Data Protection Officer Requirements: When Is a DPO Mandatory?
Data protection officer requirements use three GDPR tests and national law. Decide whether to appoint a DPO, then document and revisit the outcome.

Data protection officer requirements begin with the processing that a controller or processor actually carries out. Employee numbers and turnover do not settle the question. A defensible decision tests four legal routes against named evidence, reaches a clear yes or no, and leaves a record that another decision-maker can follow without reconstructing the analysis.
Quick Answer Data protection officer requirements do not turn on employee numbers or turnover. A controller or processor must test three Article 37 cases and any applicable Member State law. A yes requires a protected, properly supported DPO. A no requires a dated assessment, named privacy owner and review triggers as facts or law change.
Last updated: 26 August 2026
Start with four routes, not headcount
Article 37 gives controllers and processors the same designation obligation when a mandatory route applies. Frame one assessment around one legal entity and its processing activities. Capture whether it acts as controller, processor or both; what each operation does; whom it affects; how far it reaches; and which national law applies. A group label or organisation chart cannot answer those questions.
The first three routes come from Article 37(1). The fourth is separate and equally capable of producing a mandatory result under Union or Member State law. A yes on any route ends the necessity analysis; it does not end the implementation work.
| Route | Question to decide | Evidence to retain | Result if yes |
|---|---|---|---|
| Public authority or body | Is the controller or processor a public authority or body under the applicable law, and is the courts exception relevant? | Legal status, function, national definition and capacity in which a court acts | Designate a DPO |
| Core monitoring at scale | Do core activities require regular and systematic monitoring of people on a large scale? | Activity map, monitoring method, population, duration and reach | Designate a DPO |
| Sensitive core processing at scale | Do core activities consist of large-scale processing of Article 9 data or Article 10 data? | Data categories, activity purpose, population, volume, duration and reach | Designate a DPO |
| Additional legal requirement | Does applicable Union or Member State law require designation in another case? | Jurisdiction analysis, cited legal source, effective rule and scope | Designate a DPO |
The diagram first asks whether the public-authority route applies, subject to the judicial-capacity exception for courts 1. If not, it tests large-scale core monitoring and large-scale core processing of Article 9 or Article 10 data, each of which independently leads to designation. A negative result on all three still proceeds through the distinct national-law branch under Article 37(4). The final branch is therefore either a properly implemented DPO role or a recorded no-DPO assessment that is reviewed when the facts or law change 2,3.
Complete all four lines even when the first one produces a yes, because the record may later support coverage, resourcing and group decisions. Do not turn the routes into a score where weak indicators cancel a satisfied test. Each is an independent legal gateway, supported by its own facts and conclusion.
Test the three Article 37 cases
The public-authority case is the most direct. Where processing is carried out by a public authority or body, a DPO is mandatory. Courts are excepted only when acting in their judicial capacity; the exception does not convert every operation carried out by a court into judicial activity 1. The organisation must distinguish adjudication from its other functions rather than treating its institutional name as the whole answer.
The second case applies where the controller’s or processor’s core activities consist of processing operations that, by their nature, scope or purposes, require regular and systematic monitoring of data subjects on a large scale 1. All elements matter. Occasional monitoring that is peripheral to delivering the organisation’s key service does not satisfy the same description as continuous monitoring embedded in that service.
The third case applies where core activities consist of large-scale processing of special categories of personal data under Article 9 or data about criminal convictions and offences under Article 10 1. The route is not triggered merely because a normal supporting process contains some sensitive data. Equally, describing a sensitive-data operation as administration does not make it peripheral when the operation is integral to the service delivered.
Controllers and processors must each decide their own position. Map the controller’s purposes and the processor’s contracted operations separately, then test the routes for each entity. One party’s DPO may support practical cooperation, but that appointment does not discharge the other party when its own activities satisfy a route. A contract cannot transfer the statutory test away 1.
There is no Article 37 employee-count or turnover threshold. Those figures may help describe operational capacity or provide context for scale, but neither produces an automatic yes or no. A compact organisation can conduct extensive monitoring; a much larger employer may have no core activity that falls within the second or third case.
Public authority is a national question
The GDPR uses “public authority or body” without defining the expression. The assessment therefore needs the relevant Union and Member State legal setting, including how the entity was created, what public functions it performs and which national rule determines its status. A definition borrowed from another jurisdiction is not a safe substitute 4.
