A DPO is required for public-authority processing and specified large-scale regular monitoring or sensitive-data processing. Groups may share an accessible DPO and contact details must be published and notified.
Interpretation and application must be checked against the official text and current version.
