Earlier quoted context omitted.
That seems insane, and I'm definitely not a lawyer, so maybe there's an out, but I think maybe he's right. Article 37 is pretty clear that if your core business involves processing data that's subject to the GDPR, you need to appoint a DPO, and it can't just be you, because they also require that the DPO can't have a conflict of interest. Man, that's unfortunate. https://gdpr-info.eu/art-37-gdpr/
https://ico.org.uk/for-organisations/guide-to-the-general-da... Under the GDPR, you must appoint a DPO if: you are a public authority (except for courts acting in their judicial capacity); your core activities require large scale, regular and systematic monitoring of individuals (for example, online behaviour tracking); or your core activities consist of large scale processing of special categories of data or data re…
As far as I know the GDPR doesn't change these requirements here. So even if you're a company of 5 people and just handling some email addresses or similar data you certainly don't need a DPO.