{"id":3918,"date":"2026-08-18T11:46:34","date_gmt":"2026-08-18T09:46:34","guid":{"rendered":"https:\/\/www.lablogic.pl\/how-to-determine-if-an-organization-must-appoint-a-dpo\/"},"modified":"2026-08-18T12:30:20","modified_gmt":"2026-08-18T10:30:20","slug":"how-to-determine-if-an-organization-must-appoint-a-dpo","status":"publish","type":"post","link":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/","title":{"rendered":"How to determine if an organization must appoint a DPO?"},"content":{"rendered":"\n<p class=\"ll-art-meta wp-block-paragraph\"><strong>Micha\u0142 Rutkowski<\/strong> \u2022 for management and executives \u2022 published August 18, 2026 \u2022 updated August 18, 2026 \u2022 9 min read<\/p>\n\n<div class=\"wp-block-columns ll-art-shell is-layout-flex wp-container-core-columns-is-layout-7387b849 wp-block-columns-is-layout-flex\">\n\n<div class=\"wp-block-column ll-art-rail is-layout-flow wp-block-column-is-layout-flow\">\n\n<div class=\"wp-block-group ll-art-railinner is-layout-constrained wp-block-group-is-layout-constrained\">\n\n<div class=\"wp-block-group ll-art-railcard is-layout-constrained wp-block-group-is-layout-constrained\">\n\n<p class=\"wp-block-paragraph\">On this page<\/p>\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"#krotka-odpowiedz\">Brief answer<\/a><\/li>\n<li><a href=\"#dlaczego\">Why this question arises at all<\/a><\/li>\n<li><a href=\"#co-ustalic\">What needs to be determined before making a decision<\/a><\/li>\n<li><a href=\"#zarzad\">What should management know?<\/a><\/li>\n<li><a href=\"#bledy\">Most common errors<\/a><\/li>\n<li><a href=\"#wnioski\">Conclusions and next steps<\/a><\/li>\n<\/ul>\n\n<\/div>\n\n\n\n<div class=\"wp-block-group ll-art-railcard ll-art-railmeta is-layout-constrained wp-block-group-is-layout-constrained\">\n\n<p class=\"wp-block-paragraph\">Legal status<\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>August 2026.<\/strong> The basis has not changed since 2018: Articles 37\u201339 of the GDPR and Articles 8\u201311 of the Act of May 10, 2018, on personal data protection.<\/p>\n\n\n<p class=\"wp-block-paragraph\">Last significant update: August 18, 2026.<\/p>\n\n<\/div>\n\n<\/div>\n\n<\/div>\n\n\n\n<div class=\"wp-block-column ll-art-main is-layout-flow wp-block-column-is-layout-flow\">\n\n<div class=\"wp-block-group ll-art-answer is-layout-constrained wp-block-group-is-layout-constrained\">\n\n<h2 class=\"wp-block-heading\" id=\"krotka-odpowiedz\">Brief answer<\/h2>\n\n\n<p class=\"wp-block-paragraph\">The obligation to appoint a Data Protection Officer arises in three cases specified in Article 37(1) of the GDPR: when processing is carried out by a public authority or body, when the core activity consists of regular and systematic monitoring of individuals on a large scale, or when the core activity consists of processing on a large scale of special categories of data or data relating to criminal convictions and offenses. Outside these cases, the appointment of a DPO is voluntary. None of the conditions refer to the size of the organization or the number of employees \u2014 the nature of the activity and the scale of processing are decisive, which is why the answer requires analysis, not checking a single threshold.    <\/p>\n\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"dlaczego\">Why this question arises at all<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The conditions in Article 37(1) of the GDPR are intentionally imprecise. The Regulation does not define &#8216;core activity,&#8217; &#8216;large scale,&#8217; or &#8216;regular and systematic monitoring&#8217; \u2014 these concepts were only clarified by the Article 29 Working Party guidelines, subsequently approved by the European Data Protection Board. The Personal Data Protection Office, when responding to questions about specific industries, consistently refuses to provide a universal threshold and indicates that the assessment is carried out by the controller itself.     <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For organizations, this means an unusual situation: the provision imposes an obligation but does not provide a test that can be mechanically passed. The result depends on what the organization does and on what scale, not on how large it is. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The question usually reappears at three moments: when launching a new data-driven service, when changing the organizational structure, or when an external party \u2014 a client, insurer, auditor \u2014 asks for the inspector&#8217;s contact details and it turns out that no one can indicate on what basis the organization does not have one.