Globalaw - Home
ContactMember Login
Our social network
The Role of a Data Protection Officer: Does Your Organization Need One?
Insights

The Role of a Data Protection Officer: Does Your Organization Need One?

By Globalaw APAC Data Privacy & Protection Taskforce, 15 Oct 2025

A Data Protection Officer (DPO) ensures that an organisation’s data collection, processing and use complies with applicable data protection rules and regulations. DPOs are generally data protection experts with specialized knowledge and experience. They provide advice and guidance on best practices, compliance, policies and procedures, education and training, risk management and data breach response protocols.

The rapid pace of data creation, accelerated by content generated by AI, social media, streaming, digital transactions and smart technology, has increased government intervention in data governance and protection.

As such, certain jurisdictions require that companies appoint a DPO, while others strongly recommend it. This article explores the DPO requirements, qualifications and responsibilities in countries within Globalaw’s Asia Pacific region, including Hong Kong, India, Japan, South Korea, and Taiwan.

DPO Requirements by Jurisdiction

Appointing a DPO is a recommended practice rather than a requirement in both Hong Kong and Japan. By contrast, South Korea requires most companies to appoint a DPO, except those with fewer than 10 permanent employees.

In India, DPOs are required for significant data fiduciaries. While Taiwan does not require DPOs, certain industries mandate the designation of data protection personnel.

  • Hong Kong: Recommended
  • India: Required for significant data fiduciaries (to be notified by the government)
  • Japan: Recommended
  • South Korea: Required for companies with more than 0 permanent employees
  • Taiwan: Required by certain industries to designate responsible personnel

Qualifications of a DPO

For Hong Kong, Japan, Taiwan, and South Korea, there are no mandatory certifications, licenses, or qualifications required before someone can be appointed as a company’s DPO.

While there are also no legal or technical qualification mandates for India, a DPO shall be (a) based in India, and (b) be an individual responsible to the Board of Directors or similar governing body of the significant data fiduciary.

Responsibilities of a DPO

The responsibilities of a DPO vary by jurisdiction and, in some cases, by industry and are authorized by the governing authority of that jurisdiction.

Hong Kong

Governing Body: The Office of the Privacy Commissioner for Personal Data (PCPD).

The PCPD provides the following recommendations:

  • Establish and implement the Privacy Management Programme (PMP), such as maintaining a record of the organisation's data inventory, conducting periodic risk assessments, and providing training and education.
  • Review the effectiveness of the PMP, including preparing an oversight and review plan.
  • Report regularly to top management on the organization's compliance issues, problems encountered, and complaints received related to personnel.

India

Governing Body: Government of India, Ministry of Electronics and Information Technology (MeitY)

Under the Digital Personal Data Protection Act (DPDP), the DPO shall represent the significant data fiduciary under the provisions of the legislation and be the point of contact for the grievance redressal mechanism.

Japan

Governing Body: Personal Information Protection Commission

A DPO is not subject to any legally mandated responsibilities.

South Korea

Governing Body: The Personal Information Protection Commission

Under the Personal Information Protection Act (PIPA), the DPO handles personal information for business purposes to comply with the regulations. These responsibilities include:

  • Overseeing the handling and protection of personal data,
  • Establishing internal policies and safeguards,
  • Responding to data subject requests (e.g., correction, deletion),
  • Managing incident response for data breaches,
  • Serving as the liaison with the Personal Information Protection Commission (PIPC),
  • Conducting regular audits and training

Taiwan

Governing Body: The Taiwanese government is in the process of forming the Personal Data Protection Commission.

Only specific industries are required to designate responsible personnel, and sector-specific regulations govern their responsibilities.

--

This article is part of a series by our Globalaw APAC Data Privacy & Protection Taskforce members.

Globalaw’s APAC Data Privacy & Protection Taskforce comprises 15 law firms in the Asia-Pacific region with specialized expertise in advising international companies on how to implement and manage a multijurisdictional data protection program.

Taskforce member firms combine a strategic, business-minded approach with cross-border collaboration to help clients build and maintain sophisticated and resilient data practices, effectively mitigate and respond to incidents, and provide sophisticated representation to resolve disputes or regulatory investigations.

Explore the Globalaw APAC Data Privacy & Protection Taskforce brochure for more information and regional contacts.

Disclaimer: The information provided in this article is for general informational purposes only and does not constitute legal advice. Information, including laws and statutes, cited are subject to change and is accurate as of 30 June 2025, but readers should verify such current status. We and our member firms shall not be held liable for any loss and/or damage incurred by any person acting as a result of the information contained in this article. Reliance on this content is at the reader’s own risk, and no attorney-client relationship is formed by reading or acting upon this article. Always seek professional legal counsel to ensure compliance with applicable laws and regulations.

Latest News

news
13 Aug 2026

Indonesian Member Firm Enters Strategic Agreement with Ministry of Youth & Sports

Globalaw is pleased to announce that its Indonesian member firm, Bagus Enrico & Partners, has entered into a Strategic Partnership Agreement with the Ministry of Youth and Sports of the Republic of Indonesia (Kemenpora RI).

"This is a significant milestone not only for Bagus Enrico & Partners but also for the broader development of sports law in Indonesia and the work of Globalaw's Sports Law Taskforce," said Jonathan Cheong, Co-Chairman of the Globalaw Sports Law Taskforce. "It creates a meaningful bridge between Indonesia's sporting institutions and the international legal community and provides an opportunity to further connect Indonesian sport with Globalaw's international network,"

Through Globalaw's international network of sports law practitioners, this partnership can help drive cross-border knowledge exchange, international collaboration, and access to specialised legal expertise, while bringing Indonesia's sporting opportunities and perspectives onto the global stage.

About the Globalaw Sports Law Taskforce

Globalaw’s Sports Law Taskforce is a dedicated advisory group offering specialized legal counsel and representation for athletes and stakeholders across all areas of sports law. From negotiating and drafting athlete contracts, sponsorship agreements, and marketing deals to providing expert counsel on intellectual property rights, endorsements, tax advice and dispute resolution, our cross-border advisory group is equipped to handle all legal aspects of the sports industry, ensuring that our clients receive top-tier support and protection in their careers and business ventures. Learn more about Globalaw's sports law capabilties.

Insights
07 Aug 2026

Tax Disputes in Italy: A Guide

This summary outlines how tax disputes arise and proceed in Italy, covering the self-assessment system and taxpayer registration, how the tax authority reviews and challenges returns, the treatment of tax fraud, the conduct of audits, options for resolving disputes before litigation, the appeal process through the tax courts, and the penalties and areas of dispute taxpayers are most likely to encounter.

Tax Registration

In Italy, every individual and legal entity receives a tax identification number. Legal entities and partnerships are always assigned a VAT number, while individuals receive one only if they engage in business or self-employment activities, not for salaried employment. Once a taxpayer holds a VAT number, the tax authority is fully aware of that person's existence and economic activity.

Self-Assessment and Amending Returns

The Italian system operates on self-assessment: taxpayers prepare and file their own annual returns, and the tax authority has five years from the following year to review the return and challenge any errors or omissions. A late challenge is null and void, though the taxpayer must still formally seek its annulment through an administrative appeal or legal action.

Returns may be amended to report higher income at any time before an assessment notice is served, substantially reducing potential penalties, or amended to report lower income, subject to specific time limits.

Assessment Notices and Time Limits

The tax authority must issue a reasoned assessment notice that sets out the factual and legal grounds for the challenge, which provision was violated and why, and separately justify any related penalties. In principle, notices must be issued within five years of the filing year (a 2025 return can be assessed until December 31, 2031).

Notices issued later can still be challenged: the taxpayer files a self-protection request for annulment and, failing that, a formal appeal within 60 days, citing the expiration of the deadline.

Tax Fraud

Tax fraud is a criminal, not an administrative, matter, defined by two articles of criminal tax law that cover the use of false invoices (documents recording costs for services never rendered) and other deceptive practices intended to mislead the authorities. It is punished severely, and if charges are filed, the deadlines for serving assessment notices are doubled. It is particularly relevant internationally—for instance, regarding management fees, where Italian companies can struggle to obtain precise supporting documentation for intercompany services. Fraud investigations are conducted by the local public prosecutor, assisted by the Guardia di Finanza under the Code of Criminal Procedure, and may involve restrictions on personal liberty and the seizure of assets. Tax and criminal proceedings run in parallel and both require careful handling

Audit Conduct and Standards

There is no formal code of conduct for audits beyond a general duty of fair cooperation. The Guardia di Finanza has issued a manual outlining audit procedures, and taxpayer rights are set out in the Taxpayer's Charter. Audit reports must invite the taxpayer to provide documentation, note the right to be assisted by a tax lawyer or Chartered Accountant, and state that withheld documentation cannot later be used in court. Audits now typically focus on three main risk areas for multinationals: transfer pricing, interest/dividend/royalty payments and beneficial ownership, and intercompany services.

