Outsourced DPO · European UnionRegulation (EU) 2016/679, Arts 37–39
A DPO can be hired in. Independence cannot.
Article 37(6) lets the Data Protection Officer carry out the role on a service contract. Nothing else relaxes. Whoever you appoint still takes no instructions on the tasks, still reports to your highest management level, and still may hold no other role that decides how your personal data is processed. This is a reference on where that line falls, and on how to tell whether the DPO you are being sold sits on the right side of it.
OffSeq is a security testing and consulting company, not a law firm, and it does not accept DPO appointments. Section 05 sets out why, and what it does instead.
Art. 37(1)
Mandatory designation
Three cases, and only three
The Regulation names exactly three situations in which a controller or a processor must designate a Data Protection Officer. There is no employee threshold anywhere in Article 37. The figure of 250 employees that circulates online belongs to a different obligation entirely: the record of processing activities in Article 30(5).
Art. 37(1)(a)
Processing by a public authority or body
the processing is carried out by a public authority or body, except for courts acting in their judicial capacity
Regulation (EU) 2016/679, Article 37(1)(a)
The Regulation does not define "public authority or body", and the Article 29 Working Party takes the view that the notion is determined under national law. It typically reaches beyond ministries and municipalities to a range of other bodies governed by public law. No test of scale, core activity or risk applies to this limb: if you are a public authority, the obligation is unconditional.
A single officer may be designated for several public authorities or bodies, taking account of their organisational structure and size (Art. 37(3)).
Art. 37(1)(b)
Regular and systematic monitoring of people, on a large scale
the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale
Regulation (EU) 2016/679, Article 37(1)(b)
Three conditions have to hold at once: the monitoring has to be regular and systematic, it has to be on a large scale, and it has to be a core activity rather than a support function. The Working Party reads "regular" as ongoing, recurring or periodic, and "systematic" as occurring according to a system, pre-arranged or carried out as part of a strategy. Its own examples include operating a telecommunications network, behavioural advertising, credit and insurance scoring, fraud and money-laundering detection, loyalty programmes, location tracking in mobile apps, closed circuit television and connected devices such as smart meters.
Art. 37(1)(c)
Special category or criminal data, on a large scale
the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 and personal data relating to criminal convictions and offences referred to in Article 10
Regulation (EU) 2016/679, Article 37(1)(c)
Article 9 data is health, genetic and biometric identification data, and data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sex life or sexual orientation. Article 10 data is criminal convictions and offences. The text says "and", but the Working Party is explicit that there is no policy reason for the two criteria to apply simultaneously and that the provision should be read to say "or". Either category, at scale, as a core activity, is enough.
Art. 37(4)
Everywhere else it is voluntary, and voluntary is not lighter
In cases other than those referred to in paragraph 1, the controller or processor … may or, where required by Union or Member State law shall, designate a data protection officer.
Regulation (EU) 2016/679, Article 37(4)
A voluntary designation is not a softer version of the role. The Working Party states that where an organisation designates a DPO on a voluntary basis, the requirements in Articles 37 to 39 apply to the designation, position and tasks exactly as if it had been mandatory. It also warns that an organisation which hires a privacy adviser without designating a DPO must make clear, internally and to the authority, that the person is not a Data Protection Officer.
Interpretive test one
What counts as a core activity
Recital 97 says the core activities of a controller relate to its primary activities and not to the processing of personal data as an ancillary activity. The Working Party reads that as the key operations necessary to achieve the organisation's goals, while refusing to exclude activities where the processing is an inextricable part of what the organisation does.
- A hospital's core activity is health care, but it cannot provide health care safely without processing health records. Hospitals must designate an officer.
- A private security company that runs surveillance of shopping centres and public spaces has surveillance as its core activity, and that is inextricably linked to processing personal data. It must designate one too.
- Paying your own staff and running ordinary IT support are necessary, but they are support functions rather than core activities. They do not trigger anything on their own.
Interpretive test two
What counts as large scale
No number exists. The Working Party states plainly that it is not possible to give a precise figure, for either the amount of data or the number of individuals, that would apply in all situations. It offers four factors instead, and warns that between an individual physician and a whole country there is a large grey zone.
