When does an organisation need a data protection officer? How to make a documented DPO assessment

When does an organisation need a data protection officer? How to make a documented DPO assessment

Must you designate a data protection officer? The Article 37 obligation depends on what you do with personal data, not on company size. How to assess core activities, monitoring, special categories and scale, and document the answer.

Summary: Designating a data protection officer, DPO, is mandatory for certain organisations under Article 37 of the GDPR. But the obligation is not decided by a headcount or a simple threshold for how much personal data the organisation processes. The assessment has to start from the organisation’s actual processing activities: what counts as core activities, whether people are monitored regularly and systematically, which types of data are processed and whether processing takes place on a large scale. This article walks through how a practical DPO assessment can be carried out, why the conclusion should be documented and when it needs to be revisited.

The question that comes up in almost every GDPR programme

An organisation is working on GDPR and the question comes up: do we actually need a data protection officer?

Sometimes the answer is simple. For public authorities and other public bodies there is a clear obligation. There are also organisations where processing large volumes of sensitive personal data, or extensive monitoring, obviously sits at the core of what they do. But for many private companies the question is far more nuanced. The organisation may use CCTV, track vehicles or equipment with location data, process some health data, use extensive customer data for profiling, tracking or other systematic monitoring, process data on behalf of other organisations, or have grown quickly into several countries and far more data subjects.

Then it is rarely enough to conclude that “we are not that big a company”. The GDPR rules on data protection officers start from what the organisation actually does with personal data, not from the size of the company.

The Swedish Authority for Privacy Protection, IMY, summarises the obligation in three questions. Are you a public authority or an elected assembly, in other words a public body? Do your core activities consist of regular, systematic and large-scale monitoring of individuals? Do your core activities consist of large-scale processing of special categories of personal data or data relating to criminal offences? If the answer to any of them is yes, you must designate a data protection officer.

The DPO question deserves a documented answer

It is easy to treat the data protection officer question as an administrative detail: either the organisation has someone called DPO, or it does not. But the question belongs earlier in the data protection work. The organisation should be able to explain why it has concluded that a data protection officer is, or is not, required.

The EDPB guidelines on data protection officers, adopted by the Article 29 Working Party in 2017 and since endorsed by the EDPB, explicitly recommend that organisations document the internal analysis of whether a DPO must be appointed, unless it is obvious that none is required. The analysis is part of the documentation under the accountability principle, may be requested by the supervisory authority, and should be updated when the organisation undertakes new activities or provides new services that might fall within Article 37.

That brings several benefits. Management gets a genuine basis for its decision. The assessment can be shown in a customer audit or under supervision. And above all, it is possible to return to the conclusion later and ask whether the same circumstances still apply. A DPO assessment should therefore not consist of the single sentence “we have concluded that a DPO is not required”. It should show which facts the conclusion rests on.

Start with the processing activities, not with the size of the organisation

A common first mistake is to start with how many employees or customers the organisation has. Those figures can be relevant to the assessment of scale, but they do not settle the question on their own.

A better start is to identify the processing activities that could actually be relevant to Article 37. That does not have to mean rebuilding the entire record of processing activities from scratch. In a focused DPO assessment the attention can go to the activities that could affect the conclusion: CCTV, location data, profiling, health data, biometric data, customer data used for profiling or tracking, or processing the organisation carries out on behalf of clients.

Is the processing part of the core activities?

IMY describes core activities as the necessary, central activities an organisation carries out to achieve its goals. For a shoe shop the core activity is selling shoes. A hospital’s goal is to provide healthcare, and it cannot do so without processing health data, which makes that processing part of the hospital’s core activities. The EDPB uses the same example and adds a security company monitoring shopping centres and public spaces: surveillance is the core activity, and it is inextricably linked to the processing of personal data.

Support functions such as paying salaries or standard IT support, on the other hand, are normally not core activities, even though the organisation needs them to function. That is an important distinction. Almost every company processes employee data and has customer contacts. That does not automatically mean its core activities consist of processing personal data.

In other organisations the personal data is itself a necessary part of the service being sold. An analytics company that profiles users, a healthcare provider processing health data or a supplier whose service is built on tracking therefore has to make a very different assessment from a manufacturing company with an ordinary HR and customer register.

Does the organisation monitor people regularly and systematically?

