Short answer
The regulation does not favour either model. Under Article 37(6) GDPR the data protection officer (DPO) may be a staff member or may perform the tasks on the basis of a service contract, and the requirements attached to the role are the same in both cases. The question whether the DPO is to be internal or external is therefore not about compliance, but about which arrangement lets the organisation genuinely provide the qualifications, the independence and the access to information. Three things decide: the workload of the role, whether the organisation has a candidate free of any conflict of interests, and the way in which the officer will come to know the organisation and remain available to it.
Why the question comes up at all
The GDPR describes the position, qualifications and tasks of the officer but says one sentence about the legal form of their activity and leaves it there. The rest of the requirements are identical for both models because the provisions on the officer’s position fall primarily on the controller and the processor. What binds the officer directly is secrecy or confidentiality under Article 38(5) GDPR and the catalogue of tasks in Article 39.
Organisations treat this choice as a comparison between the cost of a post and the cost of a contract. That comparison leads astray because the two models do not differ in the level of compliance, only in how the risks are distributed. The internal model gives knowledge of the organisation but usually requires combining the role with another one, and then the risk becomes a conflict of interests. The external model gives qualifications and continuity but the risk becomes availability and the depth of knowledge about the organisation. The choice of model transfers nothing: responsibility for compliance and for demonstrating it stays with the controller in either case.
The question usually returns at three moments — when the officer is first appointed, after the person holding the role leaves, or when the scope of work has outgrown the time that person has. The first of these is preceded by establishing whether the organisation must appoint an officer. The last one tends to be the hardest, because formally the organisation has an officer and only after analysis does it turn out that the conditions for performing the role are not there.
The proportions between the models are shown by the European Data Protection Board’s coordinated action of 2023, covering more than 17 thousand responses from organisations in the European Economic Area. In the organisations surveyed 70 % of officers were staff members and the external model remained a minority solution. Supervisory authorities pointed to a problem concerning precisely that model: officers acting for many controllers may end up spreading themselves too thinly and giving none of them adequate time.
What to establish before deciding
1. What the rules settle and what they do not
The rules settle three things and none of them depends on the model.
Qualifications. The officer is designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39 GDPR. The requirement in Article 37(5) works the same way for an employee and for a service provider.
Position. The controller and the processor provide the officer with the resources necessary to carry out the tasks, access to personal data and processing operations, and the resources necessary to maintain expert knowledge. They also ensure that the officer does not receive any instructions regarding the exercise of those tasks. The regulation settles two further things by itself: the officer is not dismissed or penalised for performing the tasks and reports directly to the highest management level. Article 38(6) is a separate rule — the officer may fulfil other tasks and duties, but the controller must ensure that these do not result in a conflict of interests. None of those obligations disappears when the officer comes from outside the organisation; only the way they are met changes.
Formalities. Publication of the officer’s contact details and notification of them to the supervisory authority follow from Article 37(7) GDPR, and national rules specify them further. Notification of the President of the Personal Data Protection Office within 14 days of designation (Article 10(1) of the Act on the Protection of Personal Data) and prompt publication of the officer’s details on the website (Article 11 of the act). The act also allows a person to be designated to deputise for the officer during their absence, taking into account the criteria in Article 37(5) and (6) GDPR — so the deputy may likewise be a person acting on the basis of a service contract. Designating a deputy requires notification of the authority under Article 10 of the act and publication of their details under Article 11.
One determination concerns only the external model and tends to be a source of error. The Personal Data Protection Office states that a contract with an officer from outside the organisation is to be a service contract and not a processing agreement — its subject matter is not the controller’s tasks but the tasks set out in Article 39(1) GDPR. The EDPB report points the same way and notes a supervisory authority’s position that treating the officer as a processor may infringe the independence requirement in Article 38(3) GDPR.
2. How much time the role actually requires
This question settles more than a comparison of costs and it tends to be skipped because it calls for work before the decision rather than after it. The officer’s workload is set by the nature of the processing, not by the size of the organisation.
The estimate rests on data the organisation usually already has:
- the number and complexity of processing operations and the number of systems they run in;
- the number of events assessed each year as possible personal data breaches;
- the number of data subject requests and how promptly they are handled;
- the pace of change — new services, migrations, organisational changes during the year;
- the number of suppliers processing data on the organisation’s behalf;
- the number of locations and the degree of autonomy of the organisational units.
The outcome of that estimate leads to one of two arrangements. If the role requires full commitment, the internal model becomes possible and is usually advantageous. If it requires part of a post, the internal candidate will combine it with another role — and then the question of a conflict of interests stops being a formality.
