Whether your business needs a Data Protection Officer depends on one article of UK GDPR. Article 37 makes a DPO mandatory in three situations, and if none of them applies to you, appointing one is your choice. The hard part is working out whether your processing counts as a core activity and whether it happens on a large scale. This guide explains each test, how the ICO judges large-scale processing, what changes if you appoint a DPO voluntarily, and your options for filling the role.
What Does GDPR Article 37 Actually Say?
Article 37 gives you three tests. Meet any one of them, and appointing a DPO stops being optional.
You need a DPO if you’re a public authority or body. You need one if your core activities involve regular and systematic monitoring of individuals on a large scale. And you need one if your core activities involve large-scale processing of special category data, or data relating to criminal convictions and offences. The ICO’s guidance sets out the same three conditions and confirms they apply to both controllers and processors.
UK GDPR and EU GDPR use the same three tests, so the starting question is the same on both sides of the Channel. The detail around those tests differs, though:
- In the UK, the Data Protection Act 2018 defines which organisations count as public authorities.
- EU member states can add national rules that require a DPO in more situations. Germany, for example, requires one where at least 20 people regularly work on the automated processing of personal data.
If your business is established in the EU, check the national law of each country involved, not just the GDPR itself.
The Three Types of Organisations That Must Appoint a DPO
- Public authorities and bodies: Local councils, NHS trusts, and most public sector organisations fall under this trigger automatically, regardless of size or how much data they process. Courts acting in their judicial capacity are the one exception.
- Large-scale, regular and systematic monitoring as a core activity: This covers organisations whose core activities involve tracking people on an ongoing basis. Behavioural advertising platforms, fitness apps logging location around the clock, and retail chains running facial recognition across a store network all sit inside this trigger. A single CCTV camera above a till doesn’t. A nationwide network of smart cameras feeding into an analytics platform likely does.
- Large-scale processing of special category or criminal offence data as a core activity: Special category data includes health data, genetic data, biometric data used to uniquely identify someone, and data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or a person’s sex life or sexual orientation. A private healthcare provider, a genetic testing company, or a background-checking firm handling criminal record data at volume all fall inside this trigger.
What counts as a core activity?
Core activities are the processing operations your organisation needs to carry out to meet its main objectives. A hospital can’t provide care without processing patient health data, so that processing is a core activity. Payroll and IT support for your own staff are support functions, so they don’t count, even though every organisation runs them.
What Does “Large-Scale” Actually Mean?
This is the question every UK business ends up asking. GDPR gives no number. There’s no threshold anywhere that says “10,000 records” or “50,000 customers.”
Instead, the ICO points to five factors, drawn from guidance the Article 29 Working Party originally issued and the EDPB later carried forward: the number of data subjects affected, the volume of personal data, the range of data items involved, the geographic scope of the activity, and how long or permanent the processing is.
You don’t need every factor present for processing to count as large-scale. A health app used by hundreds of thousands of people across the UK, collecting data continuously, would almost certainly qualify. Processing that involves a small number of people, for a short time, in one location, would not.
Because there’s no fixed number, the ICO expects organisations to document their own reasoning. If you conclude you don’t need a DPO, write that reasoning down. It’s your evidence of accountability if anyone ever asks.
Voluntary DPO Appointment: When Is It Worth Doing?
Some businesses outside Article 37 appoint a DPO anyway. The reasons we see most are commercial:
- Enterprise procurement questionnaires asking who oversees data protection
- Investors checking during due diligence that someone owns the privacy programme
- Working in sectors under close regulatory attention, such as FinTech, HealthTech, legal, or HR
Before you go down this route, know that a voluntary DPO carries the same statutory requirements as a mandatory one. Your DPO must:
- have expert knowledge of data protection law and practice
- carry out the tasks set out in Article 39
- report directly to your highest management level
- get the resources they need to do the job
- work without instructions on how to carry out those tasks
You also can’t dismiss or penalise them for doing the job. If you want data protection support without those formal duties, appoint a privacy lead or adviser instead, and don’t give the role the DPO title.
Three Options If You Need a DPO
- Hire in-house: A dedicated employee who handles your data protection work. Costs depend on the person’s experience and how much data protection work your organisation generates, so this suits organisations with enough ongoing work to justify a dedicated role.
- Designate an existing staff member: This works when the person has the right expertise and their other duties don’t create a conflict of interest. Article 38 sets the rules: the DPO reports directly to your highest management level, can’t take instructions on how to carry out DPO tasks, and can’t be dismissed or penalised for doing the job. They can hold other duties, as long as those duties don’t put them in a position to decide why and how personal data gets processed.
- Outsource the function: An external provider covers the role under a service contract, which Article 37(6) allows. Our outsourced DPO service covers this, alongside our wider DPO and data governance support if you need more than the DPO role alone.
Frequently Asked Questions
Is a DPO required for SMEs?
Only if one of the three Article 37 triggers applies. Size alone doesn’t create the obligation. A small company doing large-scale special category processing needs a DPO. A larger company doing low-risk, low-volume processing might not.
Can the CEO or HR director be the DPO?
It depends on their other duties. A DPO’s additional responsibilities must not create a conflict of interest, and roles that decide the purposes and means of processing are likely to. Senior positions such as chief executive or head of HR can fall into that category, so assess the specific role before designating anyone.
What happens if I don’t appoint a DPO when required?
You’re in breach of Article 37, which the ICO can act on separately from whatever underlying issue prompts an investigation. It also weakens your position if a breach or complaint happens later, since you can’t point to a documented, independent oversight function.
Do I need to register my DPO with the ICO?
Not in the sense of a formal registration process, but Article 37(7) requires you to publish your DPO’s contact details and communicate them to the ICO. This sits separately from the standard ICO data protection fee registration most organisations already complete.
Can my DPO also be my legal counsel?
It’s possible, as long as the two roles don’t conflict. The risk comes when legal counsel advises on or decides how personal data gets processed, because the DPO then has to assess decisions they helped make. Check the specific duties before combining the roles.
Not Sure Where You Stand?
You can work through the Article 37 test on your own, and if you conclude you don’t need a DPO, keep a written record of your reasoning. If you’re still unsure whether your business needs a DPO in the UK, see how KEWDATA assesses your DPO obligation, or book a free 30-minute scoping call.

