{"id":5727,"date":"2026-09-28T00:03:00","date_gmt":"2026-09-27T22:03:00","guid":{"rendered":"https:\/\/www.lablogic.pl\/?p=5727"},"modified":"2026-09-28T00:08:30","modified_gmt":"2026-09-27T22:08:30","slug":"dpo-resources","status":"publish","type":"post","link":"https:\/\/www.lablogic.pl\/en\/dpo-resources\/","title":{"rendered":"What resources must a data protection officer receive?"},"content":{"rendered":"\n<p class=\"ll-art-meta wp-block-paragraph\"><a href=\"https:\/\/www.lablogic.pl\/en\/michal-rutkowski\/\"><strong>Micha\u0142 Rutkowski<\/strong><\/a> \u2022 for the board and senior management \u2022 published September 28, 2026 \u2022 11 min read<\/p>\n\n\n\n<div class=\"wp-block-columns ll-art-shell is-layout-flex wp-container-core-columns-is-layout-7387b849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column ll-art-rail is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-group ll-art-railinner is-layout-constrained wp-block-group-is-layout-constrained\">\n\n\n\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-column ll-art-main is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-group ll-art-answer is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 id=\"krotka-odpowiedz\" class=\"wp-block-heading\">Short answer<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">DPO resources are determined by Article 38(2) GDPR, which requires the controller and the processor to support the DPO by providing resources necessary to carry out the tasks referred to in Article 39 and access to personal data and processing operations, and to maintain his or her expert knowledge. The WP 243 guidelines mention in this context items such as active support from management, sufficient time and budget and a team where needed. The scale depends on the size of the organisation and on the complexity and sensitivity of the processing. The EDPB recommends that the organisation be ready to show how it assessed that scale.<\/p>\n<\/div>\n\n\n\n<h2 id=\"dlaczego-pytanie\" class=\"wp-block-heading\">Why this question arises at all<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The provision is short and easy to read as a polite formality. Article 38(2) GDPR provides that the controller and the processor shall support the DPO in performing the tasks referred to in Article 39. That support consists in providing the resources necessary to carry out those tasks and access to personal data and processing operations, as well as the resources necessary to maintain his or her expert knowledge. The Regulation does not specify a number of hours or an amount and does not define the composition of a team.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sometimes an organisation designates a DPO and notifies the President of the Personal Data Protection Office (UODO), then treats the matter as closed. DPO resources are then reduced to a training budget or to the post itself. Yet the provision lists three different things, and only one of them concerns expert knowledge.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In 2023, 25 supervisory authorities from the European Economic Area undertook a coordinated review of the position of DPOs. In its report on that action, the European Data Protection Board (EDPB) described insufficient resources as one of the challenges. Many authorities pointed to a lack of human resources, and some also to the lack of deputy DPOs. In the six authorities examining the public sector, DPOs&#8217; resources were deemed sufficient in 66% of cases on average, and in the four examining the private sector in 91%.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The obligation does not depend on how the function is organised. The Personal Data Protection Office points out that where the DPO acts on the basis of a service contract, all GDPR requirements must be met. This covers the DPO&#8217;s proper and timely involvement in all issues relating to the protection of personal data. The WP 243 guidelines add that where a DPO is designated voluntarily, Articles 37 to 39 apply as if the designation had been mandatory. Resources therefore concern an in-house DPO, an external DPO and a DPO designated voluntarily.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The board should take this provision seriously for another reason too. UODO lists supporting the DPO among the GDPR mechanisms intended to ensure his or her independence. In my assessment, a DPO who lacks time and access gives opinions that depend on what he or she has been shown. An infringement of the obligations under Article 38 is also subject to an administrative fine under Article 83(4)(a) GDPR.<\/p>\n\n\n\n<h2 id=\"co-ustalic\" class=\"wp-block-heading\">What has to be established before a decision<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">What DPO resources cover<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Article 38(2) has three limbs, and each of them has to be implemented separately. The first limb is the most general, and the provision does not say what it covers. The WP 243 guidelines list the items which in particular are to be considered when implementing Article 38(2) as a whole. Most of them flesh out the first limb.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>active support of the DPO&#8217;s function by senior management, for example at board level;<\/li>\n\n\n\n<li>sufficient time for the DPO to fulfil his or her duties;<\/li>\n\n\n\n<li>adequate support in terms of financial resources, infrastructure (premises, facilities, equipment) and staff where appropriate;<\/li>\n\n\n\n<li>official communication of the designation of the DPO to all staff;<\/li>\n\n\n\n<li>access to other services such as HR, IT, legal and security;<\/li>\n\n\n\n<li>continuous training;<\/li>\n\n\n\n<li>a DPO team, which may prove necessary depending on the size and structure of the organisation.