Auratech Legal Solutions

Data Protection Officer: When Appointing a DPO Is Mandatory

Delegado Protección de Datos

Delegado Protección de Datos

The question almost always arrives at the same moment: once the company is already processing data seriously and somebody remembers the delegate. And the answer that circulates — “every company that handles data needs a DPO” — is false. Working out when appointing a DPO is mandatory is simpler than it looks, because the law leaves nothing to anyone’s judgement: there is a list.

The three GDPR cases

Article 37(1) of the General Data Protection Regulation requires the designation of a data protection officer in three situations:

  1. Where the processing is carried out by a public authority or body, except for courts acting in their judicial capacity.
  2. Where the core activities consist of operations that require regular and systematic monitoring of data subjects on a large scale.
  3. Where the core activities consist of large-scale processing of special categories of data — those in Article 9 — or of data relating to criminal convictions and offences.

The three phrases in bold are what decide the matter, and the guidelines of the former Article 29 Working Party, endorsed by the European Data Protection Board, give them content.

Core activities are the operations that are key to achieving the organisation’s objectives, not ancillary functions. Running payroll or providing internal IT support does not make anyone a mandatory case.

Large scale is assessed by the number of data subjects — in absolute terms or as a proportion of the population — the volume and variety of data, the duration of the processing and its geographical reach. Examples of large scale include a hospital’s patients, tracking journeys on public transport, the customer data of banks and insurers, or behavioural advertising by a search engine. It does not include the patient data of an individual doctor, or conviction data handled by a sole practitioner lawyer.

Regular and systematic means ongoing or occurring at recurring intervals, and organised according to a pre-established system rather than incidental.

The Spanish list: fifteen further cases

This is the part few people know and the one that decides most cases in Spain. Article 34(1) of the Spanish Data Protection Act adds a list of entities that must appoint a delegate regardless of their size:

If your organisation is on that list, the obligation exists even with three employees. And if it is not, voluntary designation remains possible, under exactly the same legal regime.

Ten days to notify it

Appointing is not enough. Article 34(3) requires designations, appointments and removals to be notified to the Spanish Data Protection Agency within ten days, through the specific form on its electronic register. The delegate’s contact details must also be published.

Failing to appoint a delegate when required is a serious infringement. Failing to publish the contact details or to notify the authority is a minor one. They are two distinct breaches and are penalised separately.

What is required of the person appointed

The GDPR requires professional qualities and expert knowledge of data protection law and practice. But what causes most difficulty in practice is position within the organisation: the delegate must be involved in all data protection matters, have resources, receive no instructions on the performance of their tasks, report to the highest management level, and not be dismissed or penalised for performing the role.

The Court of Justice of the European Union has drawn two relevant lines. In its judgment of 9 February 2023 in Case C-453/21, it held that a conflict of interests arises where the delegate is entrusted with tasks that would lead them to determine the purposes and means of processing; the assessment is case by case. And in its judgment of 22 June 2022 in Case C-534/20, it accepted that a Member State may protect the delegate against dismissal beyond the European minimum, provided this does not prevent removal for lacking the professional qualities or for failing to perform the role.

This is why appointing the head of IT or the finance director is usually a bad idea: those are precisely the people who determine purposes and means.

Internal or external: the GDPR allows both

Article 37(6) is explicit: the delegate may be a staff member or fulfil the tasks on the basis of a service contract. Neither option is second best. The external route removes the conflict of interests at source and tends to resolve the expert-knowledge requirement better in organisations that cannot keep a specialist on full time.

What it has cost not to appoint one

The Spanish Agency has penalised infringements of Article 37 on several occasions: 25,000 euros against a delivery platform in June 2020, 50,000 euros against a security company in November 2020 and 10,000 euros against a gambling operator in September 2021. In the public sector, most proceedings ended in a warning without a fine.

The pattern is worth noting: all three fines fell on entities that were on the Article 34 list and did not know it.

What to do with this

First check whether your activity appears on the Spanish list. If it does, the decision is made and only the format remains. If it does not, analyse whether your core activity involves regular and systematic large-scale monitoring or large-scale processing of special categories — and document that conclusion, because the absence of a delegate also has to be justifiable.

At Auratech Legal we take on that role as external Data Protection Officer, notification to the Agency included, and without the conflict of interests that any internal appointment carries with it.

Exit mobile version