Glossary

DPO (Data Protection Officer)

A Data Protection Officer is GDPR’s designated privacy overseer: an independent expert who monitors compliance, advises on DPIAs, and serves as the contact point for supervisory authorities and data subjects. The role carries legal protections — a DPO reports to top management and can’t be dismissed for doing the job.

When you actually need one

Article 37 mandates a DPO in three cases: public authorities, core activities involving large-scale systematic monitoring of individuals, or large-scale processing of special-category data (health, biometrics, etc.). Most B2B SaaS companies processing ordinary business data don’t hit the threshold — health-tech, ad-tech, and consumer apps with behavioral tracking often do.

The startup-relevant nuances

You can appoint one voluntarily — but then all the formal obligations attach, so don’t appoint casually. The role can be outsourced (DPO-as-a- service is a mature market) or shared across a group. What you can’t do is give the title to someone whose day job conflicts with it — a CTO who decides processing purposes can’t independently oversee them, a conflict regulators have fined.

What procurement asks

EU enterprise customers’ questionnaires routinely ask “have you appointed a DPO?” The correct answer when you’re below threshold isn’t a scramble to appoint — it’s a documented assessment of why Article 37 doesn’t apply, plus a named privacy contact. That answer passes review; an accidental, conflicted DPO appointment creates obligations you then have to honor.

Related Terms

Data Processing Agreement (DPA) — A DPA is the contract governing how a processor handles personal data on a controller's behalf — required under GDPR whenever a vendor touches personal data.

DPIA — A DPIA is GDPR's structured risk assessment for high-risk processing — increasingly triggered by AI features. What it covers and when you must run one.