Laws · GDPR ·art-37-par-1 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
The controller and the processor shall designate a data protection officer in any case where:
How it connects
Cited by
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR
- Comune di Luino: Non-compliance with general data processing principles
- Ministero dello Sviluppo Economico: Non-compliance with general data processing principles
- Villabate municipality: Non-compliance with general data processing principles
- Setúbal municipality: Non-compliance with general data processing principles
All 25
- Municipality of Modica: Non-compliance with general data processing principles
- Libero Consorzio comunale di Enna: Insufficient involvement of data protection officer
- POLAND DPA: Insufficient involvement of data protection officer
- Municipality of Palma di Montechiaro: Lack of appointment of data protection officer
- Comune di Conversano: Lack of appointment of data protection officer
- Interprovincial Order of Medical Radiology Technicians and Technical Health Professions in Rehabilitation and Prevention of AQ - CH - PE - TE: Insufficient legal basis for data processing
- 'Statista Aldo Moro' Higher Education Institute in Fara Sabina: Insufficient legal basis for data processing
- Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation
- Opinion 2/2026 on the Proposal for a Directive amending Directives (EU) 2016/2341 and 2016/97 as regards the strengthening of the framework for occupational retirement provision
- Hospital: Non-compliance with general data processing principles
- EDPB-EDPS Joint opinion 2/2026 on the Proposal for a Regulation as regards the simplification of the digital legislative framework (
- APD/GBA (Belgium) - 11/2022
- Opinion 15/2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Protection Seal to be used as tool for transfers pursuant to Articles 42 and 46 GDPR
- Guidelines 01/2023 on Article 37 Law Enforcement Directive
- Report of the work undertaken by the ChatGPT Taskforce
- X-FAB Dresden GmbH & Co. KG v FC
- Leistritz AG v LH
- Republic of Malta v European Commission
- NAIH (Hungary) - NAIH-450-7-2026
- Municipality of Mirabella Imbaccari: Insufficient legal basis for data processing
Related across sources
14/2021 Cypriot court backs DPA fines of €40,000 each on football clubs and €25,000 on processor On 26 July 2021, a journalist informed the Cypriot DPA of a security vulnerability on an online platform. This online platform hosted ticket purchase sites of two Cypriot football… Administrative Court of Cyprus May 12, 2026 Controllers Processors Supervisory Authorities
Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Jul 7, 2021 Controllers Processors IP Address
Guidelines 8/2022 identifying a controller or processor's lead supervisory authority Guidelines for identifying a controller or processor’s lead supervisory authority Guidelines ·EDPB Apr 17, 2023 Supervision Controllers Supervisory Authorities
Opinion 19/2026 Rubrik Group — processor BCRs ·Opinion ·EDPB Jun 8, 2026 International Transfer Processors Codes of Conduct
Opinion 17/2026 Infor Group — processor BCRs ·Opinion ·EDPB May 11, 2026 International Transfer Processors Codes of Conduct
Opinion 5/2026 Arcadis Group — processor BCRs ·Opinion ·EDPB Feb 10, 2026 International Transfer Processors Codes of Conduct