Skip to content
GlossaryLegal

Data Protection Officer (DPO)

GDPR figure: person appointed by an entity to oversee data-protection compliance. Mandatory in some cases, advisable in many others.

Definition

The Data Protection Officer (DPO) is the figure introduced by GDPR (arts. 37-39) for entities whose data processing is large-scale or involves special categories. Functions: inform and advise the controller and employees on their obligations, monitor GDPR/LOPDGDD compliance, advise on impact assessments, cooperate with the supervisory authority (AEPD in Spain) and act as contact point for data subjects.

Must have specific data-protection training, act independently and report to the highest management level. Can be internal (dedicated employee) or external (contracted firm). Contact details are published and reported to the AEPD.

When does it apply?

Mandatory when: 1) the controller's core activity requires regular and systematic large-scale monitoring of data subjects, or 2) when special categories of data (health, biometric, orientation) are processed at large scale. For the vast majority of amateur Spanish sports clubs a formal DPO is NOT mandatory, but it is strongly advisable to have an internal GDPR contact point (even without the formal DPO status).

Practical example

A club with 80 members and a single team needs no formal DPO. But C.D. Reus Esportiu (multi-sport club with 1,200 members, several sections, event video, active social media and medical files for elite federated players) does designate an external DPO: hires a local consultancy for €600/year acting as DPO, maintaining the RAT, advising on new processing activities and serving as the AEPD-registered contact.

Common mistakes

  • Confusing DPO with DPI: DPO is from GDPR; DPI from LOPIVI. They can be different people.
  • Appointing a DPO without training them: the AEPD requires verifiable training and demonstrable experience.
  • Not publishing the DPO's contact: if appointed, you must notify the AEPD and publish it in the privacy policy.
  • Thinking it's mandatory when it isn't: many small clubs appoint one 'just in case' when not formally required.

Related terms

Go deeper

Long-form guides and product pages where we cover this topic in depth:

This is not specific legal or tax advice

Information as of May 2026. Regulation evolves and every club has its own casuistry (region, federation, size, activities). For your specific case talk to a lawyer or tax advisor specialised in Spanish sports law.

Move from Excel to software built for sports clubs

SEPA + card payments with Stripe, member portal, player onboarding, ticketing. Free up to 50 members, no card required.