Skip to content

DPO Services / Do You Need a DPO?

Do you need a Data Protection Officer?

The honest answer: only if one of three Article 37 triggers applies — you are a public body, your core activities involve large-scale regular monitoring, or they involve large-scale special-category data. Most small organisations outside those triggers do not need one. Check yours below.

The two-minute check

Answers stay in your browser — nothing is stored or sent, and there is no email gate.

1. Are you a public authority or body (other than a court acting judicially)?

National, regional and local authorities, and bodies governed by public law. Private companies carrying out public tasks can also be caught in some member states.

2. Do your core activities involve regular and systematic monitoring of individuals on a large scale?

Think behavioural advertising, location tracking, telematics, wearables, loyalty analytics, CCTV networks — where monitoring is central to what you do, not incidental (like ordinary staff records).

3. Do your core activities involve large-scale processing of special-category or criminal-offence data?

Health, biometrics, genetics, sexual orientation, religion, politics, trade-union membership, or criminal data — at scale: think hospitals and insurers rather than a single occupational-health file.

The triggers, unpacked

‘Core activities’

The processing must be central to what you do — the key operations that deliver your product or service — not support functions like payroll or standard IT. A hospital’s patient records are core; its staff canteen list is not.

‘Large scale’

No fixed number exists. Regulators weigh the number of people, the volume and range of data, the duration and the geographic reach. A regional hospital: large scale. A single doctor’s practice: not, on the EDPB’s own example.

‘Regular and systematic monitoring’

Ongoing or recurring tracking that happens by design: behavioural ads, profiling and scoring, location tracking, connected devices, CCTV networks. One-off analytics on a small dataset is neither regular nor systematic.

Appointing voluntarily

Nothing stops you appointing a DPO without a trigger — and customers and procurement teams often value it. But a voluntary DPO carries every statutory duty and protection of a mandatory one: independence, no conflicting roles, direct board access. If you want the discipline without the statutory weight, a privacy lead plus external support can be the better shape — we will tell you which honestly.

Whatever you conclude — write it down

Regulators expect organisations near the line to document the assessment: which triggers were considered, the facts weighed, the conclusion reached and when it will be revisited. That record turns ‘we didn’t think we needed one’ into evidence of accountability. Our consultation produces exactly that document, whichever way the answer comes out.

Reviewed by Zuzana Ruddock, Certified DPO and EU General Data Protection Regulation Practitioner (certified by the International Board for IT Governance Qualifications). Last reviewed: 11 July 2026. This page is general information, not legal advice.