Skip to content

Data Protection Officer Requirements: When Is a DPO Mandatory?

Data protection officer requirements use three GDPR tests and national law. Decide whether to appoint a DPO, then document and revisit the outcome.

A tactile mind map sends four distinct routes through one decision hub to an appointment token or a recorded assessment.
By AI Priority Map Editorial

Data protection officer requirements begin with the processing that a controller or processor actually carries out. Employee numbers and turnover do not settle the question. A defensible decision tests four legal routes against named evidence, reaches a clear yes or no, and leaves a record that another decision-maker can follow without reconstructing the analysis.

Quick Answer Data protection officer requirements do not turn on employee numbers or turnover. A controller or processor must test three Article 37 cases and any applicable Member State law. A yes requires a protected, properly supported DPO. A no requires a dated assessment, named privacy owner and review triggers as facts or law change.

Last updated: 26 August 2026

Start with four routes, not headcount

Article 37 gives controllers and processors the same designation obligation when a mandatory route applies. Frame one assessment around one legal entity and its processing activities. Capture whether it acts as controller, processor or both; what each operation does; whom it affects; how far it reaches; and which national law applies. A group label or organisation chart cannot answer those questions.

The first three routes come from Article 37(1). The fourth is separate and equally capable of producing a mandatory result under Union or Member State law. A yes on any route ends the necessity analysis; it does not end the implementation work.

RouteQuestion to decideEvidence to retainResult if yes
Public authority or bodyIs the controller or processor a public authority or body under the applicable law, and is the courts exception relevant?Legal status, function, national definition and capacity in which a court actsDesignate a DPO
Core monitoring at scaleDo core activities require regular and systematic monitoring of people on a large scale?Activity map, monitoring method, population, duration and reachDesignate a DPO
Sensitive core processing at scaleDo core activities consist of large-scale processing of Article 9 data or Article 10 data?Data categories, activity purpose, population, volume, duration and reachDesignate a DPO
Additional legal requirementDoes applicable Union or Member State law require designation in another case?Jurisdiction analysis, cited legal source, effective rule and scopeDesignate a DPO

The diagram first asks whether the public-authority route applies, subject to the judicial-capacity exception for courts 1. If not, it tests large-scale core monitoring and large-scale core processing of Article 9 or Article 10 data, each of which independently leads to designation. A negative result on all three still proceeds through the distinct national-law branch under Article 37(4). The final branch is therefore either a properly implemented DPO role or a recorded no-DPO assessment that is reviewed when the facts or law change 2,3.

Complete all four lines even when the first one produces a yes, because the record may later support coverage, resourcing and group decisions. Do not turn the routes into a score where weak indicators cancel a satisfied test. Each is an independent legal gateway, supported by its own facts and conclusion.

Test the three Article 37 cases

The public-authority case is the most direct. Where processing is carried out by a public authority or body, a DPO is mandatory. Courts are excepted only when acting in their judicial capacity; the exception does not convert every operation carried out by a court into judicial activity 1. The organisation must distinguish adjudication from its other functions rather than treating its institutional name as the whole answer.

The second case applies where the controller’s or processor’s core activities consist of processing operations that, by their nature, scope or purposes, require regular and systematic monitoring of data subjects on a large scale 1. All elements matter. Occasional monitoring that is peripheral to delivering the organisation’s key service does not satisfy the same description as continuous monitoring embedded in that service.

The third case applies where core activities consist of large-scale processing of special categories of personal data under Article 9 or data about criminal convictions and offences under Article 10 1. The route is not triggered merely because a normal supporting process contains some sensitive data. Equally, describing a sensitive-data operation as administration does not make it peripheral when the operation is integral to the service delivered.

Controllers and processors must each decide their own position. Map the controller’s purposes and the processor’s contracted operations separately, then test the routes for each entity. One party’s DPO may support practical cooperation, but that appointment does not discharge the other party when its own activities satisfy a route. A contract cannot transfer the statutory test away 1.

