Data Protection Officer (DPO)
A data protection officer (DPO) monitors compliance with the GDPR within an organisation; the appointment is mandatory in certain cases, such as public authorities, large-scale systematic monitoring or the processing of special categories of data, but voluntary for other companies.
In practice
Whether an appointment is required does not depend on headcount – unlike Germany, Austrian law sets no such threshold – but on the qualitative criteria in Article 37(1) GDPR: being a public authority, carrying out regular and systematic monitoring of data subjects on a large scale, or processing special categories of data on a large scale. Comparing your own processing activities against those criteria brings clarity. A data protection officer can be appointed internally where there is sufficient independence and expertise, or engaged externally as a service. Even without a legal obligation, having a named contact for data protection questions inside the company can be worthwhile.