Skip to content
Do You Need a Data Protection Officer (DPO)?
Data Protection (GDPR)

Do You Need a Data Protection Officer (DPO)?

Martin BoshkoskiUpdated: 5 min read

A Data Protection Officer (officer for personal data protection / офицер за заштита на личните податоци) is an expert who oversees your compliance with the data protection law. Many owners assume every company needs one — in fact the law makes it mandatory only in specific situations. This guide explains when you must appoint a DPO, and what they do.

When a DPO is mandatory

Under the Law on Personal Data Protection, a controller or processor must appoint a DPO in any of these cases:

  • Public authority — the processing is carried out by a state body (courts acting in their judicial capacity are an exception).
  • Large-scale regular and systematic monitoring — your core activities consist of processing operations that, by their nature, scope and/or purposes, require regular and systematic monitoring of individuals on a large scale (for example, extensive tracking or profiling).
  • Large-scale sensitive data — your core activities consist of large-scale processing of special categories of data (health, biometric, religious or political data, etc.) or data on criminal convictions and offences.

The key words are core activities and large scale. Processing that is merely ancillary to your business (like ordinary payroll) does not usually trigger the requirement. If none of the three cases applies, appointing a DPO is optional — but still allowed, and sometimes worthwhile.

One DPO for a group

A group of companies may designate a single DPO, provided the officer is easily reachable by each entity in the group, by the Agency, and by data subjects. This makes compliance more efficient for company groups without each entity hiring its own officer.

Not sure how this applies to you?

Get a clear answer from a verified expert.

What the DPO does

The DPO is chosen on the basis of professional qualifications and expert knowledge of data protection law and practice. Their role is to inform and advise the organisation on its obligations, monitor compliance, advise on data protection impact assessments, cooperate with the Agency, and act as the contact point for the Agency and for individuals. Their contact details are typically published in your privacy notice and provided to the Agency.

Frequently asked questions

Does every company need a Data Protection Officer?
No. A DPO is mandatory only for public authorities, for businesses whose core activities require large-scale regular and systematic monitoring of people, or whose core activities involve large-scale processing of special categories or criminal data. Otherwise it is optional.
Can a group of companies share one DPO?
Yes. A group may appoint a single DPO, provided the officer is easily accessible to each company in the group, to the Agency, and to data subjects.
What does a DPO actually do?
They advise the organisation on its data protection obligations, monitor compliance, advise on impact assessments, cooperate with the Agency, and serve as the contact point for the Agency and individuals.
Verified Nexa network · anonymous

Need help with this?

Tell us a little about your situation and we will connect you with a verified expert from the Nexa network.

Your request is presented to the verified Nexa network anonymously — without your name. We share your contact only if a professional expresses interest, and you can withdraw at any time via info@nexa.mk. You have no financial obligation toward Nexa.

Related articles

Personal Data Protection (GDPR) for Businesses in North Macedonia
Data Protection (GDPR)

Personal Data Protection (GDPR) for Businesses in North Macedonia

If your business handles personal data — of customers, employees or website visitors — the Law on Personal Data Protection applies. It mirrors the EU GDPR: lawful bases, data-subject rights, breach notification within 72 hours, and fines of up to 4% of annual income.

22 September 20267 min read
Read more
Video Surveillance (CCTV) Rules for Businesses in North Macedonia
Data Protection (GDPR)

Video Surveillance (CCTV) Rules for Businesses in North Macedonia

If your business uses CCTV, you must adopt a formal act governing the surveillance, post a visible notice, and delete footage within 30 days. Video surveillance is regulated personal-data processing — here is what compliance requires.

22 September 20265 min read
Read more