Do I need a Data Protection Officer under the GDPR?
Under Article 37 of the GDPR, you must appoint a data protection officer if you are a public authority, if your core activities require regular and systematic monitoring of people on a large scale, or if your core activities involve large-scale processing of special category or criminal offence data. Otherwise a DPO is optional.
Applies to: Controllers and processors subject to the GDPR deciding whether they must designate a data protection officer under Article 37, including public authorities and organisations whose core activities involve large-scale monitoring or large-scale special category data.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanFounding 30% off with code FOUNDING until 15 August 2026
"Do we need a DPO?" is one of the first GDPR questions a growing company hits, and the answer is narrower than most people assume. The GDPR does not require every business to appoint a data protection officer. Article 37 sets three specific triggers, and if none of them fits you, appointing a DPO is a choice, not a legal duty. Getting the answer right matters, because a DPO carries real independence and reporting obligations once you name one.
When is a DPO mandatory?
Article 37(1) lists three cases where a controller or processor must designate a DPO. First, where the processing is carried out by a public authority or body, except for courts acting in their judicial capacity. Second, where your core activities consist of processing that, by its nature, scope, or purposes, requires regular and systematic monitoring of data subjects on a large scale. Third, where your core activities consist of large-scale processing of special category data under Article 9 or personal data about criminal convictions and offences under Article 10. If you fall into any one of these, the appointment is not optional.
What do "core activities" and "large scale" mean?
The trigger turns on core activities, meaning the processing that is essential to what you do, not support functions like running payroll or internal IT. A hospital's core activity is delivering care, which involves health data; a security firm's core activity may be surveillance. The GDPR sets no fixed number for "large scale," so you weigh the volume of data, the number of people affected, the duration, and the geographic reach. Guidance endorsed by the European Data Protection Board points to factors rather than thresholds, so a business assesses its own scale honestly and records the reasoning.
Who can be a DPO, and what must they do?
Under Article 37(5), the DPO is chosen on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices. Article 37(6) allows the DPO to be a member of your staff or to work under a service contract, so outsourcing is permitted, and a group of undertakings may share a single DPO who is easily accessible from each establishment. Once appointed, Article 37(7) requires you to publish the DPO's contact details and communicate them to your supervisory authority. The DPO then supports the wider governance duties, including your record of processing activities and any data protection impact assessment.
What if a DPO is optional?
If none of the Article 37(1) triggers applies, you are not required to appoint a DPO, but two things still matter. Member State law can impose its own DPO requirement beyond the GDPR minimum, so check the countries you operate in. And appointing a DPO voluntarily is allowed, but once you do, the same Article 38 and 39 rules on independence and tasks apply, so it is a real commitment rather than a title. Record your decision either way, so you can show your reasoning if a regulator asks.
Next step
If you are unsure whether monitoring or special category processing tips you into a mandatory DPO, the free 2-minute Obligation Scan checks whether the GDPR applies to you and flags whether an Article 37 trigger is likely, so you appoint a DPO when the law requires it and not by guesswork. The GDPR compliance hub lays out the governance duties a DPO would oversee.
Compliance checklist
- Check Article 37(1)(a): are you a public authority or body? If so, you must appoint a DPO, except for courts acting in their judicial capacity.
- Check Article 37(1)(b): do your core activities require regular and systematic monitoring of people on a large scale? Large-scale behavioural tracking usually qualifies.
- Check Article 37(1)(c): do your core activities involve large-scale processing of special category data under Article 9, or criminal conviction and offence data under Article 10?
- If none apply, record that a DPO is not mandatory, but consider appointing one voluntarily and check whether Member State law adds its own requirement.
- If you must appoint one, choose them on professional qualities and expert knowledge of data protection law, publish their contact details, and communicate them to your supervisory authority.
Sources
- Regulation (EU) 2016/679 (GDPR), Article 37 (designation of the data protection officer), official consolidated text on EUR-Lex
- Article 29 Working Party, Guidelines on Data Protection Officers (WP243 rev.01), endorsed by the EDPB
Last verified: 2026-08-12
Informational, not legal advice.