← All insights Insights

Do you actually need to appoint a DPO?

This is one of the first questions most organisations bring to me, and it’s a fair one — appointing a Data Protection Officer is a commitment, and nobody wants to take on a legal obligation that doesn’t actually apply to them.

Under Article 37 UK GDPR, appointing a DPO is mandatory in three situations:

  1. You’re a public authority or body (with limited exceptions for courts acting in a judicial capacity).
  2. Your core activities require large-scale, regular and systematic monitoring of individuals.
  3. Your core activities involve large-scale processing of special category data, or data relating to criminal convictions and offences.

The word doing most of the work here is core. Processing personal data as a side effect of running payroll or a CRM doesn’t count — the question is whether monitoring or large-scale sensitive processing is a central part of what your organisation does.

Where this gets less obvious

Most of my conversations aren’t about organisations that obviously meet the threshold — they’re about organisations sitting close to the line. An ad-tech platform profiling users at scale is likely to meet the “regular and systematic monitoring” test. A recruitment agency processing a moderate volume of health data for reasonable adjustments is a less clear case, and depends heavily on scale and regularity.

If you’re unsure which side of the line you’re on, that uncertainty is itself useful information — it usually means the answer depends on specifics I’d need to look at properly, not a general rule I can give you in the abstract.

Voluntary appointment is still worth considering

Plenty of organisations that don’t meet the mandatory threshold appoint a DPO anyway, because it:

  • Gives leadership a single, accountable point of contact for data protection risk
  • Demonstrates accountability under Article 5(2), which the ICO takes seriously as a mitigating factor
  • Avoids the scramble of appointing someone reactively, after an incident or a regulator enquiry

If you’re still not sure

Tell me what your organisation actually does — not what your privacy policy says, what actually happens with the data day to day — and I’ll give you a straight answer on whether appointment is likely to be required, and what your options are either way.

Not sure where to start? Let's talk it through.

A free 20-minute call is usually enough to tell you whether you need a DPO, a one-off review, or just some straight answers.

Book a consultation