Insight · Data protection
Insights · UK
Do You Need a Data Protection Officer?
- Author
- Michael Abtar
- Last reviewed
- 2026-10-03
- Next review
- 2027-04-03
The short answer
Under UK GDPR, some organisations must appoint a Data Protection Officer (DPO); many others choose to. The test turns on what your organisation is and what its core activities involve — not on headcount or turnover.
If you are unsure, document your assessment. Being able to show why you did, or did not, appoint a DPO is itself part of demonstrating accountability.
When a DPO is mandatory
Article 37 of UK GDPR requires a DPO where: (1) processing is carried out by a public authority or body (except courts acting in their judicial capacity); (2) your core activities consist of processing operations which, by their nature, scope or purposes, require regular and systematic monitoring of individuals on a large scale; or (3) your core activities consist of large-scale processing of special category data or criminal offence data.
"Core activities" are the operations essential to achieving your organisation's aims — for example, a digital health provider processing patient data, or a platform built on behavioural tracking. Supporting functions such as payroll or IT support do not, on their own, make processing a core activity.
For UK purposes, "public authority" and "public body" take their meaning from section 7 of the Data Protection Act 2018. The Data (Use and Access) Act 2025 did not remove the DPO requirement.
"Large scale" is not defined numerically. The ICO points to factors such as the number of individuals, the volume and range of data, the duration of processing and its geographical extent.
When a voluntary appointment makes sense
Organisations outside the mandatory criteria often still benefit from a designated privacy lead — particularly where they sell into the NHS, public sector or regulated enterprises, handle sensitive data through suppliers, or face frequent security and privacy questionnaires.
If you voluntarily designate someone as your "DPO", the same legal requirements on position, independence and tasks apply. Where you want privacy leadership without taking on those obligations, use a different title, such as privacy lead or data protection manager.
What the role requires
A DPO must be involved properly and in a timely manner in all data protection issues, report to the highest management level, be given the resources needed, and must not be instructed on how to carry out their tasks or dismissed or penalised for performing them.
The DPO must be designated on the basis of professional qualities, in particular expert knowledge of data protection law and practice. A group of undertakings may appoint a single DPO, provided the DPO is easily accessible from each establishment.
Their tasks include informing and advising the organisation and its staff, monitoring compliance (including policies, training and audits), advising on Data Protection Impact Assessments, and acting as the contact point for the ICO and for individuals.
The DPO must not hold a position that leads them to determine the purposes and means of processing. Senior roles such as chief executive, head of IT or head of marketing commonly create this conflict.
Internal, fractional or outsourced?
UK GDPR allows the DPO to be a member of staff or to fulfil the role under a service contract. The right model depends on the volume and complexity of processing, regulatory exposure, internal capability and how quickly senior judgement is needed.
An internal DPO suits organisations with high, continuous demand and the scale to support an independent, adequately resourced role. A fractional or outsourced DPO suits organisations that need senior, independent expertise and continuity without a full-time appointment — or that need to avoid internal conflicts of interest.
Whichever model you choose, publish the DPO's contact details and communicate them to the ICO.
Questions for your board
Have we assessed, and recorded, whether the mandatory criteria apply to us? Does our privacy lead have genuine independence and a reporting line to senior management? Are DPIAs, supplier due diligence and incident decisions receiving timely expert input? Could we evidence our position to the ICO, a customer or a procurement reviewer today?
Sources
- UK GDPR, Articles 37–39 (designation, position and tasks of the DPO) — legislation.gov.uk (accessed 2026-10-03)
- Data protection officers — UK GDPR guidance — Information Commissioner's Office (accessed 2026-10-03)
General guidance, not legal advice.