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"co-ustalic\">What needs to be determined before making a decision<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The analysis has three steps corresponding to the three conditions, plus two control questions. Go through them in order \u2014 the first condition is decisive and does not require a scale assessment. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. Is the organization a public authority or body?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The first condition applies regardless of the scale of processing: if processing is carried out by a public authority or body, a DPO is mandatory. The GDPR excludes only courts in the exercise of their judicial functions. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Polish law clarifies this scope. According to Article 9 of the Act of May 10, 2018, on personal data protection, public entities obliged to appoint an inspector include public finance sector units, research institutes, and the National Bank of Poland. This list resolves doubts that remain open in other member states and closes the matter for most public organizations \u2014 further scale analysis is not needed for them.    <\/p>\n\n\n\n<div class=\"wp-block-group ll-art-note is-layout-constrained wp-block-group-is-layout-constrained\">\n\n<p class=\"wp-block-paragraph\">It is worth noting an intermediate situation: a municipal company or an institution performing public tasks under a contract does not always fall into this category, yet may be subject to the obligation on other grounds. In such a scenario, one proceeds to the next steps instead of stopping at the answer &#8216;we are not a public finance sector unit.&#8217; <\/p>\n\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">2. Does the core activity consist of monitoring individuals on a large scale?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The second condition requires assessing three elements simultaneously, and all must be present concurrently.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Core activity<\/strong> is \u2014 according to the guidelines \u2014 key operations necessary to achieve the organization&#8217;s objectives, not ancillary activities. Processing employee data for HR and payroll purposes is an ancillary activity in almost every organization, even a large one. It is different where data processing is inextricably linked to the service: a security company monitoring facilities or a hospital maintaining medical records cannot provide its service without processing data, so it is an element of the core activity.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Regular and systematic monitoring<\/strong> means repetitive and organized action \u2014 carried out at defined intervals, continuous or periodic, according to an adopted data collection plan. The guidelines here include, among others, tracking online behavior, profiling, behavioral advertising, and loyalty programs. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Large scale<\/strong> has no numerical threshold. The guidelines recommend weighing four factors: the number of data subjects, the scope and variety of data processed, the duration of processing, and the geographical reach. Examples of large-scale processing include hospitals, telecommunications operators, geolocation systems, insurers, and internet search engines.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The outcome of this step can be ambiguous, and that is normal. It is important that the four factors are actually assessed, and the assessment documented. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. Does the core activity consist of processing special categories of data on a large scale?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The third condition covers special categories of data \u2014 including health data, biometric data, and data concerning trade union membership \u2014 and data relating to criminal convictions and offenses, processed on a large scale as part of the core activity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is where the question of healthcare most often arises. When answering a question about a non-public medical entity serving approximately two thousand patients, the Personal Data Protection Office did not provide a definitive ruling but pointed to reference points from the guidelines: a hospital is an example of large-scale processing, while processing by a single doctor practicing individually is not. Between these two extremes, an organization must assess its own situation, considering the nature of its activity and the scale of documentation, and revisit this assessment when the scale changes.  <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4. Does the obligation not arise from another provision?