Jump to

Data Protection Officer (“DPO”)

Data Protection Officer

Part of our KVKK Compliance Guide — Open the guide →

What is a Data Protection Officer (DPO)?

A Data Protection Officer is the person a company designates to monitor its data protection compliance, advise the business and act as the contact point for regulators and data subjects. The role comes from Articles 37 to 39 of the GDPR, which also make it mandatory in three situations: for public authorities, for organisations whose core activities involve regular and systematic monitoring of individuals on a large scale, and for organisations processing special categories of data on a large scale. An ad-tech platform profiling users, a health app and a workforce monitoring tool are all typical mandatory cases.

The DPO can be an employee or an external provider, may serve a whole group of companies, and must be given independence: no instructions on how to do the job, no dismissal for doing it, and a direct line to the highest level of management. What the GDPR does not require is a lawyer or an engineer specifically; it asks for expert knowledge of data protection law and practice, judged against the sensitivity of the processing.

The Türkiye picture: there is no Turkish DPO

The point most teams miss is that Turkish law has no equivalent institution. The KVKK regime works with different building blocks: registration with VERBİS, a contact person notified through the registry, and for foreign controllers a data controller representative in Türkiye. The contact person is an administrative liaison, not an independent compliance officer, and appointing a GDPR-style DPO in Türkiye is good practice rather than a legal duty. The Turkish authority does run a certification scheme for data protection personnel, but holding the certificate does not create a statutory role.

Issue GDPR DPO KVKK equivalents
Legal basis GDPR Arts. 37-39, mandatory in defined cases No DPO institution; VERBİS registration and contact person
Independence Protected by statute Not regulated
Foreign companies EU representative where Art. 27 applies Data controller representative for foreign controllers
Certification Not required Voluntary personnel certification scheme

A Turkish startup selling into the EU therefore often ends up with three hats at once: a DPO if its processing meets the GDPR thresholds, an EU representative if it has no EU establishment, and a VERBİS registration with a contact person at home. The three roles answer to different regulators and cannot be collapsed into one appointment without checking each rulebook.

Does every company processing personal data need a DPO?

No. Outside the public sector, the duty turns on core activities involving large-scale systematic monitoring or large-scale special category data. A SaaS company with ordinary customer data usually sits outside the mandatory zone, though many appoint one voluntarily because enterprise customers ask for it in vendor reviews.

Can the DPO be outsourced or shared?

Yes. The GDPR allows an external DPO under a service contract and a single DPO for a corporate group, provided the person remains reachable from each establishment and genuinely available. What the role cannot survive is a conflict of interest, so the CTO or the head of marketing deciding the purposes of processing cannot double as DPO.

Working on this? Vircon Legal advises on KVKK & GDPR Compliance and KVKK compliance guide. Talk to us →

If this is on your desk

Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.

Founder AcademyBook an intro call