Let’s talk
Wondering how this plays out in your organisation? Get in touch — I answer personally.
Short answer
DPO resources are determined by Article 38(2) GDPR, which requires the controller and the processor to support the DPO by providing resources necessary to carry out the tasks referred to in Article 39 and access to personal data and processing operations, and to maintain his or her expert knowledge. The WP 243 guidelines mention in this context items such as active support from management, sufficient time and budget and a team where needed. The scale depends on the size of the organisation and on the complexity and sensitivity of the processing. The EDPB recommends that the organisation be ready to show how it assessed that scale.
Why this question arises at all
The provision is short and easy to read as a polite formality. Article 38(2) GDPR provides that the controller and the processor shall support the DPO in performing the tasks referred to in Article 39. That support consists in providing the resources necessary to carry out those tasks and access to personal data and processing operations, as well as the resources necessary to maintain his or her expert knowledge. The Regulation does not specify a number of hours or an amount and does not define the composition of a team.
Sometimes an organisation designates a DPO and notifies the President of the Personal Data Protection Office (UODO), then treats the matter as closed. DPO resources are then reduced to a training budget or to the post itself. Yet the provision lists three different things, and only one of them concerns expert knowledge.
In 2023, 25 supervisory authorities from the European Economic Area undertook a coordinated review of the position of DPOs. In its report on that action, the European Data Protection Board (EDPB) described insufficient resources as one of the challenges. Many authorities pointed to a lack of human resources, and some also to the lack of deputy DPOs. In the six authorities examining the public sector, DPOs’ resources were deemed sufficient in 66% of cases on average, and in the four examining the private sector in 91%.
The obligation does not depend on how the function is organised. The Personal Data Protection Office points out that where the DPO acts on the basis of a service contract, all GDPR requirements must be met. This covers the DPO’s proper and timely involvement in all issues relating to the protection of personal data. The WP 243 guidelines add that where a DPO is designated voluntarily, Articles 37 to 39 apply as if the designation had been mandatory. Resources therefore concern an in-house DPO, an external DPO and a DPO designated voluntarily.
The board should take this provision seriously for another reason too. UODO lists supporting the DPO among the GDPR mechanisms intended to ensure his or her independence. In my assessment, a DPO who lacks time and access gives opinions that depend on what he or she has been shown. An infringement of the obligations under Article 38 is also subject to an administrative fine under Article 83(4)(a) GDPR.
What has to be established before a decision
What DPO resources cover
Article 38(2) has three limbs, and each of them has to be implemented separately. The first limb is the most general, and the provision does not say what it covers. The WP 243 guidelines list the items which in particular are to be considered when implementing Article 38(2) as a whole. Most of them flesh out the first limb.
- active support of the DPO’s function by senior management, for example at board level;
- sufficient time for the DPO to fulfil his or her duties;
- adequate support in terms of financial resources, infrastructure (premises, facilities, equipment) and staff where appropriate;
- official communication of the designation of the DPO to all staff;
- access to other services such as HR, IT, legal and security;
- continuous training;
- a DPO team, which may prove necessary depending on the size and structure of the organisation.
The size of the organisation matters, but the scale of resources also depends on the nature of the processing. The guidelines state that in general the more complex and/or sensitive the processing operations, the more resources must be given to the DPO. For example, processing patients’ health data would be sensitive.
Time — how much is needed and how to record it
Time is not visible in the budget, so it is easy to overlook. The guidelines indicate that sufficient time is particularly important where an internal DPO is appointed on a part-time basis or where an external DPO carries out data protection in addition to other duties. Conflicting priorities could then result in the DPO’s duties being neglected.
The guidelines also give four good practices that can be translated directly into a document. The first is to establish a percentage of time for the DPO function where it is not performed on a full-time basis. The second is to determine the time needed to carry out the function. The third is to set the priority of the DPO’s duties. The fourth is for the DPO or the organisation to draw up a work plan.
