GDPR DPO Requirements: Do You Need a Data Protection Officer? (2026)

GDPR Articles 37-39 require certain controllers and processors to appoint a Data Protection Officer (DPO). The obligation is mandatory in three scenarios: you are a public authority or body; your core activities require large-scale regular and systematic monitoring of individuals; or your core activities involve large-scale processing of special-category or criminal-conviction data.
When Is a DPO Mandatory? The Three Triggers of Article 37(1)
Article 37(1) of Regulation (EU) 2016/679 sets out three conditions, any one of which triggers a mandatory obligation to designate a DPO. Meeting a single trigger is sufficient.
| Trigger | Article | Representative Example |
|---|---|---|
| Public authority or body (other than courts in their judicial capacity) | Art 37(1)(a) | A national tax agency, a municipal government, a public university, a state hospital |
| Core activities require regular and systematic monitoring of data subjects on a large scale | Art 37(1)(b) | An internet advertising network, a telecommunications provider tracking call records, a bank conducting credit-scoring |
| Core activities consist of large-scale processing of special-category data (Art 9) or criminal-conviction data (Art 10) | Art 37(1)(c) | A hospital chain processing patient health records, a private security company processing criminal-record checks at scale |
Recital 97 confirms this framework and adds that the required level of DPO expert knowledge should correspond to the complexity of the processing operations.
Trigger One: Public Authority or Body (Article 37(1)(a))
Every public authority or body must appoint a DPO regardless of the scale or sensitivity of its processing. The trigger is unconditional: no volume threshold, no particular data category, no specific activity type is required.
The express carve-out covers courts acting in their judicial capacity. Recital 20 explains that judicial independence requires supervisory authorities not to scrutinise courts' case-handling directly. Courts' other administrative functions (payroll, human resources, building management) remain subject to GDPR; those activities fall outside the judicial-capacity exemption.
What counts as a public authority depends on national law in each EU Member State. Central government departments, regional and local authorities, regulatory agencies, state-funded public broadcasters, publicly funded universities, and public hospitals are the paradigm cases. Mixed public-private bodies and state-owned enterprises may or may not qualify depending on the constitutional and administrative law of the relevant Member State.
Trigger Two: Large-Scale Regular and Systematic Monitoring (Article 37(1)(b))
Trigger Two applies to controllers and processors whose core activities require regular and systematic monitoring of data subjects on a large scale. Both limbs require scrutiny: "regular and systematic monitoring" and "large scale" are distinct qualifications.
What "Regular and Systematic Monitoring" Means
The former Article 29 Working Party (WP29), whose guidelines were adopted by the European Data Protection Board (EDPB) on 25 May 2018, addressed this in WP243 rev.01. "Regular" means ongoing, recurring at fixed intervals, or occurring constantly or periodically. "Systematic" means occurring according to a system, pre-arranged or methodical, or carried out as part of a general data-collection plan.
WP29 examples of regular and systematic monitoring: operating a telecommunications network; providing internet services; tracking location data from mobile applications; loyalty programmes with behavioural analysis; processing biometric data for access control; CCTV monitoring of individuals in public spaces; behavioural advertising; and tracking through connected devices.
What "Large Scale" Means
GDPR does not define "large scale" numerically. Recital 91 states that large-scale processing aims to handle a considerable amount of personal data at a regional, national, or supranational level and could affect a large number of data subjects. As a counterexample, Recital 91 notes that a single doctor or lawyer handling patient or client data does not constitute large-scale processing.
WP29 identified four assessment factors: the number of data subjects (absolute or as a proportion of the relevant population); the volume or range of data items processed; the duration or permanence of the activity; and the geographical extent.
The EDPB treats these as large scale: a hospital processing patient data in the ordinary course of operations; a transport company processing travel data across a city's public transport system; a real-time geo-location processor covering a national road network; a search engine processing data for behavioural advertising globally. Not large scale: a single doctor or specialist processing patient records; a single lawyer processing client data.
Trigger Three: Large-Scale Processing of Special-Category or Criminal-Conviction Data (Article 37(1)(c))
Trigger Three focuses on data sensitivity rather than monitoring type. It applies when core activities consist of large-scale processing of the special categories listed in Article 9(1) or criminal-conviction data under Article 10.
