> ## Content Index
> Fetch the complete content index at: https://www.thedelatorrereview.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# The GDPR Data Protection Officer (DPO) Explained: When You Need One and What They Do
- URL: https://www.thedelatorrereview.com/the-gdpr-data-protection-officer-dpo-explained-when-you-need-one-and-what-they-do/
- Published: 2019-03-13T20:37:00.000Z
- Updated: 2026-08-15T21:30:18.000Z
- Description: A practical guide to Data Protection Officers under the GDPR: when organizations must appoint a DPO, the qualifications and independence the role requires, key responsibilities, conflicts of interest, and how DPOs support effective data protection governance and accountability.
- Author: Lydia
- Tags: Data Protection Officer (DPO), GDPR, EU, Accountability, European Data Protection Board (EDPB), Article 29 Working Party (WP29), Data Protection Impact Assessment (DPIA) / Privacy Impact Assessment (PIA), Records of Processing Activities (ROPAs), Data Protection Law

> **Key Points:** (1) **DPOs are mandatory in certain cases**, including public authorities and organizations engaged in large-scale monitoring or large-scale processing of sensitive data. (2) Organizations may **voluntarily appoint a DPO**, but the GDPR’s DPO requirements then apply. (3) DPOs must have appropriate **data protection expertise** and may be internal, external, or shared across a group.(4) **Independence is essential:** DPOs must report to senior management, have adequate resources, and be protected from conflicts of interest. (5) DPOs **advise, monitor compliance, support DPIAs, cooperate with regulators, and serve as a contact point** for individuals and supervisory authorities. (6) The DPO provides independent oversight, but **the controller or processor remains responsible for GDPR compliance**.

---

European data protection law requires certain organizations to appoint a Data Protection Officer (DPO) and gives DPOs specific responsibilities, resources, and protections designed to preserve the independence of the role.

A DPO can play a central role in an organization’s data protection governance and accountability framework, helping the organization understand its obligations, monitor compliance, advise on data protection risks, and serve as an important point of contact for regulators and individuals.

Organizations must **publish the DPO's contact details and communicate them to the competent supervisory authority**. Individuals should therefore have a practical means of contacting the DPO regarding the processing of their personal data and the exercise of their GDPR rights.

The DPO isn’t personally liable for data protection compliance. Controllers and processors remain responsible to comply with EU Data Protection Law. Nevertheless, the DPO clearly plays a crucial role in an organization’s data protection program.

Importantly, **not every organization subject to the GDPR must appoint a DPO**. But the absence of a DPO requirement does not reduce an organization’s underlying compliance obligations. Controllers and processors must still ensure that they have sufficient expertise, personnel, and resources to comply with European data protection law.

## When Is Appointment of a DPO Mandatory?

Under [**Article 37 of the GDPR**](https://gdpr-info.eu/art-37-gdpr/?ref=thedelatorrereview.com), a controller or processor must designate a DPO in three principal circumstances:

1. **The organization is a public authority or body**, except for courts when they are acting in their judicial capacity.
2. **The organization’s core activities require regular and systematic monitoring of individuals on a large scale.**
3. **The organization’s core activities consist of large-scale processing of special categories of personal data or personal data relating to criminal convictions and offenses.**

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/08/Appointment_of_DPO.png)

If an organization determines that it is **not required to appoint a DPO, it is good practice to document that assessment**. The record should explain why the organization concluded that none of the circumstances requiring a DPO under Article 37 GDPR apply—for example, why its relevant processing does not constitute large-scale regular and systematic monitoring or large-scale processing of special category or criminal-offense data.

Documenting the analysis helps demonstrate compliance with the GDPR’s accountability principle and provides a record that can be revisited if the organization’s activities, technologies, data practices, or scale of processing change.

### What Are “Core Activities”?

The DPO requirement focuses on an organization’s **core activities**. These are the primary activities necessary to accomplish the organization’s objectives—not merely routine support functions that happen to involve personal data.

