
GDPR DPO Requirements: Do You Need a Data Protection Officer? (2026)
GDPR Articles 37-39 explained: the 3 mandatory DPO triggers, tasks, independence rules, conflict-of-interest bar, and fines for non-compliance.
Browse our full library of legal guides, state law breakdowns, and practical legal information.
14764 articles
Browse by Category →
GDPR Articles 37-39 explained: the 3 mandatory DPO triggers, tasks, independence rules, conflict-of-interest bar, and fines for non-compliance.

GDPR Article 35 requires a DPIA before high-risk processing. Learn when it is mandatory, what it must contain, and when to consult your supervisory authority.

GDPR Article 28 requires a written DPA with every processor. Learn the 8 mandatory clauses, sub-processor rules, and consequences of non-compliance.

Connecticut's Public Act 26-64, signed May 27, 2026, requires signs at entrances where businesses use facial recognition for security. Here is what it does.

Colorado Gov. Polis signed SB26-051 on June 3, 2026, moving online age checks to the device operating system. It takes effect January 1, 2028.

MCDPA compliance (Mont. Code Ann. 30-14-2803): applicability at 25,000/15,000 thresholds, notice, opt-in, assessments. Cure period ended October 1, 2025.

Montana's MCDPA (Mont. Code Ann. 30-14-2808) gives access, correction, deletion, portability, and opt-out rights, with a 45-day response window.

The Montana Consumer Data Privacy Act (Mont. Code Ann. 30-14-2801) took effect Oct 1, 2024 and now carries the nation's lowest thresholds: 25,000/15,000.

Comply with Oregon's OCPA (ORS 646A.570 to 646A.589): applicability, privacy notice, sensitive-data opt-in, universal opt-out by Jan 1 2026, $7,500 penalties.

Oregon's OCPA (ORS 646A.574) gives access, deletion, opt-out, and a rare specific-third-party-list right. Controllers must respond within 45 days; appeals allowed.

The OCPA (ORS 646A.570 to 646A.589) took effect July 1, 2024, with no dollar threshold and a rare specific-third-party-list right. AG penalties up to $7,500.

A step-by-step UCPA compliance checklist: applicability ($25M+), privacy notice, sensitive-data opt-out, processor contracts, 45-day requests, $7,500 penalties.