During audits, inspectors may request any relevant documents, including those from foreign subsidiaries via international information exchange; a refusal generally bars later use of those documents in court. Requests to third parties to cross-check data (e.g., verifying that invoices were recorded by the issuer) are also routinely permitted.

Pre-Litigation Settlement Options

Before litigation, taxpayers have three main options: accept the audit report and pay in full to secure a significant penalty reduction; take voluntary corrective action on specific issues; or negotiate a settlement with the tax authority ("accertamento con adesione"). If none of these options succeed, the only remaining route is the courts, where judicial settlement may still be attempted. The audit relationship is governed by the Taxpayer's Bill of Rights; taxpayers should always respond carefully and in writing. Auditors may remain on the taxpayer's premises for up to 30 days (extendable to 60), though in practice the overall audit, including off-site document review, often takes three to four months.

The Appeal Process

A taxpayer has 60 days from the date of service of an assessment notice to appeal, first to the Revenue Agency that issued it and then, within 30 days, to the Tax Court of First Instance. The appeal must include all arguments at the outset, as further objections cannot be added later. First-instance hearings in Milan take about nine months; the losing party may then appeal to the Second-Instance Tax Court and, finally, to the Court of Cassation, which reviews only legal principles and the soundness of reasoning.

The Tax Court is an independent judicial body covering all tax and related charges. Hearings and judgments are public, and Court of Cassation decisions are published on its website. The procedure is mainly written, with only brief oral argument; the appeal must concisely set out procedural and substantive objections, which may later be clarified—but not expanded—in further briefs. Written documentary evidence is admissible; witness testimony is not generally central, though it can matter in specific disputes, such as demonstrating non-payment.

Burden of Proof

On the burden of proof: the tax authority must justify its challenge in detail (e.g., explaining why an expense should not be considered business-related), while the taxpayer must substantiate the item's legitimacy and show that the authority's findings are unreasonable; the authority cannot rely on generic, unsupported challenges.

Duration and Payment Obligations

Proceedings can be lengthy—up to about 12 years from assessment to a Court of Cassation decision in complex cases. Upon assessment, taxpayers must pay one-third of the additional tax claimed; a stay of payment is possible but difficult to obtain, requiring both urgency (periculum in mora) and a reasonable likelihood of success (fumus boni iuris), and is particularly hard to secure for large corporations, banks, or insurers.

Representation, Costs, and Alternative Dispute Resolution

Representation before the first two levels of the tax courts must be by qualified professionals, and for cassation proceedings, by an attorney qualified before the Court of Cassation. It is advisable to use a Chartered Accountant and a tax lawyer together. The losing party generally bears the costs of the proceedings. There are two levels of tax adjudication before the Court of Cassation.

For international disputes, particularly transfer pricing, arbitration (conventional or EU) is available to avoid double taxation. Purely domestic disputes have no alternative to litigation apart from mechanisms like "accertamento con adesione."

Penalties

Penalties for additional assessed tax are generally 70% of the tax due, plus interest. Penalties may be mitigated or waived in cases of objective legal uncertainty, assessed on a case-by-case basis; for transfer pricing specifically, penalties can be avoided by preparing appropriate documentation in advance.

Outlook

Looking ahead, the main areas expected to generate disputes are tax avoidance (abuse of right), transfer pricing, and beneficial ownership. No single area is seen as uniquely difficult, though the relationship with tax authorities remains complex: local offices are sometimes aggressive, rely on one-sided ministerial circular interpretations while disregarding contrary case law, and case law itself is not always fully consistent.