For many organizations, for example, processing employee information for payroll and human resources purposes is an important administrative function, but it is generally ancillary to the organization’s core business.

> **Example: HR Processing**  
>  
> A manufacturing company processes personal data about its employees for payroll and HR administration. Although this processing is necessary to operate the business, manufacturing—not HR data processing—is the company's core activity.  
>  
> An HR services provider, by contrast, processes employee information on behalf of its clients as an essential part of providing its services. That processing therefore forms part of its **core activities**. The provider's processing of information about its own employees would generally remain an ancillary activity.

### What Is “Regular and Systematic Monitoring”?

The GDPR does not expressly define “regular and systematic monitoring.” Guidance originally issued by the Article 29 Working Party (WP29), and subsequently endorsed by the European Data Protection Board (EDPB), provides additional guidance on the concept.

**Regular and systematic monitoring can encompass many forms of** **tracking and profiling of individuals, both online and offline**. Behavioral advertising is a prominent example, but the concept is broader and can include activities in which individuals are continuously or periodically observed, tracked, scored, profiled, or otherwise evaluated according to an organized or predefined system.

The important limitation is that the monitoring must also occur on a large scale before this particular DPO requirement is triggered.

> **Example: Online Behavioral Monitoring**  
>  
> A large online retailer continuously monitors users' searches, browsing behavior, and purchases and uses algorithms to develop profiles and generate personalized recommendations. Because the monitoring occurs continuously, according to predefined criteria, and across a substantial user base, it may constitute **regular and systematic monitoring of individuals on a large scale**.

### What Does “Large Scale” Mean?

The GDPR does not establish a numerical threshold for determining when processing becomes large scale. There is no simple rule based on a particular number of individuals or records.

Instead, the WP29/EDPB guidance identifies several factors that should be considered, including:

- **the number of individuals affected**, either as a specific number or as a proportion of the relevant population;
- **the volume of personal data** and the range of data elements being processed;
- **the duration or permanence** of the processing activity; and
- **the geographical extent** of the processing.

These factors should be considered together and in the context of the particular processing activity.

### Voluntary Appointment of a DPO

Organizations may choose to appoint a DPO voluntarily, even when the GDPR does not require them to do so. A voluntary appointment may be useful where an organization engages in significant or complex processing activities or simply wants to strengthen its data protection governance and compliance framework.

However, formally designating an individual as the organization’s DPO has legal consequences. Where an organization voluntarily appoints a DPO, the GDPR provisions governing the DPO’s role, responsibilities, independence, resources, and protections apply in the same way as they do to a mandatory appointment. An organization should therefore distinguish between formally appointing a DPO and assigning privacy or data protection responsibilities to an employee who is not designated as the DPO.

## Who Can Serve as the DPO?

The GDPR provides organizations with considerable flexibility in structuring the DPO function:

- **An existing employee may serve as the DPO.** The DPO may perform other duties within the organization, provided those responsibilities do not create a **conflict of interest** with the DPO's independent role.
- **The DPO function may be outsourced.** An organization may engage an external individual or organization under a service contract. An external DPO is subject to the same substantive requirements concerning the DPO's position and tasks as an internally appointed DPO.
- **A group of companies may appoint a single DPO**, provided the DPO is easily accessible from each establishment. Similarly, several public authorities or bodies may designate a single DPO, taking account of their organizational structure and size.

Where one DPO serves multiple entities, the organization should consider whether that arrangement realistically allows the DPO to perform the required functions effectively. Depending on the size and complexity of the organization, this may require additional staff, technical resources, or a broader privacy team supporting the DPO.

### Qualifications of the DPO

Under [Article 37 GDPR](https://gdpr-info.eu/art-37-gdpr/?ref=thedelatorrereview.com), a DPO must be designated on the basis of their **professional qualities**, particularly their **expert knowledge of data protection law and practices** and their ability to perform the functions assigned to the DPO.

