Entry 01

Do you need a Data Protection Officer?

Updated 12 min read dpoasaservice.eu

Most organisations arrive at this question the wrong way round, by asking how big they have to be. Article 37 contains no size test at all. It asks what you do, whether that is your business or a support function, and at what scale, and it answers the question the same way for a twelve-person company and a four-hundred-person one.

The short answer

A controller or a processor must designate a Data Protection Officer in three cases, and in no others unless Union or Member State law says so. The three cases are set out in Article 37(1) of Regulation (EU) 2016/679: processing carried out by a public authority or body; core activities that require regular and systematic monitoring of people on a large scale; and core activities consisting of large-scale processing of special categories of data or of data relating to criminal convictions and offences.

Everything difficult about the question lives inside two phrases: core activities and large scale. Neither is defined in the Regulation. Both are addressed in the Article 29 Working Party's Guidelines on Data Protection Officers, WP 243 rev.01, which the European Data Protection Board endorsed at its first plenary meeting in May 2018 and which remains the reference document supervisory authorities work from.

The three cases in Article 37(1)

A public authority or body

The first limb reads: "the processing is carried out by a public authority or body, except for courts acting in their judicial capacity". No test of scale, risk or core activity applies. If you are a public authority, the designation is unconditional, and the officer is designated for all of the processing operations you carry out, not only for the ones connected to your public task.

The Regulation does not define "public authority or body". The Working Party considers the notion to be determined under national law, and observes that it typically extends beyond national, regional and local authorities to a range of other bodies governed by public law. Where a group of public authorities is involved, Article 37(3) permits a single officer for several of them, taking account of their organisational structure and size.

A separate and frequently missed point concerns private bodies that carry out public tasks or exercise public authority: public transport, water and energy supply, road infrastructure, public service broadcasting, public housing, or the disciplinary bodies of regulated professions. Those organisations are not caught by the first limb. The Working Party nevertheless recommends designation as a good practice, on the ground that data subjects are in a very similar position to those dealt with by a public authority, and that individuals often have little or no choice over whether and how their data are processed.

Regular and systematic monitoring, on a large scale

The second limb applies where "the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale". Three conditions have to hold together, and dropping any one of them takes you out of scope.

The Working Party reads "regular" as meaning one or more of: ongoing or occurring at particular intervals for a particular period; recurring or repeated at fixed times; or constantly or periodically taking place. It reads "systematic" as: occurring according to a system; pre-arranged, organised or methodical; taking place as part of a general plan for data collection; or carried out as part of a strategy. Monitoring is not confined to the online world, and online tracking is described as only one example of it.

Its own list of activities that may amount to regular and systematic monitoring is worth reading in full, because it is broader than most organisations expect: operating a telecommunications network; providing telecommunications services; email retargeting; data-driven marketing activities; profiling and scoring for the purposes of risk assessment, including credit scoring, establishing insurance premiums, fraud prevention and the detection of money laundering; location tracking, for example by mobile apps; loyalty programmes; behavioural advertising; monitoring of wellness, fitness and health data via wearable devices; closed circuit television; and connected devices such as smart meters, smart cars and home automation.

Special category or criminal data, on a large scale

The third limb applies where "the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 and personal data relating to criminal convictions and offences referred to in Article 10". Article 9 data means data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, together with genetic data, biometric data processed to identify a person uniquely, health data, and data concerning sex life or sexual orientation. Article 10 data means criminal convictions and offences.

The provision as drafted says "and". The Working Party addresses that directly: although the provision uses the word "and", there is no policy reason for the two criteria having to be applied simultaneously, and the text should therefore be read to say "or". Either category, at scale, as a core activity, is enough on its own.

The two words that decide most cases

What counts as a core activity

Recital 97 provides the anchor: "In the private sector, the core activities of a controller relate to its primary activities and do not relate to the processing of personal data as ancillary activities." The Working Party translates that into a workable test: core activities can be considered as the key operations necessary to achieve the controller's or processor's goals.

It then removes the obvious escape route. Core activities should not be interpreted as excluding activities where the processing of data forms an inextricable part of the controller's or processor's activity. Its example is a hospital: the core activity of a hospital is to provide health care, but a hospital could not provide health care safely and effectively without processing health data such as patients' health records. Processing those data is therefore one of any hospital's core activities, and hospitals must designate officers.

Its second example moves the same logic into the private security sector. A company that carries out surveillance of a number of private shopping centres and public spaces has surveillance as its core activity, and surveillance is in turn inextricably linked to the processing of personal data. That company must designate an officer too.

On the other side of the line: all organisations pay their employees and run IT support. Those are necessary support functions for the organisation's core activity or main business, and the Working Party treats them as ancillary rather than core. A manufacturer whose only personal data is its own payroll and its own staff records is not caught by anything in Article 37(1), no matter how many people it employs.

What counts as large scale

Here the guidance is unusually candid. It is not possible, the Working Party writes, to give a precise number either with regard to the amount of data processed or the number of individuals concerned, which would be applicable in all situations. It leaves open the possibility that a standard practice may develop over time for particular kinds of processing, but it declines to invent one.

What it offers instead is four factors to weigh: the number of data subjects concerned, either as a specific number or as a proportion of the relevant population; the volume of data and the range of different data items being processed; the duration, or permanence, of the processing activity; and the geographical extent of the processing activity.

It also warns explicitly about the middle ground. Recital 91, which supplies the language, gives examples at the extremes of the scale, from an individual physician up to processing across a whole country or across Europe, and there is a large grey zone in between. The recital was written for data protection impact assessments rather than for DPO designation, so some of it may not transfer exactly. In the grey zone the honest position is that the call is yours and the reasoning has to be recorded.

The Working Party's own examples of large-scale and non-large-scale processing
Large scaleNot large scale
Processing of patient data in the regular course of business by a hospitalProcessing of patient data by an individual physician
Processing of travel data of individuals using a city's public transport system, for example tracking via travel cardsProcessing of personal data relating to criminal convictions and offences by an individual lawyer
Processing of real-time geolocation data of customers of an international fast food chain for statistical purposes, by a specialised processor
Processing of customer data in the regular course of business by an insurance company or a bank
Processing of personal data for behavioural advertising by a search engine
Processing of content, traffic and location data by telephone or internet service providers
From WP 243 rev.01, section 2.1.3. The empty cells are not an omission: the guidance gives only two counter-examples, both of them individual practitioners, which is itself informative about where the boundary sits.

Processors have to run the test on themselves

Article 37 applies to controllers and processors alike, and each has to apply it to its own activities. The results diverge more often than people expect. Even if the controller meets the criteria for mandatory designation, its processor is not necessarily required to appoint an officer, and the reverse holds equally.

The Working Party gives two worked examples. In the first, a small family business distributing household appliances in a single town uses a processor whose core activity is to provide website analytics services and assistance with targeted advertising and marketing. The family business does not process on a large scale, given the small number of customers and the limited activities, and is under no obligation. The processor, having many clients like that small enterprise, is carrying out large-scale processing when they are taken together, and must designate an officer under Article 37(1)(b).

In the second, a medium-sized tile manufacturer subcontracts its occupational health services to an external processor with a large number of similar clients. The processor must designate an officer under Article 37(1)(c) provided the processing is on a large scale. The manufacturer is not necessarily obliged to.

One consequence is easy to miss. An officer designated by a processor also oversees the activities that processor organisation carries out as a controller in its own right: its own human resources, IT and logistics processing. The appointment is not scoped to the client work.

Two things that are not triggers

The first is the record of processing activities. Article 30(5) exempts an enterprise or organisation employing fewer than 250 persons from the obligations in Article 30(1) and (2), unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or it includes Article 9 or Article 10 data. The exemption is narrow, and it says nothing about designating an officer.

The second is the representative in the Union. Article 27 requires a controller or processor not established in the Union, but caught by Article 3(2), to designate a representative in writing. That is a different role with different tasks, and having one does not satisfy Article 37, nor does needing an officer create a need for a representative. Organisations outside the Union sometimes buy one thinking they have bought the other.

Voluntary designation, and the naming rule

You may designate an officer where nothing obliges you to. What you may not do is designate a lighter version of one. The Working Party states that when an organisation designates an officer on a voluntary basis, the requirements under Articles 37 to 39 will apply to the designation, position and tasks as if the designation had been mandatory. Finland's Data Protection Ombudsman makes the same point in its own guidance for organisations.

There is a third path, and the guidance is careful to keep it open. Nothing prevents an organisation which is not legally required to designate an officer, and which does not wish to designate one voluntarily, from employing staff or outside consultants with tasks relating to the protection of personal data. In that case it must be clear, in communications within the company and with data protection authorities, data subjects and the public, that the title of that individual or consultant is not Data Protection Officer.

That rule has teeth for job titles that already exist. The Working Party notes that chief privacy officers and other privacy professionals already in place may not always meet the criteria, for instance in terms of available resources or guarantees for independence, and if they do not, they cannot be considered or referred to as Data Protection Officers.

Documenting the decision

Unless it is obvious that no designation is required, the Working Party recommends that controllers and processors document the internal analysis carried out to determine whether or not an officer is to be appointed, so that they can demonstrate that the relevant factors were properly taken into account. That documentation forms part of the accountability documentation under Article 24(1), it may be requested by the supervisory authority, and it should be updated when circumstances change, for example when new activities or new services are launched.

In practice a short memorandum does the job: which limb was considered, what the organisation actually does, whether that is core or ancillary, how the four scale factors came out, the conclusion, the date and the person who signed it. Producing that after a complaint is expensive. Producing it now costs an afternoon.

The obligation checker on the home page walks the same sequence and will return "no designation required" where that is the honest answer. If the answer is that you do need one, the next question is whether to appoint internally or externally, which is the subject of the next entry.

Sources

  1. Regulation (EU) 2016/679 (General Data Protection Regulation) EUR-Lex · 2016 Article 37(1) to (4) on mandatory and voluntary designation, Recital 97 on core activities, Article 9 and Article 10 on the data categories, Article 30(5) on the records exemption, and Article 27 on the representative in the Union.
  2. Guidelines on Data Protection Officers (DPOs), WP 243 rev.01 Article 29 Data Protection Working Party · 2017 Sections 2.1.1 to 2.2 on public authorities, core activities, large scale, regular and systematic monitoring, the disjunctive reading of Article 37(1)(c), and the processor examples.
  3. Endorsement of GDPR-related WP29 guidelines European Data Protection Board · 2018 The Board endorsed WP 243 rev.01 at its first plenary meeting on 25 May 2018.
  4. Designating a data protection officer Office of the Data Protection Ombudsman, Finland National statement of the three cases, and confirmation that a voluntary designation carries the full regime.

Queries

Queries

Related questions

Is there a company size at which a DPO becomes mandatory?

No. Article 37 contains no headcount test. The 250-employee figure belongs to Article 30(5) and the record of processing activities, which is a separate obligation with its own conditions.

We are a processor and our client has a DPO. Do we need our own?

Possibly. Each party applies Article 37(1) to its own activities. A processor with many similar clients can reach large-scale processing when those clients are taken together, even where no individual client does. Where both designate, the two officers are expected to cooperate.

Does a single CCTV camera make monitoring "regular and systematic"?

Closed circuit television appears in the Working Party's list of activities that may constitute regular and systematic monitoring, but the limb also requires the monitoring to be a core activity and to be on a large scale. A camera over a shop door is neither. Surveillance of shopping centres and public spaces as a business is both.

Our processing is borderline. What should we do?

Work the four scale factors individually and write down the answer to each, then record the conclusion and its date as part of your Article 24(1) accountability documentation. The Working Party recommends exactly this where the answer is not obvious, and a documented borderline call is defensible in a way that an undocumented one is not.