
A DPO appointment is not a badge to acquire when a business reaches a certain headcount. It is a governance decision triggered by the nature, scale and purpose of personal data processing. For organisations expanding across Europe, the question of when is a DPO required should be answered early, before privacy risks become embedded in products, supplier arrangements and operational processes.
Under both the GDPR and UK GDPR, the requirement can apply to controllers and processors. A business does not need to be headquartered in the EU or UK for the issue to arise. If its processing is subject to those regimes, its DPO obligations may be too.
When is a DPO required under GDPR and UK GDPR?
Article 37 of the GDPR, reflected in the UK GDPR, requires an organisation to designate a Data Protection Officer in three principal situations.
First, a DPO is required where processing is carried out by a public authority or public body, except for courts acting in their judicial capacity. This is generally clear in practice, although the status of particular bodies should be assessed against the relevant national framework.
Second, a DPO is required where the organisation's core activities consist of processing operations that require regular and systematic monitoring of individuals on a large scale. This is the provision most often relevant to technology businesses, financial services, digital platforms, insurers, adtech providers and organisations operating sophisticated employee or customer analytics.
Third, appointment is mandatory where core activities consist of large-scale processing of special category data or personal data relating to criminal convictions and offences. Special category data includes health information, biometric data used for identification, genetic data, racial or ethnic origin, political opinions, religious beliefs, trade union membership and data concerning sex life or sexual orientation.
The decisive terms are not always self-explanatory. There is no universal employee-count or record-count threshold that automatically determines whether a DPO is needed. The assessment must look at the organisation's actual processing operations, not just its industry label or stated intention.
Core activities are central business functions
A core activity is an operation that is integral to achieving an organisation's commercial or operational objectives. A hospital processing patient records, for example, processes health data as part of its central purpose. A software provider whose service depends on observing user behaviour to personalise outputs may conduct monitoring as a core activity.
By contrast, processing employee payroll records or maintaining a small internal contact database will usually be necessary support activity rather than a core activity. That distinction matters. Every employer handles some personal data, but not every employer must appoint a DPO.
The answer can change as a business model develops. A manufacturer may not require a DPO merely because it holds staff and customer data. It may, however, need one if it launches connected products that continuously analyse user behaviour across multiple markets, or creates a health-data service line that becomes central to its operations.
What counts as regular, systematic and large-scale monitoring?
Regular monitoring is recurring or ongoing rather than isolated. Systematic monitoring is organised, planned or part of a defined strategy. It may include online behavioural tracking, profiling, location tracking, credit scoring, fraud detection, telematics, remote patient monitoring or workforce monitoring conducted through digital systems.
Large scale requires a contextual assessment. Relevant factors include the number of people affected, the volume and range of data, the duration of processing and the geographical reach of the activity. A multi-country platform analysing millions of customer interactions is plainly different from a local business reviewing a limited number of service enquiries.
Scale is not solely about volume. A smaller number of highly sensitive records processed continuously across several jurisdictions can still create a strong case for formal DPO oversight. Organisations should document the reasoning behind their assessment, including the assumptions used and the data flows considered. This creates a defensible governance record and makes future reassessment more straightforward.
A DPO may be sensible even where one is not mandatory
The statutory test is the starting point, not the only decision point. A voluntary DPO appointment can provide clear accountability where an organisation has substantial cross-border operations, frequent data subject requests, complex vendor ecosystems, recurring DPIAs, or a board expectation of structured privacy reporting.
There is a trade-off. Calling someone a DPO carries obligations around independence, expertise, access to senior management and avoidance of conflicts of interest. An organisation should not use the title casually for an executive whose role requires them to determine the purposes and means of processing, such as a chief executive, head of marketing or head of IT. Those responsibilities may conflict with the DPO's duty to monitor compliance independently.
Where a business does not need a formal DPO, a privacy lead, privacy manager or outsourced advisory function may be more appropriate. The role can still coordinate records of processing, vendor due diligence, impact assessments, incident handling and privacy training without creating ambiguity about statutory DPO status.
A DPO is not the same as an EU or UK Representative
This distinction is especially relevant for US and APAC organisations entering European markets without a local establishment. An EU Representative under GDPR Article 27, or a UK Representative under the UK GDPR, acts as a local contact point for regulators and individuals in defined circumstances. The Representative requirement is driven by the absence of an establishment and the nature of processing directed at people in the relevant territory.
A DPO, meanwhile, has a wider internal monitoring and advisory role. They inform and advise the organisation, monitor compliance, advise on DPIAs where requested, cooperate with supervisory authorities and act as a contact point on processing issues. One appointment does not automatically satisfy the other requirement.
Depending on the facts, an organisation may need a DPO, an EU Representative, a UK Representative, or a combination of these arrangements. International groups should assess each legal entity and processing model while also considering whether a group-level DPO structure can provide a practical, accessible point of contact for relevant teams and data subjects.
What an effective DPO function looks like
Appointing a named individual is only the beginning. A DPO must have sufficient expert knowledge of data protection law and practice, adequate resources, access to information and the ability to report directly to the highest management level. They need visibility of product changes, supplier onboarding, security incidents, international transfers and major data-use decisions before those decisions are finalised.
In practical terms, an effective DPO function needs operating rhythms: a defined escalation route for incidents, a process for reviewing DPIAs, a current record of processing activities, ownership of DSAR workflows, clear vendor-risk controls and regular reporting that gives senior leaders a usable view of exposure and progress. These controls should work across business units rather than rely on informal knowledge held by one person.
For organisations using an outsourced DPO, continuity and breadth of support are critical. A single advisor may provide valuable expertise, but complex international operations also require legal interpretation, privacy programme management and technical operational capability. Formiti's Three-Team Model brings Legal, Privacy and Technical Operations teams into the DPO support model, helping translate obligations into controls, workflows and evidence that business teams can maintain.
AI systems can change the DPO assessment
Deploying AI does not automatically create a DPO requirement under the GDPR or UK GDPR. However, AI systems can materially alter the underlying assessment where they introduce large-scale profiling, ongoing monitoring, biometric processing, health-data analysis or significant automated decision-making.
Privacy and AI governance should therefore be connected. An AI system registry, data-flow mapping, risk classification, vendor assessment and DPIA process can reveal whether a new deployment changes the organisation's DPO position. The EU AI Act creates its own governance obligations, but it does not replace GDPR accountability or the DPO function where that function is required.
This is particularly relevant where an organisation procures AI capabilities from third parties. The provider's assurances do not remove the deployer's responsibilities for the personal data it controls or processes. Privacy review should be built into procurement, design, testing and change management, rather than added after deployment.
How to make the decision operational
A reliable assessment begins with an accurate view of processing. Identify the entities involved, the jurisdictions reached, the categories of data handled, the affected populations, the purpose of each processing operation and whether monitoring or sensitive-data processing is central to the business. Review current systems as well as planned products, acquisitions and market-entry activity.
Next, test those facts against the mandatory DPO criteria and record the outcome. If a DPO is appointed, define the mandate, reporting line, budget, access rights and conflict-of-interest safeguards. If one is not appointed, assign clear privacy ownership and set a review trigger, such as a new AI use case, expansion into a new market, a material rise in data volumes or a change in the types of data processed.
The most useful question is not whether a DPO can be avoided. It is whether the organisation has the independent expertise, operational visibility and senior-level accountability needed to manage its data responsibilities as the business changes.