What is a technical DPO?
A technical DPO is a Data Protection Officer (DPO) who combines knowledge of GDPR with hands-on knowledge of the technology a company uses to process personal data: web analytics, consent platforms, tag managers, CDPs and CRMs, marketing tools, cloud providers and processors. They perform the duties set out in Article 39 of GDPR (inform, advise, monitor, act as the point of contact with the supervisory authority) and, on top of that, they can read an implementation, understand which data actually leaves and where it goes, and translate compliance into concrete changes a technical or marketing team can carry out.
How is it different from a legal DPO or a traditional outsourced DPO?
Most outsourced DPOs in Spain come from law firms or compliance consultancies. They know the regulation, the clauses and the procedure before the AEPD (Spain's data protection authority), but they usually don't know what a tag manager does before consent, how Consent Mode works, which data a CDP shares with an advertising platform, or how to assess a technical sub-processor. The technical DPO covers both layers: the legal one, to comply; and the technical one, to verify that what the policy says is what the system does. In practice, it's the difference between a record of processing written from interviews and one checked against what actually flows.
What does a technical DPO do day to day?
The same as any DPO — record of processing activities, handling data subjects' rights requests, impact assessments, managing and notifying data breaches within 72 hours, liaising with the AEPD — plus what a traditional DPO tends to delegate or miss: reviewing the cookie and consent implementation, auditing which tags and SDKs send data and on what legal basis, technically assessing processors and sub-processors, reviewing international transfers at the level of the actual data flow, and answering large customers' security and privacy questionnaires with evidence.
Who needs a technical DPO?
Two profiles above all. First, SaaS companies and scale-ups: they process their customers' data at scale, run a complex technical stack, sign DPAs and receive security questionnaires from large buyers; a DPO who doesn't understand the product can't answer them convincingly. Second, SMEs where digital marketing or customer data carries real weight (e-commerce, professional services, private healthcare, tourism), where the real risk sits in the tools — analytics, advertising, CRM — rather than in the paper archive. In addition, any organisation required to appoint a DPO under Article 34 of Spain's data protection act (LOPDGDD) can opt for a technical profile if its data processing is essentially digital.
Can the technical DPO be the same person who implements security?
Within limits. GDPR (Article 38) requires the DPO to be independent, to receive no instructions on how to perform their duties, and to have no conflict of interest: they can't be the one who determines the purposes and means of processing, nor audit their own decisions. In practice, a technical DPO advises and supervises, points out what needs fixing and verifies that it gets fixed; the decisions and the implementation stay with the company or with another team, even one from the same consultancy, with the separation documented. That separation is a guarantee for the client, not an obstacle.
Does the DPO have to hold a certification?
No. GDPR requires 'professional qualities' and 'expert knowledge' of data protection law and practice, but not a specific certification. In Spain there is a voluntary DPO certification scheme promoted by the AEPD and accredited by ENAC (Spain's national accreditation body), and there are recognised international certifications (such as those from the IAPP). They're a useful signal of competence, not a legal requirement. What is mandatory is notifying the DPO's appointment to the AEPD.
How much does an outsourced technical DPO cost?
It depends on the volume and sensitivity of the processing, the size of the technical stack, and whether it includes support for customer questionnaires and DPAs. It's usually contracted as a monthly retainer with no lock-in. We always ask for a short description of the company and of what its customers are asking for, so we can give a fixed price, agreed in writing before we start.