{"id":3918,"date":"2026-06-30T08:50:00","date_gmt":"2026-06-30T06:50:00","guid":{"rendered":"https:\/\/www.lablogic.pl\/how-to-determine-if-an-organization-must-appoint-a-dpo\/"},"modified":"2026-09-27T19:58:33","modified_gmt":"2026-09-27T17:58:33","slug":"how-to-determine-if-an-organization-must-appoint-a-dpo","status":"publish","type":"post","link":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/","title":{"rendered":"How to determine if an organization must appoint a DPO?"},"content":{"rendered":"\n<p class=\"ll-art-meta wp-block-paragraph\"><a href=\"https:\/\/www.lablogic.pl\/en\/michal-rutkowski\/\"><strong>Micha\u0142 Rutkowski<\/strong><\/a> \u2022 for management and executives \u2022 published June 30, 2026 \u2022 updated September 27, 2026 \u2022 9 min read<\/p>\n\n\n\n<div class=\"wp-block-columns ll-art-shell is-layout-flex wp-container-core-columns-is-layout-7387b849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column ll-art-rail is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-group ll-art-railinner is-layout-constrained wp-block-group-is-layout-constrained\">\n\n\n\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-column ll-art-main is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-group ll-art-answer is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 id=\"krotka-odpowiedz\" class=\"wp-block-heading\">Brief answer<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The obligation to appoint a Data Protection Officer arises in three cases specified in Article 37(1) of the GDPR. These are when processing is carried out by a public authority or body, when the core activity consists of processing operations which, by virtue of their nature, scope or purposes, require regular and systematic monitoring of data subjects on a large scale, or when the core activity consists of processing on a large scale of special categories of data referred to in Article 9 of the GDPR, or of personal data relating to criminal convictions and offenses referred to in Article 10 of the GDPR. Outside these cases, the appointment of a DPO is voluntary, unless the obligation arises from another provision of Union or national law. None of the conditions refer to the size of the organization or the number of employees \u2014 the nature of the activity and the scale of processing are decisive, which is why the answer requires analysis, not checking a single threshold.    <\/p>\n<\/div>\n\n\n\n<h2 id=\"dlaczego\" class=\"wp-block-heading\">Why this question arises at all<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The conditions in Article 37(1) of the GDPR are intentionally imprecise. The Regulation does not define &#8216;core activity,&#8217; &#8216;large scale,&#8217; or &#8216;regular and systematic monitoring&#8217; \u2014 these concepts were only clarified by the Article 29 Working Party guidelines, subsequently approved by the European Data Protection Board. The Personal Data Protection Office, when responding to questions about specific industries, consistently refuses to provide a universal threshold and indicates that the assessment is carried out by the controller itself.     <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For organizations, this means an unusual situation. The provision imposes an obligation but does not provide a test that can be mechanically passed. The result depends on what the organization does and on what scale, not on how large it is. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The question usually reappears at three moments. These are when launching a new data-driven service, when changing the organizational structure, or when an external party \u2014 a client, insurer, auditor \u2014 asks for the inspector&#8217;s contact details and it turns out that no one can indicate on what basis the organization does not have one.<\/p>\n\n\n\n<h2 id=\"co-ustalic\" class=\"wp-block-heading\">What needs to be determined before making a decision<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The analysis has three steps corresponding to the three conditions, plus two control questions. Go through them in order \u2014 the first condition is decisive and does not require a scale assessment. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. Is the organization a public authority or body?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The first condition applies regardless of the scale of processing. If processing is carried out by a public authority or body, a DPO is mandatory. The GDPR excludes only courts in the exercise of their judicial functions. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Polish law clarifies this scope. According to Article 9 of the Act of May 10, 2018, on personal data protection, public entities obliged to appoint an inspector include public finance sector units, research institutes, and the National Bank of Poland. This list resolves doubts that remain open in other member states and closes the matter for most public organizations \u2014 further scale analysis is not needed for them.    <\/p>\n\n\n\n<div class=\"wp-block-group ll-art-note is-layout-constrained wp-block-group-is-layout-constrained\">\n<p class=\"wp-block-paragraph\">It is worth noting an intermediate situation. A municipal company or an institution performing public tasks under a contract does not always fall into this category, yet may be subject to the obligation on other grounds. In such a scenario, one proceeds to the next steps instead of stopping at the answer &#8216;we are not a public finance sector unit.&#8217; <\/p>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">2. Does the core activity require monitoring individuals on a large scale?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The second condition does not require monitoring itself to be the core activity \u2014 it is enough that the core activity requires it by virtue of its nature, scope or purposes. Three elements must be assessed, and all of them must be present together.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Core activity<\/strong> is \u2014 according to the guidelines \u2014 key operations necessary to achieve the organization&#8217;s objectives, not ancillary activities. Processing employee data for HR and payroll purposes is an ancillary activity in almost every organization, even a large one. It is different where data processing is inextricably linked to the service. A security company monitoring facilities or a hospital maintaining medical records cannot provide its service without processing data, so it is an element of the core activity.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Regular and systematic monitoring<\/strong> means repetitive and organized action \u2014 carried out at defined intervals, continuous or periodic, according to an adopted data collection plan. The guidelines here include, among others, tracking online behavior, profiling, behavioral advertising, and loyalty programs. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Large scale<\/strong> has no numerical threshold. The guidelines recommend weighing four factors. These are the number of data subjects, the scope and variety of data processed, the duration of processing, and the geographical reach. Examples of large-scale processing include hospitals, telecommunications operators, geolocation systems, insurers, and internet search engines.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The outcome of this step can be ambiguous, and that is normal. It is important that the four factors are actually assessed, and the assessment documented. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. Does the core activity consist of processing special categories of data on a large scale?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The third condition covers special categories of data referred to in Article 9 of the GDPR \u2014 including health data, biometric data, and data concerning trade union membership \u2014 and personal data relating to criminal convictions and offenses referred to in Article 10 of the GDPR, processed on a large scale as part of the core activity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is where the question of healthcare most often arises. When answering a question about a non-public medical entity serving approximately two thousand patients, the Personal Data Protection Office did not provide a definitive ruling but pointed to reference points from the guidelines. A hospital is an example of large-scale processing, while processing by a single doctor practicing individually is not. Between these two extremes, an organization must assess its own situation, considering the nature of its activity and the scale of documentation, and revisit this assessment when the scale changes.  <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4. Does the obligation not arise from another provision?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Article 37(4) of the GDPR allows for the obligation to appoint an inspector to arise from Union law or national law also in cases not covered by paragraph 1. Before concluding your analysis with a negative result, check the sectoral regulations applicable to your industry.   <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Distinguish between a DPO and roles introduced by other regimes. The Act on the National Cybersecurity System requires essential and important entities to appoint at least two persons responsible for maintaining contacts with entities of the national cybersecurity system; one person is sufficient only for a micro or small enterprise and for an important entity that is a public entity. This is a separate obligation, with a different basis and scope \u2014 its fulfillment does not replace the appointment of a data protection officer, and the appointment of an inspector does not exempt from that obligation.  <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5. Has the analysis been carried out separately for the role of controller and processor?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Article 37(1) of the GDPR addresses the obligation to both the controller and the processor. An organization that provides services to others \u2014 hosting, HR support, archiving, system maintenance \u2014 also assesses the conditions for processing carried out on behalf of others. It sometimes happens that the result is different for both roles. An entity may not have an obligation as a controller of its own data, but it does as a processor handling data on a large scale for clients. The number of inspectors is a separate organizational decision. A group of undertakings may appoint a single data protection officer provided that they are easily accessible from each establishment (Article 37(2)), and several public authorities or bodies may appoint a joint officer, taking account of their organizational structure and size (Article 37(3)).    <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Three possible outcomes of the analysis<\/h3>\n\n\n\n<figure class=\"wp-block-table ll-art-table\"><table><thead><tr><th>Outcome<\/th><th>What it implies<\/th><th>What must be established<\/th><\/tr><\/thead><tbody><tr><td>At least one condition met<\/td><td>DPO appointment is mandatory<\/td><td>Appointment document, notification to the President of the Personal Data Protection Office, publication of data, ensuring conditions for performing the function<\/td><\/tr><tr><td>Conditions not met, organization voluntarily appoints a DPO<\/td><td>The WP 243 guidelines state that the same requirements apply to a voluntarily appointed inspector as to a mandatory one<\/td><td>Same as above \u2014 voluntariness applies to the decision, not the regime<\/td><\/tr><tr><td>Conditions not met, organization does not appoint a DPO<\/td><td>No obligation, but the accountability obligation remains<\/td><td>Documented analysis with date, input data, and approving person<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The third variant is the one most often forgotten. The guidelines explicitly recommend that the controller and processor document the internal analysis carried out \u2014 unless the lack of obligation is obvious \u2014 precisely to be able to demonstrate that the appropriate factors have been taken into account. <\/p>\n\n\n\n<div class=\"wp-block-group ll-art-board is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 id=\"zarzad\" class=\"wp-block-heading\">What should management know?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The decision to appoint an inspector is not a technical decision of the IT or HR department. The choice of the role, its placement in the structure, and ensuring independence are management decisions, and responsibility for them remains with the controller \u2014 i.e., the organization represented by its management. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Three things management should understand before making a decision.<\/p>\n\n\n\n<div class=\"wp-block-group ll-art-zdanie is-layout-constrained wp-block-group-is-layout-constrained\">\n\n<p class=\"wp-block-paragraph\">Remember<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The determination that there is no obligation must be demonstrable \u2014 an analysis without a document is practically non-existent.<\/p>\n\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Secondly, appointing a DPO does not transfer responsibility for compliance to them; the inspector monitors, advises, and acts as a contact point, while decisions remain with the controller. Thirdly, the function requires conditions. These are access to information, resources, absence of conflicts of interest, and direct reporting to top management \u2014 an inspector appointed without these conditions creates the appearance of compliance, not actual compliance. The Act also allows a person to be designated to stand in for the inspector during their absence, taking account of the criteria in Article 37(5) and (6) of the GDPR; the provisions on the inspector apply accordingly to the deputy, and their designation is subject to notification and publication on the same terms (Article 11a of the Act of May 10, 2018).   <\/p>\n<\/div>\n\n\n\n<h2 id=\"bledy\" class=\"wp-block-heading\">Most common errors<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Supervisory practice shows that more problems arise after the decision than during its making.<\/p>\n\n\n\n<ul class=\"wp-block-list ll-art-errors\">\n<li><strong>Assessment based on organization size instead of activity nature.<\/strong> The number of employees is not a criterion under Article 37(1) of the GDPR. A small company conducting user profiling may be subject to an obligation that a large manufacturing plant does not have.   <\/li>\n\n\n\n<li><strong>Oral or implied appointment.<\/strong> The Personal Data Protection Office indicates that an effective appointment requires an internal act \u2014 a resolution, decision, delegation of duties \u2014 or a contract, with a defined scope of tasks. A person &#8216;informally dealing with GDPR&#8217; is not an inspector. Form alone is not enough. An inspector is designated on the basis of professional qualities, in particular expert knowledge of data protection law and practices and the ability to fulfill the tasks referred to in Article 39 of the GDPR (Article 37(5)). <\/li>\n\n\n\n<li><strong>Failure to notify and publish.