A Data Protection Officer (DPO) is the independent expert who oversees an organisation's GDPR compliance — advising on data practices, running DPIAs, and acting as the contact point for data subjects and regulators. Under GDPR Article 37, aDPO is mandatory only when an organisation is a public authority, conducts large-scale systematic monitoring, or processes special category or criminal data at scale.The DPO can be internal or outsourced but must report to top management; a CTO or marketing head can't double up without a conflict of interest. Non-appointment risks fines up to €10 million or 2% of global turnover. CCPA and CPRA don't require one.