Under GDPR, when is a Data Protection Officer (DPO) mandatory for a data controller?
-
A
Whenever a controller processes any personal data of EU residents
-
B
When core activities involve large-scale systematic monitoring of individuals or processing of special category data
-
C
Only for controllers with more than 250 employees
-
D
Whenever a controller operates in more than one EU member state