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The size of the organisation matters, but the scale of resources also depends on the nature of the processing. The guidelines state that in general the more complex and\/or sensitive the processing operations, the more resources must be given to the DPO. For example, processing patients&#8217; health data would be sensitive.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Time \u2014 how much is needed and how to record it<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Time is not visible in the budget, so it is easy to overlook. The guidelines indicate that sufficient time is particularly important where an internal DPO is appointed on a part-time basis or where an external DPO carries out data protection in addition to other duties. Conflicting priorities could then result in the DPO&#8217;s duties being neglected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The guidelines also give four good practices that can be translated directly into a document. The first is to establish a percentage of time for the DPO function where it is not performed on a full-time basis. The second is to determine the time needed to carry out the function. The third is to set the priority of the DPO&#8217;s duties. The fourth is for the DPO or the organisation to draw up a work plan.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">UODO points in the same direction. According to the Office, when designating a DPO the controller should agree with him or her on rules covering three matters. These are sufficient time, help in drawing up a work plan and support from a team of specialists where needed. The Office links the accountability principle in Article 5(2) GDPR with the requirement to analyse carefully whether the designated person will be able to fulfil all of his or her duties properly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The starting point for such an analysis is the set of tasks in Article 39(1). The DPO performs them with due regard to the risk associated with processing operations (Article 39(2)). He or she also takes into account the nature, scope, context and purposes of processing.<\/p>\n\n\n\n<div class=\"wp-block-group ll-art-zdanie is-layout-constrained wp-block-group-is-layout-constrained\">\n\n<p class=\"wp-block-paragraph\">Remember<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I recommend calculating time from the tasks, not from the position.<\/p>\n\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">It is worth counting how many data protection impact assessments there are in a year for which the DPO provides advice where requested and monitors their performance (Article 39(1)(c)). Breach assessments, new suppliers and issues raised by data subjects come on top of that (Article 38(4)). Finally, you add ongoing monitoring and advice. The sum of the time needed for these tasks determines the size of the function, which you compare with the time actually available. How to collect these figures is described in <a href=\"https:\/\/www.lablogic.pl\/en\/external-or-internal-dpo\/\">External or internal DPO? What to consider before deciding?<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the case of an external DPO, time also depends on how many entities he or she serves. Asked about the number of entities served by one DPO, UODO replies that the provisions give no direct answer. However, the Office stresses that one DPO may be designated for several entities only in justified cases and that the number of entities must remain within reasonable limits. Among other things, the assessment depends on the effective availability of the DPO, the ability to get to know the entity and the time the DPO has for the tasks. The EDPB report states that controllers and processors must carefully verify that the DPO has sufficient resources. In some cases, where an external DPO is used, this may require controllers and processors to verify how many clients that DPO has.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Budget, facilities and team<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The guidelines mention adequate support in terms of financial resources, infrastructure and staff \u2018where appropriate\u2019. If the DPO has a team, its internal structure and the tasks and responsibilities of each of its members should be clearly drawn up. When the function is exercised by an external DPO, the tasks may be carried out by the service provider&#8217;s team under the responsibility of a designated lead contact.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The GDPR does not explicitly require a team or a deputy to be appointed. UODO answered a question about a team from the DPO of a hospital employing more than 2,000 people. The Office indicated that the way the obligations under Article 38(2) are fulfilled depends on the size, structure and type of activity of the controller and on the nature of the processing, among other factors. It is the controller who is responsible for the DPO performing the tasks effectively. The EDPB report also states that the GDPR does not strictly require a deputy DPO and does not prohibit part-time DPOs. The requirement of sufficient resources nevertheless still applies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Polish Act provides a tool that the GDPR does not. The entity that designated the DPO may designate a person substituting for the DPO during his or her absence (Article 11a(1) of the Act on the Protection of Personal Data). In doing so, it takes into account the criteria in Article 37(5) and (6) GDPR. When the deputy performs the DPO&#8217;s duties during the DPO&#8217;s absence, the provisions on the DPO apply to him or her accordingly (Article 11a(2)). After designating a deputy, the entity notifies the President of UODO under Article 10 of the Act (that is, among other things, within 14 days of the date of designation) and makes the deputy&#8217;s details available in accordance with Article 11 of the Act (Article 11a(3)). The deputy ensures continuity during the DPO&#8217;s leave or illness, that is, in situations which the EDPB report describes explicitly. However, he or she acts only during the DPO&#8217;s absence. After the DPO has been dismissed, an entity subject to the obligation in Article 37(1) GDPR must designate a new one.