Skip to content
News · GDPRhub EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Article 39 of the GDPR (General Data Protection Regulation).

Commentary. Article 39 of the GDPR, titled "Tasks of the Data Protection Officer," describes the key responsibilities of the Data Protection Officer (DPO).

Summary

This provision should therefore be read in conjunction with the other provisions relating to the role of the DPO, namely Article 37 GDPR (appointment of the DPO) and Article 38 GDPR (position of the DPO). Article 39 of the GDPR, titled "Tasks of the Data Protection Officer."

Full text

Commentary. Article 39 of the GDPR, titled "Tasks of the Data Protection Officer," describes the main responsibilities of the Data Protection Officer (DPO). This provision should therefore be read in conjunction with the other provisions relating to the role of the DPO, namely Article 37 GDPR (appointment of the DPO) and Article 38 GDPR (position of the DPO). Article 39 of the GDPR, titled "Tasks of the Data Protection Officer," describes the main responsibilities of the Data Protection Officer (DPO). This provision should therefore be read in conjunction with the other provisions relating to the role of the DPO, namely Article 37 GDPR (appointment of the DPO) and Article 38 GDPR (position of the DPO). Article 39(1) of the GDPR contains a list of tasks of the DPO, which should be considered a minimum set of tasks assigned to the DPO. "Bergt, Herbort --- This content has been automatically translated using machine translation. The original version is available in the source language. --- This content was automatically translated using machine translation. The original version is available in the source language.

How it connects

C-422/24 Case C-422/24 - AB Storstockholms Lokaltrafik. A new page has been created with the following information: "" CJEU Jan 7, 2026 Personal Data Fairness & Transparency Controllers
C-203/22 CK v Magistrat der Stadt Wien In Case C-203/22, the Court of Justice of the European Union interpreted Article 15(1)(h) of the GDPR in response to a preliminary ruling from the Verwaltungsgericht Wien… CJEU ·First Chamber Feb 27, 2025 Profiling Automated Decision-Making Marketing
C-252/21 Meta Platforms v noyb C-252/21 (Meta Platforms (noyb)) CJEU Jan 12, 2023 Supervisory Authorities IP Address Supervision
W211 2281442-1 The data subject and the controller both worked as nurses at the same hospital, on different wards Over ten years before the events in question, the data subject had been hospitalised as a patient on the ward where the controller worked as a nurse. The controller's daughter, a… BVwG - W211 2281442-1 ·Federal Administrative Court Jun 12, 2024 Professional Secrecy Personal Data Health Data
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… CJEU ·Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Supervision