European Union · English

Data protection and compliance across the EU

Data Protection Officer services, training and regulatory support for public and private organisations in every Member State, under the GDPR and national law.

Data Protection Officer

Choose your segment

Four offers built on Articles 37 to 39 of the GDPR.

DPO for Public Bodies

Central, regional and local government, agencies and public universities.

DPO for Private Organisations

Controllers and processors, under a mandatory or voluntary designation.

Shared DPO for Public Bodies

Associations of municipalities, inter-municipal bodies and groups of agencies.

DPO for Corporate Groups

One DPO for a group of undertakings, accessible from every establishment.

The European framework

The General Data Protection Regulation applies directly in all Member States and, through the EEA Agreement, in Iceland, Liechtenstein and Norway. Articles 37 to 39 set out when a Data Protection Officer must be designated, the DPO's position and the DPO's tasks. National laws complement these rules, for example by extending the list of organisations that must appoint a DPO or by setting specific procedures for public bodies, and the supervisory authorities cooperate within the European Data Protection Board.

The Office works from this common European core and adapts each engagement to the national law that applies. Where we have published national offers, they are written in the language of the country concerned.

National pages

  • Portugal, in Portuguese;

  • Spain, in Spanish;

  • Brazil, in Brazilian Portuguese, for groups operating on both sides of the Atlantic.

Beyond data protection

Cybersecurity (NIS2) · Artificial intelligence · Whistleblower protection · Anti-corruption · All domains

Other jurisdictions

International · Países da CPLP · Iberoamérica

General information as at October 2026; it does not constitute legal advice.

Keep up with the changes that matter

Subscribe to the Office's weekly regulatory alerts.