UODO points in the same direction. According to the Office, when designating a DPO the controller should agree with him or her on rules covering three matters. These are sufficient time, help in drawing up a work plan and support from a team of specialists where needed. The Office links the accountability principle in Article 5(2) GDPR with the requirement to analyse carefully whether the designated person will be able to fulfil all of his or her duties properly.
The starting point for such an analysis is the set of tasks in Article 39(1). The DPO performs them with due regard to the risk associated with processing operations (Article 39(2)). He or she also takes into account the nature, scope, context and purposes of processing.
Remember
I recommend calculating time from the tasks, not from the position.
It is worth counting how many data protection impact assessments there are in a year for which the DPO provides advice where requested and monitors their performance (Article 39(1)(c)). Breach assessments, new suppliers and issues raised by data subjects come on top of that (Article 38(4)). Finally, you add ongoing monitoring and advice. The sum of the time needed for these tasks determines the size of the function, which you compare with the time actually available. How to collect these figures is described in External or internal DPO? What to consider before deciding?.
In the case of an external DPO, time also depends on how many entities he or she serves. Asked about the number of entities served by one DPO, UODO replies that the provisions give no direct answer. However, the Office stresses that one DPO may be designated for several entities only in justified cases and that the number of entities must remain within reasonable limits. Among other things, the assessment depends on the effective availability of the DPO, the ability to get to know the entity and the time the DPO has for the tasks. The EDPB report states that controllers and processors must carefully verify that the DPO has sufficient resources. In some cases, where an external DPO is used, this may require controllers and processors to verify how many clients that DPO has.
Budget, facilities and team
The guidelines mention adequate support in terms of financial resources, infrastructure and staff ‘where appropriate’. If the DPO has a team, its internal structure and the tasks and responsibilities of each of its members should be clearly drawn up. When the function is exercised by an external DPO, the tasks may be carried out by the service provider’s team under the responsibility of a designated lead contact.
The GDPR does not explicitly require a team or a deputy to be appointed. UODO answered a question about a team from the DPO of a hospital employing more than 2,000 people. The Office indicated that the way the obligations under Article 38(2) are fulfilled depends on the size, structure and type of activity of the controller and on the nature of the processing, among other factors. It is the controller who is responsible for the DPO performing the tasks effectively. The EDPB report also states that the GDPR does not strictly require a deputy DPO and does not prohibit part-time DPOs. The requirement of sufficient resources nevertheless still applies.
The Polish Act provides a tool that the GDPR does not. The entity that designated the DPO may designate a person substituting for the DPO during his or her absence (Article 11a(1) of the Act on the Protection of Personal Data). In doing so, it takes into account the criteria in Article 37(5) and (6) GDPR. When the deputy performs the DPO’s duties during the DPO’s absence, the provisions on the DPO apply to him or her accordingly (Article 11a(2)). After designating a deputy, the entity notifies the President of UODO under Article 10 of the Act (that is, among other things, within 14 days of the date of designation) and makes the deputy’s details available in accordance with Article 11 of the Act (Article 11a(3)). The deputy ensures continuity during the DPO’s leave or illness, that is, in situations which the EDPB report describes explicitly. However, he or she acts only during the DPO’s absence. After the DPO has been dismissed, an entity subject to the obligation in Article 37(1) GDPR must designate a new one.
A separate matter is a budget that the DPO controls. The EDPB report indicates that the GDPR does not strictly require this, but such a budget makes it easier for the DPO to manage resources in a responsive and independent manner. In the report, one supervisory authority described the consequences of the DPO lacking control over his or her own budget. A DPO without such control may fear that criticising the organisation’s practices will end in budget cuts. Article 38(3) GDPR prohibits dismissing or penalising the DPO for performing his or her tasks, and the WP 243 guidelines indicate that penalties may be direct or indirect. In my assessment, an arbitrary reduction of funds after a critical opinion may be regarded as such an indirect penalty.
Board support and the DPO’s place in the organisation
Some DPO resources cost nothing and yet are sometimes overlooked. They include official communication of the DPO’s designation to staff and access to other services. That access is meant to enable the DPO to receive essential support, input and information from those services.
