•The GDPR introduces a duty for you to appoint a data protection officer (DPO) if you are a public authority, or if you carry out certain types of processing activities.
If you are a public authority or if you carry out specific type of activities you have a duty to appoin DPO.
[DPOs Role]
- assist you to monitor internal compliance
- inform and advise on your data protection obligations
- provide advice regarding Data Protection Impact Assessments (DPIAs)
- act as a contact point for data subjects and the supervisory authority.
[DPO responsiblitiy]
- independent, an expert in data protection, adequately resourced, and report to the highest management level.
- existing employee or externally appointed.
Furthermore Spain has their own requirement of appointing the DPO.
http://www.agpd.es/portalwebAGPD/temas/certificacion/common/pdf/SCHEME_AEPD_DPD.pdf