When a Data Protection Officer Is Required under the GDPR — and Who Can Be Appointed

The designation of a Data Protection Officer (DPO) is one of the most distinctive structural obligations introduced by the General Data Protection Regulation (GDPR). While many organisations associate GDPR compliance with policies, notices, or technical safeguards, the requirement to appoint a DPO represents something deeper: a commitment to embedding privacy governance into the organisation’s decision‑making architecture.

However, the DPO obligation is also one of the most consistently misunderstood elements of the Regulation. Some organisations appoint a DPO unnecessarily, diluting the role’s authority. Others conclude incorrectly that no appointment is required and later face regulatory scrutiny for failing to designate one where Article 37 demanded it.

This page explains when a DPO is legally required under the GDPR, how supervisory authorities interpret the key triggering concepts, and who can serve as a DPO—including the qualifications, independence requirements, and organisational constraints that apply.


The Legal Framework: Article 37 GDPR

The obligation to appoint a DPO is governed primarily by Article 37 GDPR, supported by Recital 97 and authoritative guidance issued by the European Data Protection Board (EDPB), which endorsed earlier Article 29 Working Party guidance after the GDPR entered into force.

Article 37 does not require every organisation that processes personal data to appoint a DPO. Instead, it defines three specific circumstances in which designation is mandatory, based on the nature, scale, and purpose of processing activities, rather than on organisational size, turnover, or sector alone.


The Three Mandatory Cases Where a DPO Must Be Appointed

1. Processing Is Carried Out by a Public Authority or Body

A DPO must be appointed where processing is carried out by a public authority or body, except for courts acting in their judicial capacity.

Supervisory authorities interpret “public authority or body” broadly to include entities governed by public law or performing public functions, such as:

  • government departments and ministries;
  • local authorities and municipalities;
  • public hospitals and healthcare bodies;
  • public universities and research institutions;
  • public employment agencies.

The rationale for this automatic obligation is twofold. First, public bodies routinely process large volumes of personal data, often including sensitive categories, over long periods. Second, individuals typically have no meaningful ability to opt out of such processing. In this context, the GDPR treats the DPO as a structural safeguard, not a risk‑based optional measure.


2. Core Activities Require Regular and Systematic Monitoring of Data Subjects on a Large Scale

The second trigger is the most complex and frequently misapplied. A DPO is required where the core activities of the controller or processor consist of processing operations which, by virtue of their nature, scope, and/or purposes, require regular and systematic monitoring of data subjects on a large scale

Each element of this test must be satisfied.

Core Activities

“Core activities” are processing operations that are essential to achieving the organisation’s primary objectives. Ancillary or support processing—such as payroll, billing, or basic IT services—does not usually qualify unless the organisation’s business consists of providing those services.

By contrast, processing is likely to be a core activity where it:

  • enables the organisation’s main service;
  • generates revenue directly; or
  • underpins the organisation’s strategic business model.

For example, payroll processing is ancillary for most employers, but core for an outsourced payroll provider.

Regular and Systematic Monitoring

Supervisory authorities interpret “regular and systematic monitoring” to include:

  • ongoing or recurring monitoring;
  • monitoring organised according to a defined strategy;
  • tracking or profiling individuals for analysis or prediction.

This commonly includes online behavioural tracking, location monitoring, credit scoring, loyalty programmes, and pervasive analytics. Monitoring need not be intrusive or covert to qualify; structured tracking as part of normal service delivery is sufficient.

Large‑Scale Processing

The GDPR does not define “large scale” numerically, but EDPB guidance identifies relevant factors such as:

  • the number of data subjects involved;
  • the volume and range of data processed;
  • the duration or permanence of processing;
  • the geographical extent of processing.

A hospital processing patient records typically qualifies as large scale; a single practitioner’s private practice generally does not.

Only when all three elements—core activity, regular and systematic monitoring, and large scale—are present does Article 37 mandate appointment of a DPO under this limb.


3. Core Activities Involve Large‑Scale Processing of Special Category or Criminal Offence Data

The third mandatory trigger applies where the controller’s or processor’s core activities consist of large‑scale processing of special categories of personal data under Article 9 GDPR or personal data relating to criminal convictions and offences under Article 10.