Article 9(1) enumerates eight special categories: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade-union membership; genetic data; biometric data processed to uniquely identify a person; health data; and sex life or sexual orientation data.
Article 10 data relates to criminal convictions and offences. Most organisations processing Article 10 data in their core activities do so under a specific statutory gateway. The large-scale requirement still applies; a small charity running a single background check on a volunteer does not trigger this limb.
Organisations likely to meet Trigger Three: a private health insurer processing medical-underwriting data for its entire customer base; a recruitment firm conducting large-scale criminal-record checks; a genetic testing service processing DNA from hundreds of thousands of consumers; a biometric access-control provider covering a large workforce.
The Concept of "Core Activities"
Triggers Two and Three both require that the relevant processing form part of the organisation's "core activities." Processing that is ancillary or supportive does not trigger the DPO obligation.
WP29 drew the line between primary business functions and support functions such as payroll, IT management, and human resources. A hospital processes health data as a core activity because healthcare is its primary purpose. Its payroll processing, though it involves personal data, is ancillary and does not trigger Trigger Three.
A security company monitoring shopping centres and public spaces with CCTV engages in regular and systematic monitoring as a core activity because surveillance is the primary service it sells. A supermarket that installs CCTV for theft prevention uses surveillance as a secondary tool, not a primary offering.
Many medium-sized businesses process personal data extensively in HR systems, CRM platforms, and accounting software, but none of those activities are core in the GDPR sense. A manufacturer whose primary activity is producing goods processes employee and customer data as support functions. If its core activity does not involve large-scale monitoring or large-scale special-category processing, no mandatory DPO obligation arises under Triggers Two or Three.
Voluntary DPO Appointment
Article 37(4) confirms that where appointment is not mandatory, organisations "may or shall" designate a DPO. The "shall" language refers to possibilities in Member State or Union law requiring designation beyond the Article 37(1) baseline; organisations should check national implementing legislation.
The EDPB recommends voluntary appointment for any organisation processing significant personal data volumes, regardless of whether mandatory thresholds are met. A voluntary DPO can demonstrate accountability, build regulatory trust, and reduce the risk of undetected violations.
Critically, Articles 38 and 39 apply in full to a voluntary DPO. An organisation cannot appoint a nominal DPO stripped of independence or shielded from the conflict-of-interest rules.
Who Can Serve as DPO?
Qualifications Required
Article 37(5) requires designation based on professional qualities and expert knowledge of data protection law and practices, plus the ability to carry out the Article 39 tasks. No prescribed qualification or examination exists. Required expertise is proportionate to data sensitivity and processing complexity.
WP29 identified relevant areas of expertise: national and European data protection laws; the organisation's sector and subject matter; the organisation's business and IT infrastructure; compliance-function management; and international data transfer frameworks.
For a small organisation collecting only basic contact data for a newsletter, a competent employee with a reasonable GDPR understanding may suffice. For a large multinational processing biometric data, running behavioural advertising, and transferring data across jurisdictions, specialised legal and technical expertise is appropriate.
Staff Member or External Service Provider
Article 37(6) expressly allows the DPO to be a staff member or to fulfil the role under a service contract. The external DPO model has grown significantly since GDPR took effect. Law firms, consultancies, and specialist privacy providers offer shared or fractional DPO services.
When the DPO is external, the service contract must be structured so that Articles 38 and 39 are met. The external DPO must have genuine access to the organisation's processing operations and management, not merely serve as a nominal compliance contact.
Group-Level DPO and Multi-Authority DPO
Article 37(2) permits a group of undertakings to appoint a single DPO, provided that DPO is easily accessible from each establishment. Article 37(3) similarly permits a single DPO for several public authorities or bodies, taking into account their organisational structure and size.
"Easily accessible" is a functional requirement. The DPO must be reachable by employees, data subjects, and supervisory authorities without undue difficulty. WP29 identified supporting factors: clear communication of the DPO's contact details throughout the group; availability for consultation on data-protection questions; and physical presence where complex or sensitive processing occurs.
