DPO Designation
Designation of the Data Protection Officer (DPO) under GDPR Art. 37–39 + Law 190/2018. Documents the appointment, tasks, reporting line, and ANSPDCP notification. v1 drafted 2026-05-15.
Counsel-review status
Developer-drafted v1. Counsel confirms (a) whether DPO designation is mandatory (Art. 37(1) criteria) or voluntary, (b) the correct ANSPDCP notification procedure, and (c) any Law 190/2018-specific tasks the DPO assumes. See counsel brief.
Is a DPO required?
Under GDPR Art. 37(1), DPO designation is mandatory when any one of the following applies:
| Trigger | Applies to RestartiX? |
|---|---|
| (a) Public authority / body | No |
| (b) Core activities require regular and systematic monitoring of data subjects on a large scale | Yes — telerehab adherence telemetry monitors session completion, exercise drop-off, video watch percentage, and self-reported clinical instruments for ~5,000 patients at launch, growing with each tenant clinic. This is regular, systematic, and at scale |
| (c) Core activities consist of processing on a large scale of special-category data (Art. 9) or criminal-conviction data | Yes — health data is the core data type of the platform. Even with launch-day scale at ~5,000 patients, the platform is built for and committed to scaling tenant clinics; "large scale" is the design point |
Conclusion: DPO designation is mandatory, not voluntary. Two independent triggers apply.
Romania-specific overlay — Law 190/2018 Art. 10 also designates a DPO mandatorily when processing CNP and the entity meets the general Art. 37(1) GDPR criteria. Counsel confirms applicability.
Designated DPO
Fill before publication
Name: {{DPO_NAME}}
Function: {{DPO_FUNCTION}} // e.g. "External DPO service" or "Senior counsel, internal"
Provider: {{DPO_PROVIDER}} // for external designation only
Postal address: {{DPO_POSTAL_ADDRESS}}
Email: dpo@restartix.pro
Phone: {{DPO_PHONE}}
Effective: {{DPO_START_DATE}} // typically the engagement-letter dateA dedicated mailbox dpo@restartix.pro is the public-facing contact and is provisioned in the launch operations checklist. Mail to this address routes to the designated DPO. The address is published on the public-facing privacy notice and the sub-processor transparency page.
Internal vs. external — decision
The platform has effectively two choices at launch scale:
Option 1 — External DPO service (recommended at launch)
A specialised firm acting as outsourced DPO. Typical price range for Romanian DP-specialist firms providing DPO-as-a-service: €250–€600/month for our scale, plus a one-off setup project (assessment, register review, training) usually €1,000–€2,500.
Why recommended:
- Independence is structurally easier — the DPO does not report into operations, engineering, or marketing.
- Romanian DP-law fluency is baseline at a specialised firm; internal staff would need ramp.
- Insurance-shaped engagement: the firm carries professional indemnity that an internal hire would not.
- Aligns with the F11.0.5 counsel engagement — the same firm (if their scope permits) can hold both engagements with a clear conflict-management wall, OR two separate firms.
Option 2 — Internal designation
A staff member (typically senior management or counsel) designated and given protected DPO status under Art. 38(3) — cannot be dismissed for performing the function; reports directly to top management.
Why not at launch:
- Internal headcount is not in place. The DPO function alone does not justify a hire pre-launch.
- Independence from operational influence is harder to demonstrate when the designated person also wears product or engineering hats.
Decision
External DPO service. Engagement letter signed concurrently with the F11.0.5 counsel engagement letter (target 2026-05-22). Re-evaluation at the 12-month mark or when headcount > 20, whichever comes first.
DPO tasks (Art. 39)
The designated DPO performs the following on behalf of {{LEGAL_ENTITY}}:
| # | Task | Frequency / trigger |
|---|---|---|
| 1 | Inform and advise the controller / processor and its employees of their obligations under GDPR + Law 190/2018 | Ongoing; on-demand |
| 2 | Monitor compliance with GDPR + Law 190/2018, including assignment of responsibilities, training, audits | Quarterly compliance review |
| 3 | Provide advice on DPIA / TIA, monitor performance | On-demand; sign-off on each DPIA in DPIA |
| 4 | Cooperate with ANSPDCP | As required |
| 5 | Act as ANSPDCP contact point | Continuous |
| 6 | Handle data-subject contact for DPO-routed inquiries (Art. 38(4)) | On-demand |
| 7 | Review the ROPA, sub-processor changes, and material consent flow changes | Per change |
| 8 | Sign off on the annual privacy notice template revision (1B.10) | Annual + on material change |
| 9 | Approve break-glass elevation policy changes (scope codes, default expiry, etc.) | Per change |
| 10 | Investigate and route data-subject access / erasure / rectification requests; escalate to clinic-as-controller for tenant-clinic patients | Per request |
Reporting line + independence guarantees (Art. 38)
The DPO:
- Reports directly to
{{TOP_MANAGEMENT_TITLE}}(e.g. "the Sole Administrator of RestartiX SRL"). No intermediate reporting layer. - Cannot be dismissed or penalised for performing DPO tasks.
- Does not receive instructions on the exercise of DPO tasks.
- Has no other position or task that would result in a conflict of interest (Art. 38(6)). For an external service, the firm's engagement letter contains a conflict-management clause.
Operational interfaces
The DPO interfaces with the platform via the following channels:
- Mailbox —
dpo@restartix.pro(incoming inquiries from data subjects, regulators, internal staff). - Quarterly review meeting — calendar-scheduled review of ROPA, sub-processor changes, consent purposes, audit-log anomalies, break-glass session log, open data-subject requests, incident log.
- On-demand consultation — DPIA sign-off, sub-processor onboarding sign-off, new high-risk feature review.
- Annual report — written report to
{{TOP_MANAGEMENT_TITLE}}summarising the year's compliance posture, incidents, ANSPDCP interactions, recommended changes. - Documented platform read access — the DPO has Console read-access to: audit log (organization_id IS NULL — platform-level), break-glass session log, consent_purpose_versions, organization_legal_documents (for template-version-currency review). Access does not include identifiable patient data outside break-glass elevation, in line with the processor boundary.
ANSPDCP notification
The designation must be notified to ANSPDCP (the Romanian DP authority) per their published procedure. The notification includes:
- DPO name (or firm name for an external designation)
- DPO contact details
- Description of the controller / processor
Notification reference: {{ANSPDCP_NOTIFICATION_REF}} (fill once submitted).
Change log
| Date | Change |
|---|---|
| 2026-05-15 | Initial draft. Decision: external DPO service. Engagement target 2026-05-22 |