Special category data includes:

  • health data;
  • biometric and genetic data;
  • racial or ethnic origin;
  • political opinions;
  • religious or philosophical beliefs;
  • sexual orientation;
  • trade union membership.

Where such data is processed at scale as part of the organisation’s primary operations, a DPO is required regardless of whether monitoring is involved. Healthcare providers, insurance companies, biometric technology providers, and certain research organisations commonly fall within this category.


When a DPO Is Not Mandatory — and Why Documentation Still Matters

In cases outside the three Article 37(1) triggers, organisations are not legally required to designate a DPO. However, supervisory authorities consistently emphasise that organisations must be able to justify and document that conclusion.

Regulators increasingly expect:

  • a written assessment of Article 37 applicability;
  • analysis of core activities and processing scale;
  • periodic review as processing evolves.

Failure to document this analysis can undermine an organisation’s credibility during regulatory inquiries, even where no DPO appointment was strictly required.


Voluntary Appointment of a DPO

Article 37(4) explicitly permits organisations to appoint a DPO voluntarily, even where not required by law.

Many organisations choose voluntary appointment where:

  • processing approaches large‑scale thresholds;
  • multiple complex data‑flows exist;
  • regulatory exposure is high;
  • stakeholders expect demonstrable governance.

Once appointed, a voluntary DPO is subject to the same Articles 38 and 39 obligations as a mandatory DPO. Organisations cannot selectively limit independence or tasks simply because the appointment was optional.


Group and Multi‑Entity Appointments

The GDPR permits a single DPO to be appointed for:

  • a group of undertakings; or
  • multiple public authorities or bodies;

provided the DPO is easily accessible from each establishment, taking account of organisational structure and size.

This flexibility recognises modern corporate structures while preserving effective accessibility. Regulators assess accessibility by reference to:

  • language capabilities;
  • availability across time zones;
  • knowledge of local processing activities;
  • practical ability to engage with local staff and data subjects.

Who Can Be a Data Protection Officer?

Article 37(5) sets clear criteria for who may be designated as a DPO. The role is not defined by job title, seniority, or certification alone.

Professional Qualities and Expertise

A DPO must be designated on the basis of professional qualities and expert knowledge of data protection law and practices, as well as the ability to perform the tasks set out in Article 39

The level of expertise required is relative to complexity and risk. Organisations engaged in high‑risk or large‑scale processing require correspondingly advanced expertise.


Internal or External DPOs

The GDPR expressly allows the DPO to be:

  • an employee of the organisation; or
  • an external service provider acting under a service contract. [gdpr-info.eu]

There is no legal preference for one model over the other. Regulators focus on whether the arrangement ensures:

  • independence;
  • availability;
  • adequate resources;
  • avoidance of conflicts of interest.

Conflicts of Interest

A person cannot serve as DPO if their other duties involve determining the purposes and means of processing. Regulators have consistently identified conflicts where DPOs also act as:

  • head of IT;
  • chief information security officer;
  • head of HR;
  • marketing or operations leadership.

Conflict‑free positioning is a core compliance requirement, not a best‑practice recommendation.


Publishing and Notifying DPO Contact Details

Once designated, the controller or processor must:

  • publish the DPO’s contact details; and
  • communicate those details to the supervisory authority.

This reinforces the DPO’s role as both internal advisor and external accountability point.


Common Regulatory Pitfalls

Supervisory authorities repeatedly identify the same problems:

  • failing to appoint a DPO when Article 37 requires one;
  • appointing a DPO without sufficient authority or resources;
  • assigning the role to individuals with conflicting duties;
  • treating voluntary DPOs as exempt from Articles 38 and 39.

These failures often result in enforcement action not because personal data was mishandled, but because governance structures were inadequate.


Conclusion

Article 37 GDPR reflects a shift away from checkbox compliance toward structural accountability. Whether a DPO is required depends not on organisational size, but on the nature and significance of data processing activities. Once designated, the DPO must meet strict criteria of expertise, independence, and accessibility.

Organisations that correctly assess DPO requirements and appoint qualified, conflict‑free officers position themselves far more strongly in the eyes of regulators. Conversely, failure to understand or document Article 37 analysis remains a persistent and avoidable compliance risk.

See Also