Do you actually need to appoint a DPO?
This is one of the first questions most organisations bring to me, and it’s a fair one — appointing a Data Protection Officer is a commitment, and nobody wants to take on a legal obligation that doesn’t actually apply to them.
The legal question
Under Article 37 UK GDPR, appointing a DPO is mandatory in three situations:
- You’re a public authority or body (with limited exceptions for courts acting in a judicial capacity).
- Your core activities require large-scale, regular and systematic monitoring of individuals.
- Your core activities involve large-scale processing of special category data, or data relating to criminal convictions and offences.
The word doing most of the work here is core. Processing personal data as a side effect of running payroll or a CRM doesn’t count — the question is whether monitoring or large-scale sensitive processing is a central part of what your organisation does.
Where this gets less obvious
Most of my conversations aren’t about organisations that obviously meet the threshold — they’re about organisations sitting close to the line. An ad-tech platform profiling users at scale is likely to meet the “regular and systematic monitoring” test. A recruitment agency processing a moderate volume of health data for reasonable adjustments is a less clear case, and depends heavily on scale and regularity.
If you’re unsure which side of the line you’re on, that uncertainty is itself useful information — it usually means the answer depends on specifics I’d need to look at properly, not a general rule I can give you in the abstract.
Voluntary appointment is still worth considering
Plenty of organisations that don’t meet the mandatory threshold appoint a DPO anyway, because it:
- Gives leadership a single, accountable point of contact for data protection risk
- Demonstrates accountability under Article 5(2), which the ICO takes seriously as a mitigating factor
- Avoids the scramble of appointing someone reactively, after an incident or a regulator enquiry
If you’re still not sure
Tell me what your organisation actually does — not what your privacy policy says, what actually happens with the data day to day — and I’ll give you a straight answer on whether appointment is likely to be required, and what your options are either way.