What is, and which organizations have to appoint a DPO?
A Data Protection Officer (DPO) is a person in charge of verifying the compliance of personal data processing with the applicable law. The DPO communicates information on processing personal data such as its purposes, interconnections, types, categories of data subjects, length of retention and department(s) in charge of implementing processing. DPOs may be required by law or recommended.
There is no legal requirement in China for organizations to appoint a DPO. However, the 2020 Specification includes the recommendation to appoint a specific institution and specific personnel to be responsible for the internal management of personal data protection when:
- the main business involves processing personal information and there are 200 or more employees;
- the business has processed personal data on more than 1million individuals or is expecting to process data on more than 1million individuals within 12 months; or,
- the business has processed personal sensitive information for over 100,000 individuals.