Comparing costs makes sense only after that estimate and both sides have to cover the same things. On the internal side the salary is joined by maintaining expert knowledge, tools and cover during absences. On the external side — the hours covered by the contract and the rules for billing work beyond that scope, because a breach or an inspection by the authority can take more time than a quarter of ordinary work.
3. Whether there is an internal candidate free of any conflict of interests
The basis is Article 38(6) GDPR. The officer may fulfil other tasks but the controller must ensure that these do not result in a conflict of interests. The guidelines on data protection officers show where that line runs — the officer cannot hold a position that leads to determining the purposes and means of processing. As giving rise to a conflict of interests they list senior management roles, including the head of IT, the head of HR and members of the board.
In a medium or large organisation this is the bottleneck of the internal model. The people who know the data and the processes best are usually the very ones who manage them. A candidate free of any conflict of interests therefore tends to be either someone without sufficient knowledge of the organisation or someone without the standing to change anything in it — both variants have to be named before the decision and not a year later.
A conflict of interests is not, however, a problem only for the internal model. The EDPB report points to a situation in which a law firm designated as officer is at the same time given tasks that clash with that role, for instance representing the client in data protection litigation. When choosing a provider, the question about other roles performed for the same organisation is therefore just as legitimate as the question about internal structure.
4. Whether the officer will know the organisation and stay available to it
Article 38(1) GDPR requires the officer to be involved properly and in a timely manner in all issues relating to the protection of personal data, and Article 38(4) gives data subjects the right to contact them. Both requirements describe availability rather than the form of the contract and it is they that mark the limit of the external model.
In April 2026 the Personal Data Protection Office took a position squarely on that limit. The rules do not state how many entities one officer may serve but the number has to stay within reasonable bounds. The assessment depends among other things on the officer’s effective availability, on their ability to obtain detailed knowledge of how the entity operates, and on an amount of time appropriate to the scope of tasks and the specific nature of the processes. The Office adds that choosing the person for the role is a decision taken in full awareness of the controller’s responsibility for compliance.
What follows is an expectation of the organisation and not of the provider. The EDPB report frames it as a recommendation: a controller using an external officer should verify how many clients that officer serves, in order to be sure they have the time and capacity to carry out the tasks. The question about the number of entities served is therefore worth asking before the contract is signed, and the answer worth recording — because it is what justifies the choice should the authority ask about it.
The guidelines also allow the officer’s tasks to be carried out by a team on the provider’s side. The condition is a clear allocation of tasks within the team and the designation of a single lead contact person. The team model can therefore be a strength of the external arrangement, provided the organisation knows who specifically answers for its matters and not merely which firm does.
5. Continuity of the role and what remains after a change
Each model has a different point of fragility.
In the internal model absence and departure are fragile. Knowledge of the organisation does stay inside it, but largely in one head, and reconstructing it after the officer leaves tends to be long and costly. The instrument provided by the act is a person deputising for the officer during their absence. It is worth designating that person in advance and not in the middle of an event that calls for a decision.
In the external model the end of the contract is fragile. Continuity while it runs is usually provided by the provider’s team, but knowledge of the organisation accumulates outside it. Before signing, it is therefore necessary to establish what stays on the controller’s side — the documentation of the officer’s work, the record of events assessed and reported, and the correspondence with the supervisory authority and with data subjects.
There is also a matter that looks different in the two models even though the provision is the same. The prohibition on dismissing or penalising the officer for performing their tasks, expressed in Article 38(3) GDPR, does not refer to the legal form in which the officer acts. As a practical assessment this means that in the external model the limit is terminating the contract because of the substance of the officer’s position and not because of the quality or timeliness of the service. The EDPB report notes in this context that supervisory authorities support strengthening the officer’s independence regardless of the form of contract under which they hold the role. A second limit follows from the same provision: the contract may set the framework of cooperation, the hours covered, availability, the manner of reporting, but it cannot dictate how the officer is to carry out the tasks under Article 39 GDPR.
Four variants and what has to be closed in each
| Variant | When it works | Main risk to close |
|---|---|---|
| Dedicated internal officer | Large-scale processing, many processes and locations, the role requires full commitment | Maintaining expert knowledge and cover during absences |
| Internal officer combining the role with another one | Limited scope of processing, a candidate exists outside the roles that determine purposes and means | Conflict of interests and the actual time available for the tasks |
| External officer on a service contract | No candidate free of conflict of interests, broad qualifications needed, the role requires part of a post | Availability, knowledge of the organisation and the number of entities served |
| Internal officer with external support | A permanent presence in the organisation is needed alongside access to specialist knowledge | Separating the roles: the officer is the designated person and not the adviser |
The fourth variant is often overlooked, yet it answers a common arrangement in medium and large organisations. There is a candidate who understands the company but lacks experience in matters that arise rarely. The condition for it to work is an unambiguous separation: the notification to the authority and the publication of details concern the designated person, while external support remains support and does not take over the tasks under Article 39(1) GDPR.
