A data protection coordinator is an internal role in your organisation, not a GDPR concept. The word does not appear in the Regulation, and the Regulation gives a coordinator no tasks. A coordinator does what you assign: keeps the records, receives people’s requests, maintains the breach log, reminds colleagues of the rules. The organisation, not the coordinator, is responsible for meeting the GDPR obligations. A data protection officer (DPO) is something else. It is a function set by the Regulation, with independence, protection from dismissal for doing the job, and published contact details.
The difference is not just a name. If your documents call the coordinator a DPO, you risk this being treated as a voluntary DPO appointment, and then all the DPO requirements apply. Whether you need a DPO at all is covered in “Do we need a data protection officer?”. This article is about what remains when you do not appoint one, and how to keep the two roles apart.
Why the Regulation does not mention a coordinator
The GDPR places responsibility on the controller. Article 5(2) GDPR says the controller is responsible for compliance with the principles and must be able to demonstrate it. Article 24(1) GDPR requires the controller to implement appropriate technical and organisational measures. How you divide those measures internally is your decision. A coordinator is one such organisational decision.
So you write the coordinator’s duties yourself: in an order, a job description or an internal data protection procedure. The Regulation does not define them, and it does not limit them either.
What a coordinator usually does
A coordinator can be given the day-to-day work that the Regulation assigns to the organisation:
- keeps the records of processing activities and updates them when the business changes;
- receives people’s requests for access or erasure and tracks the response deadlines;
- keeps the breach log and gathers the facts when something happens;
- deals with service providers on data processing agreements;
- organises staff training and reminds colleagues of internal rules.
There is one place where the coordinator does appear in the Regulation, though not by name. A breach notification to the supervisory authority must give the name and contact details of the DPO or of another contact point (Article 33(3)(b) GDPR). In an organisation without a DPO, that contact point can be the coordinator. When such a notification is required is explained in “Personal data breach: when to notify VDAI and the people affected”.
A coordinator is an internal organiser, not a substitute for a DPO. If a DPO is mandatory for you, a coordinator does not meet that obligation. When we prepared internal documents for one company, we provided for an authorised employee, that is, a coordinator. But because of the scale and nature of the data it processed, we also recommended appointing a DPO.
A coordinator only helps if they are given time, access to information and a clear mandate. Otherwise, as we wrote in the DPO article, an appointed “one of our own” creates a false sense of security: the order exists, but nobody does the work.
How a DPO differs from a coordinator
Legal basis. You appoint a coordinator by your own order. The Regulation requires a DPO in the cases listed in Article 37 GDPR and where Union or Member State law requires it, and otherwise allows one to be appointed voluntarily (Article 37(4) GDPR).
Qualifications. A DPO is designated on the basis of professional qualities, in particular expert knowledge of data protection law and practice (Article 37(5) GDPR). The Regulation sets no requirements for a coordinator. You set them.
Instructions and dismissal. A DPO receives no instructions on how to carry out their tasks, cannot be dismissed or penalised for performing them, and reports directly to the highest management level (Article 38(3) GDPR). A coordinator is an ordinary employee. You give them instructions, and they report to whoever you decide.
Publicity. The DPO’s contact details must be published and communicated to the supervisory authority (Article 37(7) GDPR). They are also given in the information provided to people when data is collected (Article 13(1)(b) GDPR) and in the records of processing activities (Article 30(1)(a) GDPR). None of this applies to a coordinator.
Tasks. A DPO monitors compliance with the Regulation and with the organisation’s own policies, and cooperates with the supervisory authority (Article 39(1) GDPR). A coordinator mostly carries things out. They can check things too, but not independently, because they are checking decisions made by their own managers.
Liability. GDPR fines are imposed for breaches of the controller’s and processor’s obligations (Article 83(4)(a) GDPR), that is, on the organisation, not on an employee. The WP 243 rev.01 guidelines say this plainly about the DPO: data protection officers are not personally responsible for non-compliance. The same logic applies to a coordinator, with one exception. The Lithuanian Code of Administrative Offences (ANK) allows VDAI to fine natural persons as well, including heads of legal entities or other responsible persons: for breaches of personal data processing and privacy rules in electronic communications (Article 83(1) ANK) and for failing to comply with officials’ lawful demands (Article 505(1) ANK). Whether a coordinator is such a responsible person depends on the duties assigned to them.