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A separate matter is a budget that the DPO controls. The EDPB report indicates that the GDPR does not strictly require this, but such a budget makes it easier for the DPO to manage resources in a responsive and independent manner. In the report, one supervisory authority described the consequences of the DPO lacking control over his or her own budget. A DPO without such control may fear that criticising the organisation&#8217;s practices will end in budget cuts. Article 38(3) GDPR prohibits dismissing or penalising the DPO for performing his or her tasks, and the WP 243 guidelines indicate that penalties may be direct or indirect. In my assessment, an arbitrary reduction of funds after a critical opinion may be regarded as such an indirect penalty.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Board support and the DPO&#8217;s place in the organisation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Some DPO resources cost nothing and yet are sometimes overlooked. They include official communication of the DPO&#8217;s designation to staff and access to other services. That access is meant to enable the DPO to receive essential support, input and information from those services.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Board support also has a basis in other paragraphs of the same Article. The DPO directly reports to the highest management level of the controller or the processor (Article 38(3)). The organisation must also ensure that the DPO is involved, properly and in a timely manner, in all issues which relate to the protection of personal data (Article 38(1)). The WP 243 guidelines point out that all relevant information must be passed on to the DPO in a timely manner in order to allow him or her to provide adequate advice. Among other things, they also recommend that the DPO be invited to participate regularly in meetings of senior and middle management and be present where decisions with data protection implications are taken.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Access to personal data and processing operations<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The second limb of Article 38(2) concerns access to the data themselves and to processing operations. Without it, the DPO checks only documents and not actual processing in the systems. UODO describes this access broadly. Access to information about data processing, to the data themselves and to processing operations is necessary for the DPO to perform the tasks properly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Broad access should not be confused with unlimited access. Access to data covered by statutory secrecy may require a separate basis. In my assessment, the obligation of secrecy or confidentiality by which the DPO is bound in accordance with Union or Member State law (Article 38(5)) does not replace that basis. UODO addressed the separate basis using the example of a bank. The Office indicated that the DPO needs access to data covered by banking secrecy. If the DPO performs the function on the basis of a service contract, the provision of the Banking Law that allows this should apply to that contract. I recommend checking for a similar basis for other statutory secrets before designating the DPO, not at the first inspection.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Describe access with a list, not a general formula. The list indicates the systems, registers and places to which the DPO has access. It also indicates the people who provide the DPO with information on request. Such a record shows whether access covers processing operations and not just documentation.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Expert knowledge and maintaining it<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The third limb concerns maintaining knowledge. The DPO is to have the baseline knowledge already at the time of designation. He or she is designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39 (Article 37(5)). The necessary level of that knowledge should be determined in particular according to the data processing operations carried out and the protection required for the data (recital 97). Article 38(2) adds an obligation on the organisation&#8217;s side. The organisation has to provide the DPO with the resources necessary to maintain that knowledge.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The guidelines list continuous training and state that DPOs must be given the opportunity to stay up to date with developments within the field of data protection. The aim should be to constantly increase their level of expertise. The DPO should be encouraged to participate in training courses and other forms of professional development, such as fora and workshops.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The EDPB report also addresses training. According to the report, a strong majority of DPOs received 24 hours of training a year or less. The EDPB cautions that these statistics cannot be used to draw hard-and-fast conclusions as to the adequacy of DPOs&#8217; knowledge. The EDPB recommends that organisations document their knowledge and training needs and progress. It also recommends giving the DPO opportunities, time and resources to refresh his or her knowledge and learn about the latest developments. This also covers new EU digital- and AI-related legislation where relevant to the organisation&#8217;s activities. The obligation under Article 38(2) rests with the controller also where the DPO is external. Therefore, settle in the contract whether the fee covers the cost of maintaining that knowledge.