GDPR › GDPR Documentation & Compliance
Compliance Checklist: How to be GDPR Compliant
Modules
.legal AI
All AI features →Integrations
See all integrations →Platform & features
Understand the rules
See it in action
All customer stories →Plan your switch
Stay up to date
A data protection officer is the GDPR's mandatory advisory and oversight role for public bodies and certain private organisations. See the three Article 37 criteria, the DPO's tasks under Article 39, the independence rules, the choice between an internal and an external DPO, and what happens if you should have one and do not.
The question "do we need a data protection officer?" usually lands with the lawyer, compliance lead or IT manager who already has GDPR as a side job. The answer does not depend on how many staff you employ or how much personal data you hold. It depends on three criteria in Article 37 of the GDPR. Most private companies do not meet them. Every public authority does.
This article explains what a data protection officer (DPO) is, when appointing one is mandatory, and which tasks the role has and deliberately does not have under Article 39. It draws on the regulation, the Court of Justice's rulings on conflicts of interest, the European Data Protection Board's 2024 report on DPOs and the position under UK GDPR, and ends with a fictional worked example.
A data protection officer is required if you are a public authority or body (Article 37(1)(a)), if your core activities consist of regular and systematic monitoring of data subjects on a large scale (Article 37(1)(b)), or if your core activities consist of large-scale processing of special categories of data or data relating to criminal convictions and offences (Article 37(1)(c)). The criteria apply to controllers and processors alike.
For private organisations all three elements must be present at once: a core activity, a large scale, and either monitoring or special categories. A company whose processing is limited to HR, customer records, invoicing and bookings is not caught, whatever its size. A voluntary DPO is subject to every requirement in Articles 37 to 39 all the same.
Searches for data protection officer sit alongside searches for GDPR compliance manager, chief information security officer and data controller. They are four different things, and only one of them is a legally regulated function with its own rights.
| Role | What it is | Regulated by the GDPR? |
|---|---|---|
| Data protection officer (DPO) | Independent advisory and oversight function that monitors compliance and acts as contact point for the supervisory authority and for data subjects | Yes, Articles 37 to 39. Mandatory in three situations, protected against dismissal and instructions |
| GDPR compliance manager / privacy lead | Internal role the organisation defines itself, typically the person who runs the practical compliance work | No. No formal requirements, no special protection |
| Chief information security officer (CISO) | Owns security measures and the ISMS, often anchored in ISO 27001 or NIS2 | No. Security of processing is required by Article 32, but the role itself is not regulated |
| Data controller | The organisation (not a person) that determines the purposes and means of processing and carries the responsibility | Yes, Article 4(7) and Article 24. Fines are addressed to the controller, not to the DPO |
The last row matters most. The controller, not the DPO, is responsible for compliance. The Article 29 Working Party guidelines on DPOs, WP243 rev.01, say plainly that DPOs are not personally responsible for non-compliance.

A data protection officer is the function the GDPR introduces in Articles 37 to 39 to give certain organisations a permanent, independent expert in data protection. The regulation was adopted on 27 April 2016 and has applied since 25 May 2018. It covers people who are in the EU and the EEA, including Norway, Iceland and Liechtenstein, and the UK GDPR keeps the same three articles.
The role stands on three legs: advising the organisation and its staff, monitoring compliance, and acting as contact point for the supervisory authority and data subjects. The DPO is chosen for professional qualities, in particular expert knowledge of data protection law and practices (Article 37(5)), and may be staff or contracted (Article 37(6)).
The interpretation most authorities rely on is WP243 rev.01, the Article 29 Working Party guidelines on data protection officers from April 2017, which the EDPB endorsed at its first plenary on 25 May 2018. The ICO's guidance for UK GDPR follows the same structure.