This boundary matters for hybrid bodies, statutory corporations, professional organisations and entities delivering public services under contract. Funding, ownership and public purpose may be evidence, yet none is a universal shortcut. The assessment should quote no borrowed definition; instead, it should identify the applicable source, set out the relevant characteristics and explain the classification reached under that source.
For a court, record the capacity in which the processing occurs. Case-file adjudication may sit inside the judicial-capacity exception, while workforce management, building access, procurement or public communications may require separate analysis. The exception in Article 37(1)(a) is framed around courts acting in a particular capacity, not an institution-wide exemption 1.
An unresolved classification is not a no. Mark it as an open legal dependency, name the question, owner and target date, and avoid approving a final negative assessment while it remains material. Work need not stop: the organisation can complete the other three routes and preserve every fact already established.
Define core activity, scale and monitoring
“Core activities” are the key operations necessary to achieve the controller’s or processor’s objectives. Supporting functions such as payroll or routine IT support are normally ancillary, even though they process personal data. By contrast, data processing can be core when the service could not realistically be delivered without it; processing does not have to be the organisation’s stated commercial purpose to be integral 4.
Large scale has no universal numerical safe harbour. WP243 points to a combined assessment of the number of people concerned, either as an absolute number or proportion of a relevant population; the volume or range of data; the duration or permanence of processing; and its geographical extent 4. The conclusion should show those inputs, not announce that a made-up number is always safe.
Regular monitoring can be ongoing or occur at intervals, recur at fixed times, repeat constantly or periodically, or follow a defined programme. Systematic monitoring is organised, methodical, planned, part of a strategy, or carried out through a system for collecting data 4. Examples may include behaviour tracking, connected-device observation, profiling for decisions, loyalty programmes or location tracking. The examples illuminate the working meaning; they do not remove the need to test core activity and scale.
Evidence should be assembled per processing operation, not copied from an enterprise-wide data total. A useful evidence sheet links the service map to categories and approximate proportions of people affected, data fields, geographical coverage, monitoring cadence, retention duration, decision logic and the process that depends on it. Reasoned ranges are more candid than unsupported precision.
Scale is contextual, but context is not permission to decide by intuition. The same record count can mean something different in a regional service covering most of its relevant population and in an isolated, short-lived exercise. Preserve the underlying number or range, the population against which it is judged, and the duration and reach that make the conclusion intelligible.
Check the Member State law branch
Article 37(4) allows Union or Member State law to require a DPO in cases beyond Article 37(1) 1. This is the fourth route, not an optional legal footnote. A complete EU assessment therefore identifies the Member State law relevant to each establishment and processing operation, checks the rule in force for that situation, and retains the exact source used.
No national threshold should be generalised across the EU. Rules may differ in triggers, terminology, covered entities and interaction with sector law. For several establishments, use a jurisdiction matrix rather than one group-wide sentence. Give each entity and processing operation its own law checked, source date, conclusion, unresolved advice point and review trigger.
Operating under UK GDPR? Use the UK DPO guide.
That link marks a jurisdiction boundary. It does not supply an EU definition, and the UK statutory definition must not be imported into an EU Article 37 assessment. The EU file should stand on the Union rule and the Member State sources that actually apply.
When the national-law answer remains uncertain, place the assessment in “decision pending” status. Record who will obtain the interpretation, the exact scope question and the update date. The organisation may choose interim controls while the point is resolved, but it should not issue a final no that silently depends on an unchecked branch.
A voluntary DPO is still a DPO
An organisation may designate a DPO even when neither Article 37(1) nor an additional legal rule requires one 1. That choice can be valuable, particularly where a credible independent adviser and supervisory-authority contact would improve governance. But the title carries the whole framework: voluntary designation activates the requirements for the DPO’s designation, position and tasks under Articles 37–39 4.
The practical trap is using “DPO” as an honorary label while withholding the role’s protections or capacity. Before announcing a voluntary appointment, run the same readiness check used for a mandatory one: expertise, timely involvement, resources, access, independence, protection from instructions and penalties, direct highest-management reporting, confidentiality and no conflict 1,2. The statutory task charter must also be ready 3.
If the organisation reaches a defensible no and does not intend to assume those obligations voluntarily, assign privacy responsibility without the DPO title. A privacy lead, compliance owner or information-governance manager can coordinate records, requests, training and reviews. The role description should expressly say that the person is not the designated DPO and should avoid presenting them as such externally.
That alternative is not a way to evade a mandatory route. It is the honest governance design only after all four routes have been tested and found not to require designation.