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Article 37(4) of the GDPR allows for the obligation to appoint an inspector to arise from Union law or national law also in cases not covered by paragraph 1. Before concluding your analysis with a negative result, check the sectoral regulations applicable to your industry.   <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Distinguish between a DPO and roles introduced by other regimes. The Act on the National Cybersecurity System requires key and essential entities to appoint a person responsible for contacts in cybersecurity matters. This is a separate obligation, with a different basis and scope \u2014 its fulfillment does not replace the appointment of a data protection officer, and the appointment of an inspector does not exempt from that obligation.  <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5. Has the analysis been carried out separately for the role of controller and processor?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Article 37(1) of the GDPR addresses the obligation to both the controller and the processor. An organization that provides services to others \u2014 hosting, HR support, archiving, system maintenance \u2014 also assesses the conditions for processing carried out on behalf of others. It sometimes happens that the result is different for both roles: an entity may not have an obligation as a controller of its own data, but it does as a processor handling data on a large scale for clients.    <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Three possible outcomes of the analysis<\/h3>\n\n\n\n<figure class=\"wp-block-table ll-art-table\"><table><thead><tr><th>Outcome<\/th><th>What it implies<\/th><th>What must be established<\/th><\/tr><\/thead><tbody><tr><td>At least one condition met<\/td><td>DPO appointment is mandatory<\/td><td>Appointment document, notification to the President of the Personal Data Protection Office, publication of data, ensuring conditions for performing the function<\/td><\/tr><tr><td>Conditions not met, organization voluntarily appoints a DPO<\/td><td>The same requirements apply to a voluntarily appointed inspector as to a mandatory one<\/td><td>Same as above \u2014 voluntariness applies to the decision, not the regime<\/td><\/tr><tr><td>Conditions not met, organization does not appoint a DPO<\/td><td>No obligation, but the accountability obligation remains<\/td><td>Documented analysis with date, input data, and approving person<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The third variant is the one most often forgotten. The guidelines explicitly recommend that the controller and processor document the internal analysis carried out \u2014 unless the lack of obligation is obvious \u2014 precisely to be able to demonstrate that the appropriate factors have been taken into account. <\/p>\n\n\n\n<div class=\"wp-block-group ll-art-board is-layout-constrained wp-block-group-is-layout-constrained\">\n\n<h2 class=\"wp-block-heading\" id=\"zarzad\">What should management know?<\/h2>\n\n\n<p class=\"wp-block-paragraph\">The decision to appoint an inspector is not a technical decision of the IT or HR department. The choice of the role, its placement in the structure, and ensuring independence are management decisions, and responsibility for them remains with the controller \u2014 i.e., the organization represented by its management. <\/p>\n\n\n<p class=\"wp-block-paragraph\">Three things management should understand before making a decision. Firstly, the determination that there is no obligation must be demonstrable \u2014 an analysis without a document is practically non-existent. Secondly, appointing a DPO does not transfer responsibility for compliance to them; the inspector monitors, advises, and acts as a contact point, while decisions remain with the controller. Thirdly, the function requires conditions: access to information, resources, absence of conflicts of interest, and direct reporting to top management \u2014 an inspector appointed without these conditions creates the appearance of compliance, not actual compliance.   <\/p>\n\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"bledy\">Most common errors<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Supervisory practice shows that more problems arise after the decision than during its making.<\/p>\n\n\n\n<ul class=\"wp-block-list ll-art-errors\">\n\n<li><strong>Assessment based on organization size instead of activity nature.<\/strong> The number of employees is not a criterion under Article 37(1) of the GDPR. A small company conducting user profiling may be subject to an obligation that a large manufacturing plant does not have.   <\/li>\n\n\n<li><strong>Oral or implied appointment.