Do You Need a DPO? UK GDPR Article 37 | KEWDATA
ARTICLE 37 RADAR
SCANNING OBLIGATION REQUIREMENTS...
GDPR ARTICLE 37 | DPO OBLIGATIONS

When Does Your UK Business Legally Need a Data Protection Officer?

Understanding the Article 37 obligation and what to do if you need a DPO but cannot justify a full-time hire.

100% Independent ICO Assessment
CIPP/E & CIPM Certified DPOs
ARTICLE_37_ASSESSMENT_ENGINE.LOG
ARTICLE_37_SCREENING_ACTIVE
✓
Public Authority Status
Local councils, NHS trusts, public bodies: Mandatory
✓
Core Activities: Systematic Monitoring
Behavioural profiling, location tracking, CCTV networks
✓
Special Category Data at Scale
Health, biometric, genetic, criminal offence records
ASSESSMENT RESULT
Article 37 Trigger Analysis & Fractional DPO Mapping
THE ARTICLE 37 QUESTION

When UK GDPR Requires a DPO

UK GDPR Article 37 requires you to appoint a Data Protection Officer if you're a public authority or body, or if your core activities involve either of these on a large scale:

  • regular and systematic monitoring of individuals
  • processing special category data, or personal data relating to criminal convictions and offences
MANDATORY APPOINTMENT

When a DPO Is Mandatory Under Article 37

A DPO becomes a legal requirement if any one of these applies to your organisation:

01

Public Authority or Body

You're a public authority or body: Local councils, NHS trusts, regulators, and other public bodies, whatever their size. Courts acting in their judicial capacity are exempt.

02

Large-Scale Systematic Monitoring

Your core activities involve large-scale, regular and systematic monitoring: For example, behavioural advertising, location tracking, or CCTV networks, where monitoring people sits at the centre of what the organisation does.

03

Large-Scale Special Category Data

Your core activities involve large-scale processing of special category or criminal offence data: Special category data covers health data, genetic data, and biometric data used to uniquely identify someone, along with data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or a person's sex life or sexual orientation.

Two Terms Decide Most Cases

Core Activities

Core activities means the processing your organisation needs to carry out to meet its main objectives. A hospital handling patient records counts. Running payroll or IT support for your own staff doesn't.

Large-Scale

Large-scale has no fixed number in GDPR. The ICO looks at how many people are involved, the volume and range of data, how long the processing lasts, and its geographical reach.

Want the full detail on how the core activity and large-scale tests work? Read our guide: GDPR Article 37 Explained: When Is a DPO Mandatory?

VOLUNTARY APPOINTMENT

When a DPO Is Recommended, Even If Not Required

Some UK businesses outside Article 37 still choose to appoint a DPO. The reasons we see most:

Enterprise Bids & Procurement

You're bidding for enterprise contracts in regulated sectors, where procurement questionnaires ask who oversees data protection.

High-Risk Regulated Sectors

You handle personal data in sectors under close regulatory attention, such as FinTech, HealthTech, legal, or HR.

Investor Due Diligence

You're raising investment, and investors want evidence of a working privacy programme.

Statutory Duties of Voluntary Appointments

A voluntary DPO carries the same statutory requirements as a mandatory one, including independence, proper resources, and reporting to your highest management level. If you'd rather have data protection support without those formal duties, you can appoint a privacy lead or adviser instead, as long as the role isn't called a DPO.

APPOINTMENT OPTIONS

Your Options for Appointing a DPO

UK GDPR lets you appoint a DPO from your own staff or through a service contract. Every route has to meet the same standard: expert knowledge of data protection law and practice, independence, and direct reporting to your highest management level.

1. Hire an in-house DPO

A dedicated employee who handles your data protection work. Costs depend on the person's experience and how much data protection work your organisation generates.

2. Designate an existing staff member

This works when the person has the right expertise and their other duties don't create a conflict of interest. Your DPO can't take instructions on how to carry out DPO tasks and can't be dismissed or penalised for doing the job. Roles that decide why and how personal data gets processed can create conflicts, so check this before you designate anyone.