Article 37(1) lists three situations in which controllers and processors must always designate a DPO. The table sets out the criteria and the interpretation from WP243 and the ICO.
| Criterion | Legal basis | Interpretation and examples |
|---|---|---|
| Public authority or body | Art. 37(1)(a) | Defined by national law. Ministries, agencies, regional and local government, and in most member states universities and public hospitals. Courts acting in their judicial capacity are exempt. WP243 recommends that private bodies carrying out public tasks, such as utilities and public transport operators, appoint one as good practice |
| Core activity involving regular and systematic monitoring on a large scale | Art. 37(1)(b) | Behavioural advertising, tracking and profiling, location data, credit scoring, telecoms operators, connected devices, loyalty programmes. The monitoring must be part of what the business exists to do, not a support function |
| Core activity involving large-scale processing of special categories or criminal data | Art. 37(1)(c), read with Arts 9 and 10 | Hospitals and clinic chains, health insurers, background-screening firms, cloud and hosting providers processing health data for many clients. WP243 contrasts a single GP with a hospital: both process health data as a core activity, only the hospital does so on a large scale |
Two concepts carry the whole assessment for private organisations. Core activities are the key operations needed to achieve the organisation's goals, or processing that is an inextricable part of them. WP243 treats payroll, HR and standard IT support as ancillary. Large scale is judged on the number of data subjects, the volume and range of data, the duration of the processing and its geographical extent. There is no fixed numerical threshold.
A group of undertakings may appoint a single DPO who is easily accessible from each establishment (Article 37(2)), and public authorities may share one (Article 37(3)). The DPO's contact details must be published and communicated to the supervisory authority (Article 37(7)). In the UK the ICO asks for the DPO's contact details as part of its registration and fee process, and most EU authorities offer an online notification form.
A DPO is not an alternative to the rest of the GDPR work. With or without a DPO, you still need a record of processing activities under Article 30, a legal basis for every processing activity, and documentation showing you meet the seven principles in Article 5, accountability included.

Article 39(1) sets out the data protection officer duties that every DPO has as a minimum. The list is short on purpose. The DPO advises and monitors, the organisation executes. The table shows each task and what it means in practice.
| Task | Legal basis | In practice |
|---|---|---|
| Inform and advise | Art. 39(1)(a) | Advise management and staff on their obligations under the GDPR and national data protection law, for instance when new systems, vendors or marketing initiatives are planned |
| Monitor compliance | Art. 39(1)(b) | Check that policies are followed, that responsibilities are assigned, run spot checks and internal audits, and make sure staff who handle personal data receive awareness training |
| Advise on data protection impact assessments | Art. 39(1)(c) and Art. 35(2) | Advise on whether a DPIA is needed, which method to use, and whether the conclusions hold. The assessment itself belongs to the controller |
| Cooperate with the supervisory authority | Art. 39(1)(d) | Be the authority's way in during investigations, complaints and prior consultations |
| Act as contact point | Art. 39(1)(e) and Art. 38(4) | Data subjects may contact the DPO on all issues relating to the processing of their data and the exercise of their rights |
| Work risk-based | Art. 39(2) | Prioritise according to the risk of each processing operation. New systems and special categories of data come first |
What Article 39 does not say matters just as much. These are the controller's duties, not the DPO's: the record of processing activities (Article 30, shared with processors), notifying a breach to the supervisory authority within 72 hours (Article 33), telling data subjects without undue delay where the risk is high (Article 34), the DPIA (Article 35) and data processing agreements with processors (Article 28).
The DPO advises on all of these and often coordinates the handling of a security breach or quality-assures the data protection impact assessment. That is lawful, as long as the controller takes the decisions. The EDPB's 2024 report found that a median of 32.88 per cent of organisations had the DPO prepare or carry out DPIAs, and flagged this as a potential conflict of interest, because the DPO ends up checking their own work.

Article 38 is what separates a DPO from an ordinary employee with GDPR responsibilities. The controller must involve the DPO properly and in a timely manner in all issues relating to personal data (Article 38(1)), provide the resources necessary and access to personal data and processing operations (Article 38(2)), and ensure the DPO receives no instructions on how to perform the tasks, is not dismissed or penalised for performing them, and reports directly to the highest management level (Article 38(3)). The DPO may have other tasks, but they must not result in a conflict of interests (Article 38(6)).
