All articles
15. 8. 2017
3 min read

Basic GDPR terminology: data controller and data protection officer

In the basic terminology section, we would like to briefly, clearly and understandably explain the basic terms of the GDPR


The European Data Protection Regulation (GDPR) is a new regulation that will come into force on 25 May 2018. Private companies and public authorities (data controllers) will have to establish the position of data protection officer

Privacy Officerany entity that processes, collects and stores personal data of its employees or clients or other persons. The controller is responsible for processing personal data for which it must have a legal basis, for complying with its obligations under the GDPR and for properly securing personal data against leakage. The controller must apply deliberate data protection, appoint a DPO (only some controllers), report breaches or leaks of personal data to the Data Protection Authority and to the individuals to whom the data relates.

Data Protection Officer – DPO (Data Protection Officer) – monitors the compliance of personal data processing with the requirements of the GDPR, conducts internal audits, staff training and overall management of the internal data protection agenda. The DPO also informs, advises and makes recommendations to the controller or processor. The Controller appoints the Data Protection Officer on the basis of his/her professional qualities, in particular his/her knowledge of the law. The controller shall provide the trustee with resources to maintain his or her knowledge.

Who must appoint the DPO and in what cases?

  • If the controller or processor of personal data is a public authority or public body
  • If the core business of the controller or processor requires extensive, regular and systematic monitoring of personal data subjects
  • Where the main activities of the controller or processor consist of large-scale processing of special categories of data or personal data relating to criminal convictions and offences

Custodian as a service
It is up to companies whether they choose to handle the fiduciary function internally or externally. If they choose in-house staff, they must ensure they are sufficiently qualified. The advantages of outsourcing lie in the financial savings, plus the fiduciaries will already be trained. By choosing an external DPO, companies also eliminate the complexity of finding a suitable employee.

The DPO must work closely with the Data Protection Authority, which is the official representative and guarantor of compliance with the new European GDPR regulation.

If you are interested in DPO outsourcing options or any other information, please contact us. We will be happy to advise and address your needs and questions individually.

Have a project?

Get in touch and we'll discuss how we can help.
Contact us

More articles

1 Aug 2026

Cyber Resilience Act: New Rules for Secure Software and Digital Products

The European Union is introducing another important regulation in the field of cybersecurity. It is called the Cyber Resilience Act, or CRA for short, and applies to all products with a digital component. This means not only smart devices, but also software, applications, and systems that connect to a network or communicate with another service…
Read the article
15 Jul 2026

Withdrawal button – Wontilles responds in advance to new legislative requirements

The legislative environment in the field of e-commerce is undergoing constant changes, which place high demands on online shop operators.
Read the article
1 Jun 2026

Railsformers at the Faculty of Arts at the OU: Ruby on Rails in practice and now also in IT business

At the Faculty of Science of the University of Ostrava, we have long been giving students practical experience with Ruby on Rails development and showing them what it looks like to work on real web applications. From the original pilot course, we have developed a stable course Ruby on Rails I and II, which we…
Read the article