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How to demonstrate that DPO resources are sufficient<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The provision does not require a separate document on resources. Without a record, however, it is difficult to demonstrate that the obligation has been fulfilled. After all, the controller implements appropriate measures to ensure and to be able to demonstrate that processing is performed in accordance with the Regulation (Article 24(1)). The EDPB report states that controllers and processors must at all times perform an analysis of what resources a DPO needs. The analysis is to be tailored to the specific case, and the EDPB recommends that controllers be ready to show how it was carried out.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The report also suggests a form in its part on the DPO&#8217;s independence. Organisations and DPOs could formalise the DPO&#8217;s duties and the conditions for performing them in a separate \u2018engagement letter\u2019. I recommend that such a document contain six elements.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>the tasks under Article 39(1) and their priorities, set with regard to risk;<\/li>\n\n\n\n<li>the amount of time or percentage of working time devoted to the function, together with the estimate on which it is based;<\/li>\n\n\n\n<li>the budget for tools, expert opinions and training, and who controls it;<\/li>\n\n\n\n<li>the composition of the team and the deputy, or a justification of why they are not needed;<\/li>\n\n\n\n<li>a list of the systems and registers to which the DPO has access and of the people who provide information;<\/li>\n\n\n\n<li>how and how often these arrangements are reviewed.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The review is as important as the content. DPO resources that are sufficient at the time of designation may cease to be sufficient after an acquisition, the implementation of a new system or a change in the scale of processing. I recommend that the DPO assess in the annual report to the board whether his or her resources match the tasks. It is then worth recording the board&#8217;s decision on resources.<\/p>\n\n\n\n<h2 id=\"najczestsze-bledy\" class=\"wp-block-heading\">Common mistakes<\/h2>\n\n\n\n<ul class=\"wp-block-list ll-art-errors\">\n<li><strong>Resources reduced to training.<\/strong> A training budget concerns only the third limb of Article 38(2). You cannot use it to demonstrate the DPO&#8217;s time and access.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list ll-art-errors\">\n<li><strong>Time set from the position, not from the tasks.<\/strong> Without an estimate of the number of impact assessments and breaches, the organisation does not know whether a half-time post is enough, and it will struggle to demonstrate it.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list ll-art-errors\">\n<li><strong>The contract with an external DPO treated as closing the matter.<\/strong> The number of hours in the contract does not say how many clients the same person serves or who pays for maintaining his or her knowledge.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list ll-art-errors\">\n<li><strong>Access on request instead of access by default.<\/strong> A DPO forced to ask for every piece of information learns about processing only after the decision has been made.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list ll-art-errors\">\n<li><strong>No plan for the DPO&#8217;s absence.<\/strong> A deputy is not mandatory. Without a deputy or another solution, the organisation loses advice during the DPO&#8217;s leave or illness, for example when assessing a breach.<\/li>\n<\/ul>\n\n\n\n<h2 id=\"wnioski\" class=\"wp-block-heading\">Conclusions and next steps<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">DPO resources are best treated as a board decision with a justification, not as the cost of the function. A recorded decision helps the organisation during an inspection and gives the DPO a point of reference when resources start to run short.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Count the DPO&#8217;s tasks from the last twelve months and compare them with the time the function actually gets.<\/li>\n\n\n\n<li>For an external DPO, ask about the number of entities served and record the answer.<\/li>\n\n\n\n<li>Record in a document adopted by the board the arrangements on tasks and time, budget and team, and access and training.<\/li>\n\n\n\n<li>Include the assessment of resources in the DPO&#8217;s annual report and review the arrangements after every significant change in processing.<\/li>\n<\/ol>\n\n\n\n<h2 id=\"materialy-powiazane\" class=\"wp-block-heading\">Related materials<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.lablogic.pl\/en\/contract-with-an-external-dpo\/\"><strong>What should a contract with an external data protection officer contain?<\/strong><\/a> \u2014 how to record time, access and costs in a service contract without infringing the DPO&#8217;s independence.<\/li>\n\n\n\n<li><a href=\"https:\/\/www.lablogic.pl\/en\/what-information-should-the-board-expect-from-the-dpo\/\"><strong>What information should the board expect from the DPO?<\/strong><\/a> \u2014 how to structure the DPO&#8217;s report so that it includes an assessment of the conditions for performing the function.<\/li>\n\n\n\n<li><a href=\"https:\/\/www.lablogic.pl\/en\/external-or-internal-dpo\/\"><strong>External or internal DPO? What to consider before deciding?<\/strong><\/a> \u2014 how to estimate the workload of the function before choosing a model.<\/li>\n\n\n\n<li><a href=\"https:\/\/www.lablogic.pl\/en\/who-cannot-act-as-a-data-protection-officer\/\"><strong>Who cannot act as a data protection officer?<\/strong><\/a> \u2014 conflict of interests when the DPO combines the function with other duties.<\/li>\n<\/ul>\n\n\n\n<h2 id=\"zrodla\" class=\"wp-block-heading\">Sources<\/h2>\n\n\n\n<ul class=\"wp-block-list ll-art-sources\">\n<li>Regulation (EU) 2016\/679 of the European Parliament and of the Council (GDPR), consolidated version \u2014 Article 5(2), Article 24(1), Article 37(1), (5) and (6), Article 38(1) to (5), Article 39 and Article 83(4)(a) \u2014 <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX%3A02016R0679-20160504\" target=\"_blank\" rel=\"noreferrer noopener\">eur-lex.europa.eu<\/a>.