The Court of Justice of the European Union has settled the two questions that come up most often. In X-FAB Dresden (C-453/21), decided on 9 February 2023, the Court held that a conflict of interests may exist where a DPO is entrusted with other tasks that would result in that person determining the purposes and means of processing personal data. The assessment is made case by case. KISA (C-560/21), decided the same day, says the same. In Leistritz (C-534/20) of 22 June 2022 the Court held that member states may give DPOs stronger protection against dismissal than the regulation does, provided the GDPR's objectives are not undermined.
WP243 translates the principle into job titles. Senior management positions such as chief executive, chief operating officer, chief financial officer, chief medical officer, head of marketing, head of HR and head of IT are, as a rule, in conflict, because they set the purposes and means of processing. Lower positions can conflict too if they lead to determinations of purposes and means. The guidelines recommend identifying the conflicting positions, setting internal rules to avoid them and documenting the assessment when you appoint.
Enforcement shows the cost. On 28 April 2020 the Belgian Data Protection Authority fined a telecoms company EUR 50,000 because its DPO also headed the compliance, risk management and audit department and so decided on processing there. In September 2022 the Berlin Commissioner for Data Protection fined a subsidiary of an e-commerce group EUR 525,000 because its DPO was also managing director of two group companies acting as its processors. Both decisions rest on Article 38(6).
The EDPB's coordinated enforcement action of 2023, with 25 authorities and 17,490 responses reported in January 2024, shows where the weaknesses sit. A median of 13.82 per cent of DPOs said they receive instructions on how to carry out their tasks. A median of 16.9 per cent said no reporting to the highest management level was expected of them. Only 66 per cent in the public sector reported sufficient resources, against 91 per cent in the private sector. The report recommends written terms for the DPO, direct access to top management, and a recorded reason whenever the DPO's advice is not followed.
Article 37(6) allows both, and the ICO's guidance states expressly that the role can be contracted out to an individual or an organisation on a service contract, with the same position, tasks and duties as an internal DPO. The choice turns on knowledge of the organisation, independence, vulnerability and cost.
| Aspect | Internal DPO | External DPO |
|---|---|---|
| Legal basis | Member of staff, Art. 37(6) | Service contract, Art. 37(6) |
| Knowledge of the organisation | High, knows systems, culture and colleagues | Has to be built, usually through a named internal coordinator |
| Independence | Needs deliberate positioning outside the line, risk of conflict from dual roles | Structurally easier, but the contract must secure freedom from instructions and access to management |
| Vulnerability | Holiday, sickness and resignations hit the function directly | Provider normally offers cover. WP243 recommends a clear allocation of tasks within the provider's team and one named lead contact |
| Keeping skills current | Organisation pays for training and time, Art. 38(2) | Usually included in the fee |
| Sharing | One DPO for a group of undertakings, Art. 37(2) | One DPO for several public bodies, Art. 37(3), common among local authorities across Europe |
| Cost | Salary for all or part of a post plus training | Fixed monthly or annual fee, often with an agreed number of hours and a rate for extra work |
The EDPB's 2024 figures confirm that sharing is normal. A median of 33.97 per cent of DPOs were shared between several organisations, and only 54.5 per cent worked on the role full time. The report does not warn against sharing, but against nobody having calculated how many hours the task takes. It also asks organisations with an external DPO to check how many clients that DPO serves.
Whether the appointment is mandatory or voluntary, this is the sequence we see work.
Harbourview Health Ltd and Aoife Brennan are fictional. We invented them for this article, and the figures are assumptions, not market prices.
Harbourview Health runs 14 physiotherapy and primary care clinics in Ireland with 180 staff and around 60,000 active patient records. Aoife Brennan, finance and HR director, has carried GDPR on the side since 2018. The board asks whether the company needs a data protection officer, and whether Aoife can be it.
The first question is decided by Article 37(1)(c). Processing health data is the clinics' core activity and inseparable from treating patients. Sixty thousand patients across 14 clinics in several counties is large scale under the WP243 factors, and health data is a special category under Article 9. All three elements are met. Harbourview Health must appoint a DPO, and the assessment is written down.