For more information, contact:

Image

Paolo Comuzzi

pcomuzzi@lawal.it

Lawal Legal & Tax Advisory

news
14 Jul 2026

Globalaw Forms First-of-its-Kind Strategic Global Collaboration with Legora, Providing Members with Leading AI Legal Solutions

Globalaw, a global Band 1 Chambers-ranked network of approximately 80 independent law firms in more than 60 countries, announces a strategic collaboration with Legora, a leading legal AI platform. This first-of-its-kind collaboration between Legora and a global network of law firms gives Globalaw members exclusive access to AI capabilities that deliver innovative solutions for their firms and clients.

“AI is intensifying competition in the legal industry, and a responsible but forward-looking approach to the adoption of technology-enabled legal services is paramount,” said Peter J. Brown, Globalaw President and Partner at Edwards, Kenny & Bray. “Firms that know how to leverage advanced technology have a distinct competitive advantage. That’s why Globalaw is excited to introduce Legora across the network and empower members to strategically implement AI solutions designed specifically to elevate the way attorneys and law firms work.”

Globalaw’s innovative approach is a hallmark of its 30-year history, underscored by an enduring commitment to equipping its members with game-changing technology and resources. As law firm investment in AI escalates, membership in Globalaw becomes even more valuable as its collaboration with Legora fosters knowledge sharing and capability building, enabling members to deploy AI tools more quickly and with greater confidence.

"Globalaw's members represent some of the most respected independent firms in the world, and this collaboration reflects a shared belief that AI should make lawyers more effective, not replace their judgment," said Linda Björkenheim, Head of Partnerships at Legora. "By bringing Legora's platform to the Globalaw network, we're giving member firms a faster path to adopting AI in a way that's rigorous, secure, and built around how lawyers actually work, so they can spend more time on what clients value most."

About Legora

Legora is the agentic operating system for legal work, supporting lawyers in research, review, and drafting across complex matters. It is used by more than 100,000 legal professionals at more than 1,200 leading law firms and in-house legal teams across over 50 markets.

About Globalaw

Founded in 1994, Globalaw is a global Band 1 Chambers-ranked leading network of approximately 80 independent law firms and 4,000 lawyers in over 60 countries. Our mission is to foster seamless legal collaboration among member firms and to help them deliver high-quality, cost-effective solutions to their clients worldwide. We take pride in our commitment to excellence, global reach, and innovative approach to legal services. Visit www.globalaw.net to learn more.

Media Contact:

Jaime Luckey

marketing@globalaw.net

Insights
22 Jun 2026

India’s New Privacy Regime: What it means for Global Business and Data Governance

India’s approach to personal data protection has undergone a decisive shift. The Digital Personal Data Protection Act, 2023, read with accompanying Rules, 2025 (collectively, the “DPDPA”), is currently being implemented in India in a phased manner. Once operational (by May 2027) it will apply to all businesses processing personal data in connection with any goods or service offerings in India – including offshore entities.

While India’s DPDPA draws inspiration from the EU GDPR, businesses should note that it introduces terminology, rights and roles unique to its framework. The DPDPA operates on a binary consent regime – where personal data may only be processed with the individual’s explicit consent or for specified “certain legitimate uses.” Data Fiduciaries (entities determining means and purposes of processing personal data) are required to discharge comprehensive obligations under the DPDPA, with non-compliance entailing significant penalties (to the tune of $25 million).

For Fiduciaries, formal Data Processing Agreements comprise a statutory requirement as well as a practical necessity – since they bear non-delegable statutory liability for the Data Processors they engage.

The DPDPA’s implementation will place India alongside a growing number of APAC jurisdictions that provide for extraterritorial application of data protection laws. For multinationals operating in India, the regulatory divergence between India and other data protection regimes, including in the EU or APAC, may present immediate and material compliance challenges.

Key Compliance Considerations

Given the extensive compliance requirements under the DPDPA and its structural divergences with other data protection frameworks, multinational businesses operating in India should engage qualified counsel at the earliest to determine their specific roles and cross-border obligations under the DPDPA. Carefully structured and interoperable Data Processing Agreements, in particular, may serve as a practical compliance pathway for businesses navigating obligations across multiple jurisdictions.

Our lawyers advise clients on DPDPA compliance, cross-border data transfer arrangements, and DPA structuring. If your organization is seeking clarity on its obligations under India’s evolving data protection regime, please contact our member firm identified below.

For more information, contact:

Image

Ashneet Hanspal

ashneet.hanspal@ahlawatassociates.in

Ahlawat & Associates