Do I Need a Data Protection Officer for My Small Business?
Most small businesses don't need a formal DPO under GDPR, but the exceptions catch more small teams than you'd expect. Here's how to think about it at small-business scale specifically.
The short answer for most small businesses is no, GDPR’s Data Protection Officer requirement wasn’t designed to apply to every company that processes any personal data, and company size isn’t even the formal trigger. But “most small businesses don’t need one” isn’t the same as “your small business definitely doesn’t,” and a few common small-business situations land closer to the requirement than founders usually expect.
The formal trigger isn’t about size at all
GDPR’s Article 37 requires a DPO when a business’s core activities involve either:
- Regular and systematic monitoring of individuals on a large scale, or
- Large-scale processing of special category data (health, biometric, genetic, religious, political, etc.) or criminal conviction data, as a core activity.
Notice what’s absent: revenue, headcount, and funding stage aren’t part of the test at all. A five-person company can trigger the requirement; a five-hundred-person company that mostly processes basic contact and billing data might not. We walk through the full three-part test in our detailed DPO test guide, this piece focuses specifically on where small teams tend to land.
Where small businesses actually get caught
- Health, wellness, and fitness startups. A small telehealth or fitness-tracking app processing health data as its core product can hit “large-scale special category processing” well before it hits any meaningful revenue milestone, “large-scale” is about volume of data subjects and sensitivity, not company size.
- Ad-tech and analytics tooling companies. A small team building a tracking pixel, heatmap tool, or analytics SDK that’s embedded on many client sites can be “systematically monitoring” a large number of individuals through its core product, even with a tiny internal team.
- Recruiting and HR tech. Processing large volumes of candidate data, sometimes including special categories via diversity questions, as a core service.
Where small businesses usually don’t get caught
- A standard small e-commerce store, agency, or SaaS tool whose core activity is selling a product or service, and whose personal data processing (customer contact info, billing, basic site analytics) is incidental to that, not the core business itself. Running Google Analytics doesn’t automatically make monitoring your “core activity”, it has to be central to what the business does.
If you don’t need a formal DPO, you still have obligations
Not needing a DPO doesn’t mean nobody in your company owns privacy compliance. Every business subject to GDPR still needs:
- A documented understanding of what personal data it processes and why (see our personal data guide for the scope question, and our ROPA guide for record-keeping)
- A valid lawful basis for each processing activity (see our lawful basis guide)
- A compliant privacy policy and cookie consent setup
CookieYes
Whether or not you formally need a DPO, someone still has to own the actual technical controls, consent banners, opt-out mechanisms, and disclosures, that make the rest of GDPR real. CookieYes handles the technical layer so a small team doesn't need a dedicated privacy hire just to get the basics right.
A quick gut-check for founders
Ask honestly: is monitoring people or processing sensitive data what your product does, or is it incidental to running the business? If it’s incidental (most small businesses), you’re likely fine without a formal DPO. If it’s the product itself, run the full Article 37 test rather than assuming your size exempts you.
This guide is educational and not legal advice. Whether your specific business needs a DPO depends on facts a privacy attorney should review, particularly the “core activity” and “large-scale” determinations, which are fact-specific.