Article 37 also applies to organisations whose core activities consist of regular and systematic monitoring of data subjects on a large scale. The concept is broader than classic physical surveillance. IMY describes regular and systematic monitoring as constant or recurring monitoring that follows a system or a plan, and mentions all forms of tracking and profiling on the internet as well as connected devices such as smart meters and other IoT. The EDPB’s examples range from telecommunications operators and data-driven marketing to risk profiling for credit scoring and insurance, location tracking by mobile apps, loyalty programmes, behavioural advertising, health data from wearables and CCTV.

The organisation should therefore ask: Is the monitoring recurring? Is it structured? Is it part of how the service works? And does it happen on a scale that makes Article 37 relevant? Occasional technical logging is not the same as a business model built on continuous tracking of people. It is the actual use that needs to be understood.

Do you process special categories of data on a large scale?

The second assessment area concerns special categories of personal data under Article 9, for example health data, genetic data, biometric data for unique identification, religious beliefs or sexual orientation, as well as data relating to criminal convictions and offences under Article 10. Article 37 uses the word “and” between the two categories, but the EDPB notes that there is no policy reason to require both at the same time. The text should be read as “or”.

But again there is a condition: the processing has to take place on a large scale and be part of the core activities. An organisation occasionally handling a medical certificate is not in the same position as one whose main service is built on large volumes of health data.

“Large scale” has no numeric threshold

This is often the hardest part of a DPO assessment. The GDPR does not say that more than a certain number of data subjects means a DPO. There is no such threshold, and the EDPB states explicitly that it is not possible to give a precise number that would apply in all situations. Instead the EDPB sets out four factors to be weighed together:

  • the number of data subjects concerned, as a specific number or as a proportion of the relevant population,
  • the volume of data and the range of different data items,
  • the duration or permanence of the processing,
  • the geographical extent of the processing.

IMY and the EDPB use hospitals, public transport, banks and insurance companies as examples of large-scale processing, and an individual physician processing patient data or an individual lawyer processing criminal offence data as examples of processing that is normally not large scale. Between those extremes lies a grey zone, and that is where many assessments end up. When the processing is not close to either end, the organisation needs to weigh the four factors together, set out its reasoning and, ideally, define which future changes would alter the conclusion.

Large scale is therefore not a standalone criterion that automatically triggers a DPO requirement. Scale must be assessed together with the Article 37 criteria on regular and systematic monitoring or the processing of special categories of data and criminal offence data.

Do not forget the processor role

Another common simplification is to assess only the organisation’s own customer and employee data. But the DPO requirement applies to both controllers and processors. A company that processes relatively little personal data for its own purposes may still be covered because its core activities consist of processing large volumes of personal data on behalf of clients.

IMY gives the example of a small company whose processor has many similar clients. The processor then handles large volumes of personal data from many different clients and may need a data protection officer, even though the small company does not. The EDPB adds that the reverse also holds: the controller having to designate a DPO does not automatically mean the processor must. Every organisation makes its own assessment, and one that holds both roles should assess from both perspectives.

A practical DPO assessment in seven steps

A structured assessment can be done without turning into a large legal project:

  1. Delimit the organisation and the roles. Which legal entity is being assessed, and does it act as controller, processor or both?
  2. Identify the relevant processing activities. Focus on activities that could matter for Article 37, not on every administrative piece of personal data in the company.
  3. Assess the core activities. Is the processing an inextricable part of what the organisation exists to do, or a support activity?
  4. Assess monitoring. Is there regular and systematic monitoring, for example profiling, location data or CCTV?
  5. Assess data types and scale. Are special categories or criminal offence data involved? How many data subjects, how much data, for how long and across which geographical area?
  6. Document the conclusion. Describe the facts and assumptions the assessment rests on and why Article 37 is, or is not, considered applicable.
  7. Define when the question is to be revisited. The assessment should not have to be redone every month, but it should be clear which changes could affect the conclusion.

The last step matters most. A well-made DPO assessment does not only give an answer for today. It helps the organisation understand when today’s answer may stop being valid.

When should the assessment be revisited?

A company that does not need a DPO today may need one later. Typical events that justify a new assessment:

  • the business expands geographically or the number of data subjects grows sharply,
  • a new service is built on profiling or tracking,
  • CCTV or location data is extended,
  • large volumes of health data or other special categories start being processed,
  • a new processor engagement means processing on behalf of many more clients,
  • acquisitions, new business models or major changes in how data is used.

A good assessment therefore documents concrete review triggers, not just a conclusion: the facts, the assessment against Article 37, the recommended organisational solution and which changes should trigger a new assessment.

If no DPO is required: who is responsible then?

Not having to designate a data protection officer does not make the data protection work disappear. Someone still needs to hold together the record of processing activities, processor agreements, data subject rights, incidents, impact assessments and ongoing follow-up. That can be solved through a data protection coordinator, legal, compliance, a privacy function or external specialist support.