<\/li>\n\n\n\n<li>Regulation (EU) 2016\/679 of the European Parliament and of the Council (GDPR), published text \u2014 recital 97 \u2014 <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX%3A32016R0679\" target=\"_blank\" rel=\"noreferrer noopener\">eur-lex.europa.eu<\/a>.<\/li>\n\n\n\n<li>Act of 10 May 2018 on the Protection of Personal Data, consolidated text as at 18 August 2026 \u2014 Article 10, Article 11 and Article 11a (in Polish) \u2014 <a href=\"https:\/\/isap.sejm.gov.pl\/isap.nsf\/DocDetails.xsp?id=WDU20180001000\" target=\"_blank\" rel=\"noreferrer noopener\">isap.sejm.gov.pl<\/a>.<\/li>\n\n\n\n<li>Article 29 Data Protection Working Party, Guidelines on Data Protection Officers (\u2018DPOs\u2019) (WP 243 rev.01), endorsed by the European Data Protection Board \u2014 points 2.1, 3.1, 3.2 and 3.4 \u2014 English version <a href=\"https:\/\/ec.europa.eu\/newsroom\/article29\/items\/612048\" target=\"_blank\" rel=\"noreferrer noopener\">ec.europa.eu<\/a>, Polish version (in Polish) <a href=\"https:\/\/uodo.gov.pl\/data\/filemanager_pl\/15.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">uodo.gov.pl<\/a>.<\/li>\n\n\n\n<li>Personal Data Protection Office (UODO), What guarantees of independence are granted to the DPO under the GDPR? (in Polish) \u2014 <a href=\"https:\/\/uodo.gov.pl\/pl\/499\/4158\" target=\"_blank\" rel=\"noreferrer noopener\">uodo.gov.pl<\/a>.<\/li>\n\n\n\n<li>Personal Data Protection Office (UODO), Is the controller obliged under the GDPR to provide the DPO with a DPO team? (in Polish) \u2014 <a href=\"https:\/\/uodo.gov.pl\/pl\/499\/4178\" target=\"_blank\" rel=\"noreferrer noopener\">uodo.gov.pl<\/a>.<\/li>\n\n\n\n<li>Personal Data Protection Office (UODO), What is the maximum number of entities one DPO may serve? (in Polish) \u2014 <a href=\"https:\/\/uodo.gov.pl\/pl\/669\/4168\" target=\"_blank\" rel=\"noreferrer noopener\">uodo.gov.pl<\/a>.<\/li>\n\n\n\n<li>Personal Data Protection Office (UODO), Can a person from outside the organisation of the controller or processor act as DPO? (in Polish) \u2014 <a href=\"https:\/\/uodo.gov.pl\/pl\/670\/4172\" target=\"_blank\" rel=\"noreferrer noopener\">uodo.gov.pl<\/a>.<\/li>\n\n\n\n<li>Personal Data Protection Office (UODO), Should a data processing agreement be concluded with an external DPO performing tasks for a bank? (in Polish) \u2014 <a href=\"https:\/\/uodo.gov.pl\/pl\/670\/4174\" target=\"_blank\" rel=\"noreferrer noopener\">uodo.gov.pl<\/a>.<\/li>\n\n\n\n<li>European Data Protection Board, 2023 Coordinated Enforcement Action. Designation and Position of Data Protection Officers, report adopted on 16 January 2024 \u2014 executive summary and points 4.2, 4.3 and 4.5.2 \u2014 <a href=\"https:\/\/www.edpb.europa.eu\/system\/files\/documents\/2024-01\/edpb_report_20240116_cef_dpo_en.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">edpb.europa.eu<\/a>.<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-group ll-art-cta is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading ll-nietoc\">Let us check whether your DPO has the conditions to do the job<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If the DPO&#8217;s resources in your organisation have never been described, the first step is to estimate the tasks and compare them with the time the DPO actually has. <a href=\"https:\/\/www.lablogic.pl\/en\/external-dpo\/\">Support and performance of the DPO function<\/a> starts with such a diagnosis.<\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/www.lablogic.pl\/en\/external-dpo\/\">External DPO support<\/a><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Article 38(2) GDPR requires the DPO to be given resources for the tasks, access to personal data and processing operations and resources to maintain expert knowledge. The provision sets no hours or amounts, so the organisation assesses the scale for its own case and should be able to show that assessment.<\/p>\n","protected":false},"author":2,"featured_media":5730,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ll_stan_prawny":"","footnotes":""},"categories":[70],"tags":[],"class_list":["post-5727","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-dpo"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"DPO resources under Article 38(2) GDPR mean time, budget, a team, access to data and maintaining expert knowledge. See how to assess them and record them.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Micha\u0142 Rutkowski\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.lablogic.pl\/en\/dpo-resources\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"LabLogic - Micha\u0142 Rutkowski | DPO, GDPR, NIS2 and cybersecurity in practice\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"DPO resources \u2014 what the organisation has to provide\" \/>\n\t\t<meta property=\"og:description\" content=\"DPO resources under Article 38(2) GDPR mean time, budget, a team, access to data and maintaining expert knowledge. See how to assess them and record them.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.lablogic.pl\/en\/dpo-resources\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-dpo-resources-en.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-dpo-resources-en.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t\t<meta property=\"article:section\" content=\"DPO and GDPR\" \/>\n\t\t<meta property=\"article:tag\" content=\"dpo\" \/>\n\t\t<meta property=\"article:tag\" content=\"gdpr\" \/>\n\t\t<meta property=\"article:tag\" content=\"resources\" \/>\n\t\t<meta property=\"article:tag\" content=\"board\" \/>\n\t\t<meta property=\"article:tag\" content=\"independence\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-09-27T22:03:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-09-27T22:08:30+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"DPO resources \u2014 what the organisation has to provide\" \/>\n\t\t<meta name=\"twitter:description\" content=\"DPO resources under Article 38(2) GDPR mean time, budget, a team, access to data and maintaining expert knowledge. See how to assess them and record them.