Entry 04
Notifying your DPO to the supervisory authority
Article 37(7) is nineteen words of obligation and no procedure at all. There is no European register of Data Protection Officers, no common form and no shared portal. What there is, is twenty-seven national answers, and the four nearest to Riga differ from each other in ways that catch organisations expecting a single European filing.
What the Regulation requires
The obligation reads: "The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority." Two separate duties, one facing the public and one facing the regulator, and both of them continuing rather than one-off.
The Article 29 Working Party explains the purpose. The objective of the requirements is to ensure that data subjects, both inside and outside the organisation, and the supervisory authorities can easily and directly contact the officer without having to contact another part of the organisation. Confidentiality matters here too: employees may be reluctant to complain to an officer if the confidentiality of their communications is not guaranteed, and Article 38(5) binds the officer to secrecy or confidentiality in accordance with Union or Member State law.
On what counts as contact details, the guidance is practical. They should include information allowing data subjects and the supervisory authorities to reach the officer easily: a postal address, a dedicated telephone number, or a dedicated email address. Where appropriate, other means may be added for communication with the public, for example a dedicated hotline or a contact form addressed to the officer on the organisation's website. A general enquiries queue that happens to be read by the same team does not meet the standard the guidance describes.
Does the name have to be published?
No, and this trips up organisations that publish more than they need to. Article 37(7) does not require the published contact details to include the name of the officer. The Working Party treats publishing it as possibly good practice but leaves the decision to the controller or processor and the officer, in the circumstances.
The position with the authority is different. Communication of the name to the supervisory authority is described as essential, so that the officer can serve as the contact point between the organisation and the authority under Article 39(1)(e). And there is a third asymmetry that the guidance points out in a footnote: Article 33(3)(b), which lists what must be provided when notifying a personal data breach, requires the name of the officer and not only the contact details. Publish contact details, tell the authority the name, and have the name ready for a breach notification.
The Working Party also recommends, as good practice, that the organisation inform its own employees of the name and contact details, for example on the intranet, in the internal telephone directory or in organisational charts.
Latvia
The Data State Inspectorate (Datu valsts inspekcija) wants a submission from the controller or processor itself, not from the officer or the provider. Its guidance asks for at least the designated officer's given name, surname and contact details, for example an email address or telephone number. The submission has to be signed by a person entitled to represent the organisation, or by an authorised person accompanied by the power of attorney, and sent electronically to the Inspectorate's address or to its official e-address. The Inspectorate publishes three separate forms: appointment, change of officer, and termination of the assignment. Free-form submissions on the organisation's own letterhead are accepted as long as they carry the same information.
Latvia then adds something no other authority in this group has. Under Section 19 of the Personal Data Processing Law the Inspectorate organises a qualification examination for data protection specialists, and under Section 18 it maintains a list of everyone who has passed it, published on its website. The examination fee is 188.78 EUR under Cabinet Regulation No. 621 of 6 October 2020, and each sitting is announced at least two months in advance in the official gazette Latvijas Vēstnesis. Maintaining the qualification afterwards is governed by Cabinet Regulation No. 620 of the same date.
Section 20 sets out when a person is removed from the list, and provides that someone removed on certain grounds may ask to be restored once the reasons have been resolved, with a fresh examination required if at least two years have passed since removal. Transitional provision 5 of the same law required the Cabinet of Ministers to evaluate, by 1 June 2024, whether the examination regime was worth keeping and to report to the Saeima on the possibility of abandoning it. The obligation to review is in the statute; the outcome of that review is not something this site has verified, so treat the examination as current and check before relying on its future.
Lithuania
The State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija) asks for a document signed by an authorised person, sent to the Inspectorate by email. Its published list of what the notification must contain is more detailed than Latvia's: the name and contact details of the controller or processor; whether the officer is designated by the controller or by the processor; the officer's name and surname; where the officer is an employee of the controller or processor, the job title, and where the officer is an employee of another legal entity, the name of that legal entity; and the officer's address, telephone number, email address and other means of communication.
That penultimate item is the one to note if you are buying the role. Lithuania asks you to disclose which company your outsourced officer works for, as part of the filing. The identity of the provider is regulator-visible from the start.
Lithuania has also been active on the substance. It carried out the 2023 coordinated enforcement action nationally, investigating the role of Data Protection Officers in ten Lithuanian companies against an approved questionnaire, and in April 2025 it published a national Recommendation on Data Protection Officers. That document addresses when the duty to designate applies, how to assess the officer's competence, whether to appoint your own employee or a service provider, the group-of-undertakings case, and how to ensure independence and when the officer's activity may raise a conflict-of-interest risk.
