Since its full implementation on May 25, 2018, the European Union's General Data Protection Regulation (GDPR) has become a benchmark law in the field of global data protection. For Chinese companies entering the European market, GDPR compliance is not only a legal obligation but also a cornerstone for winning the trust of European customers. The Data Protection Officer (DPO) system is one of the most distinctive institutional designs within the GDPR compliance framework, profoundly influencing corporate data governance structures and compliance operational models. This article will delve into the core provisions of the DPO system based on the original text of the GDPR and provide practical compliance recommendations for Chinese companies expanding overseas.
Article 37: Three Triggering Conditions for the Appointment of a DPO
GDPR Article 37(1) outlines three specific scenarios where the appointment of a DPO is mandatory. It is important to note that GDPR adopts a "conditional mandatory" approach—not all organizations subject to GDPR are required to appoint a DPO; the obligation arises only when one of the following specific conditions is met. However, even if these mandatory conditions are not satisfied, GDPR encourages organizations to voluntarily appoint a DPO as a best practice for data protection. The European Data Protection Board (EDPB), formerly known as the Article 29 Working Party, provides detailed explanations of these three conditions in its "Guidelines on Data Protection Officers" (WP243 rev.01).
- ›Condition 1: Data processing by public authorities or bodies. According to Article 37(1)(a), except when courts act in their judicial capacity, any public authority or body that processes data must appoint a DPO. For Chinese companies expanding overseas, this condition generally does not apply. However, if a company provides data processing services to EU public authorities, it should note that clients may require the service provider to also have a DPO.
- ›Condition 2: Core activities involve large-scale systematic monitoring. According to Article 37(1)(b), the core activities of a data controller or processor require regular and systematic large-scale monitoring of data subjects. Typical scenarios include user behavior tracking, targeted advertising, credit scoring, and location tracking services. The Article 29 Working Party has clarified that "core activities" refer to the essential operational activities necessary to achieve the objectives of the controller or processor, rather than auxiliary activities such as human resources or IT support.
- ›Condition 3: Core activities involve large-scale processing of special categories of data. According to Article 37(1)(c), core activities involve large-scale processing of special categories of data as defined in Article 9 (e.g., race, political opinions, religious beliefs, genetic data, biometric data, health data, sex life, or sexual orientation) or data related to criminal convictions and offenses as defined in Article 10. Overseas companies in fields such as health technology, biometric authentication, and HR technology should pay special attention to this condition.
Article 38: Status Protection of the DPO—Independence is the Core
Article 38 is the most easily overlooked yet crucial provision of the GDPR's DPO system for Chinese enterprises. It establishes the independent status of the DPO, ensuring at an institutional level that the DPO can effectively perform their duties without undue interference from corporate management. For Chinese companies accustomed to hierarchical management, understanding and implementing the independence safeguards for the DPO represents a significant challenge in achieving GDPR compliance.
- ›Resource Guarantee (Article 38(2)): Enterprises must provide the DPO with the resources necessary to perform their duties, including sufficient time, financial budget, training opportunities, and necessary team support. The DPO must also have access to relevant information regarding personal data processing operations. ---ITEM--- Independence Guarantee (Article 38(3)): Enterprises must not issue instructions to the DPO regarding the manner in which they perform their duties. This means the DPO enjoys professional autonomy in compliance matters, and management cannot direct the DPO to make specific compliance judgments or recommendations. ---ITEM--- Dismissal Protection (Article 38(3)): The DPO must not be dismissed or penalized for performing their duties. This protection is designed to ensure that the DPO can provide independent and objective compliance advice to the enterprise, even if such advice conflicts with management's business decisions. ---ITEM--- Direct Reporting Line (Article 38(3)): The DPO must report directly to the highest management level of the controller or processor. This means the DPO should bypass intermediate management and report data protection matters directly to the CEO, board of directors, or equivalent management. ---ITEM--- Confidentiality Obligation (Article 38(5)): The DPO must adhere to confidentiality obligations while performing their duties. At the same time, Article 38(6) allows the DPO to hold other positions concurrently, provided the enterprise ensures that such concurrent roles do not lead to conflicts of interest. The EDPB notes that the DPO should generally not simultaneously hold executive positions involving data processing decisions, such as CEO, COO, CFO, CMO, HR head, or IT head.
Article 39: The Five Statutory Duties of the Data Protection Officer
- ›Compliance Notification and Advice (Article 39(1)(a)): Informing the enterprise and its employees and providing advice on data protection compliance, covering the requirements of the GDPR and other EU or member state data protection laws. ---ITEM--- Compliance Monitoring (Article 39(1)(b)): Monitoring the enterprise's compliance with the GDPR and other data protection laws, including the allocation of responsibilities, awareness-raising, employee training, and related audit activities. ---ITEM--- DPIA Consultation (Article 39(1)(c)): Providing advice on Data Protection Impact Assessments (DPIAs) and supervising their implementation. According to Article 35, enterprises must conduct a DPIA when data processing is likely to result in a high risk to the rights and freedoms of natural persons. ---ITEM--- Cooperation with Supervisory Authorities (Article 39(1)(d)): Cooperating with data protection supervisory authorities and serving as the contact point between the enterprise and the authorities. ---ITEM--- Consultation and Liaison with Supervisory Authorities (Article 39(1)(e)): Consulting with supervisory authorities on any matters related to data processing, including the prior consultation procedures stipulated in Article 36.
Key Considerations for Chinese Companies Going Global When Selecting External DPO Services
GDPR Article 37(6) explicitly allows the DPO to be appointed from an external organization or individual based on a service contract, providing flexible compliance solutions for Chinese companies expanding overseas. When selecting external DPO services (DPO-as-a-Service), companies should focus on the following aspects: whether the service provider possesses GDPR professional qualifications and deep expertise in EU data protection laws; whether it can cover the local legal requirements of all EU member states involved in the company's operations; whether it can communicate with regulatory authorities and data subjects in the language of the member state where the company operates; whether it can provide ongoing compliance supervision rather than one-time consulting services; and whether the service contract clearly specifies response timelines, confidentiality obligations, and conflict resolution mechanisms.
Common Compliance Misconceptions
- ›Misconception 1: Believing that a DPO is unnecessary if there is no physical presence in the EU. In fact, the extraterritorial application rules under Article 3 of the GDPR mean that Chinese companies offering goods or services to EU residents or monitoring their behavior may also fall under the jurisdiction of the GDPR. ---ITEM--- Misconception 2: Equating a DPO with a legal manager or compliance manager. The GDPR's requirements for the independence of a DPO far exceed those for ordinary management positions, as a DPO does not accept instructions regarding their professional judgment from the company. ---ITEM--- Misconception 3: Assuming that appointing a DPO equates to compliance. The appointment of a DPO is only the starting point; companies must also ensure that the DPO has sufficient resources and authority and that their compliance recommendations are effectively integrated into business processes. ---ITEM--- Misconception 4: Believing that a DPO must be an EU citizen or reside in the EU. The GDPR does not impose requirements on the nationality or residence of a DPO; the key is that the DPO must be accessible to data subjects and regulatory authorities.
Conclusion
The DPO system under the GDPR reflects the EU's high standards for data protection. For Chinese companies expanding overseas, a deep understanding of the specific provisions of Articles 37-39, along with selecting an appropriate DPO configuration based on their business characteristics, is fundamental to compliant operations in the EU market. Whether opting for internal appointment or external services, the key lies in ensuring the DPO's independence, expertise, and accessibility. DataAigis possesses extensive experience in GDPR DPO services and is capable of providing professional DPO support that meets the stringent requirements of the GDPR for Chinese companies venturing abroad.