Board support also has a basis in other paragraphs of the same Article. The DPO directly reports to the highest management level of the controller or the processor (Article 38(3)). The organisation must also ensure that the DPO is involved, properly and in a timely manner, in all issues which relate to the protection of personal data (Article 38(1)). The WP 243 guidelines point out that all relevant information must be passed on to the DPO in a timely manner in order to allow him or her to provide adequate advice. Among other things, they also recommend that the DPO be invited to participate regularly in meetings of senior and middle management and be present where decisions with data protection implications are taken.
Access to personal data and processing operations
The second limb of Article 38(2) concerns access to the data themselves and to processing operations. Without it, the DPO checks only documents and not actual processing in the systems. UODO describes this access broadly. Access to information about data processing, to the data themselves and to processing operations is necessary for the DPO to perform the tasks properly.
Broad access should not be confused with unlimited access. Access to data covered by statutory secrecy may require a separate basis. In my assessment, the obligation of secrecy or confidentiality by which the DPO is bound in accordance with Union or Member State law (Article 38(5)) does not replace that basis. UODO addressed the separate basis using the example of a bank. The Office indicated that the DPO needs access to data covered by banking secrecy. If the DPO performs the function on the basis of a service contract, the provision of the Banking Law that allows this should apply to that contract. I recommend checking for a similar basis for other statutory secrets before designating the DPO, not at the first inspection.
Describe access with a list, not a general formula. The list indicates the systems, registers and places to which the DPO has access. It also indicates the people who provide the DPO with information on request. Such a record shows whether access covers processing operations and not just documentation.
Expert knowledge and maintaining it
The third limb concerns maintaining knowledge. The DPO is to have the baseline knowledge already at the time of designation. He or she is designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39 (Article 37(5)). The necessary level of that knowledge should be determined in particular according to the data processing operations carried out and the protection required for the data (recital 97). Article 38(2) adds an obligation on the organisation’s side. The organisation has to provide the DPO with the resources necessary to maintain that knowledge.
The guidelines list continuous training and state that DPOs must be given the opportunity to stay up to date with developments within the field of data protection. The aim should be to constantly increase their level of expertise. The DPO should be encouraged to participate in training courses and other forms of professional development, such as fora and workshops.
The EDPB report also addresses training. According to the report, a strong majority of DPOs received 24 hours of training a year or less. The EDPB cautions that these statistics cannot be used to draw hard-and-fast conclusions as to the adequacy of DPOs’ knowledge. The EDPB recommends that organisations document their knowledge and training needs and progress. It also recommends giving the DPO opportunities, time and resources to refresh his or her knowledge and learn about the latest developments. This also covers new EU digital- and AI-related legislation where relevant to the organisation’s activities. The obligation under Article 38(2) rests with the controller also where the DPO is external. Therefore, settle in the contract whether the fee covers the cost of maintaining that knowledge.
How to demonstrate that DPO resources are sufficient
The provision does not require a separate document on resources. Without a record, however, it is difficult to demonstrate that the obligation has been fulfilled. After all, the controller implements appropriate measures to ensure and to be able to demonstrate that processing is performed in accordance with the Regulation (Article 24(1)). The EDPB report states that controllers and processors must at all times perform an analysis of what resources a DPO needs. The analysis is to be tailored to the specific case, and the EDPB recommends that controllers be ready to show how it was carried out.
The report also suggests a form in its part on the DPO’s independence. Organisations and DPOs could formalise the DPO’s duties and the conditions for performing them in a separate ‘engagement letter’. I recommend that such a document contain six elements.
- the tasks under Article 39(1) and their priorities, set with regard to risk;
- the amount of time or percentage of working time devoted to the function, together with the estimate on which it is based;
- the budget for tools, expert opinions and training, and who controls it;
- the composition of the team and the deputy, or a justification of why they are not needed;
- a list of the systems and registers to which the DPO has access and of the people who provide information;
- how and how often these arrangements are reviewed.