There is no Article 37 employee-count or turnover threshold. Those figures may help describe operational capacity or provide context for scale, but neither produces an automatic yes or no. A compact organisation can conduct extensive monitoring; a much larger employer may have no core activity that falls within the second or third case.

Public authority is a national question

The GDPR uses “public authority or body” without defining the expression. The assessment therefore needs the relevant Union and Member State legal setting, including how the entity was created, what public functions it performs and which national rule determines its status. A definition borrowed from another jurisdiction is not a safe substitute 4.

This boundary matters for hybrid bodies, statutory corporations, professional organisations and entities delivering public services under contract. Funding, ownership and public purpose may be evidence, yet none is a universal shortcut. The assessment should quote no borrowed definition; instead, it should identify the applicable source, set out the relevant characteristics and explain the classification reached under that source.

For a court, record the capacity in which the processing occurs. Case-file adjudication may sit inside the judicial-capacity exception, while workforce management, building access, procurement or public communications may require separate analysis. The exception in Article 37(1)(a) is framed around courts acting in a particular capacity, not an institution-wide exemption 1.

An unresolved classification is not a no. Mark it as an open legal dependency, name the question, owner and target date, and avoid approving a final negative assessment while it remains material. Work need not stop: the organisation can complete the other three routes and preserve every fact already established.

Define core activity, scale and monitoring

“Core activities” are the key operations necessary to achieve the controller’s or processor’s objectives. Supporting functions such as payroll or routine IT support are normally ancillary, even though they process personal data. By contrast, data processing can be core when the service could not realistically be delivered without it; processing does not have to be the organisation’s stated commercial purpose to be integral 4.

Large scale has no universal numerical safe harbour. WP243 points to a combined assessment of the number of people concerned, either as an absolute number or proportion of a relevant population; the volume or range of data; the duration or permanence of processing; and its geographical extent 4. The conclusion should show those inputs, not announce that a made-up number is always safe.

Regular monitoring can be ongoing or occur at intervals, recur at fixed times, repeat constantly or periodically, or follow a defined programme. Systematic monitoring is organised, methodical, planned, part of a strategy, or carried out through a system for collecting data 4. Examples may include behaviour tracking, connected-device observation, profiling for decisions, loyalty programmes or location tracking. The examples illuminate the working meaning; they do not remove the need to test core activity and scale.

Evidence should be assembled per processing operation, not copied from an enterprise-wide data total. A useful evidence sheet links the service map to categories and approximate proportions of people affected, data fields, geographical coverage, monitoring cadence, retention duration, decision logic and the process that depends on it. Reasoned ranges are more candid than unsupported precision.

Scale is contextual, but context is not permission to decide by intuition. The same record count can mean something different in a regional service covering most of its relevant population and in an isolated, short-lived exercise. Preserve the underlying number or range, the population against which it is judged, and the duration and reach that make the conclusion intelligible.

Check the Member State law branch

Article 37(4) allows Union or Member State law to require a DPO in cases beyond Article 37(1) 1. This is the fourth route, not an optional legal footnote. A complete EU assessment therefore identifies the Member State law relevant to each establishment and processing operation, checks the rule in force for that situation, and retains the exact source used.

No national threshold should be generalised across the EU. Rules may differ in triggers, terminology, covered entities and interaction with sector law. For several establishments, use a jurisdiction matrix rather than one group-wide sentence. Give each entity and processing operation its own law checked, source date, conclusion, unresolved advice point and review trigger.

Operating under UK GDPR? Use the UK DPO guide.

That link marks a jurisdiction boundary. It does not supply an EU definition, and the UK statutory definition must not be imported into an EU Article 37 assessment. The EU file should stand on the Union rule and the Member State sources that actually apply.

When the national-law answer remains uncertain, place the assessment in “decision pending” status. Record who will obtain the interpretation, the exact scope question and the update date. The organisation may choose interim controls while the point is resolved, but it should not issue a final no that silently depends on an unchecked branch.

