A hospital’s core activities consist of processing health data on a large scale as part of care delivery. Which DPO conclusion aligns with GDPR mandatory-appointment criteria?
Select an answer to reveal the explanation.
Short Explanation
A hospital living on health files at scale is exactly the kind of shop that needs a named privacy coach under the mandatory DPO rules. Waiting for a fine, or claiming only vendors need one, misses Article 37. Care delivery is the core activity, not a side hobby.
Full Explanation
Article 37(1)(c) requires designation of a DPO where the core activities of the controller or processor consist of processing on a large scale of special categories of data under Article 9. Hospital care processing of health data typically meets that trigger. Appointment is not deferred until enforcement. Controllers are included; the duty is not limited to processors.