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-dpo-resources-en.jpg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/dpo-resources\\\/#article\",\"name\":\"DPO resources \\u2014 what the organisation has to provide\",\"headline\":\"What resources must a data protection officer receive?\",\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ll-og-dpo-resources-en.jpg\",\"width\":1200,\"height\":630,\"caption\":\"Time, budget and access for the DPO \\u2014 LabLogic article graphic by Micha\\u0142 Rutkowski\"},\"datePublished\":\"2026-09-28T00:03:00+02:00\",\"dateModified\":\"2026-09-28T00:08:30+02:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/dpo-resources\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/dpo-resources\\\/#webpage\"},\"articleSection\":\"DPO and GDPR\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/dpo-resources\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"position\":1,\"name\":\"LabLogic\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/dpo\\\/#listItem\",\"name\":\"DPO and GDPR\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/dpo\\\/#listItem\",\"position\":2,\"name\":\"DPO and GDPR\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/dpo\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/dpo-resources\\\/#listItem\",\"name\":\"What resources must a data protection officer receive?\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"name\":\"LabLogic\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/dpo-resources\\\/#listItem\",\"position\":3,\"name\":\"What resources must a data protection officer receive?\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/dpo\\\/#listItem\",\"name\":\"DPO and GDPR\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#organization\",\"name\":\"LabLogic\",\"description\":\"DPO, GDPR, NIS2 and cybersecurity in practice\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"email\":\"m.rutkowski@lablogic.pl\",\"telephone\":\"+48586231777\",\"foundingDate\":\"2004\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/cropped-lablogic-site-icon-512.png\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/dpo-resources\\\/#organizationLogo\",\"width\":512,\"height\":512},\"image\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/dpo-resources\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/michal-rutkowski-iod\"],\"additionalType\":\"https:\\\/\\\/schema.org\\\/ProfessionalService\",\"legalName\":\"LabLogic Consulting Micha\\u0142 Rutkowski\",\"address\":{\"@type\":\"PostalAddress\",\"streetAddress\":\"ul. Wolno\\u015bci 15\",\"postalCode\":\"81-327\",\"addressLocality\":\"Gdynia\",\"addressRegion\":\"pomorskie\",\"addressCountry\":\"PL\"},\"vatID\":\"PL9580972114\",\"taxID\":\"9580972114\",\"areaServed\":{\"@type\":\"Country\",\"name\":\"Poland\"},\"knowsAbout\":[\"GDPR\",\"Data Protection Officer (DPO)\",\"NIS2 Directive\",\"Polish National Cybersecurity System Act (KSC)\",\"Cybersecurity incident and data breach response\",\"EU AI Act\",\"ISO\\\/IEC 27001\",\"Information security management\"],\"founder\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\"},\"hasOfferCatalog\":{\"@type\":\"OfferCatalog\",\"name\":\"Services\",\"itemListElement\":[{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"External Data Protection Officer (DPO)\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/external-dpo\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"NIS2 and KSC implementation support\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/nis2-ksc\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"Incident and data breach response\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/incident-response\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"GDPR and NIS2 training\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/training\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"AI Act: roles, obligations and preparation\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/ai-act\\\/\"}}]}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/michal-rutkowski\\\/\",\"name\":\"Micha\\u0142 Rutkowski\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski-portret\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/michal-rutkowski-iod-dpo-rodo-nis2-lablogic.webp\",\"width\":864,\"height\":1080,\"caption\":\"Micha\\u0142 Rutkowski\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/michal-rutkowski-iod\"],\"jobTitle\":\"Data Protection Officer (DPO), NIS2\\\/KSC and cybersecurity advisor\",\"description\":\"Data protection and cybersecurity practitioner, owner of LabLogic. Since 2004 he has supported medium and large organisations: audits, implementations, incidents and training.\",\"email\":\"m.rutkowski@lablogic.pl\",\"knowsAbout\":[\"GDPR\",\"Data Protection Officer (DPO)\",\"NIS2 Directive\",\"Polish National Cybersecurity System Act (KSC)\",\"Cybersecurity incident and data breach response\",\"EU AI Act\",\"ISO\\\/IEC 27001\",\"Information security management\"],\"worksFor\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/dpo-resources\\\/#webpage\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/dpo-resources\\\/\",\"name\":\"DPO resources \\u2014 what the organisation has to provide\",\"description\":\"DPO resources under Article 38(2) GDPR mean time, budget, a team, access to data and maintaining expert knowledge. See how to assess them and record them.