Privacy and data protection

Data Protection Officer (DPO)

Lawyers and (in-house) legal counsel for your DPO issues

Are you required to appoint a Data Protection Officer, and how do you structure that role independently? Our lawyers and in-house counsel assess your situation, act as an external DPO if desired, and support your internal DPO – from international corporations to the baker around the corner.

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner

What we do

Within an organization, a person must oversee the handling of personal data. This person is referred to as the Data Protection Officer (DPO). One of our privacy specialists from the Privacy and Data Protection practice group can fill the position of DPO within an organization. Additionally, legal advice can be provided so that the DPO within an organization knows what is expected of him or her.

Questions regarding the position of Data Protection Officer? Please contact us.

When is a Data Protection Officer mandatory?

Whether your organization must appoint a DPO follows from Article 37 of the General Data Protection Regulation (GDPR). A DPO is mandatory in three situations: (1) you are a public authority or public body; (2) your core activities consist of large-scale, regular and systematic observation of individuals; or (3) your core activities consist of large-scale processing of special categories of personal data (such as health, biometric or criminal data). Whether there is a case of “large-scale” and “core activity” is often a case-by-case legal assessment. Our lawyers and in-house counsel assess this for each organization individually – from an international group to a healthcare practice or the webshop around the corner. Even if appointment is not mandatory, a voluntary DPO can be sensible; ensure that a voluntarily appointed DPO meets the same GDPR requirements.

Tasks of the DPO (Article 39 GDPR)

The minimum duties of a Data Protection Officer are set out in Article 39 of the GDPR. The DPO:

  • informs and advises the organization and its employees about their obligations under the GDPR and other privacy regulations;
  • oversees compliance with the GDPR, including the allocation of responsibilities, staff awareness and training, and the conduct of audits;
  • advises, upon request, on a Data Protection Impact Assessment (DPIA) and supervises its implementation;
  • collaborates with the Dutch Data Protection Authority (AP) and acts as a point of contact, including in the event of data breaches.

The DPO is a supervisor and advisor, not an implementer: he or she is not personally responsible for compliance – that responsibility remains with the controller.

Position, facilities and independence (Article 38 GDPR)

Article 38 of the GDPR safeguards the position of the DPO. The organization must involve the DPO in a timely and proper manner in all matters concerning the protection of personal data, provide him or her with sufficient resources and access to data, and not dismiss or punish the DPO for performing his or her duties. The DPO reports directly to senior management. An important feature is legally enshrined independence: the DPO receives no instructions regarding the manner in which he or she performs the duties. The DPO may perform other duties, provided this does not lead to a conflict of interest – for instance, someone who decides on processing purposes themselves cannot simultaneously be an independent DPO. Finally, the DPO is bound by confidentiality regarding the performance of his or her duties.

Internal DPO, external DPO or Privacy Officer?

A DPO can be an in-house employee or hired externally; the GDPR permits both, and organizations may also share a joint DPO. For many SMEs, healthcare institutions, and educational organizations, an external DPO is attractive: you gain independent expertise without having to set up a permanent position. Our (corporate) legal counsel and lawyers from the Privacy and Data Protection practice group can act as an external DPO or provide legal support to an internal DPO. Note the distinction with a Privacy Officer: the latter implements the privacy policy in practice (maintaining registers, handling requests), whereas the DPO exercises independent oversight. Combining both roles in one person can quickly lead to a conflict of interest.

Reporting to the AP and risks of non-compliance

If your organization has appointed a DPO, you must register them with the Dutch Data Protection Authority and make their contact details public (Article 37, paragraph 7 GDPR). The DPO actively checks whether mandatory organizations have a DPO. Failing to appoint or register a DPO incorrectly is a violation of the GDPR for which the DPO may impose a fine. A well-positioned, independent DPO is therefore not only a legal obligation but also limits your liability risk. We are happy to combine this assessment with a privacy audit to bring your entire privacy management into order.

Our approach: from corporations to the baker on the corner

MKB Juristen works with mixed teams of lawyers and in-house counsel. This allows us to switch seamlessly between strategic privacy advice for an international group and practical, affordable support for the small business owner. We assess whether you require a DPO, fulfill that role as an external DPO if desired, support your internal DPO, and assist with the setup of your broader privacy compliance. This page is part of our Privacy and Data Protection, where you can also turn to us for related topics such as data breaches, DPIAs, and privacy audits.

Mr. Jaime Boogaers
Mr. Jaime Boogaers
Corporate Law · Lawyer

In specialized legal cases, it is not just about the legal rule. It is also about evidence, timing, negotiating position, and the business implications of every step.

How we help you

Our privacy specialists support you at every stage regarding the Data Protection Officer.

  • Assessing whether a DPO is mandatory or advisable for your organization
  • Acting as an independent external DPO
  • Legal support for your internal DPO or Privacy Officer
  • Structuring the position, independence, and confidentiality of the DPO
  • Registration with the Dutch Data Protection Authority and broader privacy compliance

Risks associated with a missing or poorly positioned Data Protection Officer

The wrongful failure to appoint or register a DPO is a violation of the GDPR for which the Dutch Data Protection Authority can impose a fine. A DPO who is not independent or has a conflict of interest also increases your liability risk.

  • Fine from the AP due to a missing or unregistered DPO
  • Conflict of interest because the DPO also decides on processing operations
  • DPO without sufficient resources, access, or independence
  • Reputational damage following a data breach without proper oversight

Our approach

With mixed teams of lawyers and in-house counsel, we switch between strategic privacy advice for corporations and practical, affordable support for small business owners. We assess the DPO obligation, fulfill or support the role, and ensure an independent, well-positioned DPO.

This is how we work

A clear process from assessment to setting up your DPO.

01

Intake and initial assessment

We will briefly discuss the situation, the available documents, and your primary interests.

02

Analysis of position and risks

We assess your legal position, supporting documents, deadlines, and possible next steps.

03

Strategic advice

You will receive concrete advice on the best course of action: responding, negotiating, settling, or litigating.

04

Execution

We assist with correspondence, negotiation, litigation strategy, or further legal assistance.

Specialists for entrepreneurs

We combine legal analysis with practical experience in cases for entrepreneurs, directors, and organizations.

Our team is engaged to provide legal and strategic support in the field of privacy and data protection. We offer this support to a wide variety of clients, ranging from companies to non-profit organizations. Our practice group's excellent knowledge of privacy law and data protection results in sound and pragmatic advice. In addition to outlining the legal framework, our lawyers and legal experts specialize in implementing this advice within the organization.

Frequently asked questions about the Data Protection Officer

The most frequently asked questions about the Data Protection Officer.

When is legal advice advisable?

Legal advice is wise as soon as pressure arises, deadlines are running, an opposing party takes a position, or when the financial or strategic interests are significant.

Can MKB Juristen also help if there is already a conflict?

Yes. We assess your legal position, advise on strategy, and can assist with correspondence, negotiation, defense, or further legal steps.

How much does specialist legal advice cost?

Specialist advice is provided on an hourly basis in principle. Where possible, we provide clarity in advance regarding the expected approach, costs, and next steps.

Can I have a no-obligation consultation first?

Yes. You can request a free consultation. We will briefly discuss your situation and indicate which course of action is likely the sensible one.

Submit an FG issue?

Contact our privacy specialists without obligation. We will assess your situation and help you move forward quickly.

Contact us

Contact us

Leave your details. We will contact you to briefly discuss your situation.

Contact us

Jaime Boogaers

Want to know more about our services?
Then contact our specialists.

Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation