A data protection officer must be designated where processing is carried out by public-sector bodies (Art. 225 of the Constitution); where the activities of the controller or processor require permanent and systematic control because of volume, nature, scope or purposes; where special categories are processed on a large scale; and in the cases the Authority defines. The Reglamento explains permanent control (continuous, recurrent or constant processing) and systematic control (pre-established, organised or methodical processing, part of a general collection plan or strategy), with binding answers from the Authority to consultations. Resolution SPDP-SPD-2025-0028-R makes designation mandatory, even for non-profits, for schools and any institution processing minors' data, universities, activities involving minors' special-category data, financial entities, insurers and insurance intermediaries, advertising, marketing and market research firms relying on preferences, interests, behaviour or profiling, health actors keeping clinical records (except individual practitioners), the pharmaceutical sector, private security and residential complex administrators controlling access, professional sports bodies, professional associations, telecommunications providers, providers of mass video surveillance, geolocation or information technology including artificial intelligence, and public-service concessionaires and public-private partnerships.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.