DPO Services / Do You Need a DPO?
Do you need a Data Protection Officer?
The honest answer: only if one of three Article 37 triggers applies — you are a public body, your core activities involve large-scale regular monitoring, or they involve large-scale special-category data. Most small organisations outside those triggers do not need one. Check yours below.
The two-minute check
Answers stay in your browser — nothing is stored or sent, and there is no email gate.
The triggers, unpacked
‘Core activities’
The processing must be central to what you do — the key operations that deliver your product or service — not support functions like payroll or standard IT. A hospital’s patient records are core; its staff canteen list is not.
‘Large scale’
No fixed number exists. Regulators weigh the number of people, the volume and range of data, the duration and the geographic reach. A regional hospital: large scale. A single doctor’s practice: not, on the EDPB’s own example.
‘Regular and systematic monitoring’
Ongoing or recurring tracking that happens by design: behavioural ads, profiling and scoring, location tracking, connected devices, CCTV networks. One-off analytics on a small dataset is neither regular nor systematic.
Appointing voluntarily
Nothing stops you appointing a DPO without a trigger — and customers and procurement teams often value it. But a voluntary DPO carries every statutory duty and protection of a mandatory one: independence, no conflicting roles, direct board access. If you want the discipline without the statutory weight, a privacy lead plus external support can be the better shape — we will tell you which honestly.
Whatever you conclude — write it down
Regulators expect organisations near the line to document the assessment: which triggers were considered, the facts weighed, the conclusion reached and when it will be revisited. That record turns ‘we didn’t think we needed one’ into evidence of accountability. Our consultation produces exactly that document, whichever way the answer comes out.