<\/strong> The obligation to publish the inspector&#8217;s contact details and to communicate them to the supervisory authority arises from Article 37(7) of the GDPR; the Act of May 10, 2018 adds the deadline, the form, and the manner. Notification to the President of the Personal Data Protection Office must be submitted within 14 days of appointment, in electronic form, signed with a qualified electronic signature or a signature confirmed with the ePUAP trusted profile (Article 10(6) of the Act); the same deadline applies to changes in data and the dismissal of an inspector, and where one inspector is appointed for several public entities or for a group of undertakings, each of those entities files its own notification. The inspector&#8217;s data must be made available immediately on the website, or if there is no website, in a generally accessible manner at the place of business. The Personal Data Protection Office has conducted proceedings resulting in administrative monetary penalties precisely for the lack of effective appointment, lack of notification, and lack of data publication.  <\/li>\n\n\n\n<li><strong>Conflict of interest.<\/strong> Entrusting the function to a person who decides on the purposes and means of processing \u2014 an IT, HR, marketing manager, or a board member \u2014 undermines the independence of the role. This is one of the elements the office directly asks about during verification. <\/li>\n\n\n\n<li><strong>Confusing DPO with roles from other regimes.<\/strong> The contact persons appointed under the KSC Act, the information security coordinator, and the data protection officer are three different functions with different legal bases.<\/li>\n\n\n\n<li><strong>Treating the analysis as a one-off activity.<\/strong> A change in business profile, entry into new markets, launching a loyalty program, or acquiring another entity can change the outcome. An assessment without a date and without a review cycle ages with the organization. <\/li>\n<\/ul>\n\n\n\n<h2 id=\"wnioski\" class=\"wp-block-heading\">Conclusions and next steps<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The answer to the question of the obligation to appoint a DPO is the result of an analysis of three conditions, not a check of a single criterion. For public entities listed in the Act, the matter is settled. For other organizations, the nature of the core activity and the scale of processing, assessed according to the factors from the guidelines \u2014 number of individuals, scope of data, duration, and geographical reach \u2014 are decisive.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The sensible sequence of actions is brief. Determine whether the organization falls within the catalog of public entities under Article 9 of the Act. If not, assess both scale conditions separately for the role of controller and processor. Check sectoral regulations for Article 37(4) of the GDPR. Document the result along with input data, date, and approving person \u2014 regardless of whether the result is positive or negative. If the obligation exists or the organization decides to appoint voluntarily, immediately plan three things. These are the appointment document with the scope of tasks, notification within 14 days, and data publication. The inspector may be a member of the controller&#8217;s staff or perform tasks under a service contract (Article 37(6)) \u2014 the choice of model is an organizational decision, not a condition for the effectiveness of the appointment. Finally, set a moment for re-review \u2014 the simplest way is to link it to the review of the record of processing activities.         <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Related materials<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/\">Does every data breach need to be reported?<\/a><\/strong>  \u2014 the decision to report a breach and the role of the data protection officer in it.<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/how-often-should-employees-be-trained-on-personal-data-protection\/\">How often should employees be trained on personal data protection?<\/a><\/strong>  \u2014 who in the organization is responsible for awareness-raising activities and staff training.<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/who-cannot-act-as-a-data-protection-officer\/\">Who cannot act as a data protection officer?<\/a><\/strong>  \u2014 the next question, namely whom the organisation may appoint once the duty is settled.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Sources<\/h2>\n\n\n\n<ul class=\"wp-block-list ll-art-sources\">\n<li>Regulation (EU) 2016\/679 of the European Parliament and of the Council (GDPR), Articles 37\u201339, consolidated text \u2014 EUR-Lex: <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX%3A02016R0679-20160504\" target=\"_blank\" rel=\"noreferrer noopener\">eur-lex.europa.eu<\/a> <\/li>\n\n\n\n<li>Act of May 10, 2018, on personal data protection, Articles 8\u201311a \u2014 ISAP: <a href=\"https:\/\/isap.sejm.gov.pl\/isap.nsf\/DocDetails.xsp?id=WDU20180001000\" target=\"_blank\" rel=\"noreferrer noopener\">isap.sejm.gov.pl<\/a> (in Polish)<\/li>\n\n\n\n<li>Should a DPO be appointed in a non-public healthcare facility with approximately 2000 patients \u2014 Personal Data Protection Office: <a href=\"https:\/\/uodo.gov.pl\/pl\/499\/4146\" target=\"_blank\" rel=\"noreferrer noopener\">uodo.gov.pl<\/a> (in Polish)<\/li>\n\n\n\n<li>Verification of compliance with regulations concerning the data protection officer \u2014 Personal Data Protection Office: <a href=\"https:\/\/uodo.gov.pl\/pl\/138\/2438\" target=\"_blank\" rel=\"noreferrer noopener\">uodo.gov.pl<\/a> (in Polish)<\/li>\n\n\n\n<li>Effective DPO appointment as a necessary condition for effective data protection \u2014 Personal Data Protection Office: <a href=\"https:\/\/uodo.gov.pl\/pl\/138\/3421\" target=\"_blank\" rel=\"noreferrer noopener\">uodo.gov.pl<\/a> (in Polish)<\/li>\n\n\n\n<li>Guidelines on Data Protection Officers (WP 243 rev. 01), Article 29 Working Party, adopted December 13, 2016, amended April 5, 2017, approved by the European Data Protection Board, Polish version \u2014 Personal Data Protection Office: <a href=\"https:\/\/uodo.gov.pl\/data\/filemanager_pl\/15.