The review is as important as the content. DPO resources that are sufficient at the time of designation may cease to be sufficient after an acquisition, the implementation of a new system or a change in the scale of processing. I recommend that the DPO assess in the annual report to the board whether his or her resources match the tasks. It is then worth recording the board’s decision on resources.
Common mistakes
- Resources reduced to training. A training budget concerns only the third limb of Article 38(2). You cannot use it to demonstrate the DPO’s time and access.
- Time set from the position, not from the tasks. Without an estimate of the number of impact assessments and breaches, the organisation does not know whether a half-time post is enough, and it will struggle to demonstrate it.
- The contract with an external DPO treated as closing the matter. The number of hours in the contract does not say how many clients the same person serves or who pays for maintaining his or her knowledge.
- Access on request instead of access by default. A DPO forced to ask for every piece of information learns about processing only after the decision has been made.
- No plan for the DPO’s absence. A deputy is not mandatory. Without a deputy or another solution, the organisation loses advice during the DPO’s leave or illness, for example when assessing a breach.
Conclusions and next steps
DPO resources are best treated as a board decision with a justification, not as the cost of the function. A recorded decision helps the organisation during an inspection and gives the DPO a point of reference when resources start to run short.
- Count the DPO’s tasks from the last twelve months and compare them with the time the function actually gets.
- For an external DPO, ask about the number of entities served and record the answer.
- Record in a document adopted by the board the arrangements on tasks and time, budget and team, and access and training.
- Include the assessment of resources in the DPO’s annual report and review the arrangements after every significant change in processing.
Related materials
- What should a contract with an external data protection officer contain? — how to record time, access and costs in a service contract without infringing the DPO’s independence.
- What information should the board expect from the DPO? — how to structure the DPO’s report so that it includes an assessment of the conditions for performing the function.
- External or internal DPO? What to consider before deciding? — how to estimate the workload of the function before choosing a model.
- Who cannot act as a data protection officer? — conflict of interests when the DPO combines the function with other duties.
Sources
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), consolidated version — Article 5(2), Article 24(1), Article 37(1), (5) and (6), Article 38(1) to (5), Article 39 and Article 83(4)(a) — eur-lex.europa.eu.
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), published text — recital 97 — eur-lex.europa.eu.
- Act of 10 May 2018 on the Protection of Personal Data, consolidated text as at 18 August 2026 — Article 10, Article 11 and Article 11a (in Polish) — isap.sejm.gov.pl.
- Article 29 Data Protection Working Party, Guidelines on Data Protection Officers (‘DPOs’) (WP 243 rev.01), endorsed by the European Data Protection Board — points 2.1, 3.1, 3.2 and 3.4 — English version ec.europa.eu, Polish version (in Polish) uodo.gov.pl.
- Personal Data Protection Office (UODO), What guarantees of independence are granted to the DPO under the GDPR? (in Polish) — uodo.gov.pl.
- Personal Data Protection Office (UODO), Is the controller obliged under the GDPR to provide the DPO with a DPO team? (in Polish) — uodo.gov.pl.
- Personal Data Protection Office (UODO), What is the maximum number of entities one DPO may serve? (in Polish) — uodo.gov.pl.
- Personal Data Protection Office (UODO), Can a person from outside the organisation of the controller or processor act as DPO? (in Polish) — uodo.gov.pl.
- Personal Data Protection Office (UODO), Should a data processing agreement be concluded with an external DPO performing tasks for a bank? (in Polish) — uodo.gov.pl.
- European Data Protection Board, 2023 Coordinated Enforcement Action. Designation and Position of Data Protection Officers, report adopted on 16 January 2024 — executive summary and points 4.2, 4.3 and 4.5.2 — edpb.europa.eu.
Let us check whether your DPO has the conditions to do the job
If the DPO’s resources in your organisation have never been described, the first step is to estimate the tasks and compare them with the time the DPO actually has. Support and performance of the DPO function starts with such a diagnosis.
This material is general and educational in nature. It is not an individual legal opinion or a recommendation for any specific organisation. The scope of the obligations should be assessed against the situation of the organisation concerned.
Legal status: September 2026.