- The number of data subjects concerned, either as a number or as a proportion of the relevant population.
- The volume of data, and the range of different data items being processed.
- The duration, or permanence, of the processing activity.
- The geographical extent of the processing activity.
Where the answer is not obvious, the Working Party recommends documenting the internal analysis that led to it, as part of the documentation required by the accountability principle in Article 24(1). The long version of that analysis, with the Working Party's own worked examples, is in Do you need a Data Protection Officer?
Determination
DPO obligation checker
Work out whether you have to designate one
Five questions, drawn from the text of Article 37(1) and from the Working Party guidance on how to read it. The result is a band, not a legal opinion, and it is perfectly willing to tell you that you do not need an officer at all. Nothing you select leaves your browser.
Interactive mode is not available. You can read the full reference content below. No answers are assessed and no result is calculated.
The interactive determination needs JavaScript. The rules it applies are set out below in full, and you can work through them by hand in about the same time.
The test the checker applies
- Art. 37(1)(a) Processing is carried out by a public authority or body. The limb applies on status alone, with no test of scale or core activity, and the only exclusion is a court acting in its judicial capacity.
- Art. 37(1)(b) Regular and systematic monitoring of people, as a core activity, on a large scale.
- Art. 37(1)(c) Special categories of data under Article 9, as a core activity, on a large scale.
- Is that a core activity, or a support function?. Recital 97 excludes processing carried out as an ancillary activity. Payroll, your own staff records and ordinary IT support are support functions. Processing that is inextricable from what you sell counts as core, which is why a hospital's patient records do and a tile manufacturer's payroll does not.
- At what scale?. Judge this against the four factors the Working Party gives, not against a headcount: the number of people affected or the proportion of the relevant population, the volume and range of data items, how long or how permanently you hold it, and how far it reaches geographically.
What the role carries
- Inform and advise the controller or processor and the staff who carry out processing about their obligations. Art. 39(1)(a)
- Monitor compliance with the Regulation and with your own data protection policies, including the assignment of responsibilities, awareness-raising, training and the related audits. Art. 39(1)(b)
- Advise on the data protection impact assessment where asked, and monitor its performance. Art. 39(1)(c)
- Cooperate with the supervisory authority. Art. 39(1)(d)
- Act as the contact point for the supervisory authority, including for prior consultation. Art. 39(1)(e)
What independence means in practice
- No instructions on the tasks. Not on what result to reach, not on how to investigate a complaint, not on whether to consult the authority, and not on what view to take of the law.
- No dismissal or penalty for doing the job. A withheld promotion or a threatened one counts; so does terminating a service contract because the officer gave advice you disliked.
- A direct line to the top. The officer reports to the highest management level, and where you decide against the advice, the officer must be able to put the dissent in front of the people deciding.
- No role that decides purposes or means. The Court of Justice has held that a conflict may exist wherever the other tasks would have the officer determining the objectives and methods of the processing.
- Resources, not just a title. Time, budget, access to the processing operations, and the training to stay current. The more sensitive the processing, the more of each.
What to ask an external provider
- Who, by name, is the lead contact in charge of our file, and who covers when they are away?
- How many other clients does that named person carry? Supervisory authorities have asked controllers to verify exactly this.
- Does the contract instruct you on how to perform the tasks, directly or indirectly? If so, it breaches Article 38(3).
- Is the engagement papered as a data processing agreement? Treating the officer as your processor is itself a threat to the independence requirement.
- Do you sell us anything else that decides how our personal data is processed, or that you would then be monitoring under Article 39(1)(b)?
- Are you located in the Union, and can you work in the language of our supervisory authority and our data subjects?
- What protects you against termination for advice we do not like, and how stable is the contract term?
Art. 39(1)
The task list
What the officer is actually for
Article 39 opens with the words "at least the following tasks". It is a floor, not a ceiling: you may add to the list, and in practice most organisations do. What you may not do is hand the officer a task that prevents the five below from being performed.
Art. 39(1)(a)
Inform and advise
to inform and advise the controller or the processor and the employees who carry out processing of their obligations pursuant to this Regulation and to other Union or Member State data protection provisions
Regulation (EU) 2016/679, Article 39(1)(a)
The advice runs to the staff who actually process, not only to management. That is why the Working Party expects the officer to be a discussion partner inside the organisation and to sit in the working groups where processing is designed.
Art. 39(1)(b)
Monitor compliance, including the related audits
to monitor compliance with this Regulation … and with the policies of the controller or processor in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits
Regulation (EU) 2016/679, Article 39(1)(b)
In practice this means collecting information to identify processing activities, checking those activities against the rules, and issuing recommendations. The Court of Justice leaned on the closing words of this provision, "and the related audits", when it held that the review of purposes and means has to be carried out independently by the officer. It is the reason the role cannot be combined with the work it would have to review.
Art. 39(1)(c)
Advise on the impact assessment
to provide advice where requested as regards the data protection impact assessment and monitor its performance pursuant to Article 35
Regulation (EU) 2016/679, Article 39(1)(c)
Article 35(2) makes this a two-way obligation: the controller shall seek the advice of the officer when carrying out an assessment. The Working Party lists what to ask about, including whether an assessment is needed at all, what methodology to use, whether to carry it out in house or to outsource it, and whether the conclusions comply with the Regulation. Where you disagree, the documentation should say in writing why the advice was not followed.
Art. 39(1)(d)
Cooperate with the supervisory authority
to cooperate with the supervisory authority
Regulation (EU) 2016/679, Article 39(1)(d)
The officer is bound by secrecy or confidentiality under Article 38(5), but that duty does not prevent the officer from contacting the authority and asking for advice. Those two facts sit together deliberately.
Art. 39(1)(e)
Act as the contact point
to act as the contact point for the supervisory authority on issues relating to processing, including the prior consultation referred to in Article 36, and to consult, where appropriate, with regard to any other matter
Regulation (EU) 2016/679, Article 39(1)(e)
Data subjects may also contact the officer about anything to do with their data and their rights (Article 38(4)), so the published contact route has to be one an individual can actually use: a postal address, a dedicated telephone number, an email address, or a form addressed to the officer.
What the officer is not answerable for
- Your compliance. The Working Party is unambiguous: monitoring compliance does not make the officer personally responsible for an instance of non-compliance. Data protection compliance is a corporate responsibility of the controller.
- Carrying out the impact assessment. Article 35(1) puts that on the controller. The officer advises on it and monitors its performance.
- Maintaining the record of processing. Article 30 puts that on the controller or processor. Officers often keep the inventory in practice, and nothing stops you assigning it, but the obligation does not move.
- Deciding purposes and means. That is the definition of a controller, and an officer who does it has walked into the conflict Article 38(6) prohibits.
Article 39(2) adds a prioritisation rule: the officer has to give due regard to the risk associated with the processing operations, which in practice means focusing effort on the higher-risk areas without abandoning the rest. The full task-by-task reading is in Internal or external DPO.
Art. 38
Position of the officer
Six guarantees you cannot contract away
Article 38 is the part of the regime that outsourcing tends to erode, because a service contract is a commercial document and these are not commercial terms. Read them as the specification an external appointment has to meet before anyone signs.
Art. 38(1)
Involved properly, and in time
The controller and the processor shall ensure that the data protection officer is involved, properly and in a timely manner, in all issues which relate to the protection of personal data.
Regulation (EU) 2016/679, Article 38(1)
The Working Party translates this into things you can check: the officer is invited to senior and middle management meetings, is present where decisions with data protection implications are taken, receives the information in time to give useful advice, and is consulted promptly once a breach or other incident has occurred.
Art. 38(2)
Resourced to do the work
The controller and processor shall support the data protection officer … by providing resources necessary to carry out those tasks and access to personal data and processing operations, and to maintain his or her expert knowledge.
Regulation (EU) 2016/679, Article 38(2)
Board-level support, enough time, budget, access to the processing operations, access to human resources, legal, IT and security, and continuous training. Where the role is not full time, the Working Party treats it as good practice to fix the percentage of time it gets. The rule scales: the more complex or sensitive the processing, the more resource the function needs.
Art. 38(3)
No instructions on the exercise of the tasks
The controller and processor shall ensure that the data protection officer does not receive any instructions regarding the exercise of those tasks.
Regulation (EU) 2016/679, Article 38(3)
No instruction on what result to reach, how to investigate a complaint, whether to consult the authority, or what interpretation of the law to adopt. This is also the provision that a service contract most easily breaks, and one supervisory authority found an organisation that had papered its external officer as a data processor, which would put the officer under documented instructions by construction.
Art. 38(3)
No dismissal or penalty for performing the tasks, and a direct report to the top
He or she shall not be dismissed or penalised by the controller or the processor for performing his tasks. The data protection officer shall directly report to the highest management level of the controller or the processor.
Regulation (EU) 2016/679, Article 38(3)
A penalty can be indirect: a delayed promotion, a blocked career step, a withheld benefit, and a mere threat is enough. For an external officer the equivalent is a service contract terminated because of the advice given. The Working Party notes that the more stable the contract and the stronger the guarantees against unfair termination, the more likely the officer is to act independently.
Art. 38(5)
Bound by secrecy or confidentiality
The data protection officer shall be bound by secrecy or confidentiality concerning the performance of his or her tasks, in accordance with Union or Member State law.
Regulation (EU) 2016/679, Article 38(5)
This matters most for staff who want to raise something. Employees are reluctant to complain to an officer whose communications are not confidential, which is also why Article 37(7) asks for a contact route that does not run through another part of the organisation.
Art. 38(6)
Other tasks, but no conflict of interests
The data protection officer may fulfil other tasks and duties. The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests.
Regulation (EU) 2016/679, Article 38(6)
Holding another role is not forbidden. The Court of Justice has confirmed that the Regulation establishes no fundamental incompatibility between the officer's duties and other duties. What is forbidden is a combination that would have the officer determining the objectives and methods of the processing, or otherwise impair the performance of the role.
Art. 38(6)
Positions that conflict with the role
The Working Party's rule of thumb is that the officer cannot hold a position that leads to determining the purposes and the means of processing, and it names senior management roles as the usual offenders. Finland's Data Protection Ombudsman adds one that matters to every security buyer: a conflict may arise if an information security officer is designated as the Data Protection Officer. The last entry below is the Working Party's own example of a conflict that arises specifically for an external officer.
- Chief executive officer
- Chief operating officer
- Chief financial officer
- Chief medical officer
- Head of marketing
- Head of human resources
- Head of IT
- Information security officer
- Litigation counsel in a data protection case
A "conflict of interests" … may exist where a data protection officer is entrusted with other tasks or duties, which would result in him or her determining the objectives and methods of processing personal data on the part of the controller or its processor, which is a matter for the national court to determine, case by case, on the basis of an assessment of all the relevant circumstances. Court of Justice of the European Union, Case C-453/21 X-FAB Dresden, 9 February 2023, operative part
Art. 37(6)
The service-contract model
Buying the role without breaking it
Twenty-five supervisory authorities across the European Economic Area spent 2023 investigating how the role is actually being performed, and published the aggregate. The numbers below are the ones an organisation buying an external officer should read before it signs anything.
-
70%
of the officers in the survey were staff members of the organisation, not outside providers
EDPB CEF 2023, §3.1
-
45.8%
worked on the role full time (median across Member States)
EDPB CEF 2023, Q18
-
34.0%
were shared among several organisations (median)
EDPB CEF 2023, Q5
-
15
supervisory authorities reported likely conflicts of interest or risks to independence
EDPB CEF 2023, §4.5
From the European Data Protection Board's report on the 2023 Coordinated Enforcement Action on the designation and position of Data Protection Officers, adopted on 16 January 2024. Medians are across the participating Member States, and the question numbers are the report's own. Infringements of Articles 37 to 39 sit in the lower fining tier of Article 83(4): up to 10 000 000 EUR, or 2 % of total worldwide annual turnover, whichever is higher.
Check 01
A named individual, in charge of your file
A provider may run the role as a team, and the Working Party expressly allows it. It also recommends a clear allocation of tasks inside that team and a single individual assigned as lead contact and person in charge for each client, specified in the service contract. Ask for the name.
Check 02
A client load you are allowed to see
Supervisory authorities raised the concern that external officers acting for multiple controllers may spread themselves too thinly. The Board's recommendation is addressed to you, not to the provider: verify how many clients that officer has, to be satisfied they have the time and capacity to meet the obligations.
Check 03
A contract that gives no instructions on the tasks
Read the service contract for anything that tells the officer how to carry out the Article 39 tasks, directly or indirectly. Approval workflows, deliverable sign-off and scope caps on what may be reviewed are the usual ways it creeps in.
Check 04
Not papered as a data processing agreement
One authority in the coordinated action found exactly that arrangement and pointed out that treating the officer as a data processor could breach the independence requirement in Article 38(3). A processor acts on documented instructions. An officer cannot.
Check 05
No other engagement that the officer would then be monitoring
The Board records the failure mode plainly: external officers entrusted with additional tasks can end up monitoring their own activities. If the same firm designs your controls, writes your policies or tests your systems, ask how it proposes to review that work independently under Article 39(1)(b).
Check 06
Located in the Union, and working in the right language
The Working Party recommends that the officer be located within the Union whether or not the controller is, and that communication take place in the language or languages used by the supervisory authority and the data subjects concerned. Estonia's authority states outright that its proceedings run in Estonian.
Check 07
Term and termination that protect the advice
Article 38(3) forbids dismissal or penalty for performing the tasks, and for an outside provider that means the contract cannot be terminated because of the advice given. The Working Party observes that the more stable the contract, and the more guarantees exist against unfair termination, the more likely the officer is to act independently.
Scope of this site
What a security firm may do here, and what it may not
Work OffSeq does
- Data protection impact assessments under Article 35, including data flow mapping, necessity and proportionality analysis, a scored risk register and a treatment plan.
- Technical evidence for Article 32: testing and assessing the security of processing so that your officer has something to monitor other than assurances.
- Governance documentation: security policies, standards and procedures aligned to the obligations that actually apply to you.
- Readiness work for NIS2 and ISO/IEC 27001, where the security obligations sit next to the data protection ones without being the same thing.
Work OffSeq refuses
- Holding the DPO appointment. Article 39(1)(b) makes the officer monitor compliance "and the related audits". A firm that also tests your systems would be reviewing its own work.
- Being your DPO and your security provider at once. Security work is bought under instruction and usually under a processing agreement. The officer must be under no instruction on the tasks.
- Legal advice. OffSeq is not a law firm. Whether a specific arrangement creates a conflict of interests is a question for your counsel and, ultimately, for a court.
- Representing you before a court or an authority in a data protection case. The Working Party names that as a conflict for an external officer specifically.
Art. 37(7)
Notification
Four authorities, four different filings
Article 37(7) says only that the contact details must be published and communicated to the supervisory authority. How that communication is made is entirely national, and in the Baltic and Nordic states it varies more than most organisations expect. There is no European register.
| Country and authority | How the designation is notified | National particularity |
|---|---|---|
| Latvia · Datu valsts inspekcija | A submission signed by a person authorised to represent the organisation, sent by the controller or processor to the Inspectorate by email or to its official e-address. Separate forms exist for appointment, change and termination. | The Inspectorate runs a state qualification examination and publishes a list of those who pass. Section 17 of the Personal Data Processing Law allows you to appoint a listed person or another person. |
| Lithuania · Valstybinė duomenų apsaugos inspekcija | A document signed by an authorised person, sent to the Inspectorate by email. It has to state whether the officer is designated by the controller or the processor, and where the officer is external, the name of the employing legal entity. | The Inspectorate published a national Recommendation on Data Protection Officers in April 2025, covering appointment, tasks, responsibility and when the officer's activity raises a conflict-of-interest risk. |
| Estonia · Andmekaitse Inspektsioon | Entered in the e-Business Register by a board member with the right of representation, in which case no separate notice to the Inspectorate is needed. Otherwise by post or with an eIDAS-valid digital signature. | The Inspectorate states that communication with the authority, the public and data subjects is expected in Estonian, and that its proceedings are conducted in Estonian. |
| Finland · Tietosuojavaltuutetun toimisto | A "Declaration of Data Protection Officer" filed with the Office of the Data Protection Ombudsman, with a separate form for a change of officer. | The Ombudsman states in its own guidance that a conflict of interests may arise if, for example, an information security officer or a senior manager is designated as the Data Protection Officer. |
Latvia
A state examination that is real, and optional
The Data State Inspectorate organises a qualification examination for data protection specialists and maintains a public list of everyone who has passed it. The examination costs 188.78 EUR under Cabinet Regulation No. 621 of 6 October 2020, and sittings are announced at least two months ahead in the official gazette. What most vendor copy leaves out is Section 17 of the Personal Data Processing Law: a controller may appoint a listed person, or another person. Passing the examination is a credential, not a licence.
Estonia
The register does the filing for you
The Inspectorate's stated preference is that a board member with the right of representation enters the notice directly in the e-Business Register, in which case no separate notification is required. It also asks for the officer's personal identification code or date of birth and citizenship, which is a more demanding data set than any of the other three authorities requests.
Finland
The warning that names your security lead
Alongside the declaration form, the Ombudsman publishes twelve instructions for organisations that have designated an officer. Two are worth quoting in any appointment discussion: that officers are not personally responsible for infringements, because compliance is the responsibility of the controller or processor; and that the officer should have a deputy, because breach notifications and data-subject rights cannot wait for a return from leave.
Lithuania
National guidance, and a national inspection round
The State Data Protection Inspectorate carried out the 2023 coordinated action nationally, investigating the role of Data Protection Officers in ten Lithuanian companies against an approved questionnaire. Its 2025 Recommendation answers, among other things, the question this whole site is about: whether to appoint your own employee or a service provider.
Dir. (EU) 2022/2555
Adjacent regimes
NIS2 does not give you a second officer
Organisations in scope of NIS2 often assume the directive creates a security counterpart to the Data Protection Officer, and then look for one person to hold both. It does not, and the difference is structural rather than cosmetic: the two regimes point accountability in opposite directions.
| Question | GDPR, Articles 37 to 39 | NIS2, Directive (EU) 2022/2555 |
|---|---|---|
| Is there a named statutory role? | Yes. The data protection officer. | No. The directive creates no in-house security officer of any kind. |
| Who carries the duty? | The controller or processor designates; the officer monitors compliance independently. | The management body approves the risk-management measures, oversees implementation, and can be held liable for infringements (Art. 20(1)). |
| Is independence guaranteed in law? | Yes. No instructions on the tasks, no dismissal for performing them, and a direct report to the highest management level (Art. 38(3)). | Not applicable. Accountability runs towards the board, not away from it. |
| Can it be outsourced? | Yes, on a service contract (Art. 37(6)). | The obligation on the management body cannot be transferred. Advisory and delivery work can be bought in. |
| Training obligation | The officer must be resourced to maintain expert knowledge (Art. 38(2)). | Members of the management body are required to follow training (Art. 20(2)). |
| Where the two touch | Security of processing under Art. 32, and breach handling under Arts 33 and 34. | Risk-management measures under Art. 21(2), and incident reporting under Art. 23. |
The only "officer" NIS2 mentions in this sense is in Article 32(4)(b), which lets a competent authority designate a monitoring officer with well-defined tasks, for a determined period, to oversee a non-compliant entity's compliance with Articles 21 and 23. That is a supervisor imposed from outside, not an appointment you make. Any page telling you NIS2 obliges you to appoint a security officer is describing something that is not in the text.
Cluster
Guides
Four entries, worked through
Longer treatments of the questions the register above can only summarise, each sourced to the instrument, the guidance or the judgment it relies on.
-
Do you need a Data Protection Officer?
Three cases, no headcount threshold, and two words that decide almost every borderline call. The Article 37(1) test worked through with the Working Party's own examples.
Open entry -
Internal or external DPO: what the service contract has to carry
Article 37(6) permits an outsourced officer in fourteen words. The other thirty provisions of Section 4 decide whether the arrangement actually works.
Open entry -
DPO conflict of interest: where the line actually falls
The Court of Justice has given the test, the Working Party has named the positions, and supervisory authorities have found the failure modes. Including the ones that only appear when the officer is external.
Open entry -
Notifying your DPO to the supervisory authority
One sentence of European law, four completely different national filings. Latvia runs an examination, Estonia uses the business register, Finland publishes a warning, and Lithuania wants the employer named.
Open entry
Queries
Questions
What people ask before they appoint
The answers below are the ones this site can support from a primary source. Where the honest answer is "it depends, and here is what it depends on", that is what you get.
Can a Data Protection Officer be an external company rather than a person?
Yes. Article 37(6) says the officer may be a staff member or may fulfil the tasks on the basis of a service contract, and the Article 29 Working Party guidance confirms that the contract can be concluded with an individual or with an organisation. Where an organisation holds it, each member of that organisation exercising the function has to meet every requirement of Section 4 of the GDPR, including having no conflict of interests, and each has to be protected by those provisions in turn.
The guidance also recommends a clear allocation of tasks inside the team and a single individual assigned as lead contact and person in charge for each client, specified in the service contract.
Does a Data Protection Officer have to be a lawyer?
No. Article 37(5) requires designation on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices, and the ability to fulfil the Article 39 tasks. It names no qualification, no certification and no professional body. The Working Party declines to fix a level of expertise and says only that it must be commensurate with the sensitivity, complexity and amount of data processed.
How many employees do you need before a DPO becomes mandatory?
There is no employee threshold in Article 37. The 250-employee figure that circulates online comes from Article 30(5), which exempts smaller organisations from the record of processing activities unless the processing is risky, non-occasional or involves Article 9 or Article 10 data. It has nothing to do with designating an officer. A twelve-person company doing large-scale behavioural profiling as its core activity is caught; a 400-person manufacturer whose only personal data is its own payroll is not.
What does "large scale" actually mean?
The Working Party states that it is not possible to give a precise number, for either the volume of data or the number of individuals, that would work in every situation. It gives four factors instead: the number of data subjects concerned, either absolutely or as a proportion of the relevant population; the volume and range of data items; the duration or permanence of the processing; and its geographical extent.
Its examples of large-scale processing include a hospital's patient records, a city transport system's travel data, a bank's or insurer's customer data, behavioural advertising by a search engine, and content, traffic and location data held by telecommunications providers. Its counter-examples are an individual physician's patient data and an individual lawyer's criminal-offence data.
If we appoint one voluntarily, do the rules apply?
In full. The Working Party states that where an organisation designates an officer on a voluntary basis, the requirements in Articles 37 to 39 apply to the designation, position and tasks as if the designation had been mandatory. Finland's Data Protection Ombudsman repeats the same point in its own guidance. If you want the advice without the regime, you can hire a privacy adviser instead, but then you must be clear, internally and with the authority, that the person is not a Data Protection Officer.
Can our Head of IT or our security officer be the DPO?
Almost certainly not. The Working Party names head of IT among the positions that as a rule of thumb conflict with the role, because such positions determine the purposes and the means of processing. Finland's Data Protection Ombudsman says explicitly that a conflict may arise if an information security officer is designated as the officer. The Court of Justice held in Case C-453/21 that a conflict may exist wherever the other tasks would result in the officer determining the objectives and methods of processing, and that the assessment is made case by case on all the relevant circumstances.
Can the same firm be our DPO and run our penetration tests?
Our answer is no, and we decline that combination. Article 39(1)(b) makes the officer monitor compliance including the related audits, and the Court of Justice relied on those exact words when holding that the review of purposes and methods must be carried out independently by the officer. A firm that scoped, ran and reported your security testing would be monitoring its own work.
The European Data Protection Board records the same failure mode in its 2024 report: external officers entrusted with additional tasks can end up monitoring their own activities. Whether a particular arrangement crosses the line is a case-by-case judgment for you and your counsel, and one supervisory authority went further and warned that papering the officer as a data processor could itself breach Article 38(3).
Do we have to register the DPO somewhere?
You have to publish the contact details and communicate them to your supervisory authority, under Article 37(7). There is no European register, and the mechanism is national: Latvia takes a signed submission by email or e-address, Lithuania a signed document by email, Estonia an entry in the e-Business Register made by a board member, and Finland a declaration form filed with the Data Protection Ombudsman. Article 37(7) does not require the published contact details to include the officer's name, although communicating the name to the authority is essential, and Article 33(3)(b) does require the name in a breach notification.
Does NIS2 require a security officer the way the GDPR requires a DPO?
No. Directive (EU) 2022/2555 creates no equivalent role. It puts the duty on the management body, which has to approve the cybersecurity risk-management measures, oversee their implementation, can be held liable for infringements, and is required to follow training. The only officer the directive mentions in this sense is a monitoring officer that a competent authority may designate to oversee a non-compliant entity, under Article 32(4)(b).
Is the Latvian DPO examination compulsory?
No. Latvia's Data State Inspectorate does organise a qualification examination and does publish a list of everyone who has passed it, but Section 17 of the Personal Data Processing Law permits a controller or processor to appoint a person from that list or another person. The examination is a credential recognised nationally, not a condition of holding the role.
Sources
- Regulation (EU) 2016/679 (General Data Protection Regulation) Articles 37, 38 and 39 on the designation, position and tasks of the data protection officer; Recital 97; Article 30(5) on the records exemption; Article 35(2); Article 83(4) on the fining tier.
- Guidelines on Data Protection Officers (DPOs), WP 243 rev.01 Adopted 13 December 2016, last revised and adopted 5 April 2017. Copy published by the Finnish Data Protection Ombudsman; the European Commission newsroom copy is currently unavailable.
- Endorsement of GDPR-related WP29 guidelines, including WP243 rev.01 The Board endorsed the WP29 guidelines at its first plenary meeting, 25 May 2018.
- 2023 Coordinated Enforcement Action: Designation and Position of Data Protection Officers Adopted 16 January 2024. Twenty-five supervisory authorities; survey findings on resources, independence and conflicts of interest, including the specific risks of the outsourced model.
- Case C-453/21, X-FAB Dresden GmbH & Co. KG v FC Judgment of 9 February 2023, ECLI:EU:C:2023:79. The conflict-of-interest test under Article 38(6).
- Case C-534/20, Leistritz AG v LH Judgment of 22 June 2022, ECLI:EU:C:2022:495. Article 38(3) sets a floor; stricter national dismissal protection is compatible with it.
- Fizisko personu datu apstrādes likums (Personal Data Processing Law) Chapter V, Sections 17 to 20: the requirements for a data protection specialist, the Inspectorate's list, the qualification examination, and removal from the list.
- Datu aizsardzības speciālists: paziņojums par iecelšanu un kvalifikācijas eksāmens How the Inspectorate wants a designation notified, and the forms for appointment, change and termination. The examination fee is published at dvi.gov.lv/lv/kvalifikacijas-eksamens.
- Data protection officer: information for organisations Notification through the e-Business Register, the data requested, and the Estonian-language expectation. Page last updated 29 January 2024.
- Designating a data protection officer The conflict-of-interest statement naming an information security officer, the voluntary-designation rule, and the declaration forms.
- Data protection officers: instructions for organisations and managers Twelve operational instructions, including the deputy recommendation and the statement that officers are not personally responsible for infringements.
- VDAI rekomendacijos dėl duomenų apsaugos pareigūno paskyrimo, užduočių ir atsakomybės National Recommendation on data protection officers, published 16 April 2025. Archived capture; the authority's live site does not serve automated requests.
- How to inform the State Data Protection Inspectorate about the Data protection officer of your organization The information the Inspectorate requires in a notification, including the name of the employing legal entity where the officer is external. Archived capture.
- Directive (EU) 2022/2555 (NIS2) Article 20 on governance and management-body liability, Article 21 on risk-management measures, and Article 32(4)(b) on the monitoring officer a competent authority may designate.