When Does Your UK Business Legally Need a Data Protection Officer?
Understanding the Article 37 obligation and what to do if you need a DPO but cannot justify a full-time hire.
When UK GDPR Requires a DPO
UK GDPR Article 37 requires you to appoint a Data Protection Officer if you're a public authority or body, or if your core activities involve either of these on a large scale:
- regular and systematic monitoring of individuals
- processing special category data, or personal data relating to criminal convictions and offences
When a DPO Is Mandatory Under Article 37
A DPO becomes a legal requirement if any one of these applies to your organisation:
Public Authority or Body
You're a public authority or body: Local councils, NHS trusts, regulators, and other public bodies, whatever their size. Courts acting in their judicial capacity are exempt.
Large-Scale Systematic Monitoring
Your core activities involve large-scale, regular and systematic monitoring: For example, behavioural advertising, location tracking, or CCTV networks, where monitoring people sits at the centre of what the organisation does.
Large-Scale Special Category Data
Your core activities involve large-scale processing of special category or criminal offence data: Special category data covers health data, genetic data, and biometric data used to uniquely identify someone, along with data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or a person's sex life or sexual orientation.
Two Terms Decide Most Cases
Core Activities
Core activities means the processing your organisation needs to carry out to meet its main objectives. A hospital handling patient records counts. Running payroll or IT support for your own staff doesn't.
Large-Scale
Large-scale has no fixed number in GDPR. The ICO looks at how many people are involved, the volume and range of data, how long the processing lasts, and its geographical reach.
Want the full detail on how the core activity and large-scale tests work? Read our guide: GDPR Article 37 Explained: When Is a DPO Mandatory?
When a DPO Is Recommended, Even If Not Required
Some UK businesses outside Article 37 still choose to appoint a DPO. The reasons we see most:
Enterprise Bids & Procurement
You're bidding for enterprise contracts in regulated sectors, where procurement questionnaires ask who oversees data protection.
High-Risk Regulated Sectors
You handle personal data in sectors under close regulatory attention, such as FinTech, HealthTech, legal, or HR.
Investor Due Diligence
You're raising investment, and investors want evidence of a working privacy programme.
Statutory Duties of Voluntary Appointments
A voluntary DPO carries the same statutory requirements as a mandatory one, including independence, proper resources, and reporting to your highest management level. If you'd rather have data protection support without those formal duties, you can appoint a privacy lead or adviser instead, as long as the role isn't called a DPO.
Your Options for Appointing a DPO
UK GDPR lets you appoint a DPO from your own staff or through a service contract. Every route has to meet the same standard: expert knowledge of data protection law and practice, independence, and direct reporting to your highest management level.
How KEWDATA Assesses Your DPO Obligation
Free scoping call (30 minutes)
We talk through your organisation, your sector, and your main processing activities, then give you an initial view on whether Article 37 is likely to apply. No cost and no commitment.
Written Article 37 assessment
If you want a formal record, we review:
- your processing activities and which of them count as core activities
- the number of people involved, the volume and range of data, how long processing lasts, and its geographical reach
- any special category or criminal offence data you handle
- any monitoring of individuals
What you receive
A written assessment stating whether a DPO is mandatory, recommended, or not needed, with the reasoning behind it.
The appointment options that fit your organisation, if you need or want a DPO. If you choose our outsourced DPO service, we help you publish your DPO's contact details and notify the ICO, as Article 37(7) requires.
Not Sure If Your Business Legally Needs a DPO?
Book a free 30-minute scoping call, and we'll give you an initial view on your Article 37 position. For support beyond the DPO role, explore our full suite of privacy & compliance services below.
Tom S.
Medical Practice
"Improved control over sensitive medical data"
"Practical guidance on access controls and data protection. Helped define structured access policies and introduced tokenisation for patient identifiers used in analytics."
Sarah S.
Retail, Enterprise
"Reliable partner for telecom data protection"
"Quickly understood telecom data complexity; helped classify sensitive datasets and apply protection measures for subscriber, usage, and billing data."
Pauliina H.
Entertainment, Enterprise
"Effective support for securing customer data"
"Identified where sensitive data lived and applied tokenization and anonymization strategies in a complex telecom environment."
Jordan R.
Computer Networking
"Practical approach to safeguarding e commerce"
"Helped protect PII, payment data, and order histories with tokenization and anonymization; advised on GDPR compliance for international operations."
Charmaine S.
Int. Trade & Development
"Systematic Approach Enhances Data Security"
"Methodical approach through discovery, planning, and implementation; implemented Microsoft Purview for a scalable compliance framework."
Kateryna H.
IT and Services
"Practical approach to protecting sensitive Data"
"Structured data discovery and classification combining technical analysis with finance data privacy expertise; strong masking and tokenization policies."
Snow D.
Market Research
"Practical expertise for telecom information"
"Introduced tokenization and controlled access strategies for subscriber data while still supporting analytics and reporting."
Laura H.
Hospital & Health Care
"Valuable expertise in healthcare protection"
"Strong expertise in healthcare data security; introduced anonymization techniques for safely using patient data in research and reporting."
Frequently Asked Questions
Standard questions regarding UK GDPR Article 37 DPO legal mandates and appointment options.
Failing to appoint a DPO when required under Article 37 is a direct breach of UK GDPR. Under Article 83(4), regulators can issue enforcement notices, public reprimands, or administrative fines of up to £8.7 million or 2% of global annual turnover, whichever is higher.
Yes, but under Article 38(6), those other duties must not create a conflict of interest. A DPO cannot hold roles that determine the purposes and means of processing data (such as CEO, CFO, Head of IT, Head of Marketing, or Head of HR).
Yes. Article 37(8) explicitly allows a group of undertakings or multiple organisation entities to appoint a single DPO, provided that the DPO is easily accessible from each establishment.
Under Article 37(7), you must publish the contact details of your DPO and communicate them to the Information Commissioner's Office (ICO). You do this via the ICO's online DPO reporting webform. KEWDATA assists all DPO clients with this notification process.

