Unlike certain types of organisation, it is not mandatory for the Company to appoint a data protection officer (DPO) under the GDPR. Since assigning a DPO is according to following rules:
Your company/organisation needs to appoint a DPO, whether it's a controller or a processor, if its core activities involve processing of sensitive data on a large scale or involve large scale, regular and systematic monitoring of individuals. In that respect, monitoring the behaviour of data subjects includes all forms of tracking and profiling on the internet, including for the purposes of behavioural advertising.
Public administrations always have an obligation to appoint a DPO.
Mobietrian does not fall under these criteria and thus don’t need to appoint a DPO. However, all privacy related issues can be reported to firstname.lastname@example.org