Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

UK GDPR data protection officer guide cover

UK GDPR Data Protection Officer: When You Need One 2026

A UK GDPR data protection officer is a designated person who advises your organization on data protection law, monitors compliance and acts as the contact point for the Information Commissioner’s Office. Not every organization needs one, but those that do face specific rules on independence, resources and publication. This guide sets out when a DPO is required, what the role involves and the mistakes that trigger regulator attention. It draws on the ICO’s published guidance, which you should read alongside this article.

The rules sit in Articles 37 to 39 of the UK GDPR. If you are unsure how the UK regime differs from the EU one, start with our comparison of UK GDPR and EU GDPR and the UK GDPR overview.

Free gap assessment

Could you demonstrate GDPR compliance today?

Score yourself against what a supervisory authority actually asks for, free — the records, not the policy.

Run the free GDPR gap assessment →  or  View premium report sample

When a UK GDPR data protection officer is required

According to the ICO, you must appoint a DPO if you fall into one of three groups.

TriggerWhat it meansExample
Public authority or bodyAny public authority, except courts acting in a judicial capacityA local council or NHS trust
Large-scale regular and systematic monitoringYour core activities involve monitoring individuals on a large scaleLocation tracking or online behaviour profiling
Large-scale special category or criminal dataCore activities involve processing such data at scaleA private hospital group

The key phrase is “core activities”. Payroll for your own staff is not a core activity for most companies, even if it involves health data, because it supports the business rather than being the business. The ICO expects you to assess “large scale” by looking at the number of people, the volume of data, the duration and the geographical spread. If you decide you do not need a DPO, record the reasoning so you can show it later.

Voluntary appointments

Organizations that do not need a DPO can still appoint one. Be careful, because the ICO says that a voluntary DPO carries the same duties as a mandatory one if you use the title. Many organizations avoid the confusion by naming a “privacy lead” or “data protection manager” instead, and recording that the role is not a statutory DPO.

Free privacy risk assessment

Which privacy risks would hurt the people whose data you hold?

List your personal data and processing, pick from 38 privacy risk scenarios, rate them for the people concerned and for you, and plan treatment with ISO 27701 controls. You get a heat map, a process score and the findings an auditor would raise, free.

Run the free privacy risk assessment →  or  View premium report sample

What the UK GDPR data protection officer does

The ICO lists the core tasks as informing and advising on obligations, monitoring compliance, advising on data protection impact assessments, cooperating with the ICO and acting as the contact point for the regulator. Those tasks matter more than the title. In practice, a good DPO does the following.

  • Reviews new projects early, so privacy issues are found before launch.
  • Advises on when a DPIA is required and reviews it.
  • Checks that records of processing are current, using your privacy notice as a test of accuracy.
  • Trains staff and reports on compliance to senior management.
  • Handles contact from individuals, including the escalations under your data protection complaints procedure.

The DPO is not personally liable for compliance. The ICO makes clear that responsibility stays with the controller or processor. The DPO supports it, but the organization owns it.

Independence and conflicts of interest

This is where many organizations fail. The DPO must report directly to the highest level of management, must not receive instructions on how to do the job, and must not be dismissed or penalised for performing it. Just as important, the DPO cannot hold another role that determines the purposes and means of processing. The ICO’s own example is a head of marketing, whose job is to use data to sell, and who therefore cannot also be the person who checks whether that use is lawful.

Roles that commonly create conflicts include the head of IT, the head of HR, the chief executive and the general counsel where legal acts as decision maker on processing. If you cannot avoid a conflict, consider an external DPO. Keep a short note that explains why the person appointed is free of conflicts.

Resources the DPO needs

The ICO expects adequate resources: sufficient time, budget, infrastructure and, where appropriate, staff. That means writing the DPO responsibilities into a job description with hours allocated, giving access to systems and records and funding training so their knowledge stays current. A DPO who does the role in spare time alongside a full-time job will struggle to show that resources are adequate.

Publishing details and telling the ICO

You must publish the DPO’s contact details and give them to the ICO. Publish a route people can actually use, such as a monitored email address, in your privacy notice and on your website. The DPO’s name must also appear when you report a personal data breach. Check the ICO’s current notification process for how to register the details.

Internal or external UK GDPR data protection officer

You can appoint an employee or contract an external provider. The ICO says an external DPO must have the same position, tasks and duties as an internal one. When weighing the options, think about the following.

  1. Size and complexity. Small organizations often prefer an external DPO because the workload does not justify a full-time hire.
  2. Knowledge of the business. An internal DPO understands operations. An external one may bring broader experience.
  3. Conflict risk. External appointments often avoid conflicts that internal staff face.
  4. Continuity. Put notice periods and handover duties in the contract.

How recent UK law changes affect the role

The Data (Use and Access) Act 2025 amends parts of the UK data protection framework. Check the current position on the changes and their commencement dates in our guide to the Data (Use and Access) Act 2025. Read the latest ICO guidance before you rely on any summary of the DPO rules, including this one.

Working with your UK GDPR data protection officer day to day

Appointing a UK GDPR data protection officer is only the start. The role works when the business involves the DPO early and listens to the advice. Add the DPO to your project approval process, invite them to relevant committee meetings and give them a standing slot to report to senior management. When the DPO gives advice that management does not follow, record the reasons. That record shows the organization took the advice seriously, even when it chose a different course.

Keep the DPO informed about new lawful basis decisions too. For example, when you consider relying on a recognised legitimate interest, ask the DPO to review the documented assessment before you start processing. A short review at the start costs less than a complaint later.

Measuring whether the DPO role is working

Track a few simple measures each quarter: how many projects were reviewed before launch, how many DPIAs were completed, how many requests and complaints were handled on time and how many staff completed training. Report them to senior management with the DPO’s own commentary. If the numbers fall, that tells you the role needs more time or support.

A hypothetical example

A hypothetical regional charity runs a helpline that records health and family details of callers on a large scale. The trustees decide a DPO is required. The head of fundraising volunteers, but the trustees see the conflict, because fundraising decides how supporter data is used. They appoint an external DPO on a fixed-fee contract for two days a month, publish a shared mailbox, notify the ICO, and record the decision in the board minutes. The DPO reports to the board twice a year. The example is invented for illustration.

Common mistakes with the UK GDPR data protection officer role

  • Naming a DPO with a conflicting job, such as the head of IT or marketing.
  • Giving the title to a junior person with no access to senior management.
  • Failing to publish contact details or tell the ICO.
  • Skipping a written assessment of whether a DPO is required.
  • Allocating no time or budget to the role.

The ICO’s page on data protection officers is the primary source, and it is worth rereading whenever you review your governance.

Documents for a UK GDPR data protection officer

To avoid drafting the DPO job description, appointment record, conflict check and reporting templates from scratch, the UK GDPR Toolkit provides documents you can adapt. Have counsel review them against current law.

UK GDPR data protection officer FAQ

Does every UK company need a DPO?

No. A DPO is required for public authorities, for large-scale regular and systematic monitoring, and for large-scale special category or criminal offence data. Others may appoint one voluntarily.

Can the DPO also be the head of IT?

Usually not. The role cannot combine with one that decides the purposes and means of processing, and IT leadership often does. Record how you assessed any potential conflict.

Can we hire an external DPO?

Yes. An external DPO must have the same position, tasks and duties as an internal one, so build independence and access into the contract.

Is the DPO personally liable for a breach?

No. The ICO says liability for compliance stays with the controller or processor.

What must we publish about the DPO?

Publish contact details that individuals can use, and provide them to the ICO. The DPO’s name is also needed when you report a breach.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.