A Data Protection Officer (officer for personal data protection / офицер за заштита на личните податоци) is an expert who oversees your compliance with the data protection law. Many owners assume every company needs one — in fact the law makes it mandatory only in specific situations. This guide explains when you must appoint a DPO, and what they do.
When a DPO is mandatory
Under the Law on Personal Data Protection, a controller or processor must appoint a DPO in any of these cases:
- Public authority — the processing is carried out by a state body (courts acting in their judicial capacity are an exception).
- Large-scale regular and systematic monitoring — your core activities consist of processing operations that, by their nature, scope and/or purposes, require regular and systematic monitoring of individuals on a large scale (for example, extensive tracking or profiling).
- Large-scale sensitive data — your core activities consist of large-scale processing of special categories of data (health, biometric, religious or political data, etc.) or data on criminal convictions and offences.
The key words are core activities and large scale. Processing that is merely ancillary to your business (like ordinary payroll) does not usually trigger the requirement. If none of the three cases applies, appointing a DPO is optional — but still allowed, and sometimes worthwhile.
One DPO for a group
A group of companies may designate a single DPO, provided the officer is easily reachable by each entity in the group, by the Agency, and by data subjects. This makes compliance more efficient for company groups without each entity hiring its own officer.
Not sure how this applies to you?
Get a clear answer from a verified expert.
What the DPO does
The DPO is chosen on the basis of professional qualifications and expert knowledge of data protection law and practice. Their role is to inform and advise the organisation on its obligations, monitor compliance, advise on data protection impact assessments, cooperate with the Agency, and act as the contact point for the Agency and for individuals. Their contact details are typically published in your privacy notice and provided to the Agency.

