GDPR
When do you need a data protection officer under the GDPR, and what must the DPO do?

Three short Articles of the GDPR settle almost every question about data protection officers. Article 37 says when you must have one and what expertise they need. Article 38 protects their independence and sets their reporting line. Article 39 lists their tasks. This page quotes each, so you can decide whether you need a DPO and what the role must look like.
Every quotation is from Regulation (EU) 2016/679 (GDPR), OJ L 119, 4 May 2016, read on 2 October 2026; the Publications Office recorded no adopted amendment to these Articles. This is not legal advice.
When must you appoint a DPO?
Article 37(1) requires the controller and the processor to designate a DPO "in any case where":
- "the processing is carried out by a public authority or body, except for courts acting in their judicial capacity";
- "the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale"; or
- the core activities consist of processing on a large scale of special categories of data under Article 9, or personal data relating to criminal convictions and offences under Article 10.
Outside those cases, Article 37(4) makes a DPO voluntary, unless Union or Member State law requires one. Article 37(2) lets a group of undertakings appoint one DPO "provided that a data protection officer is easily accessible from each establishment", and Article 37(6) allows a staff member or a contractor.
What qualifications does a DPO need?
Article 37(5): the DPO "shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39." The GDPR names no certificate. A credential such as the IAPP's CIPP/E, which the IAPP aims at "data protection professionals whose work is within the scope of the General Data Protection Regulation", is one way to evidence that expert knowledge; the CIPM adds running a privacy program. Our guide to the IAPP certifications compares them.
Article 38(2) also requires the organization to support the DPO with resources, access to personal data and processing operations, and "to maintain his or her expert knowledge", so the organization must support the DPO's ongoing training.
GDPR DPO checklist (Articles 37 to 39)
GDPR provision,What it requires (summary),Applies to us? (why),How we meet it,Owner,Evidence kept,Notes Article 37(1)(a),DPO required where processing is carried out by a public authority or body (except courts acting judicially),,,,, Article 37(1)(b),DPO required where core activities need regular and systematic monitoring of data subjects on a large scale,,,,, Article 37(1)(c),DPO required where core activities are large-scale processing of special category or criminal offence data,,,,, Article 37(4),Union or Member State law may require a DPO in other cases; otherwise voluntary,,,,, Article 37(5),"Designated on professional qualities, in particular expert knowledge of data protection law and practices",,,,, Article 37(6),Staff member or service contract,,,,, Article 37(7),Contact details published and communicated to the supervisory authority,,,,, Article 38(1),Involved properly and in a timely manner in all data protection issues,,,,, Article 38(2),"Given resources, access to data and processing, and support to maintain expert knowledge",,,,, Article 38(3),"No instructions on tasks; not dismissed or penalised for performing them; reports to the highest management level",,,,, Article 38(6),Other tasks allowed only without a conflict of interests,,,,, Article 39(1)(a),Inform and advise the organization and employees,,,,, Article 39(1)(b),"Monitor compliance, including assignment of responsibilities, awareness-raising and training of staff, and audits",,,,, Article 39(1)(c),Advise on and monitor DPIAs (Article 35),,,,, Article 39(1)(d) and (e),Cooperate with and act as contact point for the supervisory authority,,,,, "Regulation (EU) 2016/679, Articles 37 to 39, read 2 October 2026. Template from credentialpress.com/guides/gdpr-data-protection-officer. Not legal advice.",,,,,,
How independent must a DPO be?
Article 38(3) sets three protections: the organization "shall ensure that the data protection officer does not receive any instructions regarding the exercise of those tasks"; the DPO "shall not be dismissed or penalised by the controller or the processor for performing his tasks"; and the DPO "shall directly report to the highest management level". Article 38(1) requires the DPO to be involved "properly and in a timely manner, in all issues which relate to the protection of personal data". Article 38(6) allows other duties only if they "do not result in a conflict of interests".
What are the DPO's tasks?
Article 39(1) gives "at least the following tasks":
| Article 39(1) | Task |
|---|---|
| (a) | Inform and advise the controller or processor, and the employees who carry out processing, of their data protection obligations |
| (b) | Monitor compliance with the GDPR, other data protection law and internal policies, "including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits" |
| (c) | Advise on the data protection impact assessment, where requested, and monitor its performance under Article 35 |
| (d) | Cooperate with the supervisory authority |
| (e) | Act as the contact point for the supervisory authority, including on prior consultation under Article 36 |
Article 39(2) tells the DPO to have "due regard to the risk associated with processing operations". The DPO informs, advises and monitors; Article 24 leaves the measures to ensure compliance with the controller. Our guide to EU laws that require training covers the training part of task (b).
What should a DPO know about AI?
More each year. A DPO advising on AI systems will meet the EU AI Act's fundamental rights impact assessment, which since July 2026 can cross-refer to the DPIA, and the new Article 4a on processing special category data to detect bias. Our guide to AI impact assessments and guide to the July 2026 AI Act changes cover both.
What should you do this week?
Run the three Article 37(1) tests against your core activities and record the answer, whichever way it goes. If you need a DPO, check the reporting line and conflict rules in Article 38 before choosing who it will be. For a DPO preparing for the CIPP/E, the CIPP/E study guide and our CIPP/E exam guide are the place to start. Credential Press is independent of the IAPP and the EU institutions.
Frequently asked questions
When is a data protection officer mandatory under the GDPR?
Under Article 37(1), in three cases: processing by a public authority or body, except courts acting in their judicial capacity; core activities that require regular and systematic monitoring of data subjects on a large scale; and core activities that consist of large-scale processing of special categories of data or criminal conviction and offence data. Union or Member State law can require one in other cases.
What qualifications does a DPO need?
Article 37(5) says the DPO shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the Article 39 tasks. The GDPR names no certificate.
Who does the DPO report to?
Article 38(3) says the DPO shall directly report to the highest management level of the controller or processor, receives no instructions on how to perform the tasks, and cannot be dismissed or penalized for performing them.
Can the DPO be an external contractor?
Yes. Article 37(6) says the DPO may be a staff member or fulfil the tasks on the basis of a service contract. A group of undertakings may appoint a single DPO if one is easily accessible from each establishment.
Can the DPO have other jobs?
Yes, under Article 38(6), provided the other tasks and duties do not result in a conflict of interests.
Is a DPO responsible for GDPR compliance?
Not under Article 39. The DPO's tasks are to inform, advise, monitor and cooperate; under Article 24, the controller implements measures to ensure and demonstrate compliance.
CIPP/E: test yourself in five minutes
Which books cover EU data protection law?

Certified Information Privacy Professional, Europe. 18 chapters, 441 pages.

Sources
Every quotation above was read from the Official Journal text on 2 October 2026 through the EU Publications Office.
Credential Press is independent of the IAPP and the EU institutions. This is not legal advice.