<\/strong> The Personal Data Protection Office indicates that an effective appointment requires an internal act \u2014 a resolution, decision, delegation of duties \u2014 or a contract, with a defined scope of tasks. A person &#8216;informally dealing with GDPR&#8217; is not an inspector. <\/li>\n\n\n<li><strong>Failure to notify and publish.<\/strong> Notification to the President of the Personal Data Protection Office must be submitted within 14 days of appointment, in electronic form, signed with a qualified electronic signature or trusted signature; the same deadline applies to changes in data and the dismissal of an inspector. The inspector&#8217;s data must be made available immediately on the website, or if there is no website, in a generally accessible manner at the place of business. The Personal Data Protection Office has conducted proceedings resulting in administrative monetary penalties precisely for the lack of effective appointment, lack of notification, and lack of data publication.  <\/li>\n\n\n<li><strong>Conflict of interest.<\/strong> Entrusting the function to a person who decides on the purposes and means of processing \u2014 an IT, HR, marketing manager, or a board member \u2014 undermines the independence of the role. This is one of the elements the office directly asks about during verification. <\/li>\n\n\n<li><strong>Confusing DPO with roles from other regimes.<\/strong> The contact person appointed under the KSC Act, the information security coordinator, and the data protection officer are three different functions with different legal bases.<\/li>\n\n\n<li><strong>Treating the analysis as a one-off activity.<\/strong> A change in business profile, entry into new markets, launching a loyalty program, or acquiring another entity can change the outcome. An assessment without a date and without a review cycle ages with the organization. <\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"wnioski\">Conclusions and next steps<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The answer to the question of the obligation to appoint a DPO is the result of an analysis of three conditions, not a check of a single criterion. For public entities listed in the Act, the matter is settled. For other organizations, the nature of the core activity and the scale of processing, assessed according to the factors from the guidelines \u2014 number of individuals, scope of data, duration, and geographical reach \u2014 are decisive.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The sensible sequence of actions is brief. Determine whether the organization falls within the catalog of public entities under Article 9 of the Act. If not, assess both scale conditions separately for the role of controller and processor. Check sectoral regulations for Article 37(4) of the GDPR. Document the result along with input data, date, and approving person \u2014 regardless of whether the result is positive or negative. If the obligation exists or the organization decides to appoint voluntarily, immediately plan three things: the appointment document with the scope of tasks, notification within 14 days, and data publication. Finally, set a moment for re-review \u2014 the simplest way is to link it to the review of the record of processing activities.         <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Related materials<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/\">Does every data breach need to be reported?<\/a><\/strong>  \u2014 the decision to report a breach and the role of the data protection officer in it.<\/li>\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/how-often-should-employees-be-trained-on-personal-data-protection\/\">How often should employees be trained on personal data protection?<\/a><\/strong>  \u2014 who in the organization is responsible for awareness-raising activities and staff training.<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Sources<\/h2>\n\n\n\n<ul class=\"wp-block-list ll-art-sources\">\n\n<li>Regulation (EU) 2016\/679 of the European Parliament and of the Council (GDPR), Articles 37\u201339, consolidated text \u2014 EUR-Lex: <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX%3A02016R0679-20160504\" target=\"_blank\" rel=\"noreferrer noopener\">eur-lex.europa.eu<\/a> (accessed: 2026-08-17) <\/li>\n\n\n<li>Act of May 10, 2018, on personal data protection, Articles 8\u201311 \u2014 ISAP: <a href=\"https:\/\/isap.sejm.gov.pl\/isap.nsf\/DocDetails.xsp?id=WDU20180001000\" target=\"_blank\" rel=\"noreferrer noopener\">isap.sejm.gov.pl<\/a> (accessed: 2026-08-17)   (in Polish)<\/li>\n\n\n<li>Should a DPO be appointed in a non-public healthcare facility with approximately 2000 patients \u2014 Personal Data Protection Office: <a href=\"https:\/\/uodo.gov.pl\/pl\/499\/4146\" target=\"_blank\" rel=\"noreferrer