GDPR Article 37 role, mandatory for public authorities and organisations whose core activities involve large-scale monitoring or large-scale processing of special category data such as Biometric data. The DPO advises the Controller and monitors compliance but does not bear personal liability for the organisation’s breaches, and must be able to report directly to the highest level of management under Article 38.
