Skip to content

Do You Need a Data Protection Officer? UK Rules Explained

Do you need a data protection officer? Apply the UK GDPR tests, compare business examples, and record a defensible answer for either outcome.

A present-day workshop office with a light wood desk, a closed laptop connected to a charger, an open olive folder, a blank sheet with one unticked box, a lit lamp, an insulated bottle, a mesh chair and a window onto working machinery.
By AI Priority Map Editorial

A procurement questionnaire from a customer asks for the name of a data protection officer. A form from the insurer offers only yes or no, while nobody inside the business remembers making the decision. UK GDPR Article 37 supplies the test: a Data Protection Officer (DPO) is mandatory only in three defined cases, not whenever a form assumes that every responsible company has one 1. The useful answer is therefore more than a tick. It is a short, recorded decision that shows which activities you examined and what the business will do next.

Quick Answer. You need a data protection officer if one of three UK GDPR tests applies: public-authority processing, large-scale regular and systematic monitoring as a core activity, or large-scale core processing of special-category or criminal-offence data. If none applies, assign clear responsibility and record the no-DPO decision 1,6.

For organisations applying the EU GDPR, use the EU GDPR DPO threshold test.

The role behind the title

A DPO is an independent data-protection role with defined duties, safeguards and reporting access. The person informs and advises the organisation and monitors compliance through work including audits and training. They advise on and monitor data protection impact assessments (DPIAs), cooperate with the Information Commissioner's Office (ICO), and act as its contact point 3. In an illustrative 40-person firm, an external specialist could challenge a new tracking project and report concerns directly to senior management.

The title is not shorthand for whoever answers privacy emails. UK GDPR Article 38 requires timely involvement in data-protection issues, adequate resources, and reporting to the highest management level. The organisation cannot instruct the DPO how to perform the role, then dismiss or penalise that person for doing it 2. Independence has a concrete shape: a head of marketing cannot approve behavioural tracking as an executive and independently monitor the same decision as DPO.

There are exactly three routes to a mandatory DPO. UK GDPR Article 37(1) asks what the organisation is and what its core activities require; it does not ask how impressive the job title sounds 1.

Mandatory routePlain-language testConcrete instance
Public authority or bodyProcessing is carried out by a public authority or body, except a court acting in its judicial capacity.A body falling within the UK statutory definition checks the public-authority branch 1,5.
Large-scale monitoringCore activities require regular and systematic monitoring of people on a large scale.An ad-tech service built around behavioural tracking may meet the test 6.
Sensitive or offence data at scaleCore activities consist of large-scale processing of special-category data under Article 9 or criminal-offence data under Article 10.An illustrative specialist platform whose central service processes such records at scale may meet the test.

No separate headcount, turnover or company-size threshold appears in the test. An illustrative 40-person ad-tech business may need a DPO because monitoring is central to its service. A 400-person manufacturer may not, if it processes ordinary employee and business-contact information without profiling. Size matters only through the scale of the relevant processing, not through payroll numbers 1,6.

That distinction answers the five-employee question too. A very small team is not automatically exempt, and a large employer is not automatically caught. The work the organisation performs with personal data decides the route 1.

Core activities, scale and monitoring

Core activities are the processing operations that form an inextricable part of what the organisation actually does. Behavioural tracking by an online retailer can be core because the retailer uses it as part of how the service operates; standard payroll and ordinary HR records are support functions that most employers maintain 6. The practical question is whether the business could still deliver its central service in the same way without the processing under review.

Large scale has no numerical definition in the law. Regular and systematic monitoring also has no statutory numeric cut-off, so a spreadsheet cannot convert the test into a safe employee threshold 1,6. The organisation must examine the relevant processing honestly and preserve the reasoning, especially when scale sits near the boundary.

Phrase in the testWhat the phrase rules inWhat it rules out
Core activitiesProcessing embedded in the service, such as an online retailer's behavioural trackingStandard payroll or ordinary HR administration on the stated facts 6
Regular and systematic monitoringBehavioural advertising, profiling and scoring for credit, insurance or fraud, location tracking, loyalty programmes, connected devices or telematics, and CCTV operated at scaleOrdinary customer-contact handling without profiling on the stated facts
Large scaleThe scale of the processing operation under reviewA fixed payroll, turnover or headcount rule 1

Monitoring becomes easier to recognise when described as an activity rather than a legal phrase. A loyalty programme repeatedly observes purchases; telematics repeatedly records movement; behavioural advertising builds and uses profiles. Those are concrete examples of regular and systematic monitoring, although the DPO result still depends on whether the monitoring is both a core activity and large scale 1,6.

Special-category or criminal-offence data follows a separate route. A business can meet Article 37(1)(c) without running behavioural advertising if large-scale processing of that data is itself a core activity 1. The branches should be tested separately rather than blended into one vague impression of risk.

Worked decisions for ordinary businesses

The shortest honest answer to “who needs a DPO?” is “the organisations that meet one of the three tests”. Worked situations make that answer usable, provided the examples are treated as illustrative assessments rather than new thresholds.

Illustrative business profileLikely branchReasoned outcomeWhat happens next
40-person ad-tech firm whose central service tracks behaviour across a large audienceLarge-scale regular and systematic monitoring as a core activityLikely yes on the stated facts 1,6Appoint a DPO under the full role requirements and record the assessment.
Specialist platform whose core service processes special-category records on a large scaleLarge-scale special-category processing as a core activityLikely yes on the stated factsAppoint, resource and protect the DPO role; publish and communicate contact details.
400-person B2B manufacturer with ordinary employee and customer-contact records and no profilingNo trigger identifiedLikely no on the stated factsName an internal owner and record why the three mandatory tests were not met.
Individual professional holding ordinary client informationNo large-scale core processing identifiedUsually no on the stated factsKeep responsibility clear and retain the written decision.
Private supplier processing data under a contract with a public authorityPublic-authority status does not transfer through the contractNot automatically; run the supplier's own three-part test 5Examine the supplier's core monitoring and special-category or offence-data processing.

The table shows why a procurement question can mislead. A customer may ask for a DPO name because its form is standardised, but the customer's wording does not create a legal trigger. The supplier should answer with its recorded result: either the DPO contact details, or a clear statement that Article 37(1) was assessed and no mandatory route applied 1.

Borderline facts deserve an explicit note rather than a forced result. “We use data” is too broad; “behavioural tracking is the service and operates at scale” identifies the activity that matters. A changed service can change the conclusion even when headcount stays still.

Public bodies and private contractors take different routes

A contract with a public authority does not automatically make a private supplier a public authority or require the supplier to appoint its own DPO. Article 37(1)(a) binds the mandatory duty to processing by a public authority or body. Section 7 of the Data Protection Act 2018 defines which bodies hold that status for UK GDPR purposes 1,5.

Section 7 says “the following (and only the following)”: a FOIA 2000 public authority, a Scottish FOI public authority, ARIA, and a body designated in ministerial regulations 5. Even a body within that statutory list is a public authority only while performing a public-interest task or exercising official authority under section 7(2).

Section 7(2) is not a test for converting a private contractor into a public authority. A private supplier outside section 7(1) remains outside merely because a public-sector customer gave it work. The supplier applies its own Article 37(1) assessment, with particular attention to large-scale regular and systematic monitoring and large-scale core processing of special-category or criminal-offence data 1,5.

There is a separate good-practice point, not a hidden mandatory rule. Supervisory guidance treats voluntary DPO designation as good practice where a private organisation carries out a public task or exercises delegated public authority 6. If that organisation voluntarily designates a DPO, the normal requirements of Articles 37–39 apply in full 1,2,3.

The yes branch: appoint the role properly

A “yes” decision starts the appointment work; it does not finish it. The DPO can be a staff member or perform the tasks under a service contract, which allows outsourced and part-time arrangements. A group of undertakings may share one DPO if that person is easily accessible from each establishment 1.

Accessibility, resources and authority matter more than where the DPO sits on an organisation chart. UK GDPR Article 38 requires the organisation to involve the DPO properly and promptly in data-protection issues and provide adequate resources. The DPO must report to the highest management level, receive no instructions about performing the role, and face no dismissal or penalty for carrying out the tasks 2.

Conflicts arise when one person both determines the purposes and means of processing and is expected to monitor those decisions independently. Typical conflicting roles include managing director, COO, CFO, head of IT, head of HR and head of marketing 6. A small company may therefore use an external DPO because its senior staff already own the decisions the role would need to challenge.

The DPO's minimum task set is practical: inform and advise; monitor compliance, audits and training; advise on and monitor data protection impact assessments; cooperate with the ICO; and act as the ICO's contact point 3. Appointment also creates an outward-facing step. Article 37(7) requires the organisation to publish the DPO's contact details and communicate them to the ICO 1.

Voluntary designation is not a lighter version of the post. The ICO's position is that a voluntarily designated DPO receives the same Articles 37–39 framework as a mandatory one, including task, independence and contact requirements 1,2,3,6. A business that wants clear internal ownership without those consequences should record the responsibilities it assigns and avoid treating the owner as a voluntary DPO.

The no branch: own and record the answer

A “no” decision removes the duty to appoint a DPO, not the need for someone to own data protection. The ICO expects responsibility to be allocated clearly and treats a written assessment and decision as good practice. The accountability principle in UK GDPR Article 5(2) requires demonstrable compliance, so a reasoned record matters whichever branch the business reaches 6.

A useful record can stay concise. It identifies the organisation and date of review, describes the core activities considered, and walks through all three Article 37(1) routes. It then states the evidence behind the answer, names the person responsible for data protection, and records what change would trigger another review 1,6. For the illustrative manufacturer, the record would say that ordinary employee and customer-contact information was reviewed and that no profiling was identified. It would also record that no large-scale core monitoring, and no large-scale core processing of special-category or criminal-offence data, was found.

The named owner then has a concrete job: keep the assessment available for the next tender, insurer form or customer audit and notice when the underlying activities change. Calling that person a data-protection lead does not alter the Article 37 test. The essential point is that responsibility and the decision are visible rather than resting in somebody's inbox.

AI Priority Map's GDPR Accountability Documentation service includes the DPO-requirement assessment as a recorded, defensible decision. That is the same artefact the no branch calls for, mentioned here as context rather than as a substitute for applying the test.

The unchanged law and the penalty tier

The Data (Use and Access) Act 2025 did not replace the DPO model or alter the UK GDPR provisions governing it 7. An earlier proposal would have replaced DPOs with a “senior responsible individual”, but that proposal did not become law. Organisations should continue applying Articles 37–39 as written 1,2,3.

Getting the designation, position or tasks wrong can engage the standard maximum penalty tier. Infringements of Articles 37–39 can attract up to £8.7 million or 2 % of total worldwide annual turnover, whichever is higher 4. The number is a legal ceiling, not a substitute for the practical question facing an owner: can the business show how it tested the duty and then followed the branch it reached?

The sensible control is proportionate and visible. A short assessment that engages with the actual processing is more defensible than a confident yes or no based only on employee count. Where a DPO is required, the appointment must work in practice; where none is required, the recorded assessment explains why.

Your ten-minute decision checklist

The decision can be run in ten minutes when the business already knows what its central services do with personal data. If the answers expose uncertainty about the processing itself, the checklist has still done useful work: it has identified what must be clarified before a defensible result exists.

  1. Public-authority status: Is the organisation itself within the statutory public-authority or public-body definition, rather than merely supplying one under contract 1,5?
  2. Core activities: Which processing operations are inextricable from the central service, and which are ordinary support functions such as standard payroll or HR records 6?
  3. Monitoring: Do those core activities involve behavioural advertising, profiling or scoring, location tracking, loyalty programmes, connected devices, telematics or CCTV at scale ?
  4. Scale: Is the relevant monitoring large scale, assessed from the processing rather than from a company-size shortcut ?
  5. Data type: Do core activities consist of large-scale processing of special-category data under Article 9 or criminal-offence data under Article 10 ?
  6. Decision: Does any one of the three Article 37(1) routes apply? One route is enough for a mandatory DPO.
  7. Yes branch: Can an independent, adequately resourced DPO report to the highest management level without a conflicting management role 2?
  8. Appointment mechanics: Will the DPO be an employee, an outsourced or part-time provider, or an accessible shared DPO for a group ?
  9. No branch: Who owns data protection, where will the reasoned assessment be kept, and what business change prompts review ?
  10. External answer: If the next tender arrives tomorrow, can the business provide DPO contact details or its recorded no-DPO conclusion without starting again ?

A defensible answer for the next request

The final output is one of two complete answers. Yes: one mandatory route applies; the organisation appoints a suitably independent and resourced DPO, enables the Article 39 tasks, publishes contact details and tells the ICO 1,2,3. No: no route applies; the organisation names an owner, records the three-part assessment and keeps the conclusion available for the next outside question 6.

Neither branch is permanent when the facts change. A manufacturer that later makes large-scale behavioural profiling central to a service must run the test against the new activity. A private contractor does not become a public authority simply because the customer is one 1,5,6. Employee count can safely be ignored as a standalone threshold; the actual core processing cannot.

The tender or insurance form can now be answered in one email. More importantly, the business can show the reasoning behind the answer instead of treating a yes/no box as legal advice.


Last updated: 26 August 2026.

Frequently Asked Questions

Does every UK business have to appoint a DPO?
No. A UK business must appoint a Data Protection Officer only when one of the three tests in UK GDPR Article 37(1) applies. Those tests concern public-authority processing, except a court acting in its judicial capacity, large-scale regular and systematic monitoring as a core activity, or large-scale core processing of special-category or criminal-offence data. Headcount, turnover and company size are not separate triggers. [1]
Is there a headcount threshold for needing a DPO?
No headcount, turnover or company-size threshold decides whether a DPO is mandatory. The assessment concerns the organisation's core processing activities and whether the relevant processing is large scale. An illustrative 40-person ad-tech firm may meet the monitoring test, while a 400-person manufacturer handling ordinary contacts without profiling may not. [1][6]
Does contracting with a public authority require our own DPO?
No. A private supplier does not become a public authority merely because it processes data under a public-sector contract. The supplier applies its own UK GDPR Article 37(1) test, paying particular attention to large-scale monitoring and large-scale processing of special-category or criminal-offence data. Public-authority status has the specific meaning set by section 7 of the Data Protection Act 2018. [1][5]
Can a Data Protection Officer be outsourced or part-time?
Yes. UK GDPR Article 37 allows a DPO to be a staff member or to perform the role under a service contract, so an outsourced or part-time arrangement is lawful. A group may share one DPO when that person is easily accessible from every establishment. Whichever model is used, the independence, resources and task requirements still apply. [1][2][3]
What happens if we appoint a DPO voluntarily?
A voluntary appointment is allowed, but the title carries the full UK GDPR requirements. The Information Commissioner's Office says Articles 37–39 apply in the same way as they do to a mandatory DPO. The organisation must therefore protect the role's independence, provide resources, avoid conflicts, support the required tasks, publish contact details and communicate them to the ICO. [1][2][3][6]
Who should not act as our organisation's DPO?
A conflict arises where one person both determines the purposes and means of processing and is expected to monitor those same decisions independently. Typical conflicting posts include managing director, COO, CFO, head of IT, head of HR and head of marketing. UK GDPR Article 38(6) lets a DPO hold other duties provided the organisation ensures they create no conflict of interests, so the test is real decision-making power, not job title. [2][6]
What should we do if a DPO is not required?
Allocate data-protection responsibility clearly and keep a written assessment explaining why none of the mandatory tests applies. The record should show the activities considered and the conclusion reached, so the business can demonstrate that it made a reasoned decision. The Information Commissioner's Office treats recording the assessment as good practice even when the answer is no. [6]
Did the Data (Use and Access) Act change DPO rules?
No. The Data (Use and Access) Act 2025 left the UK GDPR provisions for Data Protection Officers unchanged. An earlier proposal would have replaced DPOs with a senior responsible individual, but that proposal did not become law. Organisations should still apply UK GDPR Articles 37–39. [1][2][3][7]

Sources

  1. 1.UK GDPR Article 37legislation.gov.uk · 2026
  2. 2.UK GDPR Article 38legislation.gov.uk · 2026
  3. 3.UK GDPR Article 39legislation.gov.uk · 2026
  4. 4.UK GDPR Article 83 (penalty tiers)legislation.gov.uk · 2026
  5. 5.Data Protection Act 2018, section 7 — Meaning of public authority and public bodylegislation.gov.uk · 2026
  6. 6.Data protection officers — guidanceInformation Commissioner’s Office · 2026
  7. 7.Data (Use and Access) Act 2025legislation.gov.uk · 2026

Want this run on your business?

AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.

Start your audit

You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.