A voluntary DPO is still a DPO

An organisation may designate a DPO even when neither Article 37(1) nor an additional legal rule requires one 1. That choice can be valuable, particularly where a credible independent adviser and supervisory-authority contact would improve governance. But the title carries the whole framework: voluntary designation activates the requirements for the DPO’s designation, position and tasks under Articles 37–39 4.

The practical trap is using “DPO” as an honorary label while withholding the role’s protections or capacity. Before announcing a voluntary appointment, run the same readiness check used for a mandatory one: expertise, timely involvement, resources, access, independence, protection from instructions and penalties, direct highest-management reporting, confidentiality and no conflict 1,2. The statutory task charter must also be ready 3.

If the organisation reaches a defensible no and does not intend to assume those obligations voluntarily, assign privacy responsibility without the DPO title. A privacy lead, compliance owner or information-governance manager can coordinate records, requests, training and reviews. The role description should expressly say that the person is not the designated DPO and should avoid presenting them as such externally.

That alternative is not a way to evade a mandatory route. It is the honest governance design only after all four routes have been tested and found not to require designation.

If yes, make the role real

The yes work product begins with a formal designation record approved by the appointing controller or processor. It identifies the start date, whether the DPO is an employee or works under a service contract, the professional qualities and expert knowledge considered, and every entity or establishment covered. A group may use one DPO only when that person is easily accessible from each establishment 1. Several public authorities or bodies may share one with regard to structure and size.

Test accessibility before signing a shared arrangement. Staff and data subjects must know how to reach the DPO; relevant languages, time zones and communication channels must work; and planned capacity must cover every entity. A single email address does not cure an arrangement in which the DPO cannot engage promptly with an establishment.

Article 38 turns the designation into a functioning position. The controller or processor must involve the DPO properly and in a timely manner in all personal-data issues, provide the resources needed for the tasks, allow access to personal data and processing operations, and support maintenance of expert knowledge 2. Governance should specify which projects, incidents, decisions and committees trigger involvement.

Independence must be designed, not merely promised. The DPO receives no instructions on how to perform the statutory tasks, must not be dismissed or penalised for performing them, and reports directly to the highest management level 2. Other duties are possible only if they create no conflict of interests. A conflict check should look at whether the person determines the purposes or means of processing, including through a senior operational role.

Data subjects need an accessible contact route for questions about processing and their rights. The DPO is bound by secrecy or confidentiality under applicable Union or Member State law 2. The organisation must publish the DPO’s contact details and communicate them to the supervisory authority 1. Publication can focus on functional contact details; the legal requirement is accessibility, not unnecessary exposure of personal details.

Article 39 supplies the minimum task charter. The DPO informs and advises the controller or processor and employees; monitors compliance, policies, allocation of responsibilities, awareness, training and audits; advises on requested data protection impact assessments and monitors their performance; cooperates with the supervisory authority; and acts as its contact point 3. The DPO performs those tasks with due regard to processing risk, considering nature, scope, context and purposes.

Appointment controlEvidence of implementationFailure signal
Formal designation and scopeSigned record naming entities, basis and start dateAn informal title with no appointing act
Expertise and capacitySelection rationale, service levels, cover and development planOne shared contact unable to serve every establishment
Timely involvement and accessGovernance triggers, committee access and information rightsDPO learns of projects only after decisions
Independence and reportingNo-instructions clause, protected escalation and highest-level reportOperational manager can direct findings or penalise challenge
Confidentiality and no conflictConfidentiality duty and recorded conflict assessmentDPO also decides purposes or means of processing
Accessible contact and notificationPublished route and communication record to the supervisory authorityContact is hidden, stale or unusable
Article 39 task charterAdvice, monitoring, training, audit, DPIA and authority-contact recordsRole is reduced to occasional policy review

Designation is not a certificate of compliance. The finished product is an operating role: appointment evidence, protections, access, decision triggers, task records and a contact route that together demonstrate how the DPO works over time.

If no, record the assessment

A no-DPO conclusion also needs a finished work product. Put the assessment date, covered controller or processor, decision owner and processing inventory at the top. Beneath them, give each Article 37(1) route and the Member State law route its own facts, evidence reference and conclusion. Cite the national legal source actually checked 1,4.

