The regulatory framework
Regulation (EU) 2016/679 devotes three articles to the data protection officer (DPO). Article 37 establishes when designation is mandatory. There are three cases: public authorities and bodies; regular and systematic monitoring of data subjects on a large scale as a core activity; and large-scale processing, again as a core activity, of special categories of data (Article 9) or of data relating to criminal convictions and offences (Article 10). Article 38 defines the DPO’s position: timely involvement in all matters relating to personal data, adequate resources, no instructions regarding the performance of the tasks, no dismissal or penalty for performing them, direct reporting to the highest management level, a duty of secrecy and the absence of any conflict of interest. Article 39 lists the tasks: to inform and advise, to monitor compliance with the Regulation, to provide advice on impact assessments, to cooperate with the supervisory authority and to act as its contact point.
The DPO’s contact details must be published and notified to the Garante through its dedicated online procedure, and they appear in privacy notices, in the record of processing activities and in breach notifications. The WP243 Guidelines of the Article 29 Working Party, endorsed by the EDPB, together with the Garante’s FAQs, clarify the notions of “large scale”, “core activities” and “regular and systematic monitoring”. Article 37(6) expressly provides that the DPO may be an external party fulfilling the tasks under a service contract; WP243 recommends that, where that party is a company, a single lead contact be identified for the client.
For the business, the stakes are real. Failure to designate a DPO where one is required, or a purely formal appointment of a DPO who lacks resources or is in a conflict of interest, is among the infringements punishable by fines of up to €10 million or 2% of total worldwide annual turnover (Article 83(4)). The designation and position of DPOs have also been the subject of a coordinated enforcement action by the European data protection authorities.
Our approach
Appointing a DPO is not a formality to be filed away: it establishes a function that has to be involved whenever the business takes decisions about data. We therefore build the service as continuous support for management and the operational functions, with an activity plan agreed at the outset and reviewed every year.
Everything we do is recorded in a DPO activity log: opinions given, consultations received, checks carried out, findings and corrective actions. It is the tool that allows the controller to demonstrate, in the event of an inspection or a complaint, that the function was involved and that the choices made were properly considered, even where the board chose not to follow a recommendation.
The service combines legal and technical expertise. We read supplier contracts and the clauses on international data transfers, and we are equally able to assess logs, configurations and security measures, and to deal with IT directly. Where the business has a 231 Model under Italian Legislative Decree 231/2001, falls within the scope of NIS2 (Italian Legislative Decree 138/2024) or operates an ISO/IEC 27001:2022 management system, we coordinate the work of the DPO with those bodies and requirements: information flows to the Supervisory Body (OdV) on computer crime offences, a single procedure for incidents and breaches, a single supplier register.
What sets our service apart
- Real independence: the outsourced DPO sits outside internal reporting lines, and the opinions given remain independent even when they are unwelcome.
- Legal and technical expertise together: we read contracts and data transfer clauses, but we also assess logs, configurations and security measures, dealing with IT directly.
- Integration with Decree 231, NIS2 and ISO/IEC 27001: we coordinate the work of the DPO with the Supervisory Body (OdV) and with management systems already in place, under a single procedure for incidents and breaches and a single supplier register.
- Measurability: the annual plan, the activity log and the report to the board show clearly what has been done, what remains to be done and in what order of priority.