If yes, make the role real
The yes work product begins with a formal designation record approved by the appointing controller or processor. It identifies the start date, whether the DPO is an employee or works under a service contract, the professional qualities and expert knowledge considered, and every entity or establishment covered. A group may use one DPO only when that person is easily accessible from each establishment 1. Several public authorities or bodies may share one with regard to structure and size.
Test accessibility before signing a shared arrangement. Staff and data subjects must know how to reach the DPO; relevant languages, time zones and communication channels must work; and planned capacity must cover every entity. A single email address does not cure an arrangement in which the DPO cannot engage promptly with an establishment.
Article 38 turns the designation into a functioning position. The controller or processor must involve the DPO properly and in a timely manner in all personal-data issues, provide the resources needed for the tasks, allow access to personal data and processing operations, and support maintenance of expert knowledge 2. Governance should specify which projects, incidents, decisions and committees trigger involvement.
Independence must be designed, not merely promised. The DPO receives no instructions on how to perform the statutory tasks, must not be dismissed or penalised for performing them, and reports directly to the highest management level 2. Other duties are possible only if they create no conflict of interests. A conflict check should look at whether the person determines the purposes or means of processing, including through a senior operational role.
Data subjects need an accessible contact route for questions about processing and their rights. The DPO is bound by secrecy or confidentiality under applicable Union or Member State law 2. The organisation must publish the DPO’s contact details and communicate them to the supervisory authority 1. Publication can focus on functional contact details; the legal requirement is accessibility, not unnecessary exposure of personal details.
Article 39 supplies the minimum task charter. The DPO informs and advises the controller or processor and employees; monitors compliance, policies, allocation of responsibilities, awareness, training and audits; advises on requested data protection impact assessments and monitors their performance; cooperates with the supervisory authority; and acts as its contact point 3. The DPO performs those tasks with due regard to processing risk, considering nature, scope, context and purposes.
| Appointment control | Evidence of implementation | Failure signal |
|---|---|---|
| Formal designation and scope | Signed record naming entities, basis and start date | An informal title with no appointing act |
| Expertise and capacity | Selection rationale, service levels, cover and development plan | One shared contact unable to serve every establishment |
| Timely involvement and access | Governance triggers, committee access and information rights | DPO learns of projects only after decisions |
| Independence and reporting | No-instructions clause, protected escalation and highest-level report | Operational manager can direct findings or penalise challenge |
| Confidentiality and no conflict | Confidentiality duty and recorded conflict assessment | DPO also decides purposes or means of processing |
| Accessible contact and notification | Published route and communication record to the supervisory authority | Contact is hidden, stale or unusable |
| Article 39 task charter | Advice, monitoring, training, audit, DPIA and authority-contact records | Role is reduced to occasional policy review |
Designation is not a certificate of compliance. The finished product is an operating role: appointment evidence, protections, access, decision triggers, task records and a contact route that together demonstrate how the DPO works over time.
If no, record the assessment
A no-DPO conclusion also needs a finished work product. Put the assessment date, covered controller or processor, decision owner and processing inventory at the top. Beneath them, give each Article 37(1) route and the Member State law route its own facts, evidence reference and conclusion. Cite the national legal source actually checked 1,4.
The record should make the reasoning reproducible. For monitoring and sensitive-data cases, show why the activity is or is not core, how scale was assessed, which data and people were included, the duration and geographical reach, and whether monitoring is regular and systematic. A bare “not large scale” conclusion gives a reviewer nothing to test.
The public-authority line should state the applicable definition and classification. The national-law line should name the jurisdiction, source and result. If either depends on unresolved legal advice, the overall status should show that dependency rather than presenting a clean no.
| Outcome | Minimum work product | Operating consequence | Review trigger |
|---|---|---|---|
| DPO required or voluntarily designated | Formal designation, protected position, task charter, accessible route, published contact details and supervisory-authority communication | DPO operates with timely involvement, resources, access, independence and direct highest-management reporting | Role, coverage, capacity, conflicts or organisational structure changes |
| DPO not designated | Dated four-route assessment, facts and evidence, national-law source, decision owner and named privacy-responsibility role without the DPO title | Privacy work remains assigned without suggesting statutory designation | Activities, scale, data, monitoring, establishment footprint or national law changes |
Assign the no branch rather than filing it away. The named privacy owner needs authority and time to maintain the assessment, coordinate privacy work and raise trigger events. If voluntary designation is not intended, the title must avoid DPO. Organisation charts, notices and contact pages should preserve the same distinction so nobody is presented as holding the statutory office.
