Whether you need a data protection officer turns on two words in Article 37 that most organisations skate over: core activities.
And if you appoint one — mandatory or not — Article 38 attaches protections that change the reporting line and rule out several of the people you were probably considering.
When a data protection officer is mandatory
Article 37(1) requires the controller and the processor to designate one in three cases.
(a) Public authorities and bodies, except courts acting in their judicial capacity. No size test, no volume test — the status is enough.
(b) Regular and systematic monitoring on a large scale, where that is what the core activities consist of, by virtue of their nature, scope and/or purposes.
(c) Large-scale processing of special category data under Article 9 and criminal conviction and offence data under Article 10 — again as a core activity.
Note that (b) and (c) both turn on core activities, not on activities in general — which is why most employers need no data protection officer. Every employer processes staff data; almost none does so as a core activity. The question is whether the processing is what you do, or supports what you do.
Outside those three cases, Article 37(4) is permissive: you may designate a DPO, and where Union or Member State law requires it, you shall. National law is a real source of obligation here — the Regulation is a floor.
What Article 38 protects in a data protection officer

Article 38(3) is three separate protections in one paragraph, and together they are what make the role meaningful:
- The DPO shall not receive any instructions regarding the exercise of those tasks.
- The DPO shall not be dismissed or penalised by the controller or processor for performing his tasks.
- The DPO shall directly report to the highest management level.
That last one is a structural requirement, not a courtesy. A data protection officer sits outside the usual chain. A DPO reporting into the head of IT or the general counsel, with no direct line to the board or its equivalent, does not satisfy Article 38(3) however good the working relationship is.
Around it, Article 38(1) requires the DPO to be involved properly and in a timely manner in all issues which relate to the protection of personal data — timely being the operative word. A DPO shown a project after the contract is signed has not been involved in a timely manner.
Article 38(2) requires the controller and processor to support the DPO with the resources necessary, access to personal data and processing operations, and the means to maintain expert knowledge. Ongoing training is an obligation on the organisation, not a perk.
The data protection officer conflict of interests problem
Article 38(6) permits a DPO to hold other roles — and then places the burden squarely on the organisation: it shall ensure that any such tasks and duties do not result in a conflict of interests.
The test follows from the data protection officer tasks. A DPO monitors compliance and advises on processing. Anyone who decides the purposes and means of processing cannot credibly monitor those decisions. That is why the roles most often proposed — head of IT, head of HR, head of marketing, chief operating officer — are usually the least suitable, and why the appointment is a governance decision rather than an org-chart convenience.
Two structural options the Regulation makes explicit, both under-used:
Article 37(6): the DPO may be an employee or work under a service contract. An external DPO is expressly contemplated, which for a smaller organisation is often the only way to get genuine independence and expertise together.
Article 37(2): a group of undertakings may appoint a single DPO, provided the DPO is easily accessible from each establishment. Accessibility is the condition — a shared DPO nobody in a subsidiary can reach does not meet it. Public authorities have an equivalent provision in 37(3), taking account of organisational structure and size.
Data protection officer tasks, and the one that sets the workload
Article 39(1) sets a floor — “at least the following tasks”:
- Inform and advise the controller or processor and the employees who carry out processing of their obligations.
- Monitor compliance with the Regulation, other data protection provisions and the organisation’s own policies — including the assignment of responsibilities, awareness-raising and training of staff, and the related audits.
- Provide advice where requested on the DPIA, and monitor its performance under Article 35.
- Cooperate with the supervisory authority.
- Act as the contact point for the supervisory authority, including on the Article 36 prior consultation.
The monitoring limb is the one that determines resourcing. It explicitly includes training and audits, which means the DPO role is not an advisory inbox — it carries an assurance programme.
Article 39(2) then tells the DPO how to prioritise: have due regard to the risk associated with processing operations, taking into account nature, scope, context and purposes. Risk-based, not alphabetical.
Two data protection officer obligations people forget
Article 37(7) is two acts, not one. Publish the DPO’s contact details and communicate them to the supervisory authority. Organisations routinely do the first and skip the second.
Article 38(4) makes the DPO a public contact point. Data subjects may contact the DPO about all issues related to the processing of their personal data and the exercise of their rights — which means access requests and objections will arrive there directly, and the DPO is bound by secrecy or confidentiality under Article 38(5).
Where the DPO sits in your other obligations
| Obligation | The DPO’s part |
|---|---|
| DPIA | Article 35(2) requires the controller to seek the DPO’s advice when carrying one out — and Article 39(1)(c) requires the DPO to monitor its performance |
| Breach notification | Article 33(3)(b) requires the DPO’s contact details in the notification to the supervisory authority |
| Records of processing | Article 30 requires the DPO’s contact details in both the controller and processor records |
| Access requests | Article 15(1)(b) sends people to the DPO or other contact point for more information |
Where to start with a data protection officer
- Test “core activities” honestly, and record the conclusion either way. A documented “not required” decision is itself useful.
- Check national law, because Article 37(4) lets Member States require a DPO where the Regulation does not.
- Fix the reporting line before the person — Article 38(3) requires a direct line to the highest management level.
- Run the conflict test against anyone who determines purposes and means. If they do, they are not eligible.
- Consider an external DPO under Article 37(6), or a shared one under 37(2) if accessibility from each establishment is genuine.
- Do both halves of Article 37(7) — publish and notify the supervisory authority.
This guide reflects Regulation (EU) 2016/679 as published on EUR-Lex, read at 16 August 2026. Member State law can extend the obligation — check yours.
The GDPR Toolkit provides 100+ editable templates including the DPO appointment and role documentation, the records of processing, the DPIA template, the breach register and the data subject rights procedures.