Article 37(7) requires that controllers and processors publish the DPO's contact details and communicate them to their supervisory authority. Full identity need not be published, but a contact address accessible to data subjects must be.
The DPO's Tasks Under Article 39
Article 39(1) enumerates five minimum tasks. The "at least" language makes clear that Member State law, the DPO's terms of engagement, or the organisation's own governance may assign additional responsibilities.
Task One: Inform and Advise (Article 39(1)(a))
The DPO must inform and advise the controller, processor, and employees about GDPR obligations and other applicable data-protection provisions. This encompasses guidance on lawful processing bases, consent mechanisms, data-subject rights procedures, staff training, and data-protection strategy.
The DPO informs and advises; the DPO does not decide. Under Article 38(3), the DPO cannot receive instructions in the exercise of their tasks, but the controller or processor retains decision-making authority over how personal data is processed. The DPO's role is to ensure decision-makers understand the legal landscape and to flag non-compliant directions.
Task Two: Monitor Compliance (Article 39(1)(b))
The DPO must monitor compliance with GDPR, other applicable data-protection provisions, and the organisation's own data-protection policies. Monitoring involves: assigning data-protection responsibilities; conducting internal audits; reviewing processing agreements and data-sharing arrangements; updating records of processing activities; monitoring data-subject rights requests; and tracking technical and organisational security measures.
Article 39(1)(b) also references raising awareness and training staff. The DPO therefore has a standing obligation to keep the workforce current on GDPR requirements as the regulatory framework and the organisation's processing operations evolve.
Task Three: Advise on DPIAs (Article 39(1)(c))
Where a new processing activity is likely to result in a high risk to data subjects, Article 35 requires a Data Protection Impact Assessment (DPIA) before processing begins. The DPO provides advice on the DPIA and monitors its performance.
Under Article 38(1), the DPO must be involved "properly and in a timely manner" and should be consulted at the outset of any project likely to require a DPIA. The DPO's advice and the controller's response should be documented alongside the DPIA record. Recital 97 notes that the DPO should assist in assessing whether a DPIA is needed and determining how to carry it out.
If a controller proceeds with a high-risk processing activity over the DPO's documented objection, both the DPO's advice and the controller's decision should be recorded in writing. That documentation evidences the DPO's independence and the controller's accountability under Article 5(2).
Task Four: Cooperate with the Supervisory Authority (Article 39(1)(d))
The DPO must cooperate with the supervisory authority. Cooperation includes facilitating inspections and investigations; providing information under the DPA's Article 58 investigative powers; participating in meetings or hearings; and managing data-breach notifications to the DPA under Article 33.
Task Five: Act as Contact Point for the Supervisory Authority (Article 39(1)(e))
The DPO acts as the contact point for the supervisory authority on processing issues and, where appropriate, conducts prior consultation under Article 36. Prior consultation is the mechanism by which a controller that cannot mitigate DPIA-identified risks to an acceptable level consults the supervisory authority before commencing processing.
The contact-point function also means data subjects have a published address for exercising GDPR rights. Article 37(7) ensures the DPO's contact details are publicly available, and Article 38(4) confirms that data subjects may contact the DPO on all processing and rights issues.
The Risk-Based Approach in Practice
Article 39(2) requires the DPO, across all five tasks, to account for the risk associated with processing operations, having regard to nature, scope, context, and purposes. A proportionate, risk-based approach directs attention toward activities most likely to create high risks: profiling, automated decision-making, large-scale special-category processing, and cross-border transfers without adequate safeguards.
DPO Independence and Protection from Dismissal (Article 38)
No Instructions Permitted
Article 38(3) states that the DPO "shall not receive any instructions regarding the exercise of those tasks." This prohibition applies at all management levels. The DPO reports directly to the highest management level, which in most corporate structures means the board or an equivalent governance body.
A DPO who determines that a processing activity is unlawful cannot be ordered to approve it. A DPO who believes the organisation is underreporting data breaches cannot be silenced. The DPO must be free to escalate concerns to the supervisory authority under Article 39(1)(d) without internal approval.