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/dpo-resources\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ll-og-dpo-resources-en.jpg\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/dpo-resources\\\/#mainImage\",\"width\":1200,\"height\":630,\"caption\":\"Time, budget and access for the DPO \\u2014 LabLogic article graphic by Micha\\u0142 Rutkowski\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/dpo-resources\\\/#mainImage\"},\"datePublished\":\"2026-09-28T00:03:00+02:00\",\"dateModified\":\"2026-09-28T00:08:30+02:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"name\":\"Micha\\u0142 Rutkowski - LabLogic\",\"alternateName\":\"LabLogic\",\"description\":\"DPO, GDPR, NIS2 and cybersecurity in practice\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"DPO resources \u2014 what the organisation has to provide","description":"DPO resources under Article 38(2) GDPR mean time, budget, a team, access to data and maintaining expert knowledge. See how to assess them and record them.","canonical_url":"https:\/\/www.lablogic.pl\/en\/dpo-resources\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.lablogic.pl\/en\/dpo-resources\/#article","name":"DPO resources \u2014 what the organisation has to provide","headline":"What resources must a data protection officer receive?","author":{"@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski"},"publisher":{"@id":"https:\/\/www.lablogic.pl\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-dpo-resources-en.jpg","width":1200,"height":630,"caption":"Time, budget and access for the DPO \u2014 LabLogic article graphic by Micha\u0142 Rutkowski"},"datePublished":"2026-09-28T00:03:00+02:00","dateModified":"2026-09-28T00:08:30+02:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.lablogic.pl\/en\/dpo-resources\/#webpage"},"isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/dpo-resources\/#webpage"},"articleSection":"DPO and GDPR"},{"@type":"BreadcrumbList","@id":"https:\/\/www.lablogic.pl\/en\/dpo-resources\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","position":1,"name":"LabLogic","item":"https:\/\/www.lablogic.pl\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/dpo\/#listItem","name":"DPO and GDPR"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/dpo\/#listItem","position":2,"name":"DPO and GDPR","item":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/dpo\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/dpo-resources\/#listItem","name":"What resources must a data protection officer receive?"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","name":"LabLogic"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/dpo-resources\/#listItem","position":3,"name":"What resources must a data protection officer receive?","previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/dpo\/#listItem","name":"DPO and GDPR"}}]},{"@type":"Organization","@id":"https:\/\/www.lablogic.pl\/#organization","name":"LabLogic","description":"DPO, GDPR, NIS2 and cybersecurity in practice","url":"https:\/\/www.lablogic.pl\/en\/","email":"m.rutkowski@lablogic.pl","telephone":"+48586231777","foundingDate":"2004","logo":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/cropped-lablogic-site-icon-512.png","@id":"https:\/\/www.lablogic.pl\/en\/dpo-resources\/#organizationLogo","width":512,"height":512},"image":{"@id":"https:\/\/www.lablogic.pl\/en\/dpo-resources\/#organizationLogo"},"sameAs":["https:\/\/www.linkedin.com\/in\/michal-rutkowski-iod"],"additionalType":"https:\/\/schema.org\/ProfessionalService","legalName":"LabLogic Consulting Micha\u0142 Rutkowski","address":{"@type":"PostalAddress","streetAddress":"ul. Wolno\u015bci 15","postalCode":"81-327","addressLocality":"Gdynia","addressRegion":"pomorskie","addressCountry":"PL"},"vatID":"PL9580972114","taxID":"9580972114","areaServed":{"@type":"Country","name":"Poland"},"knowsAbout":["GDPR","Data Protection Officer (DPO)","NIS2 Directive","Polish National Cybersecurity System Act (KSC)","Cybersecurity incident and data breach response","EU AI Act","ISO\/IEC 27001","Information security management"],"founder":{"@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski"},"hasOfferCatalog":{"@type":"OfferCatalog","name":"Services","itemListElement":[{"@type":"Offer","itemOffered":{"@type":"Service","name":"External Data Protection Officer (DPO)","url":"https:\/\/www.lablogic.pl\/en\/external-dpo\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"NIS2 and KSC implementation support","url":"https:\/\/www.lablogic.pl\/en\/nis2-ksc\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"Incident and data breach response","url":"https:\/\/www.lablogic.pl\/en\/incident-response\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"GDPR and NIS2 training","url":"https:\/\/www.lablogic.pl\/en\/training\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"AI Act: roles, obligations and preparation","url":"https:\/\/www.lablogic.pl\/en\/ai-act\/"}}]}},{"@type":"Person","@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski","url":"https:\/\/www.lablogic.pl\/michal-rutkowski\/","name":"Micha\u0142 Rutkowski","image":{"@type":"ImageObject","@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski-portret","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/michal-rutkowski-iod-dpo-rodo-nis2-lablogic.webp","width":864,"height":1080,"caption":"Micha\u0142 Rutkowski"},"sameAs":["https:\/\/www.linkedin.com\/in\/michal-rutkowski-iod"],"jobTitle":"Data Protection Officer (DPO), NIS2\/KSC and cybersecurity advisor","description":"Data protection and cybersecurity practitioner, owner of LabLogic. Since 2004 he has supported medium and large organisations: audits, implementations, incidents and training.","email":"m.rutkowski@lablogic.pl","knowsAbout":["GDPR","Data Protection Officer (DPO)","NIS2 Directive","Polish National Cybersecurity System Act (KSC)","Cybersecurity incident and data breach response","EU AI Act","ISO\/IEC 27001","Information security management"],"worksFor":{"@id":"https:\/\/www.lablogic.pl\/#organization"}},{"@type":"WebPage","@id":"https:\/\/www.lablogic.pl\/en\/dpo-resources\/#webpage","url":"https:\/\/www.lablogic.pl\/en\/dpo-resources\/","name":"DPO resources \u2014 what the organisation has to provide","description":"DPO resources under Article 38(2) GDPR mean time, budget, a team, access to data and maintaining expert knowledge. See how to assess them and record them.