Primary contact: dpo@preferium.com · Lead supervisory authority: Datatilsynet (Norway, EEA).

Data Protection Officer (DPO) Designation

Status: PLACEHOLDER — decision pending Robert (target: R171). GDPR Article: Art. 37 (designation), Art. 38 (position), Art. 39 (tasks).


Context

Preferium AS processes personal data on behalf of customers (controller-processor relationship per DPA.md). Whether designating a DPO is mandatory or voluntary depends on the criteria below.

When designation is MANDATORY (GDPR Art. 37(1))

A DPO must be designated when:

Conclusion at v1 scale (Q2 2026): designation is NOT mandatory but is RECOMMENDED for procurement-readiness.


Decision matrix

OptionWhen to chooseCostDPO contact
A — Robert as DPOv1 scale, no specific customer mandate, simple processor relationships€0 (overhead only)dpo@preferium.com → Robert
B — Outsourced DPO-as-a-service (Privacy Tools, OneTrust DPO Pro, DataGuard)One or more designated-DPO customer requirements OR ~50+ EU enterprise customers€500-2000/monthdpo@preferium.com → external party
C — Hired DPO$5M+ ARR, regulated-industry customer, or multi-country supervisory authority exposure€70-120k/yr + benefitsInternal hire

GDPR Art. 38(6) allows the DPO to have other tasks “provided that such tasks and duties do not result in a conflict of interests”. Robert as CEO + DPO is acceptable at v1 scale because Preferium does not make automated decisions about data subjects based on the data we process — we serve SEO infrastructure, not individual-affecting profiling.


Designation (FILL IN WHEN DECIDED)

The Data Protection Officer for Preferium AS is __________________________,
reachable at dpo@preferium.com.

Designation effective: __________________________

Designation method: [ ] Option A (Robert)
                    [ ] Option B (outsourced — vendor: _______________________)
                    [ ] Option C (hired)

Per GDPR Article 39 the DPO is responsible for:
  - monitoring compliance with GDPR + applicable national law
  - training of staff involved in processing
  - cooperating with supervisory authorities
  - serving as point of contact for supervisory authorities
  - advising on Data Protection Impact Assessments (DPIAs)
  - operating with appropriate independence (Art. 38(3))

Supervisory authority contact has been notified per Art. 37(7):
  - Datatilsynet (Norway): postkasse@datatilsynet.no

Once designated

  1. Update DPA.md template to reference the DPO contact
  2. Publish DPO contact at https://preferium.com/legal/dpo (Phase 14 deploy)
  3. Update privacy notice (PRIVACY.md) §“Data Protection Officer” section
  4. Add to sub-processor list page footer
  5. Notify Datatilsynet under Art. 37(7) within 30 days

Cross-references