Protection from Dismissal and Penalties
Article 38(3) prohibits dismissing or penalising the DPO for performing their tasks. A DPO who is dismissed, demoted, reduced in compensation, or subjected to other adverse action because of their DPO function has a direct claim under GDPR, and the supervisory authority may investigate and sanction the controller or processor.
The protection applies to both employed and external-service-provider DPOs. A controller cannot terminate the DPO's service contract in retaliation for the DPO raising compliance concerns. Contract terms giving the controller an unfettered right to terminate without cause may undermine the independence requirement if used to suppress lawful DPO activity.
Resources and Access
Article 38(2) requires the controller and processor to provide the resources necessary to carry out Article 39 tasks and maintain expert knowledge, plus access to personal data and processing operations. Resources include time, training and professional development funding, and administrative support. For a part-time or external DPO, this includes meaningful access to systems, documentation, and personnel.
A DPO who cannot obtain records of processing activities, attend meetings where processing decisions are made, or review procurement contracts involving personal data lacks the access necessary to carry out Article 39(1)(b) monitoring.
Conflict of Interest
Article 38(6) allows the DPO to fulfil other tasks and duties, but the controller or processor must ensure those tasks create no conflict of interest with the DPO's oversight function.
WP29's guidelines (WP243 rev.01) identified roles generally incompatible with the DPO function: CEO, COO, CFO, CMO, CHRO, CIO, and head of IT or security. In smaller organisations where one person holds multiple roles, the DPO function must remain ring-fenced from roles that set processing objectives.
The test is functional, not nominal. Changing a job title from "IT Manager" to "DPO" while leaving substantive responsibilities unchanged does not cure the conflict. A conflict exists wherever the role involves determining the purposes and means of processing personal data.
External DPOs face their own risks: a law firm that advises a client on the legality of a processing strategy while simultaneously serving as DPO may face a conflict when the DPO function requires advising against that strategy. Organisations using external DPO services should confirm the provider has governance measures to manage those conflicts.
Consequences of Non-Compliance
Fines Under Article 83(4)
Violations of Articles 37, 38, and 39 fall within GDPR's lower fine tier under Article 83(4), which covers obligations pursuant to Articles 8, 11, 25-39, 42, and 43. The maximum is EUR 10 million or 2% of the undertaking's total worldwide annual turnover for the preceding financial year, whichever is higher.
Commonly sanctioned DPO-related violations: failing to appoint a required DPO; appointing a DPO who lacks qualifications or independence; assigning the DPO to a conflicting role; failing to provide sufficient resources or access; and failing to publish the DPO's contact details.
Enforcement in Practice
Supervisory authorities across the EU have investigated and fined organisations for DPO-related violations. German data protection authorities have been particularly active given the DPO requirement's roots in German federal data protection law predating GDPR. Several DPAs have treated nominally appointed DPOs with no real authority, no adequate resources, and no protection from management interference as equivalent to having no DPO at all.
Failure to publish the DPO's contact details is among the simplest violations for a supervisory authority to detect: it is visible on the face of a privacy policy. Supervisory authorities conducting website privacy-notice sweeps routinely flag missing DPO contact information.
Non-Fine Consequences
Non-compliance with DPO requirements undermines accountability under Article 5(2). A controller that lacks a required DPO has a structural accountability deficit that can aggravate the penalty for any associated GDPR violation found in the same investigation.
For B2B businesses, procurement teams conducting GDPR due diligence on vendors and sub-processors increasingly request evidence of DPO appointment, DPO contact details, and records of processing activities. The absence of a required DPO is a material finding in enterprise vendor-risk assessments.
UK GDPR and the DPO Requirement
The United Kingdom retained GDPR as domestic law through the European Union (Withdrawal) Act 2018 and the Data Protection Act 2018. UK GDPR mirrors the EU text with minor modifications. Articles 37, 38, and 39 of UK GDPR reproduce the EU equivalents almost word-for-word, and the three mandatory triggers are unchanged.
The Information Commissioner's Office (ICO) is the supervisory authority for UK GDPR. The ICO closely tracks the WP29 approach and applies the same "large scale" and "core activities" analytical framework as EU DPAs. Organisations subject to both regimes may appoint separate DPOs or a single DPO covering both, provided that DPO is accessible to both supervisory authorities, employees, and data subjects.
