GDPR DPO Requirements: Do You Need a Data Protection Officer? (2026)

By Recording Law Editorial Team18 min read
GDPR DPO Requirements: Do You Need a Data Protection Officer? (2026)

Frequently Asked Questions

Do small businesses need a DPO under GDPR?

Small businesses are not automatically exempt from the DPO requirement under Article 37. Recital 13 permits Member States to adapt rules for micro, small, and medium-sized enterprises in a few contexts, but Article 37 contains no SME exemption. A small business that meets any of the three mandatory triggers in Article 37(1) must appoint a DPO. In practice, most small businesses do not engage in large-scale processing as a core activity and are not public authorities, so the triggers are unlikely to apply. But the obligation turns on the nature and scale of processing, not on workforce size or turnover. A startup operating a health-data app with hundreds of thousands of users could trigger Article 37(1)(c) even if it employs fewer than 20 people.

Can a DPO be an external consultant or service provider?

Yes. Article 37(6) expressly states that the DPO may fulfil the role on the basis of a service contract with an external provider. The external DPO arrangement is common for organisations that cannot justify a full-time internal hire. Articles 38 and 39 must be satisfied regardless of the employment arrangement: the external DPO must have genuine independence, must not be subject to instructions, must have access to the organisation's processing activities and senior management, and must be protected against dismissal or penalty for performing their tasks. The service contract should reflect these requirements explicitly.

Does a US company with EU customers need to appoint a GDPR DPO?

A US company subject to GDPR under Article 3(2) must assess whether it meets the Article 37(1) triggers. If its core activities require large-scale regular and systematic monitoring of EU data subjects, as is common for advertising technology companies, data brokers, and large analytics platforms, Trigger Two applies and a DPO must be designated. If the US company's EU-facing activities are limited and involve neither large-scale systematic monitoring nor large-scale special-category data, no DPO is required, though a separate EU representative under Article 27 may still be mandatory. US companies should conduct and document the Article 37 assessment as part of their overall GDPR compliance programme.

Can the business owner or CEO serve as DPO?

The CEO cannot serve as DPO under the conflict-of-interest prohibition in Article 38(6). WP29's guidelines (WP243 rev.01) specifically identified the CEO role as incompatible with the DPO function, because the CEO determines the purposes and means of the organisation's data processing, and the DPO's oversight function requires independence from that decision-making authority. The same reasoning applies to the COO, CIO, CMO, CFO, and head of information technology. A business owner who is also CEO cannot cure this conflict by designating themselves DPO, even in a small organisation. The solution for very small organisations is typically an external DPO service.

What are the penalties for not appointing a DPO when one is required?

Failure to appoint a required DPO is a violation subject to fines under Article 83(4), which covers obligations set out in Articles 25-39 and imposes fines of up to EUR 10 million or 2% of worldwide annual turnover, whichever is higher. Failure to publish the DPO's contact details under Article 37(7) is independently sanctionable. Supervisory authorities assess fines based on the nature, gravity, and duration of the violation, the intentional or negligent character of the breach, and the degree of cooperation. UK GDPR mirrors this structure, with the lower-tier maximum at GBP 8.7 million or 2% of global annual turnover.

What does a DPO actually do day to day?

A DPO's day-to-day activities flow from the five tasks in Article 39(1). They advise teams on whether a new product feature requires a DPIA and review the assessment once drafted. They audit records of processing activities under Article 30. They review data-processing agreements and standard contractual clauses before execution. They investigate data-subject rights requests and ensure responses are timely. They coordinate with IT and security following a personal data breach to determine whether Article 33 notification to the supervisory authority within 72 hours is required. They design and deliver staff training. They act as the single point of contact for the supervisory authority and ensure regulatory correspondence receives timely, accurate responses.

Does GDPR require a DPO for processors as well as controllers?

Yes. Article 37(1) applies to both controllers and processors. A data processor such as a cloud-services provider, a payroll-outsourcing company, or a marketing technology platform must appoint a DPO if its core activities as a processor meet the large-scale monitoring or large-scale special-category data triggers. The processor's DPO assessment focuses on its own core activities, not the activities of the controllers it serves. A cloud-infrastructure provider that hosts data on behalf of thousands of controllers and monitors network usage patterns at large scale may trigger Article 37(1)(b) independently of what its controller customers do with the data.

Can one DPO cover multiple companies?

Yes, in two scenarios. Article 37(2) allows a group of undertakings to designate a single DPO provided the DPO is easily accessible from each establishment. Article 37(3) allows multiple public authorities or bodies to designate a shared DPO, taking into account their organisational structure and size. The easy-accessibility requirement means the DPO must be reachable by employees, data subjects, and supervisory authorities at each entity without undue difficulty. The contact details of the shared DPO must be published by each entity under Article 37(7), and the DPO must have sufficient capacity to cover all entities' DPO tasks.

Is a DPO the same as a privacy officer or compliance officer?

Not necessarily. A DPO under GDPR is a specific statutory role with defined tasks under Article 39, a statutory independence guarantee under Article 38, and protection from dismissal. Many organisations have privacy officers or compliance officers whose job descriptions overlap with DPO functions, but those roles are not equivalent to a statutory DPO unless the person has been formally designated and their contact details published under Article 37(7). An organisation relying on an internal compliance officer without a formal designation has not met its Article 37 obligation. Equally, a formal designation alone is insufficient: the designated DPO must have the qualifications, resources, independence, and access that Articles 37 and 38 require.

What is the DPO's role in a data breach?

Article 39 does not list data-breach management as a standalone task, but the DPO's role flows from the monitoring and cooperation tasks in Article 39(1)(b), (d), and (e). In practice the DPO assesses whether a security incident constitutes a personal data breach under Article 4(12), determines whether it is likely to risk the rights and freedoms of data subjects, advises on whether Article 33 notification to the supervisory authority within 72 hours is required, advises on whether Article 34 notification to affected data subjects is needed, and acts as the supervisory authority contact throughout the investigation. The DPO should be involved from the moment a potential breach is identified, not after management has already made notification decisions.

Sources and References

  1. Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) — Article 37: Designation of the Data Protection Officer(eur-lex.europa.eu)
  2. Regulation (EU) 2016/679 — Article 38: Position of the Data Protection Officer(eur-lex.europa.eu)
  3. Regulation (EU) 2016/679 — Article 39: Tasks of the Data Protection Officer(eur-lex.europa.eu)
  4. Regulation (EU) 2016/679 — Recital 97 (Data Protection Officer)(eur-lex.europa.eu)
  5. Regulation (EU) 2016/679 — Recital 91 (Data Protection Impact Assessment and Large-Scale Processing)(eur-lex.europa.eu)
  6. WP29 Guidelines on Data Protection Officers (WP243 rev.01) — adopted by EDPB(ec.europa.eu)
  7. European Data Protection Board — Article 29 Working Party Documents Archive(edpb.europa.eu)
  8. Regulation (EU) 2016/679 — Article 83: General Conditions for Imposing Administrative Fines(eur-lex.europa.eu)
  9. Regulation (EU) 2016/679 — Article 35: Data Protection Impact Assessment(eur-lex.europa.eu)
  10. Data Protection Act 2018 (UK) — Part 2 and Schedule 6 incorporating UK GDPR(legislation.gov.uk)
  11. ICO Guide to UK GDPR — Data Protection Officers(ico.org.uk)
  12. Regulation (EU) 2016/679 — Article 9: Processing of Special Categories of Personal Data(eur-lex.europa.eu)
  13. Regulation (EU) 2016/679 — Article 10: Processing of Personal Data Relating to Criminal Convictions and Offences(eur-lex.europa.eu)
Share: