Data Protection Officer
The Data Protection Officer (DPO) is a designated role responsible for overseeing GDPR compliance within an organization, defined in Articles 37–39. Not every organization must appoint one — but the trigger tests are broader than many companies assume, several EU member states extend them further, and regulators have fined companies both for failing to appoint a DPO and for appointing one with a conflict of interest. Even where a DPO is optional, the underlying work still has to be owned by someone.
This lesson covers when a DPO is mandatory, what the role actually does, the independence rules that make it unusual among corporate functions, and how to choose between internal and external models.
When a DPO Is Required (Article 37)
A DPO is mandatory — for controllers and processors — in three situations:
- Public authority or body. Any public authority (except courts acting judicially) needs a DPO, full stop.
- Core activities involve regular and systematic monitoring of data subjects on a large scale. This catches more private companies than any other trigger.
- Core activities involve large-scale processing of special category data (Article 9) or criminal conviction data (Article 10). Health tech, insurtech, HR screening platforms, and biometric products live here.
The terms are interpreted in EDPB (formerly Article 29 Working Party) guidance:
- Core activities means processing that is integral to achieving your business goals — not merely ancillary functions like payroll or standard IT support. For an analytics company, tracking is the core activity; for a furniture maker, employee data processing is ancillary.
- Regular and systematic monitoring includes behavioral advertising, location tracking, profiling and scoring, connected devices and wearables, loyalty programs, and most persistent tracking of users across a product or the web. Any ongoing, organized tracking arrangement qualifies — one-off processing does not.
- Large scale has no fixed number. Guidance weighs the number or proportion of data subjects, data volume and range, duration, and geographic extent. A hospital's patient data is large scale; a single physician's patient list is not. A consumer app with hundreds of thousands of tracked users should assume it is large scale; a niche B2B tool with a few thousand named users is likely not.
Two additions matter in practice. Member state law can go further — Germany, notably, requires a DPO for companies where a threshold number of employees (currently 20) regularly process personal data by automated means, which sweeps in many mid-sized companies that would escape Article 37 alone. And a corporate group may appoint a single DPO for multiple entities, provided the DPO is easily accessible from each establishment.
If you assess that no DPO is required, document that assessment. It is the accountability principle in miniature: a two-page memo applying the three tests to your processing shows a regulator you took the question seriously, and it gives you a trigger list for revisiting the decision when the product changes.
What the DPO Does (Article 39)
The DPO's minimum tasks are:
- Inform and advise the organization and employees about GDPR and related obligations
- Monitor compliance with GDPR, other data protection laws, and internal policies — including assigning responsibilities, awareness raising, training, and audits
- Advise on Data Protection Impact Assessments (DPIAs) and monitor their performance
- Cooperate with the supervisory authority
- Act as the contact point for the supervisory authority and for data subjects on all processing and rights issues
Note what is not on the list: the DPO does not personally perform compliance, sign off legal risk decisions, or own the ROPA. The controller remains responsible for compliance; the DPO advises, monitors, and challenges. Day to day, a working DPO reviews new features and vendors for privacy impact, steers DSAR and breach responses, maintains the training program, tracks regulatory developments, and reports compliance status to leadership.
Independence and the Conflict-of-Interest Rule (Article 38)
GDPR gives the DPO protections unusual for a corporate role:
- The organization cannot instruct the DPO on how to carry out their tasks or what conclusions to reach
- The DPO cannot be dismissed or penalized for performing their duties
- The DPO must report to the highest level of management — board or executive team, without intermediaries filtering the message
- The DPO must be involved, properly and in a timely manner, in all data protection matters — invited early to product and vendor decisions, not consulted after launch
- The organization must provide adequate resources: time, budget, training, and access to systems and processing operations
A DPO can hold other roles, but not ones where they would determine the purposes and means of processing — because they would then be monitoring themselves. Regulators have found conflicts (and issued fines) where the DPO was simultaneously head of IT, head of compliance/legal with decision authority over processing, COO, or a similar senior operational role. Safe pairings are advisory or specialist roles without processing-decision power; risky pairings are anything with "chief" or "head of" attached to data-heavy functions.
Finally, you must publish the DPO's contact details (a dedicated email address is fine — a personal name is not required publicly) and notify the supervisory authority of the appointment through its registration process.
Internal, External, or Fractional: Choosing a Model
| Factor | Internal DPO | External / Fractional DPO |
|---|---|---|
| Typical cost | Full-time salary — commonly six figures for experienced hires in major markets, plus training and certification | Roughly 1,000–5,000 euros/month for typical SMB scopes, scaling with complexity |
| Business context knowledge | Deep — knows systems, people, and politics | Shallower at first; depends on engagement quality |
| Independence | Harder — career and reporting pressures inside the company | Structurally easier — no internal career stake |
| Expertise breadth | One person's background | Firm-level bench across industries and regulators |
| Availability | Dedicated | Shared across clients; check response SLAs |
| Conflict-of-interest risk | Higher if double-hatted with operational roles | Low, but verify the provider has no conflicting services |
| Best fit | Larger organizations, heavy or sensitive processing, regulated sectors | Startups and SMBs needing qualified coverage without a full-time hire |
The qualification bar is the same either way: expert knowledge of data protection law and practices, proportionate to the sensitivity and complexity of your processing (Article 37(5)). Certifications like CIPP/E or national DPO certifications are useful signals, not legal requirements. For a startup that trips the DPO requirement — a health app, an adtech product, a large-scale consumer platform — the external/fractional model is usually the pragmatic starting point, moving in-house as processing scales.
