How to determine if an organization must appoint a DPO?

Michał Rutkowski • for management and executives • published August 18, 2026 • updated August 18, 2026 • 9 min read

Legal status

August 2026. The basis has not changed since 2018: Articles 37–39 of the GDPR and Articles 8–11 of the Act of May 10, 2018, on personal data protection.

Last significant update: August 18, 2026.

Brief answer

The obligation to appoint a Data Protection Officer arises in three cases specified in Article 37(1) of the GDPR: when processing is carried out by a public authority or body, when the core activity consists of regular and systematic monitoring of individuals on a large scale, or when the core activity consists of processing on a large scale of special categories of data or data relating to criminal convictions and offenses. Outside these cases, the appointment of a DPO is voluntary. None of the conditions refer to the size of the organization or the number of employees — the nature of the activity and the scale of processing are decisive, which is why the answer requires analysis, not checking a single threshold.

Why this question arises at all

The conditions in Article 37(1) of the GDPR are intentionally imprecise. The Regulation does not define ‘core activity,’ ‘large scale,’ or ‘regular and systematic monitoring’ — these concepts were only clarified by the Article 29 Working Party guidelines, subsequently approved by the European Data Protection Board. The Personal Data Protection Office, when responding to questions about specific industries, consistently refuses to provide a universal threshold and indicates that the assessment is carried out by the controller itself.

For organizations, this means an unusual situation: the provision imposes an obligation but does not provide a test that can be mechanically passed. The result depends on what the organization does and on what scale, not on how large it is.

The question usually reappears at three moments: when launching a new data-driven service, when changing the organizational structure, or when an external party — a client, insurer, auditor — asks for the inspector’s contact details and it turns out that no one can indicate on what basis the organization does not have one.

What needs to be determined before making a decision

The analysis has three steps corresponding to the three conditions, plus two control questions. Go through them in order — the first condition is decisive and does not require a scale assessment.

1. Is the organization a public authority or body?

The first condition applies regardless of the scale of processing: if processing is carried out by a public authority or body, a DPO is mandatory. The GDPR excludes only courts in the exercise of their judicial functions.

Polish law clarifies this scope. According to Article 9 of the Act of May 10, 2018, on personal data protection, public entities obliged to appoint an inspector include public finance sector units, research institutes, and the National Bank of Poland. This list resolves doubts that remain open in other member states and closes the matter for most public organizations — further scale analysis is not needed for them.

It is worth noting an intermediate situation: a municipal company or an institution performing public tasks under a contract does not always fall into this category, yet may be subject to the obligation on other grounds. In such a scenario, one proceeds to the next steps instead of stopping at the answer ‘we are not a public finance sector unit.’

2. Does the core activity consist of monitoring individuals on a large scale?

The second condition requires assessing three elements simultaneously, and all must be present concurrently.

Core activity is — according to the guidelines — key operations necessary to achieve the organization’s objectives, not ancillary activities. Processing employee data for HR and payroll purposes is an ancillary activity in almost every organization, even a large one. It is different where data processing is inextricably linked to the service: a security company monitoring facilities or a hospital maintaining medical records cannot provide its service without processing data, so it is an element of the core activity.

Regular and systematic monitoring means repetitive and organized action — carried out at defined intervals, continuous or periodic, according to an adopted data collection plan. The guidelines here include, among others, tracking online behavior, profiling, behavioral advertising, and loyalty programs.

Large scale has no numerical threshold. The guidelines recommend weighing four factors: the number of data subjects, the scope and variety of data processed, the duration of processing, and the geographical reach. Examples of large-scale processing include hospitals, telecommunications operators, geolocation systems, insurers, and internet search engines.

The outcome of this step can be ambiguous, and that is normal. It is important that the four factors are actually assessed, and the assessment documented.

3. Does the core activity consist of processing special categories of data on a large scale?

The third condition covers special categories of data — including health data, biometric data, and data concerning trade union membership — and data relating to criminal convictions and offenses, processed on a large scale as part of the core activity.

This is where the question of healthcare most often arises. When answering a question about a non-public medical entity serving approximately two thousand patients, the Personal Data Protection Office did not provide a definitive ruling but pointed to reference points from the guidelines: a hospital is an example of large-scale processing, while processing by a single doctor practicing individually is not. Between these two extremes, an organization must assess its own situation, considering the nature of its activity and the scale of documentation, and revisit this assessment when the scale changes.

4. Does the obligation not arise from another provision?

Article 37(4) of the GDPR allows for the obligation to appoint an inspector to arise from Union law or national law also in cases not covered by paragraph 1. Before concluding your analysis with a negative result, check the sectoral regulations applicable to your industry.

Distinguish between a DPO and roles introduced by other regimes. The Act on the National Cybersecurity System requires key and essential entities to appoint a person responsible for contacts in cybersecurity matters. This is a separate obligation, with a different basis and scope — its fulfillment does not replace the appointment of a data protection officer, and the appointment of an inspector does not exempt from that obligation.

5. Has the analysis been carried out separately for the role of controller and processor?

Article 37(1) of the GDPR addresses the obligation to both the controller and the processor. An organization that provides services to others — hosting, HR support, archiving, system maintenance — also assesses the conditions for processing carried out on behalf of others. It sometimes happens that the result is different for both roles: an entity may not have an obligation as a controller of its own data, but it does as a processor handling data on a large scale for clients.

