The preliminary draft bill transposing the Whistleblowing Directive establishes the requirement that all companies with more than 50 employees appoint a Data Protection Officer
On March 4, the Preliminary Draft Bill regulating the protection of individuals who report regulatory violations and combat corruption was approved, transposing Directive 2019/1937—known as the Whistleblowing Directive—into Spanish law. One of the transposed obligations is to implement an internal reporting system, or whistleblowing channel, which will be mandatory for all companies with more than 50 employees. This obligation has raised a significant issue that goes beyond the scope of criminal compliance and affects compliance with data protection regulations.
The Role of the Data Protection Officer
Article 34 of the Draft Bill establishes that all companies required to have a whistleblower channel will also be required to appoint a Data Protection Officer (or DPO, for short). Thus,all companies with more than 50 employees will be required to appoint a DPO, unless they were already required to do so under applicable data protection regulations. The DPO will, of course, perform their duties with respect to all data processing carried out by the organization, not just the processing of data arising from a whistleblower channel.
The Data Protection Officer is a professional role established under both European (GDPR) and national (LOPD GDD) legislation. This role may be filled by a natural person or a legal entity, either internal or external to the company, but must always be independent.
Its functions include, among others:
- provide information, offer guidance, and monitor compliance with data protection regulations.
- serve as the point of contact for the supervisory authority—in the case of Spain, the Spanish Data Protection Agency.
New Requirements for Medium-Sized Businesses
If this new draft bill is approved, the number of companies that would be required to appoint a Data Protection Officer (DPO) would be immense, causing a surge in demand for these types of services from companies, which are not always prepared to handle these functions internally due to the high level of specialized knowledge required of a DPO.
In the coming months, it will be crucial to pay close attention to the development of this draft bill in order to identify potential changes and—if it is approved as currently drafted—to ensure that all medium-sized companies are properly prepared to assume these new obligations and have a Data Protection Officer in place.
Author: Eduardo Oliveros
