Skip to content
Legiscope
Menu
Personal Data

GDPR DPO Designation: Article 37 Requirements Explained

When a DPO is mandatory under GDPR Article 37, how to appoint one, and recent EDPB enforcement findings.

Also available in:Nederlands·Polski

Under GDPR Article 37, a DPO is mandatory for public authorities or bodies other than courts acting judicially; for core activities requiring regular and systematic monitoring on a large scale; and for core activities involving large-scale processing of special-category or criminal-conviction data. Check additional national rules as well. A headcount threshold alone does not answer the EU-level question. The EDPB’s DPO guide explains these conditions.

In January 2024, the EDPB published its coordinated enforcement report on DPO designation and position. It discusses obstacles including resources, expertise, conflicts and organisational access. Use those findings to review how the role works in practice, alongside the Article 37 designation decision.

What Are the Three Mandatory Cases?

Article 37 of the GDPR requires the designation of a DPO in three specific situations:

  1. Public authorities or bodies — All government entities and organizations governed by public law must appoint a DPO, except courts acting in their judicial capacity.
  2. Large-scale systematic monitoring — Organizations whose core activities require regular and systematic monitoring of data subjects on a large scale, such as online behavior tracking, location tracking, or loyalty programs.
  3. Large-scale processing of sensitive data — Organizations whose core activities involve processing special categories of data under Article 9 (health, biometric, racial or ethnic origin, political opinions, religious beliefs) or criminal conviction data under Article 10.

The term “large scale” is not precisely defined in the GDPR. The Article 29 Working Party guidelines consider factors including the number of data subjects, the volume of data, the geographical extent, and the duration of the processing activity. A hospital processing patient records is considered large scale; a single physician’s practice generally is not.

The “core activities” criterion is also important. It refers to the primary business operations of the controller or processor, not ancillary functions. For example, payroll processing is ancillary for most organizations and does not trigger a mandatory DPO requirement — but for an outsourced payroll provider, it is the core activity.

When Should You Appoint a DPO Even If Not Required?

An organisation can designate a DPO voluntarily. Where it uses that designation, the GDPR provisions on the role, position and tasks apply. Alternatively, an organisation may assign privacy coordination to a person whose role is clearly distinguished from a statutory DPO. Assess the organisation’s needs without implying that 250 employees creates an Article 37 threshold.

Step 1: Assess Whether Designation Is Required

Analyze your data processing activities against the three mandatory criteria. Document this assessment — regulators expect written justification of the decision, whether or not a DPO is appointed. Check core activities, regularity and scale against the actual facts; the mere presence of sensitive data or monitoring does not settle every case.

Step 2: Define the Role and Select a Candidate

The GDPR requires that the DPO be designated on the basis of “professional qualities and, in particular, expert knowledge of data protection law and practices” (Article 37(5)). The DPO can be an employee or an external service provider under contract (Article 37(6)). For a detailed comparison between internal and external options, see our guide on DPO or compliance officer.

Key requirements for the role:

  • Expert knowledge of GDPR and relevant national data protection laws
  • Understanding of the organization’s data processing operations and IT infrastructure
  • Ability to act independently without instructions on how to exercise their tasks
  • Direct reporting line to the highest level of management (Article 38(3))

A group of undertakings may appoint a single DPO, provided that the DPO is easily accessible from each establishment (Article 37(2)).

Step 3: Formalize and Notify

The appointment must be formalized in writing, with a clear job description specifying duties, reporting lines, and scope of authority. The organization must then publish the DPO’s contact details and communicate them to the relevant supervisory authority (Article 37(7)). In France, this notification is done online through the CNIL.

Internal vs. External DPO: How to Choose?

An internal DPO brings deep organizational knowledge and direct access to teams, and can support close working relationships with operational teams. However, the EDPB’s 2024 enforcement report flagged that internal DPOs frequently face conflicts of interest — particularly when they also hold IT management, HR, or compliance roles.

An external DPO offers specialized expertise and objectivity. This option suits organizations without in-house data protection expertise, or where the volume of processing does not justify a full-time position. The 2024 EDPB report found that external DPOs sometimes lack sufficient access to the organization’s processing operations, reducing their effectiveness.

Regardless of the choice, Article 38 requires that the DPO:

  • Receives no instructions regarding the exercise of their tasks
  • Cannot be dismissed or penalized for performing their duties
  • Has adequate resources, including staff, budget, and access to training
  • Is involved in all issues relating to the protection of personal data from the earliest stage

What the EDPB Found: Seven Areas of DPO Non-Compliance

The EDPB’s coordinated work identifies issues to investigate when reviewing designation and position. The following review questions translate those concerns into organisational checks:

  1. Absence of designation — Organizations subject to mandatory requirements had not appointed a DPO at all.
  2. Insufficient resources — DPOs lacked budget, staff, and time to fulfill their duties.
  3. Insufficient training — DPOs were not provided with ongoing education on legal and technical developments.
  4. Tasks not properly assigned — Organizations did not explicitly entrust DPOs with the tasks required under Article 39.
  5. Conflicts of interest — DPOs held concurrent roles (IT director, head of compliance, legal counsel) that compromised their independence.
  6. Lack of reporting to management — DPOs did not have direct access to senior leadership as required by Article 38(3).
  7. Need for additional DPA guidance — Both organizations and DPOs requested clearer practical guidance from supervisory authorities.

Check that tasks are assigned, resources are sufficient and other duties do not compromise independence. For the organisational arrangements, see the DPO position guide.

Disclaimer: This article provides general guidance on GDPR DPO designation and does not constitute legal advice. Consult a qualified data protection professional for advice specific to your situation.

Under what conditions must an organisation designate a DPO under Article 37?

The three EU triggers concern public authorities or bodies other than courts acting judicially; core activities requiring regular and systematic monitoring on a large scale; and core activities involving large-scale special-category or criminal-conviction data. Also check additional national requirements.

What does “large-scale” mean in GDPR for DPO designation?

GDPR does not define large-scale numerically. The EDPB (WP243) suggests considering: number of data subjects, geographic extent, volume of data, duration of processing, and sensitivity. Processing personal data of a regional population or millions of users online typically qualifies.

Where must DPO contact details be published?

Article 37(7) requires controllers and processors to publish the DPO’s contact details (not necessarily their name — an email address or postal address is sufficient) and communicate them to the relevant supervisory authority.

What happens if an organisation fails to designate a mandatory DPO?

Failure to designate a mandatory DPO violates Article 37 and is subject to fines of up to €10 million or, for an undertaking, 2% of total worldwide annual turnover in the preceding financial year, whichever is higher under Article 83(4). The applicable enforcement measures depend on the authority, national rules and circumstances.

Conclusion

Designating a DPO is not a formality — it is a structural compliance requirement with concrete enforcement consequences. The EDPB’s coordinated enforcement has made clear that designation alone is insufficient: the DPO must be properly resourced, independent, and involved in all data protection matters from the earliest stage.

Document the designation assessment, the selected person or service, access to management, resources and conflict checks. Revisit the assessment when a new service changes the scale or nature of core processing. AI governance can require coordination with the DPO, but the AI Act does not turn the Article 26 human-oversight task into a universal requirement to appoint a separate compliance officer.

The EDPB’s 2026 coordinated enforcement action now focuses on transparency obligations (Articles 12-14), but the lessons from the 2023 DPO action remain directly applicable. Organizations that addressed the seven findings from that report are better positioned for the transparency scrutiny ahead.

A designation file that can be reviewed

For each legal entity, record its services, controller or processor role, core processing activities and the people affected. Describe scale using more than a label: population, volume, duration and geographical reach. If the answer is no DPO required, explain how each Article 37 trigger and applicable national rule was considered.

For a candidate, document expertise, availability, accessibility and other duties. Ask whether those duties determine purposes or essential means of processing. A job title alone does not resolve conflicts; inspect actual decision powers. Record how the DPO can obtain information and escalate concerns to the highest management level.

In a hypothetical group appointment, several subsidiaries share one DPO. The group identifies local contacts, languages, access arrangements and time allocation for each subsidiary. It tests whether a person in each location can contact the DPO and whether the DPO can reach the relevant decision makers. One group contract without these arrangements does not demonstrate accessibility.

Keep the appointment record separate from the organisation’s substantive compliance decisions. The DPO advises and monitors; management remains responsible for the processing. Link the file to the DPO position requirements, Article 39 tasks and accountability evidence.

L
Written by
Legiscope
Legiscope

Put this guidance into operation

See how Legiscope connects privacy records, source material and review-controlled work.

Book a tailored demo
Continue reading

Related articles

01Personal Data

Article 28 of the GDPR: Obligations Imposed on Processors

Article 28 of the GDPR is arguably one of the most important provisions in practical terms, as it imposes a series of practical obligations on data controllers (DC) in managing the processors (PR)…

02Personal Data

DPO or compliance officer ?

It's very important to understand the difference between a Data Protection Officer and all other titles such as Data Privacy Officer, compliance officer, GDPR compliance officer, and for one reason :…

03Personal Data

EU Representative GDPR Compliance Guide 2024

Navigating the complexities of the European Union's General Data Protection Regulation (GDPR) is essential for businesses operating within or targeting the EU market. GDPR, which came into effect on…

04Personal Data

GDPR and AML: 5 Compliance Conflicts + Resolution Guide 2026

In one sentence. GDPR and AML (Anti-Money Laundering) regulations pull in opposite directions: AML mandates 5-10 year retention of identity and transaction data, sanctions screening of every…

November 29, 2022
05Personal Data

GDPR and Outbound sales : €500,000 fines for non-compliance

Commercial prospecting is undoubtedly one of the risk areas of the GDPR, where it is important to be rigorous to ensure compliance with the law. Enforcement in this area continues to intensify: by Q1…

06Personal Data

GDPR Audit Guide: Step-by-Step Compliance Checklist

- A GDPR audit is essential for identifying compliance gaps and mitigating data protection risks. - Comprehensive data mapping and inventory are foundational steps in the GDPR audit process. -…

07Personal Data

GDPR Data Storage Requirements: Retention, Security and Hosting

GDPR data storage requirements cover lawful purpose, limited retention, appropriate security and accountability. The Regulation does not prescribe one retention period, one encryption algorithm or a…

08Personal Data

GDPR Information notices, a few things you need to know

GDPR information notices are among the mandatory mentions that are important to comply with. Indeed, they will demonstrate whether an organization is in compliance or not with the European…