noopener\">uodo.gov.pl<\/a> (accessed: 2026-08-17) (in Polish)<\/li>\n\n\n<li>Verification of compliance with regulations concerning the data protection officer \u2014 Personal Data Protection Office: <a href=\"https:\/\/uodo.gov.pl\/pl\/138\/2438\" target=\"_blank\" rel=\"noreferrer noopener\">uodo.gov.pl<\/a> (accessed: 2026-08-17) (in Polish)<\/li>\n\n\n<li>Effective DPO appointment as a necessary condition for effective data protection \u2014 Personal Data Protection Office: <a href=\"https:\/\/uodo.gov.pl\/pl\/138\/3421\" target=\"_blank\" rel=\"noreferrer noopener\">uodo.gov.pl<\/a> (accessed: 2026-08-17) (in Polish)<\/li>\n\n\n<li>Guidelines on Data Protection Officers (WP 243 rev. 01), Article 29 Working Party, adopted December 13, 2016, amended April 5, 2017, approved by the European Data Protection Board, Polish version \u2014 Personal Data Protection Office: <a href=\"https:\/\/uodo.gov.pl\/data\/filemanager_pl\/15.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">uodo.gov.pl<\/a> (accessed: 2026-08-17) (in Polish)<\/li>\n\n<\/ul>\n\n\n\n<div class=\"wp-block-group ll-art-author is-layout-constrained wp-block-group-is-layout-constrained\">\n\n<h2 class=\"wp-block-heading\">Author<\/h2>\n\n\n<p class=\"wp-block-paragraph\"><strong>Micha\u0142 Rutkowski<\/strong> \u2014 LabLogic. Combines legal, organizational, and technological perspectives in working with management of medium and large organizations: DPO\/DPO support and function, preparation for NIS2 and KSC, incident response, audits, and training. Contact: M.Rutkowski@LabLogic.pl  <\/p>\n\n<\/div>\n\n\n\n<div class=\"wp-block-group ll-art-cta is-layout-constrained wp-block-group-is-layout-constrained\">\n\n<h2 class=\"wp-block-heading\">Settle it once and for all<\/h2>\n\n\n<p class=\"wp-block-paragraph\">If the result of the analysis in your organization is not unambiguous, or if an inspector has been appointed but it is unclear whether effectively, it is worth resolving both issues before further organizational decisions. External DPO\/DPO support includes assessing the obligation, organizing appointment documentation and notifications, and taking over or supporting the inspector&#8217;s function. <\/p>\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/www.lablogic.pl\/en\/external-data-protection-officer-iod-dpo\/\">External DPO\/DPO support<\/a><\/div>\n\n<\/div>\n\n<\/div>\n\n\n\n<div class=\"wp-block-group ll-art-disclaimer is-layout-constrained wp-block-group-is-layout-constrained\">\n\n<p class=\"wp-block-paragraph\">This material is general and educational in nature. It does not constitute individual legal advice or recommendations for a specific organization. The scope of obligations should be assessed taking into account its specific situation.  <\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>Legal status: August 2026.<\/strong><\/p>\n\n<\/div>\n\n<\/div>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The obligation to appoint a Data Protection Officer arises in three cases under Article 37(1) of the GDPR. None of the conditions refer to the size of the organization \u2014 the nature of the activity and the scale of processing are decisive.   <\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[70],"tags":[78],"class_list":["post-3918","post","type-post","status-publish","format-standard","hentry","category-dpo","tag-for-management"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Three conditions under Article 37 GDPR, the Polish list of public bodies and the large-scale criteria. How to run and document the DPO assessment.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Micha\u0142 Rutkowski\"\/>\n\t<meta name=\"keywords\" content=\"for-management\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"LabLogic - Micha\u0142 Rutkowski | DPO, RODO, NIS2 i Cybersecurity w praktyce\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"How to determine if an organization must appoint a DPO? | LabLogic - Micha\u0142 Rutkowski\" \/>\n\t\t<meta property=\"og:description\" content=\"Three conditions under Article 37 GDPR, the Polish list of public bodies and the large-scale criteria. How to run and document the DPO assessment.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/lablogic-logo-primary.svg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/lablogic-logo-primary.svg\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-08-18T09:46:34+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-08-18T10:30:20+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary\" \/>\n\t\t<meta name=\"twitter:title\" content=\"How to determine if an organization must appoint a DPO? | LabLogic - Micha\u0142 Rutkowski\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Three conditions under Article 37 GDPR, the Polish list of public bodies and the large-scale criteria. How to run and document the DPO assessment.