The UK GDPR fines regime is denominated in sterling: the lower tier is up to GBP 8.7 million or 2% of global annual turnover, whichever is higher.
How to Assess Whether Your Organisation Needs a DPO
Start with Trigger One: is the organisation a public authority or body under the national law of the relevant EU Member State? If yes, a DPO is mandatory. If the organisation operates across multiple Member States, check whether any of them classify the entity as a public body.
If not a public authority, identify the core business activities. For each core activity, ask: does this activity require regular and systematic monitoring of individuals? If yes, is that monitoring conducted on a large scale? If both answers are yes, Trigger Two applies.
Then for each core activity ask: does this activity involve processing Article 9(1) special-category data or Article 10 criminal-conviction data? If yes, is that processing conducted on a large scale? If both answers are yes, Trigger Three applies.
Document the analysis. Even where no mandatory DPO is required, a documented assessment demonstrates accountability under Article 5(2) and protects the organisation if a supervisory authority later questions the decision. Update the assessment whenever processing activities change materially, including through acquisitions, new product lines, or changed data-sharing arrangements.
For how DPO obligations fit within the broader GDPR compliance programme, the GDPR compliance checklist provides a structured overview of controller and processor obligations. Organisations outside the EU assessing whether GDPR applies at all can start with the GDPR for small businesses guide. For a complete introduction to the regulation, see what is GDPR.
Disclaimer: This article provides general legal information about GDPR Data Protection Officer requirements and is not legal advice. GDPR compliance is fact-specific, and the application of Articles 37-39 to any particular organisation depends on its specific processing activities, legal status, and the national law of the relevant Member State. Consult a qualified data protection practitioner or legal counsel for advice tailored to your situation.
Frequently Asked Questions
Do small businesses need a DPO under GDPR?
Small businesses are not automatically exempt from the DPO requirement under Article 37. Recital 13 permits Member States to adapt rules for micro, small, and medium-sized enterprises in a few contexts, but Article 37 contains no SME exemption. A small business that meets any of the three mandatory triggers in Article 37(1) must appoint a DPO. In practice, most small businesses do not engage in large-scale processing as a core activity and are not public authorities, so the triggers are unlikely to apply. But the obligation turns on the nature and scale of processing, not on workforce size or turnover. A startup operating a health-data app with hundreds of thousands of users could trigger Article 37(1)(c) even if it employs fewer than 20 people.
Can a DPO be an external consultant or service provider?
Yes. Article 37(6) expressly states that the DPO may fulfil the role on the basis of a service contract with an external provider. The external DPO arrangement is common for organisations that cannot justify a full-time internal hire. Articles 38 and 39 must be satisfied regardless of the employment arrangement: the external DPO must have genuine independence, must not be subject to instructions, must have access to the organisation's processing activities and senior management, and must be protected against dismissal or penalty for performing their tasks. The service contract should reflect these requirements explicitly.
Does a US company with EU customers need to appoint a GDPR DPO?
A US company subject to GDPR under Article 3(2) must assess whether it meets the Article 37(1) triggers. If its core activities require large-scale regular and systematic monitoring of EU data subjects, as is common for advertising technology companies, data brokers, and large analytics platforms, Trigger Two applies and a DPO must be designated. If the US company's EU-facing activities are limited and involve neither large-scale systematic monitoring nor large-scale special-category data, no DPO is required, though a separate EU representative under Article 27 may still be mandatory. US companies should conduct and document the Article 37 assessment as part of their overall GDPR compliance programme.
Can the business owner or CEO serve as DPO?
The CEO cannot serve as DPO under the conflict-of-interest prohibition in Article 38(6). WP29's guidelines (WP243 rev.01) specifically identified the CEO role as incompatible with the DPO function, because the CEO determines the purposes and means of the organisation's data processing, and the DPO's oversight function requires independence from that decision-making authority. The same reasoning applies to the COO, CIO, CMO, CFO, and head of information technology. A business owner who is also CEO cannot cure this conflict by designating themselves DPO, even in a small organisation. The solution for very small organisations is typically an external DPO service.
What are the penalties for not appointing a DPO when one is required?