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">uodo.gov.pl<\/a> (in Polish)<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-group ll-art-cta is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading ll-nietoc\">Settle it once and for all<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If the result of the analysis in your organization is not unambiguous, or if an inspector has been appointed but it is unclear whether effectively, it is worth resolving both issues before further organizational decisions. External DPO\/DPO support includes assessing the obligation, organizing appointment documentation and notifications, and taking over or supporting the inspector&#8217;s function. <\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/www.lablogic.pl\/en\/external-dpo\/\">External DPO\/DPO support<\/a><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The obligation to appoint a Data Protection Officer arises in three cases under Article 37(1) of the GDPR. None of the conditions refer to the size of the organization \u2014 the nature of the activity and the scale of processing are decisive.   <\/p>\n","protected":false},"author":2,"featured_media":5574,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ll_stan_prawny":"August 2026","footnotes":""},"categories":[70],"tags":[78],"class_list":["post-3918","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-dpo","tag-for-management"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Three conditions under Article 37 GDPR, the Polish list of public bodies and the large-scale criteria. How to run and document the DPO assessment.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Micha\u0142 Rutkowski\"\/>\n\t<meta name=\"keywords\" content=\"for-management\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"LabLogic - Micha\u0142 Rutkowski | DPO, GDPR, NIS2 and cybersecurity in practice\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Do you have to appoint a DPO?\" \/>\n\t\t<meta property=\"og:description\" content=\"Three conditions under Article 37, and how to document the assessment.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-determine-if-an-organization-needs-a-dpo-en.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-determine-if-an-organization-needs-a-dpo-en.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t\t<meta property=\"article:section\" content=\"DPO and GDPR\" \/>\n\t\t<meta property=\"article:tag\" content=\"gdpr\" \/>\n\t\t<meta property=\"article:tag\" content=\"dpo\" \/>\n\t\t<meta property=\"article:tag\" content=\"article 37\" \/>\n\t\t<meta property=\"article:tag\" content=\"compliance\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-06-30T06:50:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-09-27T17:58:33+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Do you have to appoint a DPO?\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Three conditions under Article 37, and how to document the assessment.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-determine-if-an-organization-needs-a-dpo-en.jpg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/#article\",\"name\":\"How to determine if an organization must appoint a DPO\",\"headline\":\"How to determine if an organization must appoint a DPO?\",\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ll-og-how-to-determine-if-an-organization-needs-a-dpo-en.jpg\",\"width\":1200,\"height\":630,\"caption\":\"Must your organization appoint a DPO? \\u2014 LabLogic article graphic by Micha\\u0142 Rutkowski\"},\"datePublished\":\"2026-06-30T08:50:00+02:00\",\"dateModified\":\"2026-09-27T19:58:33+02:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/#webpage\"},\"articleSection\":\"DPO and GDPR\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"position\":1,\"name\":\"LabLogic\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/dpo\\\/#listItem\",\"name\":\"DPO and GDPR\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/dpo\\\/#listItem\",\"position\":2,\"name\":\"DPO and GDPR\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/dpo\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/#listItem\",\"name\":\"How to determine if an organization must appoint a DPO?\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"name\":\"LabLogic\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/#listItem\",\"position\":3,\"name\":\"How to determine if an organization must appoint a DPO?