The record should make the reasoning reproducible. For monitoring and sensitive-data cases, show why the activity is or is not core, how scale was assessed, which data and people were included, the duration and geographical reach, and whether monitoring is regular and systematic. A bare “not large scale” conclusion gives a reviewer nothing to test.

The public-authority line should state the applicable definition and classification. The national-law line should name the jurisdiction, source and result. If either depends on unresolved legal advice, the overall status should show that dependency rather than presenting a clean no.

OutcomeMinimum work productOperating consequenceReview trigger
DPO required or voluntarily designatedFormal designation, protected position, task charter, accessible route, published contact details and supervisory-authority communicationDPO operates with timely involvement, resources, access, independence and direct highest-management reportingRole, coverage, capacity, conflicts or organisational structure changes
DPO not designatedDated four-route assessment, facts and evidence, national-law source, decision owner and named privacy-responsibility role without the DPO titlePrivacy work remains assigned without suggesting statutory designationActivities, scale, data, monitoring, establishment footprint or national law changes

Assign the no branch rather than filing it away. The named privacy owner needs authority and time to maintain the assessment, coordinate privacy work and raise trigger events. If voluntary designation is not intended, the title must avoid DPO. Organisation charts, notices and contact pages should preserve the same distinction so nobody is presented as holding the statutory office.

Review triggers should be event based as well as periodic. Reopen the decision when a new product changes core activities, a service expands population or geography, sensitive-data use becomes central, monitoring becomes more structured or persistent, an acquisition changes establishments, or relevant national law changes. A scheduled review date is useful, but it cannot substitute for those events.

Keep evidence proportionate and current. The purpose is to show why the answer followed from the facts at the time and how the organisation will notice when that answer may no longer hold.

Work the borderline cases

Borderline cases are manageable when the four routes remain separate and missing facts stay visible. These patterns show the structure of a decision record; they are neither numerical safe harbours nor sector-wide answers.

Fact patternRoute analysisDecision and work product
A local retailer uses routine payroll, customer orders and a basic mailing list, with no behaviour profiling; the applicable national-law check finds no additional requirementIt is not classified as a public authority. The identified monitoring is neither a core large-scale operation nor large-scale sensitive core processing. The fourth route is documented as negativeGenuine no branch: record the facts, legal source and date; name a privacy owner without the DPO title; set change triggers
A digital platform’s main service continuously profiles a wide user population to rank and personalise interactionsThe processing is integral to the service, organised and repeated, and its scale is assessed across population, data range, duration and geographic reachThe core large-scale regular and systematic monitoring route produces yes; designate and implement the protected role
A health-services processor handles special-category records at scale as the substance of its contracted serviceProcessor status does not remove the duty. Sensitive-data processing is core, and scale is assessed on the combined factsThe sensitive core processing route produces yes for the processor; document its own designation rather than relying on the controller’s DPO
A court reviews case files for adjudication and separately runs workforce, access-control and procurement systemsJudicial case work is analysed under the capacity exception. Other activities are not automatically covered by it and continue through the remaining routesSeparate the operations and preserve both analyses; designate if any non-excepted route applies
A statutory service body has mixed public and commercial functions, and counsel has not resolved its status under the relevant Member State lawThe public-authority classification and possible additional national trigger remain open; the two activity-based routes can still be completedNational-law uncertainty branch: do not record a final no; assign the legal question, source search and decision date

The patterns show why organisation size is a weak proxy. Legal status, core activity, processing nature and scale, monitoring, data categories and additional law do the real work. A sound record exposes those facts, marks unresolved dependencies and connects the conclusion to a concrete appointment or no-DPO work product.

Frequently asked questions

Do you need a data protection officer under GDPR?

A controller or processor needs a DPO if any Article 37 mandatory case applies or if applicable Union or Member State law requires one. The cases cover public authorities or bodies, apart from courts acting judicially, large-scale regular and systematic monitoring as a core activity, and large-scale core processing of Article 9 or Article 10 data 1.

