By the Aplikant Editorial Team · Magazine

How to Find a Registered Data Protection Officer

A few months ago, Maya needed to ask a university to correct personal information held in her student record. She searched the university’s website for “data protection officer” and found three nearly identical pages, an old PDF, and a general contact form that promised a reply “as soon as possible.” After ten minutes, she still had no idea where to send her request.

Her problem is common. People often assume that the GDPR created one official European register of Data Protection Officers, complete with a search box and up-to-date contact details. It did not. Finding a DPO can be straightforward, but the route depends on the organisation, the country involved, and whether you are looking for a named person or simply the correct privacy contact.

The fastest place to start is the organisation’s privacy notice. Look for headings or phrases such as “Data Protection Officer,” “DPO,” or “privacy contact.” These details may appear in a general privacy policy, a cookie notice, a page explaining data-subject rights, or a separate data protection section. Large organisations sometimes bury the information in the footer or in a document written for customers, employees, or applicants rather than the public homepage.

You do not necessarily need the DPO’s personal name. Under the GDPR, an organisation must publish the DPO’s contact details and communicate them to the relevant supervisory authority when it is required to appoint one. In practice, that may mean an email address such as dpo@company.example, a dedicated form, a postal address, or the name of an office handling data protection matters. A functional address is often preferable because it remains useful when the person in the role changes.

Try the site’s own search tool first. Search for “DPO” and then for “data protection.” If that produces nothing, add the organisation’s name to a general search engine and include “privacy notice” or “data protection officer.” Check the date on any document you find. A contact address hidden in a five-year-old policy may still work, but an outdated document is a reason to look for a newer privacy notice rather than treat the first result as definitive.

There is a practical distinction here that saves time: a company may have a privacy team without having a legally designated DPO. Not every organisation must appoint one. The obligation generally applies in specific situations, including certain public-sector bodies, organisations whose core activities involve regular and systematic monitoring of people on a large scale, and organisations processing special categories of personal data on a large scale. A privacy manager, compliance officer, or customer-support representative may handle ordinary questions even where no formal DPO exists.

That does not give an organisation permission to ignore a clear request. If you cannot locate a DPO, send your question through the organisation’s privacy contact or customer-service channel and state that it concerns personal data protection. Keep a copy of the message and note the date. The recipient may forward it internally, which is far better than spending an afternoon hunting for a person whose name was never published.

Country-specific registers can make the search easier, but they are not available everywhere. Ireland is one of the clearer examples. The Irish Data Protection Commission operates a DPO register, and organisations that are required to appoint a DPO must notify the commission of the relevant contact details. If an Irish public body, company, or other organisation does not make its DPO easy to find, the register may provide a useful second route.

France has its own tool, known as DPO-Partage. It allows users to search for DPOs by organisation. The information comes from notifications received by the French data protection authority, CNIL. That makes it particularly useful if you know the French organisation’s name but cannot find the right privacy page, although the details should still be checked against the organisation’s current information.

The United Kingdom requires a little more caution. The Information Commissioner’s Office has a public register, but it primarily records organisations registered for processing personal data. It is not a separate public directory of individual DPOs. Searching that register for a person’s name is therefore unlikely to produce what you want. For a UK organisation, its privacy notice remains the sensible first stop.

The same applies in many other European countries. A national supervisory authority may publish guidance about DPOs, explain how organisations must notify appointments, or maintain information that is not designed for public name-by-name searches. The absence of a visible national register does not mean an organisation has no DPO. It may simply mean that the authority does not publish those details in a searchable public format.

EU institutions are a separate case. The European Data Protection Supervisor publishes a list of DPOs for individual EU institutions. If you are trying to contact the DPO of an EU body, that list is more useful than a general web search. The European Commission’s current DPO is Michelle Sutton, but even here, contacting the institution through its published data protection details is usually more reliable than relying on a person’s name alone.

Sometimes the phrase “registered DPO” creates the wrong expectation. In many cases, a DPO is not a licensed professional listed in a Europe-wide professional register. The organisation appoints the person, publishes the contact details, and, where required, informs the supervisory authority. The word “registered” may refer to that notification rather than to a public certificate or official badge.

You may also come across private directories offering lists of DPOs or data protection consultants. Treat them as convenience tools, not as proof that a person currently holds an official role. A consultant can advise several organisations, and a directory entry may remain online after an appointment ends. The organisation’s own privacy notice, together with information held by the relevant supervisory authority, carries more weight.

If your goal is to exercise a data protection right, do not wait for a perfect directory entry. Send the request to the organisation’s stated privacy address, DPO address, or data protection team. You can explain what you want in plain language: access to your data, correction of an error, deletion where applicable, an objection to processing, or information about how your data is used. You do not need to write like a lawyer, and you do not need to guess the DPO’s private email address.

If the organisation does not respond or you believe it has mishandled your request, the relevant national supervisory authority may be able to help. Which authority is appropriate can depend on the organisation’s main establishment, the public body involved, and the nature of the processing. That is why keeping the organisation’s name, country, privacy notice, and correspondence together is useful. A small folder on your computer can spare you the bureaucratic equivalent of searching for one missing sock.

For most people, the search is therefore a short sequence: check the privacy notice, search the organisation’s site for DPO-related terms, look for a country-specific register where one exists, and use the supervisory authority only when the organisation’s own information is missing or inadequate. The answer may be a named officer, but just as often it will be a dedicated mailbox or privacy office designed to reach that person without the public needing to know their name.

← Back to magazine