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/lablogic-logo-primary.svg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/#article\",\"name\":\"How to determine if an organization must appoint a DPO? | LabLogic - Micha\\u0142 Rutkowski\",\"headline\":\"How to determine if an organization must appoint a DPO?\",\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/user_lablogic\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2020\\\/03\\\/LABLOGIC_LOGO2.png\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#articleImage\"},\"datePublished\":\"2026-08-18T11:46:34+02:00\",\"dateModified\":\"2026-08-18T12:30:20+02:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/#webpage\"},\"articleSection\":\"DPO and GDPR, for-management, Optional\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/dpo\\\/#listItem\",\"name\":\"DPO and GDPR\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/dpo\\\/#listItem\",\"position\":2,\"name\":\"DPO and GDPR\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/dpo\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/#listItem\",\"name\":\"How to determine if an organization must appoint a DPO?\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/#listItem\",\"position\":3,\"name\":\"How to determine if an organization must appoint a DPO?\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/dpo\\\/#listItem\",\"name\":\"DPO and GDPR\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\",\"name\":\"LabLogic Micha\\u0142 Rutkowski\",\"description\":\"DPO, RODO, NIS2 i Cybersecurity w praktyce\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"telephone\":\"+48586231777\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2020\\\/03\\\/LABLOGIC_LOGO2.png\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/#organizationLogo\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/user_lablogic\\\/#author\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/user_lablogic\\\/\",\"name\":\"Micha\\u0142 Rutkowski\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Micha\\u0142 Rutkowski\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/#webpage\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/\",\"name\":\"How to determine if an organization must appoint a DPO? | LabLogic - Micha\\u0142 Rutkowski\",\"description\":\"Three conditions under Article 37 GDPR, the Polish list of public bodies and the large-scale criteria. How to run and document the DPO assessment.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/how-to-determine-if-an-organization-must-appoint-a-dpo\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/user_lablogic\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/user_lablogic\\\/#author\"},\"datePublished\":\"2026-08-18T11:46:34+02:00\",\"dateModified\":\"2026-08-18T12:30:20+02:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"name\":\"LabLogic Consulting\",\"description\":\"DPO, RODO, NIS2 i Cybersecurity w praktyce\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"How to determine if an organization must appoint a DPO? | LabLogic - Micha\u0142 Rutkowski","description":"Three conditions under Article 37 GDPR, the Polish list of public bodies and the large-scale criteria. How to run and document the DPO assessment.","canonical_url":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/","robots":"max-image-preview:large","keywords":"for-management","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/#article","name":"How to determine if an organization must appoint a DPO? | LabLogic - Micha\u0142 Rutkowski","headline":"How to determine if an organization must appoint a DPO?","author":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/user_lablogic\/#author"},"publisher":{"@id":"https:\/\/www.lablogic.pl\/en\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2020\/03\/LABLOGIC_LOGO2.png","@id":"https:\/\/www.lablogic.pl\/en\/#articleImage"},"datePublished":"2026-08-18T11:46:34+02:00","dateModified":"2026-08-18T12:30:20+02:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/#webpage"},"isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/#webpage"},"articleSection":"DPO and GDPR, for-management, Optional"},{"@type":"BreadcrumbList","@id":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","position":1,"name":"Home","item":"https:\/\/www.lablogic.pl\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/dpo\/#listItem","name":"DPO and GDPR"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/dpo\/#listItem","position":2,"name":"DPO and GDPR","item":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/dpo\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/#listItem","name":"How to determine if an organization must appoint a DPO?"