“We’re a small company, so we can’t need a DPO.” Under the GDPR, headcount alone does not answer the question. A small provider whose service depends on analysing personal data may need one, while a larger business cannot decide solely by counting employees.
These seven questions help you assess the appointment requirement. The first three address the GDPR’s mandatory cases; the remaining four explain how to interpret them and what else to check.
What does a Data Protection Officer do?
A Data Protection Officer (DPO) informs and advises the organisation, monitors compliance with data protection requirements, supports awareness and advises on Data Protection Impact Assessments. The DPO cooperates with the supervisory authority and provides a contact point for individuals.
The DPO does not take over the controller’s decisions or accountability. They may help assess a request or a breach, but authorised managers decide on the organisational measures required. The role is governed by GDPR Articles 37–39.
1. Is the controller a public authority or body?
If so, appointment is generally mandatory. Courts acting in their judicial capacity are an exception.
A public administration body will typically fall within this category. For a privately owned business connected to public services, its legal status and the relevant national rules need to be examined: serving a public interest does not always settle the question.
2. Do core activities involve large-scale, regular monitoring of people?
The conditions apply together: regular and systematic monitoring of individuals on a large scale must form part of the controller’s or processor’s core activities.
Activities that warrant assessment include:
- continuous profiling of large numbers of users;
- regular tracking of individuals using location data;
- CCTV covering extensive areas and many people;
- extensive analysis of customers’ risk profiles or purchasing behaviour.
Having a camera or an online shop does not, by itself, establish all three conditions. Document the actual activity, the people affected and the purpose of monitoring together.
3. Do core activities involve large-scale special category or criminal data?
A DPO is required where core activities involve large-scale processing of special category personal data, or data relating to criminal convictions and offences.
Special category data includes health information, political opinions and biometric data used to uniquely identify someone. Criminal offence data has a separate regulatory basis. A hospital’s processing of patient records is a typical example of large-scale processing; European guidance does not treat an individual physician’s practice as such on that basis alone.
4. What counts as “large-scale” processing?
There is no single GDPR headcount threshold that applies to every organisation. The European DPO guidelines published by NAIH recommend assessing several factors together:
| Factor | What to examine |
|---|---|
| Number of individuals | How many people are affected, and what proportion of the relevant population? |
| Volume of data | How much data is processed, and how varied is it? |
| Duration | Is processing one-off, periodic or continuous? |
| Geographical reach | Is it limited to a local area, or does it span regions or countries? |
Avoid basing the decision on customer numbers or headcount alone. A short written assessment helps explain and substantiate your conclusion later.
5. Is the processing genuinely a core activity?
Core activities are the essential operations needed to achieve the organisation’s objectives. Healthcare cannot be delivered without processing patient data; in a profiling-based service, the analysis itself is part of the service.
General payroll and internal IT support are usually ancillary activities. They involve important processing but do not automatically make every employer subject to a DPO requirement. A processor must assess its own core activities separately.
6. Do sectoral or national rules add further requirements?
The GDPR allows EU or national law to require appointment in additional cases. Even if your answer to the first three questions is “no”, check the rules associated with your legal status and sector.
Start with your list of processing activities, organisational remit and applicable laws. If the answer remains unclear, our DPO service can help establish the requirement and the work involved.
7. Have you already appointed a DPO voluntarily?
A voluntarily appointed DPO is also subject to Articles 37–39. You must provide independence, accessibility, appropriate resources and direct reporting to the highest management level.
You can engage a privacy adviser without formally appointing a DPO. In that case, define the role and its title clearly so that individuals and the authority are not misled.
Who can be a DPO, and when does a conflict arise?
Select the DPO on the basis of professional competence, knowledge of data protection law and practice, and ability to carry out the duties. The person may be an employee or an external expert working under contract.
A DPO cannot independently review processing decisions that they make themselves. Assess conflicts against actual decision-making powers.
| Role | What to consider |
|---|---|
| Managing director or senior executive | Decisions about the purposes and means of processing usually create conflicts. |
| IT, HR or marketing lead | Examine actual decision-making powers and the allocation of responsibilities. |
| Legal or compliance employee | The job title is not decisive; reviewing their own decisions must be avoided. |
| External DPO | Check conflicts arising from other engagements as well as expertise and accessibility. |
What does an external DPO provide beyond the appointment?
An effective service includes defined work, feedback and follow-up actions. Typical activities include reviewing processing, privacy notices and processor agreements, supporting data subject requests and training staff.
During a breach, the DPO helps assess risk and notification duties. The GDPR’s 72-hour deadline concerns breaches that must be notified to the authority and runs from the controller becoming aware. The DPO also advises on impact assessments for planned high-risk processing.
Breaches of DPO obligations fall within Article 83(4): the maximum fine is €10 million or, for an undertaking, 2% of total worldwide annual turnover in the preceding financial year, whichever is higher. The actual consequences depend on the infringement and its circumstances.
How does appointment work?
- Applicability and scope: establish why a DPO is needed and which processing activities they must oversee.
- Competence and independence: check expertise, availability and conflicts of interest.
- Appointment or contract: define duties, resources and the reporting relationship with management.
- Contact details and notification: publish the DPO’s contact details and submit the required information through NAIH’s system. The GDPR does not require the DPO’s name to be publicly disclosed.
- Initial assessment: establish priorities, followed by regular expert feedback on implementation.
The zemITis outsourced DPO service covers both the appointment assessment and day-to-day privacy support. Meet the expert and explore the service, or get a tailored DPO fee estimate.

Dr Fanni Mikoss
Lawyer, cybersecurity law specialist and former NAIH expert
Fanni spent five years as a data protection expert at Hungary’s data protection authority, NAIH, working on investigations, complaints and the preparation of regulatory decisions. Today, she serves as DPO for corporate clients, supporting policies, data subject requests and everyday privacy matters.
Still unsure after the seven questions? Let’s review your organisation’s processing activities and priorities together. Discover how Fanni and the zemITis team support you from DPO appointment through ongoing operations.
Frequently asked questions
Can an external provider act as our DPO?
Yes. Article 37(6) of the GDPR permits a DPO to work under a service contract. Expertise, independence, accessibility and freedom from conflicts of interest must be ensured.
Can a group of companies appoint one DPO?
Yes, if the DPO is easily accessible from every establishment. Language, geographical distance and actual capacity must also be considered.
Is the DPO the same as the Information Security Officer?
No. The DPO advises on and monitors lawful personal data processing and GDPR compliance; the security officer coordinates information system security. Combining the roles requires a separate assessment of expertise and conflicts of interest.
Does using AI automatically make a DPO mandatory?
No. AI use alone does not trigger the requirement. You must assess the data, the nature and scale of monitoring, and your core activities. High-risk processing may also require a DPIA.