Failure to appoint a required DPO is a violation subject to fines under Article 83(4), which covers obligations set out in Articles 25-39 and imposes fines of up to EUR 10 million or 2% of worldwide annual turnover, whichever is higher. Failure to publish the DPO's contact details under Article 37(7) is independently sanctionable. Supervisory authorities assess fines based on the nature, gravity, and duration of the violation, the intentional or negligent character of the breach, and the degree of cooperation. UK GDPR mirrors this structure, with the lower-tier maximum at GBP 8.7 million or 2% of global annual turnover.
What does a DPO actually do day to day?
A DPO's day-to-day activities flow from the five tasks in Article 39(1). They advise teams on whether a new product feature requires a DPIA and review the assessment once drafted. They audit records of processing activities under Article 30. They review data-processing agreements and standard contractual clauses before execution. They investigate data-subject rights requests and ensure responses are timely. They coordinate with IT and security following a personal data breach to determine whether Article 33 notification to the supervisory authority within 72 hours is required. They design and deliver staff training. They act as the single point of contact for the supervisory authority and ensure regulatory correspondence receives timely, accurate responses.
Does GDPR require a DPO for processors as well as controllers?
Yes. Article 37(1) applies to both controllers and processors. A data processor such as a cloud-services provider, a payroll-outsourcing company, or a marketing technology platform must appoint a DPO if its core activities as a processor meet the large-scale monitoring or large-scale special-category data triggers. The processor's DPO assessment focuses on its own core activities, not the activities of the controllers it serves. A cloud-infrastructure provider that hosts data on behalf of thousands of controllers and monitors network usage patterns at large scale may trigger Article 37(1)(b) independently of what its controller customers do with the data.
Can one DPO cover multiple companies?
Yes, in two scenarios. Article 37(2) allows a group of undertakings to designate a single DPO provided the DPO is easily accessible from each establishment. Article 37(3) allows multiple public authorities or bodies to designate a shared DPO, taking into account their organisational structure and size. The easy-accessibility requirement means the DPO must be reachable by employees, data subjects, and supervisory authorities at each entity without undue difficulty. The contact details of the shared DPO must be published by each entity under Article 37(7), and the DPO must have sufficient capacity to cover all entities' DPO tasks.
Is a DPO the same as a privacy officer or compliance officer?
Not necessarily. A DPO under GDPR is a specific statutory role with defined tasks under Article 39, a statutory independence guarantee under Article 38, and protection from dismissal. Many organisations have privacy officers or compliance officers whose job descriptions overlap with DPO functions, but those roles are not equivalent to a statutory DPO unless the person has been formally designated and their contact details published under Article 37(7). An organisation relying on an internal compliance officer without a formal designation has not met its Article 37 obligation. Equally, a formal designation alone is insufficient: the designated DPO must have the qualifications, resources, independence, and access that Articles 37 and 38 require.
What is the DPO's role in a data breach?
Article 39 does not list data-breach management as a standalone task, but the DPO's role flows from the monitoring and cooperation tasks in Article 39(1)(b), (d), and (e). In practice the DPO assesses whether a security incident constitutes a personal data breach under Article 4(12), determines whether it is likely to risk the rights and freedoms of data subjects, advises on whether Article 33 notification to the supervisory authority within 72 hours is required, advises on whether Article 34 notification to affected data subjects is needed, and acts as the supervisory authority contact throughout the investigation. The DPO should be involved from the moment a potential breach is identified, not after management has already made notification decisions.
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
General Data Protection Regulation (GDPR)
Art. 10Processing of personal data relating to criminal convictions and offencesIn forcecited in 3 of our articles
Processing of personal data relating to criminal convictions and offences or related security measures based on Article 6(1) shall be carried out only under the control of official authority or when the processing is authorised by Union or Member State law providing for appropriate safeguards for the rights and freedoms of data subjects. Any comprehensive register of criminal convictions shall be kept only under the control of official authority.
