Art. 37-39 GDPR · notification to the authority
DPO software for those handling more than one organisation
A DPO software must answer one question first: how many organisations does this person handle at the same time? An internal DPO works for a single controller. An external DPO often serves ten, twenty or more - and that is exactly where generic tools, designed for a single organisation, stop working.
Article 38 GDPR requires the same organisational independence in both cases: timely and adequate involvement in all data protection matters, sufficient resources, no instructions on how the tasks are performed. What changes is how that work must be documented: whoever serves a single controller can keep everything in one archive; whoever serves twenty must be able to show, for each of them separately, what was done and when.
Notifying the DPO's contact details to the authority
Article 37(7) GDPR requires the DPO's contact details to be communicated to the supervisory authority. In Italy this is done through a dedicated online procedure on the authority's services portal. The point most often missed is the update: if the designated person changes, you file a variation of the communication already sent, and the new content replaces the previous one. Publishing the name on the website is not required, provided the contact details given allow the DPO to be reached directly and easily.
What Article 39 GDPR asks of the DPO
- Inform and advise the controller, the processor and employees
- Monitor compliance with the GDPR and internal policies
- Advise on the impact assessment and monitor its performance
- Cooperate with the supervisory authority and act as its contact point
These are continuous tasks, not one-off formalities. Monitoring compliance and advising on the impact assessment produce documents that must remain retrievable years later, tied to the right client and with a verifiable date. That is why the per-client archive matters more than any single feature.
Spreadsheet or dedicated software
Separate for each client, unified for you
DPO Workspace is built for those handling more than one organisation: separate records per client, a shared deadline view, an archive with version history. 30-day trial, no credit card.
Try it freeFrequently asked questions
What is the difference between an internal and an external DPO?
The internal DPO is an employee of the controller; the external one works under a contract and often serves several clients in parallel. The duties under Articles 38 and 39 GDPR are identical for both: timely involvement in all data protection matters, adequate resources, no instructions on how to perform the tasks, no conflict of interest.
Must the DPO appointment be notified to the Italian supervisory authority?
Yes. Article 37(7) GDPR requires the controller to communicate the DPO's contact details to the supervisory authority. In Italy this is done through a dedicated online procedure on the authority's services portal, and it must be updated whenever the data or the designated person changes: in that case you file a variation, not a revocation followed by a new communication.
Does the DPO's name have to be published on the website?
Publishing the name is not required, provided the contact details given allow the DPO to be reached directly and easily: typically a dedicated email address. What must be communicated to the authority, by contrast, is the name together with the contact details.
Which tasks does Article 39 GDPR assign to the DPO?
Among others: informing and advising the controller, the processor and employees; monitoring compliance with the GDPR and with internal policies; advising on the data protection impact assessment and monitoring its performance; cooperating with the supervisory authority and acting as its contact point.
Does DPO software replace the professional's judgement?
No. Software organises the daily work - records, deadlines, documents, impact assessments - but replaces neither the DPO's judgement nor the controller's responsibility under Articles 24 and 32. Its purpose is to evidence what was done and when, which is the part almost always missing when an inspection arrives.
Is a spreadsheet enough for an external DPO with many clients?
For a single controller with few processing activities, often yes. Once more clients, periodic reviews and links between records, impact assessments and breaches come into play, the spreadsheet becomes the point where compliance is lost: versions diverge, deadlines slip, and no useful trace remains in the event of an inspection.
A tool built for several clients
Records, impact assessments, breaches and deadlines - per client, not all in one pile.
Start free