Application

Who should assess the need for a DPO?

The assessment depends on the type of entity and the nature, scale and regularity of its processing activities.

Public-sector entities

Public authorities and bodies must appoint a DPO, with additional Portuguese provisions under Law no. 58/2019.

Companies and processors

They must assess their processing, its scale, the nature of the data and any regular and systematic monitoring of individuals.

Social-sector organizations

The need depends on the context and processing; health, vulnerability and regular service data call for careful assessment.

Possible models

Internal, external or shared — with the same safeguards.

The chosen model must protect expertise, accessibility, independence, resources and freedom from conflicts of interests.

01

Internal DPO

Part of the organization, provided the person has suitable expertise, resources, direct access to senior management and no conflict of interests.

02

External DPO

The function may be provided under a service contract while preserving independence, availability, confidentiality and access to the organization.

03

Shared DPO

A group or common structure may share a DPO when the function remains easily accessible; each entity established in Portugal notifies the CNPD individually where applicable.

Practical sequence

From assessment to ongoing oversight.

  1. 01

    Assess the requirement and context

    Map the entity, processing activities, data categories, scale, monitoring and risks.

  2. 02

    Check expertise and conflicts

    Confirm appropriate knowledge, independence, resources and compatibility with any other duties.

  3. 03

    Formalize the appointment

    Define the mandate, access, points of contact, confidentiality, resources and reporting to senior management.

  4. 04

    Publish and notify contact details

    Make contact details available to individuals and notify the appointment to the CNPD using its dedicated form.

  5. 05

    Maintain oversight and evidence

    Record advice, decisions, activities, risks, requests, incidents and review cycles.

Frequently asked questions

Direct answers.

Does a DPO need a professional certification?

No. The CNPD states that professional certification is not required; appointment should be based on professional qualities and specialist knowledge of data protection law and practice.

Is contracting DPOaaS enough?

Not by itself. Where applicable, the appointment must be formalized, the conditions for the role ensured, contact details published and the CNPD notified.

Does the DPO make decisions for the organization?

No. The DPO advises and monitors independently; accountability for decisions and compliance remains with the organization.

Primary sources

Confirm against official guidance.

DPOaaS

Do you need to assess or structure the DPO role?

We begin with the organization’s actual context, without assuming the conclusion.