The second question is decided by Article 38(6) and X-FAB. As HR director Aoife determines the purposes and means of processing data about 180 employees, and as finance director she owns the IT systems the patient records sit in. She cannot be DPO without a conflict of interests. WP243 names head of HR and head of IT as positions that conflict as a rule.
The third question is internal or external. Aoife runs the numbers, using assumptions invented for the example. An internal DPO at half time is assumed to cost EUR 45,000 a year in salary and pension plus EUR 4,000 in training, EUR 49,000 in total, and means recruiting someone with legal and clinical insight. An external DPO is assumed to cost EUR 2,000 a month for 10 hours plus EUR 160 per additional hour, and Aoife estimates 60 extra hours in the first year for DPIAs on a new patient record system, EUR 33,600 in year one and EUR 24,000 in a normal year. To the external model she adds 0.2 of a full-time post internally for a coordinator who knows the clinics.
She chooses the external model for two years, because it gives cover during absence, brings DPIA experience she cannot recruit quickly and makes direct board reporting easier to secure. She writes a cap on the DPO's number of clients and a named deputy into the contract, and plans to revisit the choice when the chain passes 250 staff. The point is not the price but the order: obligation, conflict of interests, then model.

Infringements of Articles 37 to 39 are subject under Article 83(4)(a) to administrative fines of up to EUR 10 million or 2 per cent of worldwide annual turnover, whichever is higher. The upper tier of EUR 20 million or 4 per cent in Article 83(5) covers the Article 5 principles, legal bases, data subjects' rights and transfers, not the DPO rules. Several widely read guides quote the upper tier for DPO breaches. They are wrong. Under UK GDPR the equivalent maximum in the lower tier is GBP 8.7 million or 2 per cent.
The Spanish authority AEPD fined the delivery platform Glovo EUR 25,000 in 2020 for not having appointed a DPO although its core activity involved regular and systematic monitoring on a large scale through the geolocation of customers and couriers. Luxembourg's CNPD fined several companies in 2021 whose DPOs lacked resources or did not report to top management.
The more likely consequence is supervisory. A missing or powerless DPO is often the first thing an authority notices in a complaint or breach case, and it opens the door to everything else: the record of processing, risk assessments, processor agreements and retention. In the EDPB survey, 12 organisations from seven member states admitted they had not appointed a DPO although it was mandatory.
In the UK, the Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025, and according to the ICO all its data protection provisions have been in force since 19 June 2026. It amends UK GDPR on several points, such as acknowledging complaints within 30 days, but not Articles 37 to 39. The earlier proposal to replace the DPO with a "senior responsible individual" fell with the Data Protection and Digital Information Bill in 2024 and was not revived.
In the EU, the Commission's Digital Omnibus proposal of 19 November 2025 would amend the GDPR on the definition of personal data, breach notification, DPIAs and the record of processing. It does not touch Articles 37 to 39, whose text is unchanged since 2018 even though case law and the EDPB report have tightened their interpretation. As of September 2026 it remains a proposal, with the Council still working on compromise texts, and until something else is adopted, the DPO rules are as they have been since 25 May 2018.
The practical change is in the task list, as NIS2, the AI Act and DORA often land on the DPO's desk. Tasks that involve deciding how personal data is processed, such as owning an AI system or a set of security controls, must be tested against Article 38(6) before they go to the DPO. Our article on information security risk management shows how one risk method can cover GDPR, NIS2 and ISO 27001 without mixing up the roles.
A DPO's biggest practical problem is overview: what processing exists, where the documentation sits, who is responsible and what has changed. Our GDPR module brings the Article 30 record, risk assessments, DPIAs and data processing agreements together in one place, so the DPO can monitor without having to maintain the documents personally. Data mapping shows where personal data flows between systems and vendors, and the data processor audit service documents the controls the DPO needs to see the results of.
The reporting to management that Article 38(3) requires, and the annual plan the supervisory authorities recommend, live in compliance task management, where tasks go to the responsible people in the business with deadlines and evidence, so the business executes and the DPO monitors. The platform does not appoint a DPO for you and does not make you compliant on its own, but it lets you show a supervisory authority what the DPO has seen, advised on and followed up.