Official text (excerpt) · last checked 2026-08-12 · Read the full text in our law library · Verify at eur-lex.europa.eu
Cited in 7 court opinionsMost recently applied by a court: 2025
Leading cases:
- Proceedings brought by B (Court of Justice of the European Union 2021, C-439/19)
- RL v Landeshauptstadt Wiesbaden (Court of Justice of the European Union 2024, C-61/22)
- Endemol Shine Finland Oy (Court of Justice of the European Union 2024, C-740/22)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Art. 35Data protection impact assessmentIn forcecited in 6 of our articles
1. Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks. 2. The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment. 3. A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of: (a) a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
Official text (excerpt) · last checked 2026-08-12 · Read the full text in our law library · Verify at eur-lex.europa.eu
Cited in 1 court opinionsMost recently applied by a court: 2024
Leading cases:
- RL v Landeshauptstadt Wiesbaden (Court of Justice of the European Union 2024, C-61/22)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: GDPR DPIA: When Is a Data Protection Impact Assessment Required? (2026)
Art. 37Designation of the data protection officerIn forcecited in 5 of our articles
1. The controller and the processor shall designate a data protection officer in any case where: (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; (b) the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or ▼C1 (c) the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 or personal data relating to criminal convictions and offences referred to in Article 10. ▼B 2. A group of undertakings may appoint a single data protection officer provided that a data protection officer is easily accessible from each establishment. 3. Where the controller or the processor is a public authority or body, a single data protection officer may be designated for several such authorities or bodies, taking account of their organisational structure and size. 4.
Official text (excerpt) · last checked 2026-08-12 · Read the full text in our law library · Verify at eur-lex.europa.eu
Cited in 2 court opinionsMost recently applied by a court: 2023
Leading cases:
- X-FAB Dresden GmbH & Co. KG v FC (Court of Justice of the European Union 2023, C-453/21)
- Leistritz AG v LH (Court of Justice of the European Union 2022, C-534/20)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Art. 38Position of the data protection officerIn forcecited in 3 of our articles
1. The controller and the processor shall ensure that the data protection officer is involved, properly and in a timely manner, in all issues which relate to the protection of personal data. 2. The controller and processor shall support the data protection officer in performing the tasks referred to in Article 39 by providing resources necessary to carry out those tasks and access to personal data and processing operations, and to maintain his or her expert knowledge. 3. The controller and processor shall ensure that the data protection officer does not receive any instructions regarding the exercise of those tasks. He or she shall not be dismissed or penalised by the controller or the processor for performing his tasks. The data protection officer shall directly report to the highest management level of the controller or the processor. 4. Data subjects may contact the data protection officer with regard to all issues related to processing of their personal data and to the exercise of their rights under this Regulation. 5.
Official text (excerpt) · last checked 2026-08-12 · Read the full text in our law library · Verify at eur-lex.europa.eu
Cited in 3 court opinionsMost recently applied by a court: 2023
Leading cases:
- X-FAB Dresden GmbH & Co. KG v FC (Court of Justice of the European Union 2023, C-453/21)
- Leistritz AG v LH (Court of Justice of the European Union 2022, C-534/20)
- ZS v Zweckverband 'Kommunale Informationsverarbeitung Sachsen' KISA, Körperschaft des öffentlichen Rechts (Court of Justice of the European Union 2023, C-560/21)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Art. 39Tasks of the data protection officerIn forcecited in 3 of our articles
1. The data protection officer shall have at least the following tasks: (a) to inform and advise the controller or the processor and the employees who carry out processing of their obligations pursuant to this Regulation and to other Union or Member State data protection provisions; (b) to monitor compliance with this Regulation, with other Union or Member State data protection provisions and with the policies of the controller or processor in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits; (c) to provide advice where requested as regards the data protection impact assessment and monitor its performance pursuant to Article 35; (d) to cooperate with the supervisory authority; (e) to act as the contact point for the supervisory authority on issues relating to processing, including the prior consultation referred to in Article 36, and to consult, where appropriate, with regard to any other matter. 2.