The GDPR does not prescribe particular degrees, certifications, or professional credentials. Nor does it establish a single required level of expertise. Instead, the appropriate level of expertise should reflect the nature, complexity, scale, and risks of the organization's processing activities and the level of protection required for the personal data involved.

As a result, an organization engaged in particularly complex or high-risk processing should ensure that its DPO has a correspondingly sophisticated level of data protection expertise. In practice, it is also valuable for a DPO to understand the organization's industry or sector, organizational structure, information systems, security environment, and specific processing operations.

## Ensuring the DPO Can Perform the Role Effectively

Appointing a qualified DPO is only part of the organization's obligation. Under [**Article 38 GDPR**](https://gdpr-info.eu/art-38-gdpr/?ref=thedelatorrereview.com), controllers and processors must establish conditions that allow the DPO to perform the role effectively and independently.

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/08/Position_of_the_DPO.png)

In particular, organizations must ensure that:

- the DPO is **involved, properly and in a timely manner, in all issues relating to the protection of personal data**;
- the DPO is provided with the **resources necessary** to perform their tasks and maintain their expert knowledge, including sufficient time, budget, infrastructure, training, and, where appropriate, staff;
- the DPO has appropriate **access to personal data and processing operations** and to the organizational functions and information necessary to perform the role;
- the DPO is able to **operate independently** and does not receive instructions regarding the exercise of their DPO tasks;
- the DPO **reports directly to the highest management level** of the controller or processor;
- the DPO is **not dismissed or penalized for performing their DPO tasks**; and
- any additional duties assigned to the DPO **do not create a conflict of interest**.

Reporting to the highest management level does not necessarily mean that the DPO must be administratively or line-managed by the board or equivalent governing body. Rather, the DPO must have direct access to the senior decision-makers responsible for the organization's processing activities and be able to raise data protection concerns at the appropriate level.

### One DPO, Supported by a Team

The GDPR contemplates the designation of a DPO who is responsible for the [Article 39](https://gdpr-info.eu/art-39-gdpr/?ref=thedelatorrereview.com) tasks, but this does not mean that one person must perform every privacy-related function within the organization.

A DPO may be supported by a team of privacy professionals, lawyers, security specialists, compliance personnel, or other staff. Where a DPO office or privacy team is established, the organization should clearly define the respective roles and responsibilities and identify who holds the formal DPO position.

This distinction matters because “Data Protection Officer” is a specific statutory role under the GDPR, carrying particular responsibilities, independence requirements, and protections. Organizations should therefore avoid using the DPO title loosely for other members of the privacy team.

## What Are the DPO’s Tasks?

The DPO’s responsibilities extend to all processing of personal data carried out by the organization, not merely the particular processing activities that triggered the requirement to appoint a DPO.

Under **Article 39 GDPR**, the DPO must, at a minimum:

- **inform and advise** the controller or processor and employees who carry out processing about their obligations under the GDPR and other applicable EU or Member State data protection laws;
- **monitor compliance** with the GDPR, other applicable data protection laws, and the organization’s own data protection policies;
- support compliance activities involving the **assignment of responsibilities, awareness-raising, staff training, and audits**;
- provide advice, when requested, regarding **Data Protection Impact Assessments (DPIAs)** and monitor their performance under Article 35;
- **cooperate with the competent supervisory authority**; and
- **act as the supervisory authority’s contact point** on matters relating to processing, including prior consultation under Article 36, and consult with the authority where appropriate.

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/08/Tasks_of_the_DPO.png)

The DPO also serves as an important contact for individuals whose personal data is processed. Under [Article 38](https://gdpr-info.eu/art-38-gdpr/?ref=thedelatorrereview.com), data subjects may contact the DPO regarding issues relating to the processing of their personal data and the exercise of their GDPR rights.

When carrying out these responsibilities, the DPO must have due regard to the risks associated with the organization's processing operations, taking into account the nature, scope, context, and purposes of the processing.

### The DPO and DPIAs

The DPO also has an important advisory role in connection with Data Protection Impact Assessments (DPIAs).

Under [Article 35 GDPR](https://gdpr-info.eu/art-35-gdpr/?ref=thedelatorrereview.com), where an organization is required to conduct a DPIA, the controller must seek the advice of the DPO, where one has been designated. The DPO can advise on matters such as whether a DPIA is required, the methodology used, appropriate safeguards, and whether the assessment has been conducted properly.

The responsibility for carrying out the DPIA and complying with the GDPR, however, remains with the controller—not the DPO.

### Can the DPO Perform Other Tasks?

Yes. The GDPR permits organizations to assign the DPO additional tasks and responsibilities, provided that those responsibilities do not create a conflict of interest.

Organizations should examine the substance of the person's additional responsibilities and determine whether those responsibilities compromise—or could appear to compromise—the **i**ndependence of the DPO function.

> **Example: Records of Processing Activities**  
>  
> Article 30 GDPR requires controllers and processors to maintainrecords of processing activities (ROPAs)**.** An organization may assign responsibility for maintaining those records to the DPO, provided the arrangement does not interfere with the DPO's independent responsibilities or otherwise create a conflict of interest.

The central question is whether the additional position places the DPO in a role in which they determine the purposes and means of processing personal data. A DPO must be able to independently advise and monitor the organization’s processing activities. It is therefore problematic for the same person to make significant decisions about how and why personal data will be processed and then, acting as DPO, independently oversee those same decisions.

> **Example: Head of Marketing**  
>  
> A company's Head of Marketing determines the objectives of an advertising campaign, which customers will be targeted, what personal data will be used, and how those customers will be contacted. Appointing the same individual as DPO would likely create a conflict because the person would be responsible for **making significant decisions about the processing and independently monitoring those same decisions for GDPR compliance**.

By contrast, combining the DPO function with another information-governance role does not automatically create a conflict.

> **Example: Freedom of Information Officer**  
>  
> A public authority may be able to appoint its existing **Freedom of Information (FOI) officer or records manager** as its DPO where the individual's other responsibilities concern information-rights compliance and do not involve determining the purposes and means of personal data processing. Whether the combination is appropriate ultimately depends on the individual's actual responsibilities within the organization.

---

> The practical principle is straightforward: **the DPO can advise, monitor, challenge, and support—but should not be placed in a position where they are effectively required to independently oversee processing decisions that they themselves made.**

---

## DPO Advice: A Risk-Based Approach

When performing their duties, DPOs must take a **risk-based approach to data protection oversight**. Article 39 GDPR specifically requires the DPO to have due regard to the risks associated with processing operations, taking into account the **nature, scope, context, and purposes of the processing**.

In practice, this means that the DPO should prioritize attention and resources according to the level of risk presented by the organization's processing activities. Higher-risk activities may warrant greater scrutiny—for example, processing involving special categories of personal data, systematic monitoring, vulnerable individuals, new technologies, large volumes of data, or processing that could have a significant adverse impact on individuals.

The DPO's advice is an important component of the organization's accountability framework, but the DPO does not make compliance decisions on behalf of the controller or processor. Management ultimately remains responsible for deciding how the organization will comply with the GDPR.

**Where an organization decides not to follow the DPO's advice, it is good practice to document both the DPO's recommendation and the reasons for departing from it.** Maintaining this record can help the organization demonstrate its decision-making process and compliance with the GDPR's accountability principle.

## The DPO Must Be Easily Accessible

A DPO must be easily accessible to individuals, employees, and the competent supervisory authority. Organizations must publish the DPO’s contact details, provide them to the supervisory authority, and make them readily available internally. The GDPR does not require the DPO’s name to be published; a dedicated email address or other contact method may be sufficient.

