The list of institutions where the presence of a personal data protection officer (an employee responsible for processing personal data in the organization) will be mandatory has been defined. These include:
- Public institutions (except religious and political organizations)
- Insurance organizations
- Commercial banks
- Microfinance organizations
- Credit Bureaus
- Electronic communication companies
- Airline companies
- Airports
- Medical institutions serving at least 10,000 data subjects per year
- Organizations processing a large amount of data from data subjects or engaging in systematic and large-scale monitoring of their behavior.
A personal data protection officer within an organization can be any person in the office or an individual working under a service contract. There is no requirement for the person to possess special education or certification to carry out this role. Moreover, a personal data protection officer can simultaneously perform data protection functions for multiple companies, and within a specific company, they may also undertake other job responsibilities.