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/#website"},"breadcrumb":{"@id":"https:\/\/www.lablogic.pl\/en\/dpo-resources\/#breadcrumblist"},"author":{"@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski"},"creator":{"@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski"},"image":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-dpo-resources-en.jpg","@id":"https:\/\/www.lablogic.pl\/en\/dpo-resources\/#mainImage","width":1200,"height":630,"caption":"Time, budget and access for the DPO \u2014 LabLogic article graphic by Micha\u0142 Rutkowski"},"primaryImageOfPage":{"@id":"https:\/\/www.lablogic.pl\/en\/dpo-resources\/#mainImage"},"datePublished":"2026-09-28T00:03:00+02:00","dateModified":"2026-09-28T00:08:30+02:00"},{"@type":"WebSite","@id":"https:\/\/www.lablogic.pl\/en\/#website","url":"https:\/\/www.lablogic.pl\/en\/","name":"Micha\u0142 Rutkowski - LabLogic","alternateName":"LabLogic","description":"DPO, GDPR, NIS2 and cybersecurity in practice","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.lablogic.pl\/#organization"}}]},"og:locale":"en_US","og:site_name":"LabLogic - Micha\u0142 Rutkowski | DPO, GDPR, NIS2 and cybersecurity in practice","og:type":"article","og:title":"DPO resources \u2014 what the organisation has to provide","og:description":"DPO resources under Article 38(2) GDPR mean time, budget, a team, access to data and maintaining expert knowledge. See how to assess them and record them.","og:url":"https:\/\/www.lablogic.pl\/en\/dpo-resources\/","og:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-dpo-resources-en.jpg","og:image:secure_url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-dpo-resources-en.jpg","og:image:width":1200,"og:image:height":630,"article:section":"DPO and GDPR","article:tag":["dpo","gdpr","resources","board","independence"],"article:published_time":"2026-09-27T22:03:00+00:00","article:modified_time":"2026-09-27T22:08:30+00:00","twitter:card":"summary_large_image","twitter:title":"DPO resources \u2014 what the organisation has to provide","twitter:description":"DPO resources under Article 38(2) GDPR mean time, budget, a team, access to data and maintaining expert knowledge. See how to assess them and record them.","twitter:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-dpo-resources-en.jpg"},"aioseo_meta_data":{"post_id":"5727","title":"DPO resources \u2014 what the organisation has to provide","description":"DPO resources under Article 38(2) GDPR mean time, budget, a team, access to data and maintaining expert knowledge. See how to assess them and record them.","keywords":null,"keyphrases":{"focus":{"keyphrase":"DPO resources","score":0},"additional":[{"keyphrase":"data protection officer resources","score":69},{"keyphrase":"DPO time allocation","score":69},{"keyphrase":"DPO team","score":69},{"keyphrase":"deputy DPO","score":69}]},"primary_term":null,"canonical_url":null,"og_title":"DPO resources \u2014 what the organisation has to provide","og_description":"DPO resources under Article 38(2) GDPR mean time, budget, a team, access to data and maintaining expert knowledge. See how to assess them and record them.","og_object_type":"article","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"DPO and GDPR","og_article_tags":[{"label":"DPO","value":"DPO"},{"label":"GDPR","value":"GDPR"},{"label":"resources","value":"resources"},{"label":"board","value":"board"},{"label":"independence","value":"independence"}],"twitter_use_og":true,"twitter_card":"summary_large_image","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-09-27 21:57:55","updated":"2026-09-27 22:09:08","seo_analyzer_scan_date":null,"focus_keyword":"DPO resources","additional_keywords":[{"word":"data protection officer resources","score":69},{"word":"DPO time allocation","score":69},{"word":"DPO team","score":69},{"word":"deputy DPO","score":69}],"truseo_locale":null},"spectra_blocks_featured_image_url":{"thumbnail":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-dpo-resources-en-150x150.jpg","width":150,"height":150},"medium":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-dpo-resources-en-300x158.jpg","width":300,"height":158},"medium_large":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-dpo-resources-en-768x403.jpg","width":768,"height":403},"large":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-dpo-resources-en-1024x538.jpg","width":1024,"height":538},"full":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-dpo-resources-en.jpg","width":1200,"height":630}},"spectra_blocks_author_info":{"display_name":"Micha\u0142 Rutkowski","avatar_url":"https:\/\/secure.gravatar.com\/avatar\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g","author_link":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/","description":"Micha\u0142 Rutkowski \u2014 praktyk ochrony danych i cyberbezpiecze\u0144stwa, w\u0142a\u015bciciel LabLogic. Od 2004 roku pracuje na styku technologii, ochrony danych i zarz\u0105dzania ryzykiem. Pe\u0142ni funkcj\u0119 zewn\u0119trznego IOD\/DPO, prowadzi audyty RODO, kwalifikacj\u0119 i wdro\u017cenia NIS2 oraz ustawy o KSC, wspiera organizacje przy incydentach i naruszeniach ochrony danych, szkoli zarz\u0105dy, kadr\u0119 kierownicz\u0105 oraz zespo\u0142y IT i compliance. Pracuje ze \u015brednimi i du\u017cymi organizacjami, w tym z sektora finansowego i bran\u017c regulowanych."},"_links":{"self":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/5727","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/comments?post=5727"}],"version-history":[{"count":3,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/5727\/revisions"}],"predecessor-version":[{"id":5731,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/5727\/revisions\/5731"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/media\/5730"}],"wp:attachment":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/media?parent=5727"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/categories?post=5727"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/tags?post=5727"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}