Back to the hub

GDPR Article 37: designation of the data protection officer

GDPR Article 37(1) requires a controller or processor to designate a data protection officer where processing is carried out by a public authority, where core activities require regular and systematic monitoring of data subjects on a large scale, or where core activities involve large-scale processing of Article 9 or Article 10 data.

Applies to: Controllers and processors subject to the GDPR that are working out whether Article 37 obliges them to designate a data protection officer, and on what terms.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Article 37 is the provision that decides whether you must appoint a data protection officer, and it is shorter than its reputation suggests. Seven paragraphs cover when designation is compulsory, who may share one, what the person needs to know, and what you have to publish afterwards.

The three mandatory triggers

Article 37(1) says the controller and the processor shall designate a data protection officer in any case where:

(a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity;

(b) the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or

(c) the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 or personal data relating to criminal convictions and offences referred to in Article 10.

These are alternatives, not cumulative conditions. Note also that Article 37(1) binds processors as well as controllers, which is regularly missed by vendors who assume the duty sits only with their customers.

What "core activities" is doing

Both (b) and (c) hang on the phrase "core activities". It is the difference between processing that is part of what you do and processing that merely supports it. Payroll and internal IT are usually support functions even at a large employer. Behavioural advertising, fraud scoring across a user base, location tracking in a consumer app, or running a health platform are core, because the processing is the service rather than an overhead of running it.

Neither "large scale" nor "regular and systematic" is defined in the Article itself, which is why the assessment has to be documented rather than asserted.

Sharing, outsourcing and qualifications

Article 37(2) allows a group of undertakings to appoint a single data protection officer, provided the DPO is easily accessible from each establishment. Article 37(3) gives public authorities the equivalent, allowing one DPO for several authorities or bodies, taking account of their organisational structure and size.

Article 37(4) covers the cases outside paragraph 1: the controller, processor, or associations and other bodies representing categories of them, may designate a DPO, or shall where required by Union or Member State law. Some Member States legislate lower national thresholds, so a company outside Article 37(1) can still be caught locally.

Article 37(5) sets the standard for the person. The DPO shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39. Article 37(6) then confirms the DPO may be a staff member, or may fulfil the tasks on the basis of a service contract. Outsourcing is expressly allowed.

The publication duty

Article 37(7) is one sentence and two obligations: the controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority. Publishing them in a privacy notice without notifying the regulator only does half of it.

Where this connects

The DPO sits alongside the other accountability duties. If you are carrying out high-risk processing you will also owe a data protection impact assessment under Article 35, and Article 35(2) requires you to seek the DPO's advice when doing one. Your records of processing activities under Article 30 are usually what the DPO works from. For the practical version of the question rather than the statutory text, see do I need a DPO.

Next step

If you are not sure whether your monitoring or special-category processing is at the scale Article 37(1) contemplates, the free 2-minute Obligation Scan works out whether the GDPR applies to you and which accountability duties, including a DPO, come with it. The GDPR compliance hub puts the duties in order.

Compliance checklist

  • Test your processing against each limb of Article 37(1) separately, since meeting any one of the three triggers creates the obligation.
  • Assess whether the monitoring or special-category processing is a core activity rather than an ancillary support function, which is the wording Article 37(1)(b) and (c) turn on.
  • If you designate voluntarily under Article 37(4), expect the Article 38 and 39 duties to follow, because the Regulation does not distinguish voluntary from mandatory appointments once made.
  • Select on the basis of professional qualities and expert knowledge of data protection law and practices, as Article 37(5) requires, and record how that assessment was made.
  • Publish the data protection officer's contact details and communicate them to the supervisory authority, which Article 37(7) requires as two separate steps.

Sources

Last verified: 2026-09-02

Informational, not legal advice.