What happens when you call the coordinator a DPO
This mistake can come from template documents. One company noticed that its internal policy template had a section on the data protection officer, although it had no DPO. Such a section must either be removed or rewritten to describe the coordinator. If it stays, the organisation announces in its own documents a DPO that does not exist.
There are two consequences. First, where a DPO is appointed voluntarily, the requirements of Articles 37–39 GDPR apply as if the appointment were mandatory (Article 29 Working Party guidelines WP 243 rev.01): timely involvement, resources, independence and no conflict of interests (Article 38(1)–(3) and (6) GDPR). If the person called “DPO” is the managing director or the head of HR or IT, there is usually a conflict of interests, because that person decides the purposes and means of processing. We covered this in more detail in the DPO article.
Second, the same guidelines say what to do if you do not appoint a DPO: an organisation may give data protection tasks to staff or outside consultants, but must make sure there is no confusion about their title, status and tasks. In internal communications, and in dealings with VDAI, with individuals and with the public, it should be made clear that this person is not a data protection officer. In a privacy policy, that means a general contact, for example a privacy email address, not a line saying “data protection officer”.
There is also the opposite risk. If a DPO is mandatory for you and you have only appointed a coordinator, the obligation is not met. Breaching the controller’s obligations under Articles 25–39 GDPR can lead to an administrative fine of up to 10 million euros or, for an undertaking, up to 2 % of total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(4)(a) GDPR). Both the appointment of a DPO and the DPO’s position fall within that range. For public authorities and bodies, Article 33(1) of the Law on Legal Protection of Personal Data (ADTAĮ) sets a lower cap: up to 0.5 % of the current year’s budget and other gross annual income received in the previous year, but no more than thirty thousand euros. This cap does not apply where the body carries out commercial economic activity (Article 33(3) ADTAĮ).
We told one client about one more rule as well, although the Regulation does not set it for a coordinator: the head of the company should be neither the DPO nor the coordinator.
How to set up the coordinator role properly
- In the order, use a title without the word “officer” and list the specific duties.
- State how much time per week or month they can spend on the role and what training they will receive.
- In the privacy policy and information notices, give a general contact, not “DPO”.
- In the records of processing activities, state in the DPO field that no DPO has been appointed, and keep a documented assessment of why.
- Decide who the coordinator turns to when a question goes beyond their knowledge: management, a lawyer or an external DPO.
When to call a lawyer
- You are not sure whether the Article 37 GDPR obligation applies to you, and you are choosing between a coordinator and a DPO.
- Your documents or website already say “data protection officer”, but in reality there is none.
- You are thinking of appointing as DPO someone who decides on the processing: the managing director, or the head of HR or IT.
- You have received an inquiry from VDAI or had a breach, and the coordinator’s knowledge is not enough to prepare the response.
Frequently asked questions
Is it mandatory to appoint a data protection coordinator?
No. The Regulation does not require a coordinator, and it requires a DPO only in the cases listed in Article 37 GDPR. But the duties a coordinator usually carries out remain with the organisation in any case. If they are not assigned to a specific person, there is a risk that nobody does them.
Is the coordinator liable for data protection infringements?
For GDPR infringements, no: GDPR fines are imposed for breaches of the controller’s and processor’s obligations (Article 83(4)(a) GDPR), that is, on the organisation. But under ANK, VDAI can also fine the head of a legal entity or another responsible person, for example for failing to comply with VDAI’s lawful demands (Article 505(1) ANK). Whether an employee is liable to the employer for failing to perform their duties is a separate employment law question.
Can an organisation have both a coordinator and a DPO?
Yes. A DPO may be a staff member or fulfil the tasks on the basis of a service contract (Article 37(6) GDPR). For example, an external DPO can monitor and advise, while an internal coordinator does the daily work and gathers information. If one person does both roles, that person is the DPO, and all the DPO requirements apply to them.
Do the coordinator’s contact details have to be communicated to VDAI?
No. The duty to publish contact details and communicate them to the supervisory authority applies only to a DPO (Article 37(7) GDPR). But if a breach occurs that must be notified, the notification names a contact point, and in an organisation without a DPO that can be the coordinator (Article 33(3)(b) GDPR).
How to start
Send us the order appointing the coordinator, your privacy policy and a short description of the data you process. We will tell you whether a coordinator is enough or you need a DPO, and what to fix in your documents so the two roles do not get mixed up.
You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).
Email: info@linden.lt
More about this service: external data protection officer service.