Be careful with the title itself, though. An organisation may designate a data protection officer voluntarily even without a legal obligation, but then the requirements of Articles 37 to 39 on the DPO’s designation, position and tasks apply as if the designation had been mandatory, and IMY states that a voluntary DPO must also be notified to the authority. The EDPB therefore recommends making it clear, internally and externally, that a person or consultant working on data protection without meeting those requirements is not a data protection officer. Do not appoint a “DPO light” because it sounds good.

If a DPO is required: the next assessment begins

When the conclusion is that a data protection officer is required, the next question is not just who can take the role. The organisation has to ensure expertise, independence, resources, access to top management and the absence of conflicts of interest. The DPO must be involved in data protection matters properly and at an early stage, be able to act independently and report to the highest management level. As a rule of thumb the EDPB notes that positions such as chief executive, chief financial officer, head of marketing, head of HR and head of IT are normally incompatible with the role, because they determine the purposes and means of important processing.

Then comes the choice between an internal and an external solution. What the DPO should and should not do is covered in our insight the data protection officer should review, not own all of the GDPR work, and how to compare an external solution in the guide external data protection officer: how to compare providers. But that question should only be settled after the needs assessment.

A basis for decision, not just a yes or no

A DPO assessment should give the organisation more than an answer to Article 37. A good result shows what has been assessed, which facts the conclusion rests on, which uncertainties remain, which data protection organisation is appropriate and when the assessment needs to be reviewed. That gives management a usable governance document. And if someone asks two years later why the organisation has no data protection officer, there is a far better answer than “we decided that a long time ago”.

How Kristensson i Skåne can help

Kristensson i Skåne helps organisations carry out a focused, documented assessment of the need for a data protection officer under Article 37, as part of our work on data protection and privacy. The work typically includes analysis of existing material, interviews or a workshop with the relevant people, a focused mapping of the relevant processing activities and a written assessment of core activities, systematic monitoring, large scale and special categories of data, from both the controller’s and the processor’s perspective.

The result is a traceable basis for decision with conclusion, grounds, organisational recommendation and a proposal for when the question should be revisited. If the assessment shows that a data protection officer is needed, we help with the next step, including the set-up of an internal or external DPO.

Frequently asked questions

Is there a company size at which a DPO becomes mandatory?

No. Article 37 is not based on headcount or turnover. What matters is whether the organisation is a public body and, otherwise, whether its core activities involve regular and systematic monitoring on a large scale or large-scale processing of special categories of data or criminal offence data.

Is there an exact number of data subjects that means large scale?

No. The EDPB states explicitly that no single number works in all situations. The assessment weighs the number of data subjects, the volume and type of data, the duration of the processing and its geographical extent. Hospitals, public transport, banks and insurers are examples of large scale; an individual physician processing patient data or an individual lawyer processing criminal offence data is an example of the opposite.

Can a processor need a DPO even if its client does not?

Yes. Every organisation makes its own assessment. A processor handling large volumes of personal data for many clients may be covered even if the individual clients are not, and conversely the processor does not automatically need a DPO because the client has one.

Can we designate a DPO voluntarily?

Yes. But then the requirements of Articles 37 to 39 on the DPO’s position, independence and tasks apply as if the designation had been mandatory, and according to IMY a voluntary DPO must also be notified to the authority. If you want a data protection function without those requirements, it should not be called a data protection officer.

Does the assessment have to be redone every year?

There is no general requirement for an annual DPO assessment. The documentation should, however, be updated when the organisation undertakes new activities or services that might fall within Article 37. The assessment should therefore state the concrete changes that trigger a new review.

Do you want a documented answer to whether you need a data protection officer, or have you already concluded that you do? Read more about our offer external data protection officer or contact us for a no-obligation conversation.

Sources: Regulation (EU) 2016/679 (GDPR), Articles 9, 10 and 37–39 and recitals 91 and 97; the Swedish Authority for Privacy Protection (IMY), “Måste vi utse ett dataskyddsombud?” and “Anmäla dataskyddsombud”, imy.se; Article 29 Working Party, Guidelines on Data Protection Officers (WP 243 rev.01), adopted 5 April 2017 and endorsed by the EDPB; EDPB, Data protection guide for small business, section Data Protection Officer, edpb.europa.eu. Verified 1 October 2026.

This text is general information, not legal advice. Whether your organisation must designate a data protection officer depends on your actual processing activities and has to be assessed case by case.