Under GDPR, a Data Protection Officer (DPO) must be appointed when:
- A.Every organization must appoint one regardless of size, under Article 37(3), which requires a single DPO to be appointed separately for each subsidiary in a corporate group
- B.Only when processing financial data
- C.Only organizations with more than 500 employees
- D.The processing is carried out by a public authority, involves large-scale systematic monitoring, or involves large-scale processing of special category data
Why D is correct
Article 37(1) requires DPO appointment for public authorities, organizations whose core activities require large-scale systematic monitoring, or large-scale special category data processing.
Know someone studying for GDPR? Send them this one.