\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/dpo\\\/#listItem\",\"name\":\"DPO and GDPR\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#organization\",\"name\":\"LabLogic\",\"description\":\"DPO, GDPR, NIS2 and cybersecurity in practice\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"email\":\"m.rutkowski@lablogic.pl\",\"telephone\":\"+48586231777\",\"foundingDate\":\"2004\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/cropped-lablogic-site-icon-512.png\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/#organizationLogo\",\"width\":512,\"height\":512},\"image\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/michal-rutkowski-iod\"],\"additionalType\":\"https:\\\/\\\/schema.org\\\/ProfessionalService\",\"legalName\":\"LabLogic Consulting Micha\\u0142 Rutkowski\",\"address\":{\"@type\":\"PostalAddress\",\"streetAddress\":\"ul. Wolno\\u015bci 15\",\"postalCode\":\"81-327\",\"addressLocality\":\"Gdynia\",\"addressRegion\":\"pomorskie\",\"addressCountry\":\"PL\"},\"vatID\":\"PL9580972114\",\"taxID\":\"9580972114\",\"areaServed\":{\"@type\":\"Country\",\"name\":\"Poland\"},\"knowsAbout\":[\"GDPR\",\"Data Protection Officer (DPO)\",\"NIS2 Directive\",\"Polish National Cybersecurity System Act (KSC)\",\"Cybersecurity incident and data breach response\",\"EU AI Act\",\"ISO\\\/IEC 27001\",\"Information security management\"],\"founder\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\"},\"hasOfferCatalog\":{\"@type\":\"OfferCatalog\",\"name\":\"Services\",\"itemListElement\":[{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"External Data Protection Officer (DPO)\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/external-dpo\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"NIS2 and KSC implementation support\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/nis2-ksc\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"Incident and data breach response\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/incident-response\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"GDPR and NIS2 training\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/training\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"AI Act: roles, obligations and preparation\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/ai-act\\\/\"}}]}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/michal-rutkowski\\\/\",\"name\":\"Micha\\u0142 Rutkowski\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski-portret\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/michal-rutkowski-iod-dpo-rodo-nis2-lablogic.webp\",\"width\":864,\"height\":1080,\"caption\":\"Micha\\u0142 Rutkowski\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/michal-rutkowski-iod\"],\"jobTitle\":\"Data Protection Officer (DPO), NIS2\\\/KSC and cybersecurity advisor\",\"description\":\"Data protection and cybersecurity practitioner, owner of LabLogic. Since 2004 he has supported medium and large organisations: audits, implementations, incidents and training.\",\"email\":\"m.rutkowski@lablogic.pl\",\"knowsAbout\":[\"GDPR\",\"Data Protection Officer (DPO)\",\"NIS2 Directive\",\"Polish National Cybersecurity System Act (KSC)\",\"Cybersecurity incident and data breach response\",\"EU AI Act\",\"ISO\\\/IEC 27001\",\"Information security management\"],\"worksFor\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/#webpage\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/\",\"name\":\"How to determine if an organization must appoint a DPO\",\"description\":\"Three conditions under Article 37 GDPR, the Polish list of public bodies and the large-scale criteria. How to run and document the DPO assessment.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ll-og-how-to-determine-if-an-organization-needs-a-dpo-en.jpg\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/#mainImage\",\"width\":1200,\"height\":630,\"caption\":\"Must your organization appoint a DPO? \\u2014 LabLogic article graphic by Micha\\u0142 Rutkowski\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/#mainImage\"},\"datePublished\":\"2026-06-30T08:50:00+02:00\",\"dateModified\":\"2026-09-27T19:58:33+02:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"name\":\"Micha\\u0142 Rutkowski - LabLogic\",\"alternateName\":\"LabLogic\",\"description\":\"DPO, GDPR, NIS2 and cybersecurity in practice\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"How to determine if an organization must appoint a DPO","description":"Three conditions under Article 37 GDPR, the Polish list of public bodies and the large-scale criteria. How to run and document the DPO assessment.","canonical_url":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/","robots":"max-image-preview:large","keywords":"for-management","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/#article","name":"How to determine if an organization must appoint a DPO","headline":"How to determine if an organization must appoint a DPO?","author":{"@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski"},"publisher":{"@id":"https:\/\/www.lablogic.pl\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-determine-if-an-organization-needs-a-dpo-en.jpg","width":1200,"height":630,"caption":"Must your organization appoint a DPO? \u2014 LabLogic article graphic by Micha\u0142 Rutkowski"},"datePublished":"2026-06-30T08:50:00+02:00","dateModified":"2026-09-27T19:58:33+02:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/#webpage"},"isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/#webpage"},"articleSection":"DPO and GDPR"},{"@type":"BreadcrumbList","@id":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","position":1,"name":"LabLogic","item":"https:\/\/www.lablogic.pl\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/dpo\/#listItem","name":"DPO and GDPR"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/dpo\/#listItem","position":2,"name":"DPO and GDPR","item":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/dpo\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/#listItem","name":"How to determine if an organization must appoint a DPO?"