Primary contact: dpo@preferium.com · Lead supervisory authority: Datatilsynet (Norway, EEA).
Data Protection Officer (DPO) Designation
Status: PLACEHOLDER — decision pending Robert (target: R171). GDPR Article: Art. 37 (designation), Art. 38 (position), Art. 39 (tasks).
Context
Preferium AS processes personal data on behalf of customers (controller-processor relationship per DPA.md). Whether designating a DPO is mandatory or voluntary depends on the criteria below.
When designation is MANDATORY (GDPR Art. 37(1))
A DPO must be designated when:
- (a) the processor is a public authority — N/A, we are a private company
- (b) core activities consist of processing operations which “by their nature, scope and/or purposes, require regular and systematic monitoring of data subjects on a large scale” — borderline as we scale: SEO + LLM-citation analytics could fall in scope when we onboard EU customers with high-traffic sites
- (c) core activities consist of large-scale processing of special categories of data (Art. 9) or criminal data (Art. 10) — N/A, we explicitly do not process special-category or criminal data
Conclusion at v1 scale (Q2 2026): designation is NOT mandatory but is RECOMMENDED for procurement-readiness.
When designation is RECOMMENDED regardless
- Enterprise customers increasingly require a named DPO on the procurement checklist (SIG Lite, CAIQ)
- SOC 2 + ISO 27001 both list “designated privacy officer” as a control objective even when GDPR doesn’t strictly require one
- Having a named DPO reduces the cost-of-friction in any GDPR investigation
Decision matrix
| Option | When to choose | Cost | DPO contact |
|---|---|---|---|
| A — Robert as DPO | v1 scale, no specific customer mandate, simple processor relationships | €0 (overhead only) | dpo@preferium.com → Robert |
| B — Outsourced DPO-as-a-service (Privacy Tools, OneTrust DPO Pro, DataGuard) | One or more designated-DPO customer requirements OR ~50+ EU enterprise customers | €500-2000/month | dpo@preferium.com → external party |
| C — Hired DPO | $5M+ ARR, regulated-industry customer, or multi-country supervisory authority exposure | €70-120k/yr + benefits | Internal hire |
GDPR Art. 38(6) allows the DPO to have other tasks “provided that such tasks and duties do not result in a conflict of interests”. Robert as CEO + DPO is acceptable at v1 scale because Preferium does not make automated decisions about data subjects based on the data we process — we serve SEO infrastructure, not individual-affecting profiling.
Designation (FILL IN WHEN DECIDED)
The Data Protection Officer for Preferium AS is __________________________,
reachable at dpo@preferium.com.
Designation effective: __________________________
Designation method: [ ] Option A (Robert)
[ ] Option B (outsourced — vendor: _______________________)
[ ] Option C (hired)
Per GDPR Article 39 the DPO is responsible for:
- monitoring compliance with GDPR + applicable national law
- training of staff involved in processing
- cooperating with supervisory authorities
- serving as point of contact for supervisory authorities
- advising on Data Protection Impact Assessments (DPIAs)
- operating with appropriate independence (Art. 38(3))
Supervisory authority contact has been notified per Art. 37(7):
- Datatilsynet (Norway): postkasse@datatilsynet.no
Once designated
- Update DPA.md template to reference the DPO contact
- Publish DPO contact at
https://preferium.com/legal/dpo(Phase 14 deploy) - Update privacy notice (PRIVACY.md) §“Data Protection Officer” section
- Add to sub-processor list page footer
- Notify Datatilsynet under Art. 37(7) within 30 days
Cross-references
- DPA.md — Data Processing Agreement (references DPO via dpo@preferium.com)
- PRIVACY.md — Privacy notice (will reference designation)
- VDP-policy.md — separate from data protection; DPO is NOT a security-incident contact
~/.claude/skills/preferium-edge/enterprise-readiness.md§12.6 — context + decision criteria