Whichever model you choose, avoid the failure mode regulators punish: a paper DPO who is appointed, published, and then excluded from real decisions. Documented involvement — DPIA sign-offs, meeting minutes, advisory memos — is what demonstrates the role is functioning.
The DPO's First 90 Days
Whether internal or external, a newly appointed DPO should work a predictable ramp — and leadership should expect and resource it:
Days 1–30: discover. Read the ROPA (or flag its absence as finding number one), the privacy notices, existing DPAs, past DPIAs, breach records, and any open DSARs. Map the processing landscape against what is documented — the gap between the two is the real risk register. Meet the owners of the biggest data systems: product, marketing, HR, and engineering.
Days 31–60: triage. Rank gaps by exposure: anything touching special category data, children, large-scale tracking, or international transfers goes first. Establish the operating rhythm — a recurring leadership report, a standing slot in product and vendor review, and an intake path so teams ask before launching. Quick wins here matter politically: fixing a broken DSAR workflow or an out-of-date notice builds the credibility the harder conversations will need.
Days 61–90: institutionalize. Publish or refresh the training program, set the DPIA screening criteria so teams know when to call, agree escalation rules for breaches (who decides on 72-hour notification, and how the DPO is looped in immediately), and put review dates on every major artifact. Deliver the first formal management report: current posture, top risks, remediation plan with owners.
The pattern to avoid is the DPO spending the first quarter writing policies nobody reads. Documents follow understanding; the ramp above front-loads understanding.
DPO Setup Checklist
- Article 37 assessment performed and documented (required, or voluntary, or not appointed — with reasoning)
- Member state add-ons checked for every EU country where you have establishments (especially Germany)
- DPO appointed with demonstrable data protection expertise; conflict-of-interest screen completed
- Appointment registered with the relevant supervisory authority
- DPO contact details published in the privacy notice and internally
- Reporting line established to executive leadership/board with a recurring slot
- DPO embedded in product, vendor, and incident processes early — not post-launch
- Budget allocated for DPO training and tooling
- If external: contract covers scope, availability SLAs, breach support, and authority contact duties
- DPO activities documented (advice given, DPIAs reviewed, training delivered)
- Assessment revisit trigger defined (new products, new data types, scale changes)
Frequently Asked Questions
We are a small startup — surely the DPO rule does not apply to us?
Headcount is irrelevant to Article 37; the tests are about what you process, not how big you are. A five-person startup doing large-scale behavioral tracking or processing health data at scale needs a DPO. Conversely, a 500-person B2B company with only ordinary customer and employee data may not. Run the three tests on your actual processing.
Can our founder, GC, or head of engineering be the DPO?
Usually not safely. Founders and executives determine the purposes and means of processing — the definition of a conflict of interest. A general counsel who advises on processing decisions is also risky. If you lack a conflict-free internal candidate with the expertise, appoint an external DPO.
Does a US company with EU customers need a DPO, and is that the same as an EU representative?
They are different roles, and you may need both. The DPO obligation applies to any organization within GDPR's scope that meets the Article 37 triggers, wherever it is headquartered. The Article 27 EU representative is a separate requirement for non-EU controllers/processors without an EU establishment — a locally addressable contact point, not a compliance overseer. One person or firm cannot generally serve as both without conflict concerns, since the representative acts on your mandate while the DPO must be independent.
Is the DPO personally liable for our GDPR violations?
No. GDPR liability sits with the controller or processor, not the DPO personally. The DPO also cannot be dismissed or penalized for the advice they give. This protection is deliberate — it lets the DPO deliver unwelcome findings without fear.
What qualifications should we look for?
Look for demonstrable knowledge of GDPR and national data protection law, familiarity with your sector's processing, and enough technical literacy to interrogate systems and vendors. Practical signals: prior DPO or privacy counsel experience, CIPP/E or equivalent certification, and comfort interacting with supervisory authorities. For external providers, ask who specifically will serve you, their client load, and their breach-response availability.
If we appoint a DPO voluntarily, do all the rules still apply?
Yes. A voluntarily appointed DPO is subject to the same independence, resourcing, conflict, and task requirements as a mandatory one. If you want privacy ownership without the full Article 38 regime, title the role "privacy lead" or "privacy manager" instead — and document that choice.
In the next lesson, we will cover cross-border data transfers — Chapter V, SCCs, the EU-US Data Privacy Framework, and transfer impact assessments.
A DPO (or privacy lead) is far more effective with good tooling behind them. AuditXYZ helps you compare compliance automation platforms and find auditors — so your privacy program runs on evidence, not spreadsheets.