A practical note on sources: the Inspectorate's website does not currently serve automated requests, so the two facts above are cited here from Internet Archive captures of its own pages rather than from live links. If you are acting on them, confirm the current address and the current form with the Inspectorate directly.
Estonia
Estonia has the most streamlined mechanism of the four, and the most demanding language expectation. The Data Protection Inspectorate (Andmekaitse Inspektsioon) states that the easiest way to report a Data Protection Officer is through the e-Business Register. The notice can be entered by a person who is represented in the register and has the right of legal representation, in other words a board member, and in that case it is not necessary to send a separate notice to the Inspectorate at all. Where that is not possible, a notification may be sent by regular mail or digitally, provided the digital signature is valid under Regulation (EU) No 910/2014.
The Inspectorate also asks for the officer's personal identification code or date of birth and citizenship, which is a broader data set than the other three authorities request.
The language point is stated plainly and is worth quoting to any provider proposing to run the role from another country. The Inspectorate reminds organisations that the officer designated for a local company would be the contact person for the supervisory authority and for data subjects, that intense and thorough communication between the parties would be in the local language, and that the language of public administration and of communication with the public and data subjects shall be in Estonian according to the Estonian Language Act. It adds that its proceedings will be conducted in Estonian.
Finland
The Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) takes a declaration. Its guidance says the contact details of the officer must be communicated to the Office, and publishes two forms for the purpose: a Declaration of Data Protection Officer, and a separate form for a change to an existing declaration. Notifications about officers and questions related to their duties go to the Office's registry.
Finland also publishes the most useful plain-language guidance of the four, and two statements in it are worth carrying into any appointment discussion. The first concerns conflicts: the officer cannot hold a position or duty that requires them to define the purposes and methods of the processing of personal data, and conflicts of interest may arise if, for example, an information security officer or senior manager is designated as the Data Protection Officer. The second concerns responsibility: Data Protection Officers are not personally responsible for infringements of the GDPR, and compliance with data protection regulations is the responsibility of the controller or processor.
A third is operational rather than legal, and it is the argument for a deputy that the Regulation itself does not make: the officer should have a deputy, because personal data breach notifications and the fulfilment of data subject rights may not be delayed due to the officer's absence.
The four side by side
| Country | Authority | Mechanism | Worth knowing |
|---|---|---|---|
| Latvia | Datu valsts inspekcija | Signed submission from the controller or processor, by email or official e-address, on the Inspectorate's appointment, change or termination form | State qualification examination and a public list of those who pass; appointing someone not on the list is expressly permitted |
| Lithuania | Valstybinė duomenų apsaugos inspekcija | Document signed by an authorised person, by email | The filing must name the officer's employing legal entity where the officer is external; national Recommendation published April 2025 |
| Estonia | Andmekaitse Inspektsioon | Entry in the e-Business Register by a board member, with no separate notice required; otherwise post or eIDAS-valid digital signature | Personal identification code or date of birth and citizenship requested; communication and proceedings in Estonian |
| Finland | Tietosuojavaltuutetun toimisto | Declaration of Data Protection Officer filed with the Office, plus a change form | Published warning that designating an information security officer or senior manager may create a conflict of interests |
What none of these is
None of the four is an accreditation of the officer. Latvia comes closest, and even there the statute expressly permits appointing someone who has never sat the examination. None of them approves the appointment, none confirms that the arrangement is free of conflicts, and none of them transfers any part of the compliance responsibility away from the controller. Article 24(1) leaves that where it started.
Nor is any of them a substitute for the public-facing half of Article 37(7). Filing with the authority and publishing the contact details are two distinct obligations, and Italy's supervisory authority has adopted decisions covering failures to do either.
Keeping the record current
The obligation does not stop at the first filing. Latvia's Inspectorate asks to be informed where the officer's contact details change, where the officer is replaced, and where the designation is revoked, and publishes a distinct form for each of the latter two. Finland publishes a change form alongside the original declaration. Estonia's register-based route makes an update the same operation as the original entry. In Lithuania the notification is a signed document, so a replacement is a fresh one.
Two events should trigger a review of the filing regardless of country: a change of the named individual behind an outsourced appointment, which is a change of officer even if the provider is the same company, and any change to the published contact route.