DPO contact details must also be provided in privacy notices under Articles 13 and 14 and, where applicable, in a prior consultation under Article 36\. For personal data breaches, Articles 33 and 34 require the DPO’s name and contact details or those of another appropriate contact point.

## Additional Resources

### GDPR 

- [**Article 37 of GDPR**](https://gdpr-info.eu/art-37-gdpr/?ref=thedelatorrereview.com) **–** Designation of the data protection officer
- [**Article 38 of GDPR**](https://gdpr-info.eu/art-38-gdpr/?ref=thedelatorrereview.com) **\-** Position of the DPO
- [**Article 39 of GDPR**](https://gdpr-info.eu/art-39-gdpr/?ref=thedelatorrereview.com) **\-** Tasks of the data protection officer.
- [**Articles 36 of GDPR**](https://gdpr-info.eu/art-36-gdpr/?ref=thedelatorrereview.com) **\-** on DPIAs and prior consultation,
- [**Article 83 of GDPR**](https://gdpr-info.eu/art-83-gdpr/?ref=thedelatorrereview.com) \- General conditions for imposing administrative fines
- [Recital 97 - Data Protection Officer](https://gdpr-info.eu/recitals/no-97/?ref=thedelatorrereview.com)

### EU Guidance

- **European Data Protection Board (EDPB) —** [**Guidelines on Data Protection Officers (DPOs)**](https://ec.europa.eu/newsroom/article29/items/612048?ref=thedelatorrereview.com): Originally adopted by the Article 29 Working Party (WP29) and subsequently endorsed by the EDPB. The Guidelines provide detailed guidance on mandatory and voluntary appointments, “core activities,” “large scale,” regular and systematic monitoring, DPO expertise, independence, resources, and conflicts of interest.
- **WP29 —** [**Frequently Asked Questions on Data Protection Officers**](https://ec.europa.eu/information%5Fsociety/newsroom/image/document/2016-51/wp243%5Fannex%5Fen%5F40856.pdf?ref=thedelatorrereview.com): A useful short companion to the DPO Guidelines.

### DPO Handbook

- [**The DPO Handbook**](https://ssrn.com/abstract=3428957?ref=thedelatorrereview.com) **(2019):** Prepared for the EU-funded T4DATA training-of-trainers program, this comprehensive handbook covers the development of European data protection law, the GDPR framework, and practical guidance on performing the DPO function. Although developed primarily for public-sector DPOs, much of the guidance is also useful for private-sector organizations.

### National Data Protection Authorities

- **CNIL (France) —** [**DPO Skills Certification**](https://www.cnil.fr/fr/certification-des-competences-du-dpo-la-cnil-adopte-deux-referentiels?ref=thedelatorrereview.com)**:** Guidance on the CNIL's certification framework for DPO skills and knowledge.

### Additional Commentary and Practical Resources

- **Fieldfisher —** [**Give Me a DPO!**](https://www.youtube.com/watch?v=NqRW3WlLdg0&ref=thedelatorrereview.com) **(2020):** Webinar discussing practical issues surrounding the DPO function.
- **Hunton Andrews Kurth —** [**CNIL Adopts Referentials on DPO Certification**](https://www.huntonprivacyblog.com/2018/10/18/cnil-adopts-referentials-dpo-certification/?ref=thedelatorrereview.com)**:** Overview of the CNIL's approach to DPO certification.
- **Bloomberg Law —** [**Avoiding Conflicts of Interest in Selecting a Data Protection Officer**](https://news.bloomberglaw.com/privacy-and-data-security/insight-avoiding-conflicts-of-interest-in-selecting-a-data-protection-officer?ref=thedelatorrereview.com) **(2020):** Practical discussion of one of the most important organizational issues surrounding DPO appointments: ensuring that other responsibilities do not compromise the DPO's independence.

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/08/Screenshot-2026-07-04-at-4.45.19---PM-2.jpeg)

###