Review triggers should be event based as well as periodic. Reopen the decision when a new product changes core activities, a service expands population or geography, sensitive-data use becomes central, monitoring becomes more structured or persistent, an acquisition changes establishments, or relevant national law changes. A scheduled review date is useful, but it cannot substitute for those events.
Keep evidence proportionate and current. The purpose is to show why the answer followed from the facts at the time and how the organisation will notice when that answer may no longer hold.
Work the borderline cases
Borderline cases are manageable when the four routes remain separate and missing facts stay visible. These patterns show the structure of a decision record; they are neither numerical safe harbours nor sector-wide answers.
| Fact pattern | Route analysis | Decision and work product |
|---|---|---|
| A local retailer uses routine payroll, customer orders and a basic mailing list, with no behaviour profiling; the applicable national-law check finds no additional requirement | It is not classified as a public authority. The identified monitoring is neither a core large-scale operation nor large-scale sensitive core processing. The fourth route is documented as negative | Genuine no branch: record the facts, legal source and date; name a privacy owner without the DPO title; set change triggers |
| A digital platform’s main service continuously profiles a wide user population to rank and personalise interactions | The processing is integral to the service, organised and repeated, and its scale is assessed across population, data range, duration and geographic reach | The core large-scale regular and systematic monitoring route produces yes; designate and implement the protected role |
| A health-services processor handles special-category records at scale as the substance of its contracted service | Processor status does not remove the duty. Sensitive-data processing is core, and scale is assessed on the combined facts | The sensitive core processing route produces yes for the processor; document its own designation rather than relying on the controller’s DPO |
| A court reviews case files for adjudication and separately runs workforce, access-control and procurement systems | Judicial case work is analysed under the capacity exception. Other activities are not automatically covered by it and continue through the remaining routes | Separate the operations and preserve both analyses; designate if any non-excepted route applies |
| A statutory service body has mixed public and commercial functions, and counsel has not resolved its status under the relevant Member State law | The public-authority classification and possible additional national trigger remain open; the two activity-based routes can still be completed | National-law uncertainty branch: do not record a final no; assign the legal question, source search and decision date |
The patterns show why organisation size is a weak proxy. Legal status, core activity, processing nature and scale, monitoring, data categories and additional law do the real work. A sound record exposes those facts, marks unresolved dependencies and connects the conclusion to a concrete appointment or no-DPO work product.
Frequently asked questions
Do you need a data protection officer under GDPR?
A controller or processor needs a DPO if any Article 37 mandatory case applies or if applicable Union or Member State law requires one. The cases cover public authorities or bodies, apart from courts acting judicially, large-scale regular and systematic monitoring as a core activity, and large-scale core processing of Article 9 or Article 10 data 1.
Does employee count make a DPO mandatory?
No. Article 37 contains no employee-count or turnover trigger. The analysis follows legal status, core activities, scale, monitoring, relevant data categories and any additional rule in applicable Union or Member State law 1. Headcount may form part of the factual context, but it neither creates an automatic duty nor provides a safe harbour.
What counts as large-scale processing?
There is no single numerical threshold. Assess the number or proportion of people affected, the volume or range of data, processing duration or permanence, and geographical extent together 4. Record the evidence for those factors and connect it to the particular core activity. A number copied from another organisation or jurisdiction cannot replace the contextual judgement.
Can a DPO be outsourced or shared?
Yes. The DPO may be a staff member or provide the service under contract. A group can appoint one DPO when that person is easily accessible from each establishment; several public authorities or bodies may share one with regard to structure and size 1. Expertise, capacity, independence, confidentiality, direct reporting and freedom from conflicts remain necessary 2.
What happens if a DPO is appointed voluntarily?
Voluntary designation brings the DPO within the full framework for designation, position and tasks under Articles 37–39 4. The organisation must therefore provide the same expertise, resources, access, independence, reporting line and task charter required of a mandatory DPO 1,2,3. If that is not intended, use a privacy-responsibility title that does not represent the person as the designated DPO.
Can national law require a DPO in more cases?
Yes. Article 37(4) expressly permits Union or Member State law to require designation beyond the three Article 37(1) cases 1. Check the law applicable to the relevant entity and processing, preserve the exact source and date, and avoid generalising a national threshold across the EU. An unresolved national-law question should remain an open dependency, not be converted into a no.
Frequently Asked Questions
Do you need a data protection officer under GDPR?
Does employee count make a DPO mandatory?
What counts as large-scale processing?
Can a DPO be outsourced or shared?
What happens if a DPO is appointed voluntarily?
Can national law require a DPO in more cases?
Sources
Want this run on your business?
AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.
You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.