Does employee count make a DPO mandatory?

No. Article 37 contains no employee-count or turnover trigger. The analysis follows legal status, core activities, scale, monitoring, relevant data categories and any additional rule in applicable Union or Member State law 1. Headcount may form part of the factual context, but it neither creates an automatic duty nor provides a safe harbour.

What counts as large-scale processing?

There is no single numerical threshold. Assess the number or proportion of people affected, the volume or range of data, processing duration or permanence, and geographical extent together 4. Record the evidence for those factors and connect it to the particular core activity. A number copied from another organisation or jurisdiction cannot replace the contextual judgement.

Can a DPO be outsourced or shared?

Yes. The DPO may be a staff member or provide the service under contract. A group can appoint one DPO when that person is easily accessible from each establishment; several public authorities or bodies may share one with regard to structure and size 1. Expertise, capacity, independence, confidentiality, direct reporting and freedom from conflicts remain necessary 2.

What happens if a DPO is appointed voluntarily?

Voluntary designation brings the DPO within the full framework for designation, position and tasks under Articles 37–39 4. The organisation must therefore provide the same expertise, resources, access, independence, reporting line and task charter required of a mandatory DPO 1,2,3. If that is not intended, use a privacy-responsibility title that does not represent the person as the designated DPO.

Can national law require a DPO in more cases?

Yes. Article 37(4) expressly permits Union or Member State law to require designation beyond the three Article 37(1) cases 1. Check the law applicable to the relevant entity and processing, preserve the exact source and date, and avoid generalising a national threshold across the EU. An unresolved national-law question should remain an open dependency, not be converted into a no.

Frequently Asked Questions

Do you need a data protection officer under GDPR?
A controller or processor needs a DPO when it meets any Article 37 mandatory case or when applicable Union or Member State law requires one. The cases cover public authorities or bodies, with a courts exception, large-scale regular and systematic monitoring as a core activity, and large-scale core processing of specified sensitive or criminal-offence data.
Does employee count make a DPO mandatory?
No. The GDPR does not set an employee-count or turnover trigger for DPO designation. The decision follows the nature of the organisation, its core processing activities, the scale and character of relevant processing, and any additional rule in applicable national law. Headcount may inform practical scale evidence, but it does not decide the legal test.
What counts as large-scale processing?
The GDPR provides no numerical safe harbour. Assess the number or proportion of people affected, the volume and range of data, how long processing continues, and its geographical reach. Record the evidence behind each factor and consider them together, alongside whether the relevant processing is a core activity. A single number cannot replace that judgement.
Can a DPO be outsourced or shared?
Yes. A DPO may be a staff member or work under a service contract. A group may use one DPO if the person is easily accessible from every establishment. Several public authorities or bodies may also share one, taking account of their organisational structure and size. Accessibility, capacity, expertise, independence and absence of conflicts still matter.
What happens if a DPO is appointed voluntarily?
A voluntary DPO is not an informal title. Once the organisation designates someone as its DPO, the role must meet the GDPR framework for designation, position and tasks. If that commitment is not intended, assign a clearly named privacy-responsibility role instead, without using the protected DPO title or suggesting that a statutory designation has occurred.
Can national law require a DPO in more cases?
Yes. Article 37 expressly allows Union or Member State law to require a DPO beyond the three cases in Article 37(1). Check the data protection law that applies to the relevant establishment and processing. Record the source, date and conclusion rather than assuming a threshold from another country or treating the national-law branch as an optional footnote.

Sources

  1. 1.Regulation (EU) 2016/679 — Article 37EUR-Lex · 2016
  2. 2.Regulation (EU) 2016/679 — Article 38EUR-Lex · 2016
  3. 3.Regulation (EU) 2016/679 — Article 39EUR-Lex · 2016
  4. 4.Guidelines on Data Protection Officers (WP243 rev.01)Article 29 Working Party · 2017

Want this run on your business?

AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.

Start your audit

You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.