Slovenia's authority found, in two sweeps during 2022, that roughly 520 public bodies had failed to inform it about their officers at all. The organisations were contacted, informed the authority properly, and no further sanctions followed, which is the outcome to aim for: this is the cheapest obligation in Section 4 to comply with and an avoidable one to be caught on.
If you have not yet decided whether the obligation applies, start with the Article 37(1) analysis. If you are choosing between an internal appointment and a service contract, the second entry covers what the agreement has to carry, and the third covers the conflict rules that decide most provider choices.
Sources
- Regulation (EU) 2016/679 (General Data Protection Regulation) Article 37(7) on publication and communication of contact details, Article 38(4) and (5), Article 39(1)(e), and Article 33(3)(b) on the officer's name in a breach notification.
- Guidelines on Data Protection Officers (DPOs), WP 243 rev.01 Section 2.6 on publication and communication of contact details, including the name question and the Article 33(3)(b) asymmetry.
- Fizisko personu datu apstrādes likums (Personal Data Processing Law) Sections 17 to 20 on the requirements for a data protection specialist, the Inspectorate's list, the qualification examination and removal from the list; transitional provision 5 on the review of the examination regime.
- Paziņojums par DAS iecelšanu What the Inspectorate wants in a notification, who must sign it, where to send it, and the appointment, change and termination forms.
- Datu aizsardzības speciālista kvalifikācijas eksāmens Announcement two months ahead in Latvijas Vēstnesis, and the 188.78 EUR fee under Cabinet Regulation No. 621 of 6 October 2020.
- How to inform the State Data Protection Inspectorate about the Data protection officer of your organization The full list of information the Inspectorate requires, including the employing legal entity for an external officer. Archived capture.
- VDAI rekomendacijos dėl duomenų apsaugos pareigūno paskyrimo, užduočių ir atsakomybės National Recommendation of 16 April 2025 and the questions it answers. Archived capture.
- Data protection officer: information for organisations Notification through the e-Business Register, the data requested, the eIDAS alternative, and the Estonian-language expectation. Page last updated 29 January 2024.
- Designating a data protection officer Communication of contact details to the Office, the declaration and change forms, and the conflict-of-interest statement.
- Data protection officers: instructions for organisations and managers The deputy recommendation and the statement that officers are not personally responsible for infringements.
- 2023 Coordinated Enforcement Action: Designation and Position of Data Protection Officers Section 5.1 on national enforcement, including the Slovenian sweeps and the Italian decisions on contact details.
Queries
Queries
Related questions
Is there a single European register of Data Protection Officers?
No. Article 37(7) requires the contact details to be published and communicated to the supervisory authority, and leaves the mechanism to national practice. Each authority has its own form, channel and expectations.
Do we have to publish the officer's name on our website?
Not under Article 37(7), which requires contact details rather than a name. The Working Party treats publishing the name as possibly good practice and leaves the decision to you and the officer. The name must be communicated to the supervisory authority, and Article 33(3)(b) requires it in a personal data breach notification.
Do we have to appoint someone from the Latvian list of data protection specialists?
No. Section 17 of Latvia's Personal Data Processing Law permits a controller or processor to appoint a person included in the Inspectorate's list or another person. The examination is a nationally recognised credential, not a licence to hold the role.
Can our DPO work in English if we operate in Estonia?
Not for dealings with the authority and the public. The Estonian Data Protection Inspectorate states that communication with the supervisory authority, the public and data subjects shall be in Estonian under the Estonian Language Act, and that its proceedings are conducted in Estonian. The Working Party makes the same point generally: communication must take place in the language used by the authority and the data subjects concerned.
What do we do when the person behind our outsourced appointment changes?
Treat it as a change of officer and refile. Latvia and Finland both publish a dedicated change form, Estonia's register entry is simply updated, and in Lithuania a replacement is a fresh signed notification. Update the published contact details at the same time.
Cluster
Keep reading
More entries in this register
-
Do you need a Data Protection Officer?
Three cases, no headcount threshold, and two words that decide almost every borderline call. The Article 37(1) test worked through with the Working Party's own examples.
Open entry -
Internal or external DPO: what the service contract has to carry
Article 37(6) permits an outsourced officer in fourteen words. The other thirty provisions of Section 4 decide whether the arrangement actually works.
Open entry -
DPO conflict of interest: where the line actually falls
The Court of Justice has given the test, the Working Party has named the positions, and supervisory authorities have found the failure modes. Including the ones that only appear when the officer is external.
Open entry