22 ms·
From the same site: """ Under the GDPR, you must appoint a DPO if: you are a public authority (except for courts acting in their judicial capacity); your core
by colonelxc 8y ago
From the same site:
"""
Under the GDPR, you must appoint a DPO if:
you are a public authority (except for courts acting in their judicial capacity);
your core activities require large scale, regular and systematic monitoring of individuals (for example, online behaviour tracking); or
your core activities consist of large scale processing of special categories of data or data relating to criminal convictions and offences.
"""
So if you're not doing 'large scale behaviour tracking', you would not need one. A simple company that sells a subscription service should not need one, unless they are also selling targeted ads, and maybe if they are doing identifiable tracking of how a given user uses the service. Aggregated metrics with no identifiable data do not count (This feature has been used X times). If you are, then it becomes a question of what is 'large scale' in terms of the GDPR.
- paulddraper 8y ago> 'large scale' in terms of the GDPR. I have no idea what that means. If my B2B business has a lot of revenue but few customers, am I 'large scale'? If my B2C business has little revenue but a lot of customers, am I 'large scale'? Or maybe 'large scale' applies to the number of servers I use? I have no idea the criteria.
- Karrot_Kream 8y agoThe keyword here is "large scale behavior tracking". Let's not elide over that.