Skip to main content

Appointment of a Data Protection Officer: What are their legal responsibilities?

In accordance with Art. 39 GDPR, an internal or external Data Protection Officer performs advisory, educational, and supervisory tasks in particular.  

Their main activities include:  

  • participating in the design and implementation of IT systems in accordance with data protection regulations 
  • raising awareness and training employees 
  • monitoring compliance with data protection laws and internal guidelines and processes.  

In addition, the Data Protection Officer must be consulted in an advisory capacity as part of a data protection impact assessment (DPIA) in accordance with Art. 35 para. 2 GDPR.  

Furthermore, he or she acts as a point of contact for data subjects (e.g., in the event of requests for information or deletion) and for supervisory authorities 

Note: This information does not replace individual legal advice.