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/#listItem","position":3,"name":"How to determine if an organization must appoint a DPO?","previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/dpo\/#listItem","name":"DPO and GDPR"}}]},{"@type":"Organization","@id":"https:\/\/www.lablogic.pl\/en\/#organization","name":"LabLogic Micha\u0142 Rutkowski","description":"DPO, RODO, NIS2 i Cybersecurity w praktyce","url":"https:\/\/www.lablogic.pl\/en\/","telephone":"+48586231777","logo":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2020\/03\/LABLOGIC_LOGO2.png","@id":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/#organizationLogo"},"image":{"@id":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/#organizationLogo"}},{"@type":"Person","@id":"https:\/\/www.lablogic.pl\/en\/author\/user_lablogic\/#author","url":"https:\/\/www.lablogic.pl\/en\/author\/user_lablogic\/","name":"Micha\u0142 Rutkowski","image":{"@type":"ImageObject","@id":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g","width":96,"height":96,"caption":"Micha\u0142 Rutkowski"}},{"@type":"WebPage","@id":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/#webpage","url":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/","name":"How to determine if an organization must appoint a DPO? | LabLogic - Micha\u0142 Rutkowski","description":"Three conditions under Article 37 GDPR, the Polish list of public bodies and the large-scale criteria. How to run and document the DPO assessment.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/#website"},"breadcrumb":{"@id":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/#breadcrumblist"},"author":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/user_lablogic\/#author"},"creator":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/user_lablogic\/#author"},"datePublished":"2026-08-18T11:46:34+02:00","dateModified":"2026-08-18T12:30:20+02:00"},{"@type":"WebSite","@id":"https:\/\/www.lablogic.pl\/en\/#website","url":"https:\/\/www.lablogic.pl\/en\/","name":"LabLogic Consulting","description":"DPO, RODO, NIS2 i Cybersecurity w praktyce","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.lablogic.pl\/en\/#organization"}}]},"og:locale":"en_US","og:site_name":"LabLogic - Micha\u0142 Rutkowski | DPO, RODO, NIS2 i Cybersecurity w praktyce","og:type":"article","og:title":"How to determine if an organization must appoint a DPO? | LabLogic - Micha\u0142 Rutkowski","og:description":"Three conditions under Article 37 GDPR, the Polish list of public bodies and the large-scale criteria. How to run and document the DPO assessment.","og:url":"https:\/\/www.lablogic.pl\/en\/how-to-determine-if-an-organization-must-appoint-a-dpo\/","og:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/lablogic-logo-primary.svg","og:image:secure_url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/lablogic-logo-primary.svg","article:published_time":"2026-08-18T09:46:34+00:00","article:modified_time":"2026-08-18T10:30:20+00:00","twitter:card":"summary","twitter:title":"How to determine if an organization must appoint a DPO? | LabLogic - Micha\u0142 Rutkowski","twitter:description":"Three conditions under Article 37 GDPR, the Polish list of public bodies and the large-scale criteria. How to run and document the DPO assessment.","twitter:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/lablogic-logo-primary.svg"},"aioseo_meta_data":{"post_id":"3918","title":null,"description":"Three conditions under Article 37 GDPR, the Polish list of public bodies and the large-scale criteria. How to run and document the DPO assessment.","keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-08-18 09:55:53","updated":"2026-08-18 11:41:59","seo_analyzer_scan_date":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"spectra_blocks_featured_image_url":null,"spectra_blocks_author_info":{"display_name":"Micha\u0142 Rutkowski","avatar_url":"https:\/\/secure.gravatar.com\/avatar\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g","author_link":"https:\/\/www.lablogic.pl\/en\/author\/user_lablogic\/","description":""},"_links":{"self":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/3918","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/comments?post=3918"}],"version-history":[{"count":4,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/3918\/revisions"}],"predecessor-version":[{"id":3936,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/3918\/revisions\/3936"}],"wp:attachment":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/media?parent=3918"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/categories?post=3918"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/tags?post=3918"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}