Glossary · Data protection

DPO (data protection officer)

Also known as: data protection officer, EPDIn Portuguese: EPD (encarregado de proteção de dados)

Short definition

The DPO is the person an organisation designates to advise it on the GDPR, monitor compliance and act as the contact point for data subjects and the supervisory authority (GDPR, Articles 37 to 39).

In plain language

Designating one is mandatory, among other cases, for public authorities and bodies and when the core activity involves large-scale processing of special categories of data, such as health data. The DPO must act independently and have expertise in data protection. In a health or social care institution, it is usually the DPO who reviews a new technology before it reaches service users.

Related terms

Sources

Glossary edited by the RVer team. Definitions are for information and do not replace clinical, legal or tax assessment or advice.Reviewed on 7 October 2026