Official text (excerpt) · last checked 2026-08-12 · Read the full text in our law library · Verify at eur-lex.europa.eu
Cited in 2 court opinionsMost recently applied by a court: 2023
Leading cases:
- X-FAB Dresden GmbH & Co. KG v FC (Court of Justice of the European Union 2023, C-453/21)
- Leistritz AG v LH (Court of Justice of the European Union 2022, C-534/20)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Art. 83General conditions for imposing administrative finesIn forcecited in 9 of our articles
1. Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive. 2. Administrative fines shall, depending on the circumstances of each individual case, be imposed in addition to, or instead of, measures referred to in points (a) to (h) and (j) of Article 58(2). When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to the following: (a) the nature, gravity and duration of the infringement taking into account the nature scope or purpose of the processing concerned as well as the number of data subjects affected and the level of damage suffered by them; (b) the intentional or negligent character of the infringement; (c) any action taken by the controller or processor to mitigate the damage suffered by data subjects;
Official text (excerpt) · last checked 2026-08-12 · Read the full text in our law library · Verify at eur-lex.europa.eu
Cited in 13 court opinionsMost recently applied by a court: 2026
Leading cases:
- Deutsche Wohnen SE v Staatsanwaltschaft Berlin (Court of Justice of the European Union 2023, C-807/21)
- Nacionalinis visuomenės sveikatos centras prie Sveikatos apsaugos ministerijos v Valstybinė duomenų apsaugos inspekcija (Court of Justice of the European Union 2023, C-683/21)
- Criminal proceedings against ILVA A/S (Court of Justice of the European Union 2025, C-383/23)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: The Garante Privacy: Italy's Data Protection Authority and How to Complain, GDPR in Italy: How the Codice Privacy and the Garante Fit Together, Italy Recording Laws 2025: One-Party Consent, Penalties and GDPR
Art. 9Processing of special categories of personal dataIn forcecited in 5 of our articles
1. Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited. 2. Paragraph 1 shall not apply if one of the following applies: (a) the data subject has given explicit consent to the processing of those personal data for one or more specified purposes, except where Union or Member State law provide that the prohibition referred to in paragraph 1 may not be lifted by the data subject; (b) processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law in so far as it is authorised by Union or Member State law or a collective agreement pursuant to Member State law providing for appropriate safeguards for the fundamental rights and the interests of the data subject;
Official text (excerpt) · last checked 2026-08-12 · Read the full text in our law library · Verify at eur-lex.europa.eu
Cited in 17 court opinionsMost recently applied by a court: 2025
Leading cases:
- ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts (Court of Justice of the European Union 2023, C-667/21)
- Meta Platforms Inc and Others v Bundeskartellamt (Court of Justice of the European Union 2023, C-252/21)
- European Commission v Republic of Poland (Court of Justice of the European Union 2023, C-204/21)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Search our record of EU legislation — GDPR, ePrivacy, AI Act and more, from EUR-Lex →
Sources and References
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) — Article 37: Designation of the Data Protection Officer(eur-lex.europa.eu)
- Regulation (EU) 2016/679 — Article 38: Position of the Data Protection Officer(eur-lex.europa.eu)
- Regulation (EU) 2016/679 — Article 39: Tasks of the Data Protection Officer(eur-lex.europa.eu)
- Regulation (EU) 2016/679 — Recital 97 (Data Protection Officer)(eur-lex.europa.eu)
- Regulation (EU) 2016/679 — Recital 91 (Data Protection Impact Assessment and Large-Scale Processing)(eur-lex.europa.eu)
- WP29 Guidelines on Data Protection Officers (WP243 rev.01) — adopted by EDPB(ec.europa.eu)
- European Data Protection Board — Article 29 Working Party Documents Archive(edpb.europa.eu)
- Regulation (EU) 2016/679 — Article 83: General Conditions for Imposing Administrative Fines(eur-lex.europa.eu)
- Regulation (EU) 2016/679 — Article 35: Data Protection Impact Assessment(eur-lex.europa.eu)
- Data Protection Act 2018 (UK) — Part 2 and Schedule 6 incorporating UK GDPR(legislation.gov.uk)
- ICO Guide to UK GDPR — Data Protection Officers(ico.org.uk)
- Regulation (EU) 2016/679 — Article 9: Processing of Special Categories of Personal Data(eur-lex.europa.eu)
- Regulation (EU) 2016/679 — Article 10: Processing of Personal Data Relating to Criminal Convictions and Offences(eur-lex.europa.eu)