spanish and "Data Protection Officer" in English. It is the same figure regulated by the GDPR.
When is it mandatory to appoint a Data Protection Officer
The GDPR establishes three situations in which appointment is mandatory:
- Public authorities and bodies
- Organisations whose core activities involve large-scale regular and systematic monitoring of data subjects
- Organisations that process special categories of data or data relating to criminal convictions and offences on a large scale
In addition, article 34 of the LOPDGDD provides for additional cases for certain sectors in Spain — professional associations, educational institutions, credit institutions, insurance companies, private security companies, among others — with the exception of healthcare professionals practising on an individual basis. The specific obligation depends on an individual analysis of each organisation; this information is for guidance purposes only and each case must be examined individually.
What if you do not fall within any of those situations?
Not being obligated does not mean it is not advisable. Many organisations voluntarily appoint a DPO in order to strengthen internal privacy culture, build trust, and minimise the risk of sanctions.
Functions of the Data Protection Officer
1. Informing and advising
The DPO advises the controller, the processor, and employees on their data protection obligations, translating regulatory requirements into concrete actions.
2. Supervising compliance
The DPO verifies that policies, contracts with third parties, security measures, and the Record of Processing Activities comply with the GDPR and national legislation.
3. Advising on Data Protection Impact Assessments (DPIA)
Where a data processing activity presents high risks to the rights and freedoms of individuals, the DPO supervises and advises on the preparation of the Data Protection Impact Assessment.
4. Cooperating with the supervisory authority
The DPO acts as the point of contact with the AEPD during inspections, complaints, or prior consultations.
5. Managing rights requests
The DPO oversees that the organisation responds correctly and within the required timeframes when individuals exercise their rights of access, rectification, erasure, portability, or objection.
"Having a DPO is not just an obligation for some organisations. It means having someone who understands your business and knows how to protect it. Every sector has its own particularities, and that changes everything."
Mario P. Talamillo · Managing Partner, Certix®
Internal DPO vs. external DPO: which is more suitable?
Internal DPO: Advantages: immediate knowledge of the business and availability. Disadvantages: ongoing training required and potential conflicts of interest with incompatible functions.
External DPO: Offers structural independence, access to up-to-date specialist knowledge, and predictable costs. Particularly suitable for small and medium-sized enterprises that do not have dedicated internal resources.
Consequences of not having a DPO when one is required
If an individual analysis reveals that the regulations require the appointment of a DPO and the organisation fails to do so, this may be viewed negatively by the AEPD in the event of an inspection or incident. GDPR sanctions for serious infringements may reach €10 million or 2% of global annual turnover. This information is for guidance purposes only; each situation must be analysed individually.
Frequently asked questions
What does a Data Protection Officer do?
They supervise GDPR compliance, provide internal advice, manage impact assessments, act as the point of contact with the AEPD, and oversee the management of individuals' rights.
How much does a Data Protection Officer earn?
Salaries for an internal DPO in Spain vary according to the sector and the size of the organisation. The external DPO service is a common alternative for organisations that do not have the resources to dedicate a full-time profile to the role, with costs proportional to the volume and complexity of the processing activities.
What qualifications are required to become a Data Protection Officer?
The GDPR requires "expert knowledge of data protection law and practice" with demonstrated capability. Typical profiles include lawyers, IT specialists, or consultants with accredited training in privacy.
This content is for informational purposes only and does not constitute legal advice. The application of regulations to each specific case requires individual analysis.