Privacy contact: post@preferium.no · Supervisory authority: Datatilsynet (Norway, EEA).
Privacy governance and DPO assessment
Status: Preferium AS has not appointed a Data Protection Officer under GDPR Article 37. Last corrected: 31 August 2026.
Decision
Robert André Johansen is Preferium’s operational Privacy Contact. He is not represented as an independent Data Protection Officer. As founder and chief executive, he participates in decisions about processing purposes and essential means; presenting that management role as DPO would create a conflict with the independence requirements in GDPR Articles 37–39 and current Datatilsynet/EDPB guidance.
Public privacy requests use post@preferium.no. No dpo@preferium.com address may be described as a designated-DPO channel unless an independent qualified DPO is actually appointed and the designation is completed.
Required periodic assessment
Preferium must reassess whether appointment becomes mandatory when scale, data categories, regular/systematic monitoring, customer profiles or law changes. The assessment must document:
- whether core activities require large-scale regular and systematic monitoring
- whether large-scale special-category/criminal data is processed
- relevant EU/EEA/UK establishments, targeting and representative duties
- independence, expertise, resources, reporting line and absence of conflicts for any candidate
If appointment becomes mandatory or Preferium voluntarily appoints a DPO, Preferium must appoint an independent qualified person, publish accurate contact details, protect independence, notify the competent authority where required, and update every Norwegian/English privacy, DPA, trust and signup surface in the same legal-set version.
Current public wording
Preferium AS has not appointed a Data Protection Officer. Questions and requests concerning privacy may be sent to our Privacy Contact at post@preferium.no. The Privacy Contact is an operational contact and is not represented as an independent data protection officer under Article 37 of the GDPR.
This file records current governance; it is not itself a public designation.