A Data Protection Officer (DPO) is a statutory, independent adviser and monitor under Articles 37–39 GDPR. Appointment is mandatory for public authorities or bodies (except courts acting judicially) and where core activities involve large-scale regular and systematic monitoring or large-scale processing of Article 9 or Article 10 data.
Test whether appointment is mandatory
Assess the organisation’s core activities, not every incidental task. Document:
- whether the entity is a public authority or body under applicable Member State law;
- whether monitoring of individuals is regular and systematic;
- whether that monitoring is large scale;
- whether special-category or criminal-conviction data is processed as a core activity at large scale; and
- relevant national rules that may require a DPO in additional circumstances.
“Large scale” is contextual; the GDPR does not supply a universal employee, customer or record threshold. Consider the number and proportion of individuals, volume and range of data, duration or permanence, and geographical reach. Record the reasoning even when the conclusion is that appointment is not mandatory.
An organisation may appoint a DPO voluntarily. Once designated, a voluntary DPO must comply with Articles 37–39, including the role's independence, resources, accessibility and task requirements; the title cannot be used for an ordinary compliance contact outside those safeguards.
Required position and protections
The controller or processor must:
- involve the DPO properly and in a timely manner in personal-data matters;
- provide resources and access needed to perform the role and maintain expertise;
- ensure the DPO reports directly to the highest management level;
- publish the DPO’s contact details and communicate them to the competent supervisory authority;
- permit individuals to contact the DPO about processing and their rights; and
- neither instruct nor penalise the DPO for performing DPO tasks.
The DPO may perform other work only where it does not create a conflict of interests. Roles that determine the purposes and means of processing can conflict; job title alone is not decisive, so evaluate actual decision-making power.
Core tasks
Article 39 identifies minimum tasks:
- inform and advise the organisation and relevant staff of data-protection obligations;
- monitor compliance, including policies, allocation of responsibilities, awareness, training and audits;
- provide DPIA advice where requested and monitor DPIA performance;
- cooperate with the supervisory authority; and
- act as its contact point, with due regard to processing risk.
The DPO advises and monitors; management remains accountable for decisions. The DPO should not be made the owner of all processing or the person who approves their own operational decisions.
Internal, shared or external DPO
The GDPR permits an employee or a service provider under contract. A group of undertakings may appoint one DPO if that person is easily accessible from each establishment. Public bodies may share a DPO with regard to their structure and size.
Compare models on:
| Criterion | Questions |
|---|---|
| Accessibility | Can individuals, staff and authorities reach the DPO without friction? |
| Capacity | Is there enough time, language coverage and backup? |
| Expertise | Does knowledge match the organisation’s sector, processing and jurisdictions? |
| Independence | Who sets priorities, evaluates performance and resolves conflicts? |
| Continuity | How are absence, handover and records handled? |
External appointment does not automatically guarantee independence. The contract, reporting line and actual working practice must protect the role.
Governance checklist
- Keep the documented appointment analysis.
- Approve a role charter and escalation route.
- Record conflicts for the DPO and supporting team.
- Give the DPO a standing route to senior management.
- Include the DPO early in product, vendor and incident workflows.
- Separate management decisions from DPO advice.
- Review resources and effectiveness periodically.
For a resourced external model, see our DPO as a Service. For broader programme implementation that remains separate from independent DPO oversight, see data protection services.
Sources and review
- Regulation (EU) 2016/679, Articles 37–39
- EDPB: endorsed Guidelines on Data Protection Officers (WP243 rev.01)
- European Commission: GDPR obligations and DPO guidance
Reviewed on 8 August 2026. No fixed numerical definition of “large scale” is asserted.
Ivana Ludiga, mag. iur., is an Associate at Vision Compliance focused on data protection, GDPR implementation, and regulatory advisory. She supports compliance projects for organizations across healthcare, financial services, and technology sectors.