Clym Logo

What Is a Data Protection Officer (DPO), and Do You Need One?

Published
AS
AuthorAdam Safar
8 min read

DPO requirements and responsibilities

A Data Protection Officer (DPO) advises on and monitors data protection compliance. Learn when GDPR Article 37 requires a DPO and what the role involves.

Summarize full article with:

A Data Protection Officer (DPO) is an independent privacy professional who advises an organization on its data protection obligations and monitors its compliance with the GDPR.

Not every organization needs one. Under GDPR Article 37, appointing a DPO is generally required if you are a public authority, regularly and systematically monitor individuals on a large scale, or process certain sensitive or criminal-offence data on a large scale as part of your core activities.

This guide explains what a DPO does, when one is required, and how to determine whether your organization needs one.

Key takeaways
  • DPO stands for Data Protection Officer, an independent adviser who monitors GDPR compliance.

  • GDPR Article 37 requires a DPO only for public authorities, large-scale monitoring, or large-scale special category or criminal-offence data processing.

  • There is no employee-count or revenue threshold. What matters is your organization's core activities.

  • A DPO must be independent and cannot hold a role that decides how data is processed.

  • DPOs can be internal employees or outsourced through DPO-as-a-service arrangements.

  • Failing to appoint a required DPO, or undermining a DPO's independence, can trigger fines up to 10 million euros or 2% of global turnover.  

What does DPO mean?

DPO stands for Data Protection Officer. A Data Protection Officer is an independent data protection expert who advises an organization on its privacy obligations and monitors compliance with laws such as the GDPR.

Unlike a general privacy manager, a DPO holds a legally protected position: independent, protected from dismissal for doing the job properly, and focused on monitoring and advising rather than deciding how data is processed.

Do I need a DPO under GDPR Article 37?

You need to appoint a DPO under GDPR Article 37 if at least one of three conditions applies to your organization:

  1. You are a public authority or body.

  2. Your core activities require regular and systematic monitoring of individuals on a large scale.

  3. Your core activities involve large-scale processing of special category data or data relating to criminal convictions and offences.


If none apply, appointing a DPO is optional, though still common practice for accountability. The next sections unpack what "large scale," "core activities," and "regular and systematic monitoring" mean, since that is where most of the uncertainty lives.

Public authorities and bodies

Any public authority or body processing personal data must appoint a DPO, except courts acting in their judicial capacity.

Large-scale regular and systematic monitoring

This covers organizations whose core activity requires monitoring people regularly, systematically, and at scale, not occasional or incidental monitoring.

Large-scale special category or criminal-offence data

This applies when an organization's core activities involve large-scale processing of special category data under Article 9, such as health or biometric data, or personal data relating to criminal convictions and offences under Article 10.

What does "large scale" mean under GDPR?

GDPR does not set one numerical threshold for large scale. Regulators, including the ICO, instead weigh several factors together:

  • Number or proportion of individuals affected

  • Volume of data and range of data types involved

  • Duration or permanence of the processing

  • Geographic extent of the processing

No single factor decides the answer. A local clinic with a few thousand patient records is different from a national health platform processing millions.

What are "core activities"?

Core activities are the operations central to your organization's objectives, not processing that merely supports them. A hospital's core activity is patient care, so its health data processing is core. A retailer's core activity is selling goods, so its payroll processing is ancillary, even though it involves personal data.

The EDPB's guidance for small and medium enterprises walks through more examples of this distinction.

What counts as regular and systematic monitoring?

Regulators treat monitoring as regular and systematic when it is ongoing, planned, and tracks individuals over time rather than happening once. Common examples include:

  • Online behavioral tracking and profiling

  • Location tracking

  • Loyalty programs that analyze behavior

  • Connected-device and telematics monitoring

  • Large-scale CCTV surveillance

Quick DPO requirement check

You probably need a DPO if:

  • You are a public authority or public body.

  • Monitoring people is central to your business and happens systematically at scale.

  • Processing health, biometric, genetic, or similar sensitive data at scale is core to your business.

  • Processing criminal-conviction or offence data at scale is part of your core activities.

You may not need a DPO if:

  • Personal data processing is incidental to your primary business.

  • Sensitive data is processed only occasionally or on a limited scale.

  • Your ordinary activities do not involve large-scale monitoring.

Still uncertain? Revisit the large-scale, core activities, and monitoring definitions above before deciding.

Scenario

DPO required?

Example

Public authority or body

Yes, mandatory

Government agency, public hospital

Large-scale systematic monitoring as a core activity

Yes, mandatory

Ad-tech platform, telematics provider

Large-scale special category data processing

Yes, mandatory

Health insurer, biometric ID vendor

Occasional or small-scale personal data processing

No, optional

Local retailer, small B2B software company

Ancillary data processing not tied to core business

No, optional

Manufacturer, professional services firm

What does a Data Protection Officer do?

GDPR Articles 38 and 39 set out the DPO's statutory duties.

GDPR-defined DPO responsibilities

  • Inform and advise the organization and its staff on data protection obligations.

  • Monitor compliance with GDPR and internal policies.

  • Advise on Data Protection Impact Assessments (DPIAs) for high-risk processing.

  • Cooperate with supervisory authorities and act as their point of contact.

  • Act as the contact point for data subjects on matters related to their rights.

Other activities a DPO may support

Organizations often ask their DPO to help with related work too, though GDPR does not assign these as statutory duties:

DPO independence and qualifications

GDPR does not prescribe specific qualifications, but Article 37(5) requires "expert knowledge of data protection law and practices." Most organizations look for credentials such as CIPP/E, CIPM, or BCS Data Protection Practitioner, alongside relevant experience in IT security, legal, or compliance.

Independence is not optional. A DPO cannot hold a role that determines the purposes and means of processing, so pairing the position with Head of IT, Head of Marketing, or a similar decision-making role is generally a conflict of interest under EDPB guidance. The Court of Justice of the EU has since weighed in on the same question, reinforcing that a DPO cannot review decisions they were involved in making.

This is a live enforcement issue. When 25 European supervisory authorities reviewed DPO designation and independence in 2023, the resulting EDPB report flagged conflicts of interest, under-resourcing, and inadequate training as recurring problems.

Internal vs. outsourced DPO

GDPR Article 37(6) allows organizations to appoint either an internal employee or an external provider as DPO. Both are equally valid; the right choice depends on your size, processing volume, and budget.

Internal DPO

Outsourced DPO

Best for

Larger organizations with complex, ongoing processing

SMEs and start-ups with lower processing volume

Independence

Requires careful separation from conflicting duties

Can reduce internal conflicts, but independence must still be assessed

Cost structure

Full-time or part-time salary and benefits

Retainer or project-based fee

Availability

Embedded in daily operations

Scheduled access, varies by provider

Whichever model you choose, your DPO still needs practical tools: tracking consent choices, keeping policies current, and responding to requests on time.

DPO vs. controller vs. processor: what's the difference?

These roles get confused constantly, and they are not interchangeable. A data controller decides why and how data is processed. A data processor processes data on the controller's behalf. The DPO is neither. It is an independent adviser appointed by either one.

Role

Who they are

Primary obligation

Data controller

Entity that determines purposes and means of processing

Establish a lawful basis, respond to data subject rights, notify breaches

Data processor

Entity processing data on behalf of the controller

Process only on documented instructions, implement appropriate security

Data Protection Officer

Independent adviser and monitor appointed by controller or processor

Inform, advise, and monitor compliance, liaise with supervisory authorities

DPO vs. Chief Privacy Officer (CPO)

A Chief Privacy Officer typically sits in senior leadership, setting privacy strategy and weighing it against commercial priorities. A DPO is narrower and legally protected: independent, and focused on monitoring and advising rather than deciding.

Smaller organizations sometimes combine both titles in one person, but only where no conflict of interest exists.

What happens if you do not appoint a required DPO? GDPR penalties explained

Failing to appoint a DPO when Article 37 requires one, and restricting a DPO's independence once appointed, both fall under the same GDPR penalty tier. Article 83(4) sets fines up to 10 million euros or 2% of global annual turnover, whichever is higher, for violations of Articles 25 through 39, which includes the DPO appointment and independence rules in Articles 37 and 38.

The higher tier, up to 20 million euros or 4% of turnover, applies to separate categories such as core processing principles and data subject rights, not DPO appointment itself.

Enforcement targeting missing DPO appointments specifically has been rare, but the 2023 coordinated action mentioned above suggests more scrutiny is coming.

Do other privacy laws require DPOs?

The DPO concept extends beyond GDPR. Brazil's LGPD requires an equivalent role called the "Encarregado," (Supervisor) and South Africa's POPIA uses the term "Information Officer." In the United States, no federal or state law currently mandates a dedicated DPO role, though sector-specific laws such as HIPAA require a designated compliance official instead.

Common DPO mistakes to avoid

The most common DPO mistakes are not about picking the wrong person. They are about how the role gets set up. Based on regulators' 2023 findings, watch for:

  • Not appointing a DPO at all, even when Article 37 clearly requires one.

  • Under-resourcing the DPO, leaving them without the time, budget, or team to do the job.

  • Skipping ongoing training, so the DPO's knowledge falls behind new regulations and technologies.

  • Creating conflicts of interest by pairing the DPO role with a decision-making function such as IT or marketing leadership.

  • Failing to give the DPO the access, resources, and organizational support needed to perform their responsibilities.

How Clym supports your privacy program

Clym is not a substitute for a DPO and does not provide legal advice. It takes the operational weight off whoever holds that role, an internal hire or an outsourced provider, across 190+ regulations.

That leaves your DPO more time for the judgment calls only a person can make: risk assessments, staff training, and liaising with regulators.

Many teams ask about a DPO before they even evaluate a cookie consent management platform. The two decisions are related but separate: one is about who oversees your privacy program, the other is about the tooling that operates it.

Conclusion

Whether you need a DPO depends less on your company's size than on what it does with personal data. Article 37 focuses on public bodies, large-scale regular and systematic monitoring, and large-scale processing of special category or criminal-offence data as a core activity.

There is no simple employee-count or revenue test. If you do need a DPO, get the independence and resourcing right from day one; that is where most organizations run into trouble.

Frequently asked questions

A Data Protection Officer (DPO) is an independent expert appointed to oversee an organization's data protection strategy and monitor compliance with GDPR and related privacy laws. The DPO advises on obligations, supports data subject rights processes, and acts as the main point of contact for supervisory authorities.

DPO stands for Data Protection Officer, the independent role GDPR Article 37 requires certain organizations to appoint to oversee data protection compliance.

Only if your organization is a public authority, your core activity involves large-scale systematic monitoring of individuals, or you process special category or criminal-offence data at scale. Outside those scenarios, appointing a DPO is optional but often good practice.

A DPO is mandatory under GDPR Article 37 when an organization is a public authority or body, when its core activities involve large-scale regular and systematic monitoring, or when its core activities involve large-scale processing of special category or criminal-offence data.

Usually not. Size alone does not trigger the requirement. A small business only needs a DPO if its core activities involve large-scale monitoring or large-scale special category data processing, which is uncommon for most small businesses.

Yes. GDPR Article 37(6) explicitly allows organizations to appoint an external person or firm as DPO. Outsourced arrangements are common among smaller organizations that need specialist expertise without a full-time hire. The external DPO's contact details must still be published and accessible to regulators.

GDPR does not require a specific qualification, only "expert knowledge of data protection law and practices." Many organizations look for credentials such as CIPP/E or CIPM, combined with experience in compliance, legal, or IT security relevant to the organization's sector.

Yes. GDPR Article 37 allows a group of undertakings, or several public authorities, to appoint a single DPO, provided that person is easily accessible from each location. This is common among corporate groups and organizations using outsourced DPO services.

Yes. Organizations that are not required to appoint a DPO can still do so voluntarily. Once appointed, GDPR's rules on the DPO's position, tasks, and independence apply in the same way as if the appointment were mandatory.

No. The DPO advises and monitors but does not make processing decisions, so legal responsibility and any fines fall on the data controller or processor. Dismissing a DPO for raising compliance concerns can itself constitute a separate GDPR violation.

Adam Safar

Head of Digital Marketing

Adam is the Head of Digital Marketing at Clym, where he leverages his diverse expertise in marketing to support businesses with their compliance needs and drive awareness about data privacy and web accessibility. As one of the company’s original team members, Adam has been instrumental in shaping its journey from the very beginning. When he’s not diving into marketing strategies, Adam can be found cheering on his favorite sports teams or enjoying fishing.

Find out more about Adam