Book a demo and see how DPOs in public bodies and private companies use the platform to monitor without drowning in documents.
DPO stands for data protection officer, the independent advisory and oversight function set up by Articles 37 to 39 of the GDPR. In practice the DPO tells the organisation what the law requires, checks whether it is being followed, and is the person the supervisory authority and individuals can contact. The DPO does not decide how personal data is processed and is not the one who answers for the organisation's compliance.
The DPO advises, the controller acts. Notifying the supervisory authority within 72 hours under Article 33 and informing affected individuals under Article 34 are the controller's duties. The DPO's contact details must be included in the notification (Article 33(3)(b)), and the DPO typically helps assess the risk and checks that the breach is recorded. Agree in advance when the DPO is brought in, so nobody loses hours deciding who to call.
No. The obligation depends on the three criteria in Article 37(1), not on headcount or turnover. There is no 250-employee rule for DPOs. That threshold belongs to the record of processing exemption in Article 30(5). A 2,000-person retailer that only processes HR and customer data may not need one, whilst a 40-person firm that tracks users at scale may. National law can add cases, as Germany does.
Yes, if the processor itself meets one of the Article 37(1) criteria, because the article applies expressly to controllers and processors. A cloud provider whose core business is hosting health records for many clinics processes special categories on a large scale and must appoint one. A processor is not caught simply because its customer has a DPO. The assessment is made separately for each organisation, based on its own core activities.
As a rule, no. WP243 lists senior roles such as chief executive, head of HR, head of IT and head of marketing as conflicting, because they decide the purposes and means of processing. The Court of Justice confirmed the test in X-FAB (C-453/21) in 2023. A lawyer or compliance officer without decision-making power over processing can hold the role, provided you assess the conflict case by case and keep a record of that assessment.
The GDPR requires professional qualities and expert knowledge of data protection law and practices (Article 37(5)), but it prescribes no degree, exam or certificate. The expected level rises with the sensitivity and volume of the processing, so a hospital needs deeper expertise than a small marketing agency. Knowledge of the sector and of the organisation's systems counts too. Certificates can evidence competence, and Article 38(2) obliges the organisation to fund ongoing training.
Not under the GDPR. Administrative fines and corrective orders are addressed to the controller or processor, and WP243 states that DPOs are not personally responsible for non-compliance. A DPO who acts outside the role, or breaks other laws such as those on confidentiality, can face consequences under national employment or criminal law. That is why a written mandate describing what the DPO does and does not decide protects both sides.
A DPO cannot be dismissed or penalised for performing their tasks (Article 38(3)), for instance for giving unwelcome advice. Dismissal for unrelated, legitimate reasons such as misconduct remains possible. The Court of Justice held in Leistritz (C-534/20) that member states may add stronger protection, and Germany does so for mandatory internal DPOs. Keep the reason for any dismissal well documented, because authorities will look for a link to the DPO's work.
Yes, on the same terms. UK GDPR keeps Articles 37 to 39 with the same three criteria, and the Data (Use and Access) Act 2025 did not change them. The ICO is the authority to notify. A UK company that serves customers in the EU without an establishment there may also need an EU representative under Article 27, which is a separate role from a DPO and cannot usually be filled by the same person.
There is no official price list, and providers rarely publish rates. Most sell the role as a fixed monthly or annual fee covering an agreed number of hours, the statutory tasks, a helpline and an annual report, with extra charges for large pieces of work such as DPIAs. When comparing offers, look at included hours, named cover during absence and how many clients the DPO serves, not just the headline fee.
Learn more about the key roles in GDPR compliance, from DPOs to compliance managers and data protection governance.
.legal compliance platform
Info
.legal A/S
hello@dotlegal.com
+45 7027 0127
VAT-no: DK40888888
Support
support@dotlegal.com
+45 7027 0127
Need help?
Let me help you get started
.legal is not a law firm and is therefore not under the supervision of the Bar Council.