Requisitos del Delegado de Protección de Datos por País (2026)

Verificado de forma independiente contra fuentes primarias (última auditoría: 10 de septiembre de 2026). · Revisado por el equipo editorial de RecordingLaw. · Ley verificada como vigente al 10 de septiembre de 2026. · 17 fuentes primarias citadas en esta página. Cómo verificamos nuestro contenido legal

Requisitos del Delegado de Protección de Datos por País (2026)

Actualizaciones

Corrected DPO rules across the comparison: Malaysia's residency rule is an alternative to being easily contactable and the Bahasa Melayu and English requirement was missing, with the regulator's 20,000 and 10,000 thresholds and 21-day registration added; China's PIPL Article 52 sets no number (the 10 million figure in State Council Decree 790 is a different officer) and its penalties are ceilings, not a whichever-is-higher test; India's SDF status comes only from a Central Government notification and the section 10 penalty is INR 150 crore, not 250; the UK's DPO maximum is GBP 8.7 million or 2% and the Data (Use and Access) Act 2025 dropped the senior responsible individual model; Canada already requires an accountable individual under PIPEDA and Bill C-27 died in January 2025; Indonesia's Constitutional Court ruling binds directly; Singapore's DPO filing dates from 2020 and its penalty cap includes a 10 percent turnover limb; South Africa's Information Officer duty is section 55 and carries no imprisonment; Thailand's failure-to-appoint fine is THB 1 million; Germany's BDSG catches small firms regardless of headcount; a misquoted WP29 passage was replaced with the verbatim text; Romania imposes no DPO certification; three enforcement actions were redated to 2022 and 2024 with their real facts; the French DPO figures were replaced with the CNIL's own; and Brazil's governing 2024 encarregado regulation was added. Corrected the Indonesia entry in the comparison table: failure to appoint a DPO under Article 53 of Law No. 27 of 2022 is an administrative matter under Article 57, capped at 2% of annual revenue, and the IDR 60 billion fine and six-year prison term previously shown belong to the criminal offences of unlawfully collecting, disclosing or falsifying personal data. The Japan and Australia rows no longer show a general privacy-law maximum against jurisdictions that impose no DPO duty. Added Brazil's requirement that the encarregado be able to communicate with data subjects and the ANPD in Portuguese, qualified Thailand's public-authority trigger to the bodies the Committee has announced, and updated the jurisdiction-scope note to list Canada, Japan, Australia and the EU member-state variations the article covers. Corrected the South Korea entry: failing to designate a Chief Privacy Officer carries an administrative fine under PIPA Article 75 (up to KRW 30 million once the 2026 amendment takes effect on 11 September 2026), while the 10 percent of turnover figure introduced by that amendment is a punitive surcharge for repeated or serious data leaks; restated the EDPB's 2023 coordinated enforcement findings to the report's own numbers, including that the vast majority of surveyed organisations had designated a DPO; and completed the Japanese and Indonesian penalty descriptions. Corrected how the page describes South Korea's 10% of turnover surcharge under the amended PIPA: it applies under Art. 64-2(2) to an intentional or grossly negligent repeat of any of the nine violation types in Art. 64-2(1) within three years, to any of those violations harming 10 million or more data subjects, or to a leak that follows non-compliance with a corrective order, rather than to data leaks generally, and it never applies to the CPO designation duty. Also repointed the South Korea statute reference to the consolidated-text permalink, added APPI Art. 179 to the Japan citation, and removed an unsourced 2025-2026 timeframe from the EDPB coordinated enforcement summary.

Verificado de forma independiente contra las fuentes primarias citadas; ley aplicable revisada en busca de cambios recientes

AI Act dates updated for the July 2026 Digital Omnibus (Regulation (EU) 2026/1744): high-risk obligations now apply 2 December 2027 for Annex III systems and 2 August 2028 for AI built into regulated products, while the 2 August 2026 transparency date is unchanged.

Revisado y aprobado por un editor

Fuentes y referencias

  1. RGPD, Reglamento (UE) 2016/679, arts. 37-39, 83(4)(eur-lex.europa.eu).gov
  2. Directrices del GT29 sobre Delegados de Protección de Datos (WP243rev.01)(ec.europa.eu).gov
  3. Informe CEF 2023 del CEPD sobre DPD, enero de 2024(edpb.europa.eu).gov
  4. Alemania, BDSG artículo 38 - Delegados de Protección de Datos(gesetze-im-internet.de).gov
  5. Guía de la ICO del Reino Unido sobre Delegados de Protección de Datos(ico.org.uk).gov
  6. LGPD de Brasil, artículo 41(planalto.gov.br).gov
  7. PIPL de China, artículo 52(npc.gov.cn).gov
  8. DPDPA 2023 de India, sección 10(meity.gov.in).gov
  9. Ley de Protección de Datos Personales (Enmienda) 2024 de Malasia(pdp.gov.my).gov
  10. PIPA de Corea del Sur, artículo 31(law.go.kr).gov
  11. Enmienda de 2026 a la PIPA de Corea del Sur(iapp.org)
  12. PDPA de Tailandia, secciones 41-42(mdes.go.th).gov
  13. POPIA de Sudáfrica, sección 56(gov.za).gov
  14. PDPL de los EAU, artículo 10(uaepdpl.com)
  15. Ley de Protección de Datos del DIFC N.º 5 de 2020(difc.ae).gov
  16. Guía de la Oficina de Protección de Datos del ADGM(adgm.com).gov
  17. PDPA de Singapur, sección 11(3)(pdpc.gov.sg).gov
  18. Multa de la UODO polaca de 132.000 euros por posición inadecuada del DPD (2025)(edpb.europa.eu).gov
  19. Multa de la UODO polaca de 5.814 euros por no designar a un DPD (2025)(edpb.europa.eu).gov
  20. Multa de la autoridad de Berlín de 525.000 euros por conflicto de interés del DPD(gdprhub.eu)
Compartir: