Under GDPR Art. 37, when must an organisation designate a Data Protection Officer, and could its CTO hold that role?
answer
- three mandatory cases
- core activities, not ancillary ones
- large-scale monitoring or special data
- no instructions, top-level reporting
- other duties without conflict
basics
~20 sUnder GDPR Art. 37(1), a DPO is mandatory for public authorities, and where core activities involve large-scale regular and systematic monitoring or large-scale special-category or criminal data. A CTO is a poor fit: Art. 38(6) bars conflicting duties.
solid answer
~40 s**Art. 37(1)** makes a DPO mandatory in three cases: (a) processing by a **public authority or body**, except courts acting judicially; (b) **core activities** requiring **regular and systematic monitoring** of data subjects **on a large scale**; (c) core activities of **large-scale** processing of **special categories** (Art. 9) or **criminal convictions** data (Art. 10). It binds processors as well as controllers. Recital 97 says core activities are *primary* activities, not ancillary ones like payroll. **Art. 38** protects the role: no instructions on its tasks, no dismissal or penalty for performing them, direct reporting to the highest management level. **Art. 38(6)** allows other duties only if they create no **conflict of interests**. A CTO decides how systems process personal data and would be monitoring their own decisions, which is the classic conflict.
go deeper
Recall the three Art. 37(1) triggers and that a DPO is not needed by every organisation. Know that the DPO's contact details appear in breach notices.
Explain 'core activities' against ancillary processing, the double condition in points (b) and (c), and the Art. 38 protections: no instructions, no penalty, top-level reporting.
Argue a specific conflict of interests under Art. 38(6), such as a CTO or head of marketing, and show where a DPO sits so the role can advise without deciding.
Weigh an internal versus external DPO for a multi-entity group against Art. 37(2) accessibility and Art. 38 independence, and decide what resourcing Art. 38(2) really demands.
## When a DPO is mandatory **Art. 37(1)** of the GDPR says *"the controller and the processor shall designate a data protection officer in any case where"*: | Point | Trigger | Typical reading | |---|---|---| | **(a)** | processing by a **public authority or body**, except courts acting in their judicial capacity | ministries, municipalities, public hospitals | | **(b)** | **core activities** consist of processing that, by nature, scope or purposes, requires **regular and systematic monitoring** of data subjects **on a large scale** | behavioural advertising built on tracking, location tracking as the product | | **(c)** | **core activities** consist of **large-scale** processing of **special categories** of data (Art. 9) or data on **criminal convictions and offences** (Art. 10) | a hospital's patient records, a background-check business | Three details decide most cases: - **Core activities.** Recital 97 says core activities *"relate to its primary activities and do not relate to the processing of personal data as ancillary activities."* Every company runs payroll and HR. That is ancillary and does not by itself trigger a DPO. - **Both conditions in (b) and (c).** Point (b) needs monitoring that is regular and systematic *and* on a large scale. Point (c) needs special-category or criminal data *and* large scale. The Regulation does not define "large scale" by a number. - **Processors too.** A processor whose core business is large-scale monitoring must designate its own DPO. Outside these cases, **Art. 37(4)** lets any controller or processor appoint a DPO voluntarily, and Member State law can make it mandatory more widely. Art. 37(1) has no headcount trigger. The 250-person figure some candidates cite belongs to the Art. 30(5) record-keeping exemption, not to Art. 37. ## Who can be the DPO - **Art. 37(5)**: designated on professional qualities, *in particular expert knowledge of data protection law and practices*, and the ability to do the Art. 39 tasks. The Regulation names no specific diploma. - **Art. 37(6)**: a staff member *or* someone working under a **service contract**, so an external DPO is allowed. - **Art. 37(2)**: a group of undertakings may share one DPO if the DPO is easily accessible from each establishment. - **Art. 37(7)**: the DPO's contact details are **published** and **communicated to the supervisory authority**. ## The position the Regulation protects **Art. 38** is what makes the role more than a title: 1. **Involved properly and in a timely manner** in all issues relating to personal data protection (38(1)). In a breach, that includes being brought in early. 2. **Resourced**, with access to personal data and processing operations (38(2)). 3. **No instructions** on how to exercise the tasks, **no dismissal or penalty** for performing them, and **direct reporting to the highest management level** (38(3)). 4. **Contactable by data subjects** on all issues about their data and rights (38(4)). 5. **Bound by secrecy or confidentiality** (38(5)). 6. **May hold other tasks**, but the controller must ensure *"any such tasks and duties do not result in a conflict of interests"* (38(6)). **Art. 39** sets the minimum tasks: inform and advise; **monitor compliance**, including staff training and related audits; advise on **DPIAs**; **cooperate** with the supervisory authority; and act as its **contact point**. Note the verbs: advise and monitor. The Regulation puts the compliance obligations on the controller and processor, not on the DPO personally. ## The CTO, or the head of marketing, as DPO Art. 38(6) allows a DPO to have other duties, so the question is whether *this* combination conflicts. The reasoning comes straight from the Articles: - The CTO or head of marketing **decides** how personal data is processed: which systems collect what, which campaigns target whom. - Art. 39 makes the DPO the person who **monitors** whether that processing complies and **advises** on it. - One person in both roles audits their own decisions. They also sit in the management line the DPO is meant to report to without instructions under Art. 38(3). That is the conflict Art. 38(6) forbids. A common answer is to place the DPO where they advise decision-makers without being one: in a legal, risk or compliance function, or with an external DPO under Art. 37(6). ## Where the DPO meets breach handling Under **Art. 33(3)(b)**, every breach notification gives the DPO's name and contact details (or another contact point), and Art. 34(2) carries the same item into the communication to individuals. EDPB Guidelines 9/2022 recommend informing the DPO promptly of a breach and involving them throughout the breach management and notification process.
- Under the GDPR, does a company with 300 employees automatically need a DPO?Not under Art. 37(1), which turns on core activities: public authority, large-scale regular and systematic monitoring, or large-scale special-category or criminal data. Headcount is not among them, though Art. 37(4) lets Member State law require a DPO more widely. The 250-person figure is the Art. 30(5) record-keeping exemption, a separate provision.
- Under the GDPR, may a DPO be dismissed at all?Art. 38(3) prevents the controller or processor from dismissing or penalising the DPO for performing their tasks. By its own terms it protects against removal because advice or monitoring findings were unwelcome; any wider employment protection comes from other law, not from this Article.
- Under the GDPR, can one DPO serve a whole corporate group?Yes. Art. 37(2) lets a group of undertakings appoint a single DPO provided the DPO is easily accessible from each establishment. Art. 37(3) allows the same for several public authorities, taking account of their structure and size.
saying these in an interview costs you the question
- Every organisation that processes personal data must appoint a DPO.
- A DPO becomes mandatory once a company has 250 employees.
- The DPO is personally liable for the organisation's GDPR compliance.
- A DPO must be an employee; outsourcing the role isn't allowed.
- Routine staff payroll counts as a core activity that requires a DPO.
- The DPO can be told by the CEO what conclusion to reach.