Most common mistakes
- A processing agreement instead of a service contract. The officer does not process data on the controller’s behalf, so treating them as a processor undermines their independence. It is a formal error that the authority catches without going into the substance of the officer’s work.
- Comparing the cost of a post with the price of a contract without estimating the workload. Without establishing how many hours the role actually requires, the comparison is between two different things and leads to no conclusion.
- Choosing a candidate for their knowledge of the processes. The head of IT or of HR knows the processes because they manage them, and that is precisely the reason to exclude them from the role rather than an argument for designating them.
- Not asking how many entities the external officer serves. The verification falls on the controller, not the provider, and its absence leaves the decision without the justification the authority may expect.
- A decision taken once and for all. A change in the scale of processing, an acquisition or the launch of a new service can invalidate the estimate the choice of model was based on.
Conclusions and next steps
The model of the officer is a decision about conditions, not about the level of compliance. In practice it comes down to two questions asked in the right order: how much time the role actually requires and then whether the organisation has a candidate who meets the qualification requirement and stays outside the roles that determine the purposes and means of processing. A negative answer to the second question closes the internal model faster than any cost calculation and, conversely, an organisation with intensive processing and many units will rarely meet its needs with one external officer who also serves other controllers.
The order of actions:
- Estimate the workload of the role from the number of processes, events and data subject requests and from the pace of change in the systems.
- Check whether the organisation has a candidate meeting the qualification requirement in Article 37(5) GDPR and free of any conflict of interests within the meaning of Article 38(6).
- Set the two models side by side not on cost but on the conditions that have to be provided in each: availability, knowledge of the organisation, continuity and independence.
- For the external model, conclude a service contract covering the tasks under Article 39(1) GDPR. Set out in it the hours covered and the lead contact person.
- For the external model, also ask how many entities are served and record the answer together with the reasons for the choice.
- Notify the President of UODO within 14 days and publish the officer’s details — that is an obligation in either model. Designating a deputy, by contrast, is an option worth taking.
- Describe the officer’s path of contact with the highest management level and set the point at which the decision is reviewed — the simplest is to tie it to the review of the record of processing activities.
Related materials
- How to determine if an organization must appoint a DPO? — the three grounds for the obligation and documenting the analysis, the stage that precedes the choice of model.
- What information should the board expect from the DPO? — the scope and cycle of reporting, which has to be settled regardless of the model chosen.
- What to do after detecting an incident? — the moment at which the officer’s availability is tested fastest.
Sources
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), Articles 37–39, consolidated text — EUR-Lex: eur-lex.europa.eu (accessed 19 August 2026)
- Act of 10 May 2018 on the Protection of Personal Data, Articles 8–11a, consolidated text — Chancellery of the Sejm, ISAP: isap.sejm.gov.pl (in Polish; accessed 19 August 2026)
- How many entities may one DPO serve at most?, material of 23 April 2026 — Personal Data Protection Office (UODO): uodo.gov.pl (in Polish; accessed 19 August 2026)
- Should a processing agreement be concluded with an external DPO?, material of 18 May 2021 — Personal Data Protection Office (UODO): uodo.gov.pl (in Polish; accessed 19 August 2026)
- Guidelines on Data Protection Officers (WP 243 rev. 01), Article 29 Working Party, endorsed by the European Data Protection Board — European Commission newsroom: ec.europa.eu (accessed 19 August 2026)
- 2023 Coordinated Enforcement Action. Designation and Position of Data Protection Officers, report adopted on 16 January 2024 — European Data Protection Board: edpb.europa.eu (accessed 19 August 2026)
Conditions first, model second
If the decision on the model of the officer in your organisation is still open, or the present arrangement raises doubts about time and independence, it is worth starting with an estimate of the workload of the role and a review of the conditions the organisation is able to provide. External DPO support covers assessing those conditions, putting the designation and notification records in order and supporting the current officer or taking the role over.
This material is general and educational. It is not individual legal advice or a recommendation for any specific organisation. The scope of obligations should be assessed in the light of that organisation’s circumstances.
Legal status: August 2026.