When is a DPO mandatory?
Article 37(1) of the GDPR sets out three grounds on which designating a Data Protection Officer is legally mandatory. If any of these apply to your organisation as controller or as processor, you must appoint a DPO:
- Public authorities or bodies (Art. 37(1)(a)): The processing is carried out by a public authority or body, whatever data it processes — with one express exception: courts acting in their judicial capacity are excluded from this ground.
- Regular and systematic monitoring (Art. 37(1)(b)): The core activities of the controller or the processor consist of processing operations which require, together, (i) regular and systematic monitoring of data subjects, (ii) on a large scale. All three elements — core activity, regular-and-systematic monitoring, and large scale — must be present at the same time; occasional or small-scale monitoring does not trigger this ground.
- Special-category or criminal-offence data (Art. 37(1)(c)): The core activities of the controller or the processor consist of large-scale processing of special categories of personal data under Article 9 (e.g. health data, biometric data used for the purpose of uniquely identifying a natural person, or trade-union data), or of personal data relating to criminal convictions and offences under Article 10.
Controller and processor are assessed separately. Whether a DPO must be appointed is examined independently for the controller and for the processor — one party meeting the threshold in point (b) or (c) does not automatically mean the other party must appoint a DPO too. A processor handling large-scale health data on behalf of many small clinics may need a DPO even though none of those clinics individually cross the threshold, and vice versa.
"Core activities" versus ancillary support. Per the EDPB-endorsed WP243 rev.01 guidelines, core activities are the key operations necessary to achieve the controller's or processor's objectives — not incidental support functions such as routine payroll or general IT maintenance. Where processing personal data is inseparable from the primary activity (for example, a hospital cannot provide healthcare without processing health data), that processing counts as core.
"Large scale" has no fixed numeric threshold. Neither the GDPR nor WP243 rev.01 names a specific number of data subjects or records that triggers this ground. Supervisory authorities instead weigh factors such as the number of data subjects affected, the volume and range of data processed, the duration of the processing, and its geographical extent. A small startup whose app continuously tracks the location of millions of users can meet the large-scale test regardless of its headcount, while a larger organisation processing data occasionally or for a small, defined group may not.
"Regular and systematic" is a defined pair of conditions, not a catch-all for any monitoring. "Regular" means ongoing, recurring at fixed intervals, or constantly/periodically taking place; "systematic" means occurring according to a method, as part of a general plan or strategy — for example, behavioural advertising, profiling and scoring, wearable-device or connected-car tracking, loyalty programmes, or CCTV. Both elements must be met together with the large-scale element for Article 37(1)(b) to apply.
Voluntary appointment of a DPO
Article 37(4) covers organisations that fall outside the three mandatory grounds in Article 37(1) in two distinct ways. First, such an organisation — or an association or body representing a category of controllers or processors — may choose to designate a DPO voluntarily. Second, and separately, Article 37(4) allows Union or Member State law to itself require designation of a DPO in cases beyond those in Article 37(1). What those additional cases are, and whether they apply to you, depends entirely on the specific national law in force where you operate — requirements vary between Member States, there is no single EU-wide threshold, and you should check the applicable national law directly rather than assume a particular criterion applies.
Whichever route applies, the legal consequence is the same: per the EDPB-endorsed WP243 rev.01 guidelines, once an organisation designates someone as its official DPO — whether by choice or under national law — the full position and task requirements of Articles 37, 38, and 39 apply to that person exactly as if the appointment had been mandatory under Article 37(1). This means the voluntarily appointed DPO cannot be dismissed or penalised for performing their tasks, must report directly to the highest management level, and must be free of conflicts of interest. Because of this, some organisations that want privacy expertise without triggering the full DPO regime choose to hire a "Privacy Manager" or "Compliance Officer" rather than formally designating a "Data Protection Officer".
Who can be a DPO? (Conflict of Interest)
According to Article 38(6), a DPO may fulfil other tasks and duties, but the controller or processor must ensure that any such tasks and duties do not result in a conflict of interest. A conflict of interest arises where a person's other role leads them to determine the purposes and the means of the processing of personal data — because that person would then, in effect, be auditing decisions they made themselves.