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","name":"LabLogic"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/#listItem","position":3,"name":"How to determine if an organization must appoint a DPO?","previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/dpo\/#listItem","name":"DPO and GDPR"}}]},{"@type":"Organization","@id":"https:\/\/www.lablogic.pl\/#organization","name":"LabLogic","description":"DPO, GDPR, NIS2 and cybersecurity in practice","url":"https:\/\/www.lablogic.pl\/en\/","email":"m.rutkowski@lablogic.pl","telephone":"+48586231777","foundingDate":"2004","logo":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/cropped-lablogic-site-icon-512.png","@id":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/#organizationLogo","width":512,"height":512},"image":{"@id":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/#organizationLogo"},"sameAs":["https:\/\/www.linkedin.com\/in\/michal-rutkowski-iod"],"additionalType":"https:\/\/schema.org\/ProfessionalService","legalName":"LabLogic Consulting Micha\u0142 Rutkowski","address":{"@type":"PostalAddress","streetAddress":"ul. Wolno\u015bci 15","postalCode":"81-327","addressLocality":"Gdynia","addressRegion":"pomorskie","addressCountry":"PL"},"vatID":"PL9580972114","taxID":"9580972114","areaServed":{"@type":"Country","name":"Poland"},"knowsAbout":["GDPR","Data Protection Officer (DPO)","NIS2 Directive","Polish National Cybersecurity System Act (KSC)","Cybersecurity incident and data breach response","EU AI Act","ISO\/IEC 27001","Information security management"],"founder":{"@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski"},"hasOfferCatalog":{"@type":"OfferCatalog","name":"Services","itemListElement":[{"@type":"Offer","itemOffered":{"@type":"Service","name":"External Data Protection Officer (DPO)","url":"https:\/\/www.lablogic.pl\/en\/external-dpo\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"NIS2 and KSC implementation support","url":"https:\/\/www.lablogic.pl\/en\/nis2-ksc\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"Incident and data breach response","url":"https:\/\/www.lablogic.pl\/en\/incident-response\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"GDPR and NIS2 training","url":"https:\/\/www.lablogic.pl\/en\/training\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"AI Act: roles, obligations and preparation","url":"https:\/\/www.lablogic.pl\/en\/ai-act\/"}}]}},{"@type":"Person","@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski","url":"https:\/\/www.lablogic.pl\/michal-rutkowski\/","name":"Micha\u0142 Rutkowski","image":{"@type":"ImageObject","@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski-portret","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/michal-rutkowski-iod-dpo-rodo-nis2-lablogic.webp","width":864,"height":1080,"caption":"Micha\u0142 Rutkowski"},"sameAs":["https:\/\/www.linkedin.com\/in\/michal-rutkowski-iod"],"jobTitle":"Data Protection Officer (DPO), NIS2\/KSC and cybersecurity advisor","description":"Data protection and cybersecurity practitioner, owner of LabLogic. Since 2004 he has supported medium and large organisations: audits, implementations, incidents and training.","email":"m.rutkowski@lablogic.pl","knowsAbout":["GDPR","Data Protection Officer (DPO)","NIS2 Directive","Polish National Cybersecurity System Act (KSC)","Cybersecurity incident and data breach response","EU AI Act","ISO\/IEC 27001","Information security management"],"worksFor":{"@id":"https:\/\/www.lablogic.pl\/#organization"}},{"@type":"WebPage","@id":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/#webpage","url":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/","name":"How to determine if an organization must appoint a DPO","description":"Three conditions under Article 37 GDPR, the Polish list of public bodies and the large-scale criteria. How to run and document the DPO assessment.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/#website"},"breadcrumb":{"@id":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/#breadcrumblist"},"author":{"@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski"},"creator":{"@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski"},"image":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-determine-if-an-organization-needs-a-dpo-en.jpg","@id":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/#mainImage","width":1200,"height":630,"caption":"Must your organization appoint a DPO? \u2014 LabLogic article graphic by Micha\u0142 Rutkowski"},"primaryImageOfPage":{"@id":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/#mainImage"},"datePublished":"2026-06-30T08:50:00+02:00","dateModified":"2026-09-27T19:58:33+02:00"},{"@type":"WebSite","@id":"https:\/\/www.lablogic.pl\/en\/#website","url":"https:\/\/www.lablogic.pl\/en\/","name":"Micha\u0142 