Three possible outcomes of the analysis

OutcomeWhat it impliesWhat must be established
At least one condition metDPO appointment is mandatoryAppointment document, notification to the President of the Personal Data Protection Office, publication of data, ensuring conditions for performing the function
Conditions not met, organization voluntarily appoints a DPOThe same requirements apply to a voluntarily appointed inspector as to a mandatory oneSame as above — voluntariness applies to the decision, not the regime
Conditions not met, organization does not appoint a DPONo obligation, but the accountability obligation remainsDocumented analysis with date, input data, and approving person

The third variant is the one most often forgotten. The guidelines explicitly recommend that the controller and processor document the internal analysis carried out — unless the lack of obligation is obvious — precisely to be able to demonstrate that the appropriate factors have been taken into account.

What should management know?

The decision to appoint an inspector is not a technical decision of the IT or HR department. The choice of the role, its placement in the structure, and ensuring independence are management decisions, and responsibility for them remains with the controller — i.e., the organization represented by its management.

Three things management should understand before making a decision. Firstly, the determination that there is no obligation must be demonstrable — an analysis without a document is practically non-existent. Secondly, appointing a DPO does not transfer responsibility for compliance to them; the inspector monitors, advises, and acts as a contact point, while decisions remain with the controller. Thirdly, the function requires conditions: access to information, resources, absence of conflicts of interest, and direct reporting to top management — an inspector appointed without these conditions creates the appearance of compliance, not actual compliance.

Most common errors

Supervisory practice shows that more problems arise after the decision than during its making.

  • Assessment based on organization size instead of activity nature. The number of employees is not a criterion under Article 37(1) of the GDPR. A small company conducting user profiling may be subject to an obligation that a large manufacturing plant does not have.
  • Oral or implied appointment. The Personal Data Protection Office indicates that an effective appointment requires an internal act — a resolution, decision, delegation of duties — or a contract, with a defined scope of tasks. A person ‘informally dealing with GDPR’ is not an inspector.
  • Failure to notify and publish. Notification to the President of the Personal Data Protection Office must be submitted within 14 days of appointment, in electronic form, signed with a qualified electronic signature or trusted signature; the same deadline applies to changes in data and the dismissal of an inspector. The inspector’s data must be made available immediately on the website, or if there is no website, in a generally accessible manner at the place of business. The Personal Data Protection Office has conducted proceedings resulting in administrative monetary penalties precisely for the lack of effective appointment, lack of notification, and lack of data publication.
  • Conflict of interest. Entrusting the function to a person who decides on the purposes and means of processing — an IT, HR, marketing manager, or a board member — undermines the independence of the role. This is one of the elements the office directly asks about during verification.
  • Confusing DPO with roles from other regimes. The contact person appointed under the KSC Act, the information security coordinator, and the data protection officer are three different functions with different legal bases.
  • Treating the analysis as a one-off activity. A change in business profile, entry into new markets, launching a loyalty program, or acquiring another entity can change the outcome. An assessment without a date and without a review cycle ages with the organization.

Conclusions and next steps

The answer to the question of the obligation to appoint a DPO is the result of an analysis of three conditions, not a check of a single criterion. For public entities listed in the Act, the matter is settled. For other organizations, the nature of the core activity and the scale of processing, assessed according to the factors from the guidelines — number of individuals, scope of data, duration, and geographical reach — are decisive.

The sensible sequence of actions is brief. Determine whether the organization falls within the catalog of public entities under Article 9 of the Act. If not, assess both scale conditions separately for the role of controller and processor. Check sectoral regulations for Article 37(4) of the GDPR. Document the result along with input data, date, and approving person — regardless of whether the result is positive or negative. If the obligation exists or the organization decides to appoint voluntarily, immediately plan three things: the appointment document with the scope of tasks, notification within 14 days, and data publication. Finally, set a moment for re-review — the simplest way is to link it to the review of the record of processing activities.

Related materials

Sources

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), Articles 37–39, consolidated text — EUR-Lex: eur-lex.europa.eu (accessed: 2026-08-17)
  • Act of May 10, 2018, on personal data protection, Articles 8–11 — ISAP: isap.sejm.gov.pl (accessed: 2026-08-17) (in Polish)
  • Should a DPO be appointed in a non-public healthcare facility with approximately 2000 patients — Personal Data Protection Office: uodo.gov.pl (accessed: 2026-08-17) (in Polish)
  • Verification of compliance with regulations concerning the data protection officer — Personal Data Protection Office: uodo.gov.pl (accessed: 2026-08-17) (in Polish)
  • Effective DPO appointment as a necessary condition for effective data protection — Personal Data Protection Office: uodo.gov.pl (accessed: 2026-08-17) (in Polish)
  • Guidelines on Data Protection Officers (WP 243 rev. 01), Article 29 Working Party, adopted December 13, 2016, amended April 5, 2017, approved by the European Data Protection Board, Polish version — Personal Data Protection Office: uodo.gov.pl (accessed: 2026-08-17) (in Polish)

Author

Michał Rutkowski — LabLogic. Combines legal, organizational, and technological perspectives in working with management of medium and large organizations: DPO/DPO support and function, preparation for NIS2 and KSC, incident response, audits, and training. Contact: M.Rutkowski@LabLogic.pl

Settle it once and for all

If the result of the analysis in your organization is not unambiguous, or if an inspector has been appointed but it is unclear whether effectively, it is worth resolving both issues before further organizational decisions. External DPO/DPO support includes assessing the obligation, organizing appointment documentation and notifications, and taking over or supporting the inspector’s function.

This material is general and educational in nature. It does not constitute individual legal advice or recommendations for a specific organization. The scope of obligations should be assessed taking into account its specific situation.

Legal status: August 2026.

Scroll to Top