Whether a specific role creates a conflict must be assessed case-by-case, based on the duties the person actually carries out — not on job title alone. As a rule of thumb, the WP243 rev.01 guidelines note that senior positions such as chief executive, chief operating, chief financial, or chief medical officer, and heads of marketing, human resources, or IT, will often conflict with the DPO role, because those positions typically involve deciding the purposes and means of processing. This is guidance, not a categorical ban: the same title can be conflict-free where it carries no such decision-making power in a given organisation, and conversely a role lower in the hierarchy can still conflict if it determines purposes and means in practice.
The DPO can be a staff member of the organisation or fulfil the role on the basis of a service contract (an external DPO), as permitted by Article 37(6).
(For further context on how GDPR balances different rights and operational needs, you can see our guide on legitimate interests).
Master the DPO Requirements
Practise for your GDPR / DPO certification exam with questions covering Articles 37-39 in depth, including tricky scenarios on conflict of interest.
Start free Try 30 questions free — AI-powered explanations included.Tasks of the Data Protection Officer
Article 39(1) defines the DPO's minimum tasks, which revolve around informing, advising, and monitoring — not personally guaranteeing compliance. Designating a DPO does not transfer legal responsibility away from the organisation: the controller remains accountable for its own compliance with the GDPR at all times, and a processor remains responsible for its own obligations under the GDPR. The DPO does not personally guarantee compliance; instead, the DPO acts as an independent internal advisor and monitor. Their statutory tasks include:
- Informing and advising: Advising the controller, processor, and employees who carry out processing of their obligations pursuant to the GDPR.
- Monitoring compliance: Monitoring compliance with the GDPR and the internal policies of the controller or processor, including the assignment of responsibilities, awareness-raising, and training of staff.
- DPIA advice: Providing advice where requested as regards the data protection impact assessment (DPIA) and monitoring its performance pursuant to Article 35.
- Cooperation: Cooperating with the supervisory authority.
- Supervisory-authority contact point: Acting as the contact point for the supervisory authority on issues relating to processing, including the prior consultation referred to in Article 36 (Article 39(1)(e)).
Separately, Article 38(4) — not Article 39 — gives data subjects the right to contact the DPO directly about any issue related to the processing of their personal data or the exercise of their GDPR rights.
Position and protections of the DPO
Article 38 protects the DPO's independence, requiring that they do not receive any instructions regarding the exercise of their tasks and cannot be dismissed or penalised by the controller or the processor for performing their tasks. This robust protection is designed to ensure the DPO can speak the truth to management without fear of losing their job. Furthermore, the DPO must directly report to the highest management level of the controller or the processor.
The organisation must also support the DPO by providing the resources necessary to carry out their tasks, access to personal data and processing operations, and the means to maintain their expert knowledge.
Frequently asked questions
Is a Data Protection Officer mandatory for a small business?
Under the GDPR, the requirement for a DPO depends on the processing activities, not the size of the business. A small business must appoint a DPO if its core activities involve large-scale regular and systematic monitoring of data subjects, or large-scale processing of special categories of data (Article 9) or personal data on criminal convictions and offences (Article 10). Union or Member State law may also require a DPO in additional cases (Article 37(4)).
Can the CEO or IT Manager be the DPO?
Usually not, because Article 38(6) requires that the DPO does not have a conflict of interest. Roles that determine the purposes and means of processing (like a CEO, IT Manager, or Head of HR) typically conflict with the independent monitoring duties of a DPO.
What happens if we voluntarily appoint a DPO?
If you voluntarily appoint a DPO, the same strict rules under Articles 37, 38, and 39 of the GDPR apply to them as if the appointment were mandatory. This means they must remain independent and cannot be dismissed or penalised for performing their tasks.
Can a group of undertakings appoint a single DPO?
Yes. Article 37(2) allows a group of undertakings to appoint a single data protection officer provided that the DPO is easily accessible from each establishment.