Rutkowski - LabLogic","alternateName":"LabLogic","description":"DPO, GDPR, NIS2 and cybersecurity in practice","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.lablogic.pl\/#organization"}}]},"og:locale":"en_US","og:site_name":"LabLogic - Micha\u0142 Rutkowski | DPO, GDPR, NIS2 and cybersecurity in practice","og:type":"article","og:title":"Do you have to appoint a DPO?","og:description":"Three conditions under Article 37, and how to document the assessment.","og:url":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/","og:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-determine-if-an-organization-needs-a-dpo-en.jpg","og:image:secure_url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-determine-if-an-organization-needs-a-dpo-en.jpg","og:image:width":1200,"og:image:height":630,"article:section":"DPO and GDPR","article:tag":["gdpr","dpo","article 37","compliance"],"article:published_time":"2026-06-30T06:50:00+00:00","article:modified_time":"2026-09-27T17:58:33+00:00","twitter:card":"summary_large_image","twitter:title":"Do you have to appoint a DPO?","twitter:description":"Three conditions under Article 37, and how to document the assessment.","twitter:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-determine-if-an-organization-needs-a-dpo-en.jpg"},"aioseo_meta_data":{"post_id":"3918","title":"How to determine if an organization must appoint a DPO","description":"Three conditions under Article 37 GDPR, the Polish list of public bodies and the large-scale criteria. How to run and document the DPO assessment.","keywords":null,"keyphrases":{"focus":{"keyphrase":"obligation to appoint a DPO","score":0},"additional":[{"keyphrase":"when is a DPO required","score":0},{"keyphrase":"Article 37 GDPR conditions","score":0},{"keyphrase":"large scale processing criteria","score":0},{"keyphrase":"data protection officer requirement","score":0}]},"primary_term":null,"canonical_url":null,"og_title":"Do you have to appoint a DPO?","og_description":"Three conditions under Article 37, and how to document the assessment.","og_object_type":"article","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"DPO and GDPR","og_article_tags":[{"label":"GDPR","value":"GDPR"},{"label":"DPO","value":"DPO"},{"label":"Article 37","value":"Article 37"},{"label":"compliance","value":"compliance"}],"twitter_use_og":true,"twitter_card":"summary_large_image","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":0,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-08-18 09:55:53","updated":"2026-09-27 17:59:38","seo_analyzer_scan_date":null,"focus_keyword":"obligation to appoint a DPO","additional_keywords":[{"word":"when is a DPO required","score":0},{"word":"Article 37 GDPR conditions","score":0},{"word":"large scale processing criteria","score":0},{"word":"data protection officer requirement","score":0}],"truseo_locale":null},"spectra_blocks_featured_image_url":{"thumbnail":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-determine-if-an-organization-needs-a-dpo-en-150x150.jpg","width":150,"height":150},"medium":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-determine-if-an-organization-needs-a-dpo-en-300x158.jpg","width":300,"height":158},"medium_large":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-determine-if-an-organization-needs-a-dpo-en-768x403.jpg","width":768,"height":403},"large":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-determine-if-an-organization-needs-a-dpo-en-1024x538.jpg","width":1024,"height":538},"full":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-how-to-determine-if-an-organization-needs-a-dpo-en.jpg","width":1200,"height":630}},"spectra_blocks_author_info":{"display_name":"Micha\u0142 Rutkowski","avatar_url":"https:\/\/secure.gravatar.com\/avatar\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g","author_link":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/","description":"Micha\u0142 Rutkowski \u2014 praktyk ochrony danych i cyberbezpiecze\u0144stwa, w\u0142a\u015bciciel LabLogic. Od 2004 roku pracuje na styku technologii, ochrony danych i zarz\u0105dzania ryzykiem. Pe\u0142ni funkcj\u0119 zewn\u0119trznego IOD\/DPO, prowadzi audyty RODO, kwalifikacj\u0119 i wdro\u017cenia NIS2 oraz ustawy o KSC, wspiera organizacje przy incydentach i naruszeniach ochrony danych, szkoli zarz\u0105dy, kadr\u0119 kierownicz\u0105 oraz zespo\u0142y IT i compliance. Pracuje ze \u015brednimi i du\u017cymi organizacjami, w tym z sektora finansowego i bran\u017c regulowanych."},"_links":{"self":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/3918","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/comments?post=3918"}],"version-history":[{"count":5,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/3918\/revisions"}],"predecessor-version":[{"id":5674,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/3918\/revisions\/5674"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/media\/5574"}],"wp:attachment":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/media?parent=3918"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/categories?post=3918"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/tags?post=3918"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}