Categories: Insights, Practice

Tag: DPO, Garante Privacy


27 Jul 2020

The Data Protection Officer: controls and sanctions in case of failure to designate same

With a decision dated 1 April 2020, the Spanish Data Protection Authority (hereinafter, the “Agencia Española Protección Datos” – “AEPD”) sanctioned a Spanish company doing business in the home delivery sector following the relevant online booking, used by thousands of customers, due to the failure to designate a Data Protection Officer (hereinafter, the “DPO” or the “Head of Data Protection”) pursuant to Article 37 of Regulation (EU) 2016/679 on personal data protection (hereinafter, the “Regulation”).

One of the new developments introduced by the Regulation is the role of the DPO. Indeed, Articles 37, 38 and 39 include provisions in connection (i) with the designation of the DPO (ii) with the position held by such role within an organisation and (iii) with the reference as to the minimum duties to be assigned thereto in light of the nature, scope of application, context and aims of the processing carried out by the Data Controller or by the Data Processor.  

However, if we stick to a literal interpretation of the Regulation, not all Data Controllers or Data Processors are under an obligation to designate any such role.

The above-mentioned line of interpretation arises out of the content of Article 37, based on which it is necessary to designate a DPO in any case where: “(i) the processing is carried out by a public authority or body (…)”, “(ii) the core activities (…) consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale”, or (iii) “the core activities (…) consist of processing on a large scale of special categories of data (…) or personal data relating to criminal convictions (…).

From the very first interpretation of the Regulation, such cases have started considerable debate with the corresponding different stances on the side of law scholars. The expressions “large scale” “regular monitoring of data subjects on a large scale” are rather vague and, often, in the actual implementation of the Regulation, they may bring about interpretative doubts.

In this respect, the decision of the AEPD at issue is not only significant because it includes one of the first sanctions inflicted as from the entering into force of the GDPR following the ascertainment of the failure to designate the DPO, but also and moreover, because it constitutes a precedent in the definition and demarcation of the “large scale” concept. Indeed, the Spanish Authority emphasises the numerical significance of the data subjects affected by the processing as a necessary condition in order to ascertain the vague large scale concept.

Within our domestic scope, notwithstanding the rules under the Regulation, the Italian Data Protection Authority has clarified that it is also possible to designate a DPO even in those cases not falling within those imposed by the Regulation. Indeed, in light of any such clarification, it is good practice to accurately ground and document the reasons why the Data Controller, or the Data Processor, have made the decision to identify any such role or not.

Finally, we would like to recall that infringements of the obligations under the aforesaid Articles 37, 38 and 39 of the Regulation entails, pursuant to Article 83(4) of any such Regulation to the infliction of an administrative fine up to Euro 10,000,000.00 or, in case of an undertaking, up to 2% of the total worldwide annual turnover of the preceding financial year.

Others insights related:

FAQs of the Data Protection Authority on the Data Protection Officer of Personal Data

DO YOU KNOW THAT.. The GDPR has introduced the DPO?

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

17 Mar 2026

Equal pay: green light for the decree on pay equality and wage transparency (People are People, 16 marzo 2026 – Claudia Cerbone, Martina De Angeli)

Claudia Cerbone and Martina De Angeli, professionals at the De Luca & Partners firm, author this article dedicated to the draft legislative decree approved last February 5 by…

16 Mar 2026

Illegitimacy of staff leasing due to violation of the principle of temporariness (Top 24 Lavoro, 27 febbraio 2026 – Vittorio De Luca, Alessandra Zilla)

With judgment no. 4493 of December 19, 2025, the Court of Milan addressed the issue of indefinite-term labor supply (so-called staff leasing). In particular, the Court clarified that,…

10 Mar 2026

The transfer of the employee is lawful when there is incompatibility with the company environment (Camera di Commercio Italo-Francese, 10 marzo 2026 – Vittorio De Luca, Silvia Zulato)

With Order No. 4198 of 25 February 2026, the Italian Supreme Court (Court of Cassation) – Labour Section – reaffirmed that a situation of environmental incompatibility may justify…

3 Mar 2026

Employee monitoring: when “bossware” becomes a legal risk (Agenda Digitale, 2 marzo 2026 – Martina De Angeli)

Monitoring workers through digital tools is a rapidly expanding practice, accelerated by the spread of remote work and the digital transformation of companies. Before adopting these systems, however,…

3 Mar 2026

Melismelis signs the campaign for the 50th anniversary of De Luca & Partners

For the historic labor law firm, the agency developed the 50th-anniversary logo and advertising campaign, managed online and offline media planning, and renewed the website’s visual identity. Milan,…

27 Feb 2026

Dismissals: the Corte costituzionale grants broader discretion to judges and greater scope for reinstatement (I Focus del Sole 24 Ore, 26 febbraio 2026 – Vittorio De Luca e Alessandra Zilla)

The regulation of dismissals continues to represent one of the central pillars of Italian labour law, an area of constant tension between freedom of economic initiative and the…