Under the GDPR, you must appoint a DPO if:
you are a public authority (except for courts acting in their judicial capacity); your core activities require large scale, regular and systematic monitoring of individuals (for example, online behaviour tracking); or your core activities consist of large scale processing of special categories of data or data relating to criminal convictions and offences.
So - no?
As far as I know the GDPR doesn't change these requirements here. So even if you're a company of 5 people and just handling some email addresses or similar data you certainly don't need a DPO.
And I copy-pasted direct text from the regulation. Note how it says "large scale". Twice. If he is actually processing personal data on a large scale, then maybe it is not unreasonable to have a DPO.
clause a: not a public body
clause b: not systematically monitoring (eg. installing video cameras all over the streets)
clause c: not processing large scale sensitive or criminal information.
doesn't look to me like a DPO is needed based on this article?
I'm struggling to understand why that's unclear. Is it the use of "public authority or body"?
He's not handling sensitive personal data.
He doesn't need a DPO.
See also the derogation for micro companies:
https://gdpr-info.eu/recitals/no-13/
> To take account of the specific situation of micro, small and medium-sized enterprises, this Regulation includes a derogation for organisations with fewer than 250 employees with regard to record-keeping.
How do you guaranty that nothing in the messages being handled by the server is "sensitive personal data".
Example: Parts of our software run on customer servers and as such they are processing data in their control and not ours, hence can for example used to filter out personal data before they are then sent to our servers, without causing any GDPR related triggering of sending personal information to a third party (our company).
> How do you guaranty that nothing in the messages being handled by the server is "sensitive personal data".
You guarantee it by reading the rest of GDPR. It defines sensitive personal data separately than personal data. Sensitive personal data is defined by GDPR to be things that can be used to discriminate against the individual, such as race, ethnicity, religion, health information, credit information, age, etc.
EDIT: And what I mean to say is that if the messages aren't passing through the server or being stored on the servers, then the only info being handled by the server is the meta-data including IP address, which is not included in GDPR's definition of _sensitive_ personal data.
Sounds to me like they are not a) processing b) collecting message data.
When instead it is up for interpretation, that comes with issues. The first is selective enforcement, there is also the chilling effect on both sides. Those who ought to be protected worry about the slack given to their potential predators. Meanwhile those who are 'potential predators' need to worry about the slightest move that is illegal under some interpretation.
The end result of this chilling effect is fewer willing customers, fever willing companies, and less mutual trust. Notably, this lack of trust persists even if you presume everyone still follows the law. At that point it seems to me a law has failed.
The kind of law making you’re implicitly advocating is tantamount to despotism. Drafting a law that outlaws islam might well be clear in it’s wording, but it needs to be tested against the law that allows freedom of religion, freedom from persecution, and a ton of other laws no doubt. The claritiy of language with which a ban on islam is articulated is all for nought if it’s contradicted by, and incompatible with other laws.
Although, GDPR has been explained very clearly. And we’ve been given a loooong time to digest, understand, implement, and question it. I don’t think any reasoable person can make a compelling case against GDPR. But unreasonable people can, and as we’re seeing, they will.