HOW WE HELP

How KEWDATA Assesses Your DPO Obligation

1

Free scoping call (30 minutes)

We talk through your organisation, your sector, and your main processing activities, then give you an initial view on whether Article 37 is likely to apply. No cost and no commitment.

2

Written Article 37 assessment

If you want a formal record, we review:

  • your processing activities and which of them count as core activities
  • the number of people involved, the volume and range of data, how long processing lasts, and its geographical reach
  • any special category or criminal offence data you handle
  • any monitoring of individuals
3

What you receive

A written assessment stating whether a DPO is mandatory, recommended, or not needed, with the reasoning behind it.

The appointment options that fit your organisation, if you need or want a DPO. If you choose our outsourced DPO service, we help you publish your DPO's contact details and notify the ICO, as Article 37(7) requires.

Not Sure If Your Business Legally Needs a DPO?

Book a free 30-minute scoping call, and we'll give you an initial view on your Article 37 position. For support beyond the DPO role, explore our full suite of privacy & compliance services below.

Tom S.

Reputation Manager
Medical Practice
★★★★★ May 21, 2026
"Improved control over sensitive medical data"

"Practical guidance on access controls and data protection. Helped define structured access policies and introduced tokenisation for patient identifiers used in analytics."

Sarah S.

Experience Design Manager
Retail, Enterprise
★★★★★ May 21, 2026
"Reliable partner for telecom data protection"

"Quickly understood telecom data complexity; helped classify sensitive datasets and apply protection measures for subscriber, usage, and billing data."

Pauliina H.

PR Manager
Entertainment, Enterprise
★★★★★ Apr 10, 2026
"Effective support for securing customer data"

"Identified where sensitive data lived and applied tokenization and anonymization strategies in a complex telecom environment."

Jordan R.

Senior Director, Marketing Ops
Computer Networking
★★★★★ Apr 11, 2026
"Practical approach to safeguarding e commerce"

"Helped protect PII, payment data, and order histories with tokenization and anonymization; advised on GDPR compliance for international operations."

Charmaine S.

Finance Specialist
Int. Trade & Development
★★★★★ Mar 24, 2026
"Systematic Approach Enhances Data Security"

"Methodical approach through discovery, planning, and implementation; implemented Microsoft Purview for a scalable compliance framework."

Kateryna H.

Sr. Finance & Operations
IT and Services
★★★★★ Mar 23, 2026
"Practical approach to protecting sensitive Data"

"Structured data discovery and classification combining technical analysis with finance data privacy expertise; strong masking and tokenization policies."

Snow D.

Marketing Coordinator
Market Research
★★★★★ Apr 30, 2026
"Practical expertise for telecom information"

"Introduced tokenization and controlled access strategies for subscriber data while still supporting analytics and reporting."

Laura H.

Senior Research Manager
Hospital & Health Care
★★★★★ Apr 30, 2026
"Valuable expertise in healthcare protection"

"Strong expertise in healthcare data security; introduced anonymization techniques for safely using patient data in research and reporting."

DPO Q&A

Frequently Asked Questions

Standard questions regarding UK GDPR Article 37 DPO legal mandates and appointment options.

Failing to appoint a DPO when required under Article 37 is a direct breach of UK GDPR. Under Article 83(4), regulators can issue enforcement notices, public reprimands, or administrative fines of up to £8.7 million or 2% of global annual turnover, whichever is higher.

Yes, but under Article 38(6), those other duties must not create a conflict of interest. A DPO cannot hold roles that determine the purposes and means of processing data (such as CEO, CFO, Head of IT, Head of Marketing, or Head of HR).

Yes. Article 37(8) explicitly allows a group of undertakings or multiple organisation entities to appoint a single DPO, provided that the DPO is easily accessible from each establishment.

Under Article 37(7), you must publish the contact details of your DPO and communicate them to the Information Commissioner's Office (ICO). You do this via the ICO's online DPO reporting webform. KEWDATA assists all DPO clients with this notification process.