Do You Need a Data Protection Officer (DPO)? A Simple Test
GDPR requires a Data Protection Officer in specific situations, not for every business. Here's the actual three-part test Article 37 sets out, and what to do if you're on the edge.
“Do we need a Data Protection Officer” is a question we hear from businesses of very different sizes, because the honest answer isn’t about size, it’s about what kind of processing you do. GDPR’s actual test, in Article 37, is narrower and more specific than most people assume.
The three triggers
You’re required to appoint a DPO if any one of these applies:
- You’re a public authority or body (with limited exceptions for courts acting in a judicial capacity). Straightforward, most private businesses skip this trigger entirely.
- Your core activities require large-scale, regular and systematic monitoring of individuals. The key words are “core activities” and “large-scale” and “systematic.” A company whose entire business model is behavioral tracking or profiling (ad-tech, certain analytics platforms) is squarely in scope. A small business that happens to run Google Analytics is not, that’s not your core activity, and it’s not large-scale monitoring in the sense the regulation means.
- Your core activities involve large-scale processing of special category data (health, biometric, genetic data, criminal records) or data relating to criminal convictions. A healthcare platform or background-check service is a clear yes. A general ecommerce store processing payment data is generally not, payment data isn’t a GDPR special category on its own, though it carries its own security obligations.
Why “large-scale” and “core activity” do most of the work
Most small and mid-size businesses read triggers 2 and 3 and worry they qualify because they do some monitoring or handle some sensitive data. The test is narrower than that. Regulators have generally pointed to factors like the number of individuals affected, the volume of data, the duration of processing, and the geographic scope, a single-location small business processing data on a few thousand customers a year is a very different case from a platform processing millions of records as its primary function.
CookieYes
If you're evaluating whether your tracking counts as 'large-scale, systematic monitoring,' start by actually knowing what you run, CookieYes's scanner gives you a clear inventory of every tracker on your site as a starting point for that assessment.
If you’re genuinely on the edge
Some businesses sit in a genuine gray zone, meaningful tracking or health-adjacent data, but not obviously at the scale the triggers describe. A few practical options short of a full-time hire:
- Appoint a DPO on a part-time or fractional basis, which is explicitly allowed, the role doesn’t require a dedicated full-time employee.
- Voluntarily designate someone as a privacy point of contact even if you conclude you don’t strictly need a formal DPO, this supports the accountability principle from our overview of GDPR’s core principles regardless of whether Article 37 technically requires it.
- Document your reasoning for why you concluded a DPO isn’t required, in case the question ever comes up in an audit or investigation.
What a DPO actually does, if you appoint one
The role isn’t just a title, a DPO has specific responsibilities under GDPR: monitoring compliance, advising on DPIAs, serving as the contact point for supervisory authorities and data subjects, and operating with a degree of independence (they can’t be told how to interpret GDPR by the business they serve, and can’t be penalized for doing the job).
The bottom line
Most small businesses running standard marketing analytics and processing ordinary customer data don’t meet the DPO threshold. Businesses whose core function is tracking, profiling, or handling sensitive categories of data at real scale generally do. If you’re unsure which side of that line you’re on, that uncertainty itself is worth resolving with counsel rather than guessing.
This guide is educational and not legal advice. The DPO requirement is fact-specific to your processing activities. Consult a privacy attorney to evaluate whether your business is required to appoint one.