Data protection officer

Do you need a DPO?
Three tests, five jurisdictions.

A data protection officer is a role the law defines, protects and in some cases requires. This guide covers when a DPO is mandatory under the GDPR, what the DPO does, and the matching roles under the UK GDPR, the UAE PDPL, the DIFC Data Protection Law, Australia's Privacy Act and India's DPDP Act. Not legal advice.

GDPR Arts. 37 to 39UK GDPRUAE PDPL Art. 10DIFC Art. 16APP 1DPDP s.10

Last updated Published by TryTrustableNot legal advice

Short answer

A data protection officer (DPO) is the person a company designates to advise on and monitor its compliance with data protection law, and to act as the contact point for regulators and individuals. Under GDPR Article 37, a DPO is mandatory for public authorities, and for any organisation whose core activities involve regular and systematic monitoring of people on a large scale, or large-scale processing of special category or criminal offence data. Member State law can add more cases. Everyone else may appoint one voluntarily.

01

What is a data protection officer?

A data protection officer is an independent adviser and monitor inside, or contracted to, an organisation that processes personal data. Under the GDPR the DPO is not the person who is responsible for compliance; that remains the controller or processor. The DPO's job is to tell them what the law requires, check whether they meet it, and be the point of contact for the supervisory authority and for individuals. Because the role depends on being able to say unwelcome things, the law protects it.

02

When is a DPO mandatory under GDPR?

Article 37(1) requires both controllers and processors to designate a DPO in three cases. A SaaS processor can be caught in its own right, not only through its customers.

Article 37(1)TriggerTypical examples
(a)Processing by a public authority or body (except courts acting judicially)Government departments, public hospitals, state universities
(b)Core activities consist of processing that requires regular and systematic monitoring of data subjects on a large scaleBehavioural advertising and tracking networks, location tracking apps, loyalty programmes, connected devices that report usage
(c)Core activities consist of large-scale processing of special category data (Article 9) or criminal offence data (Article 10)Health platforms, genetic testing, background-check services

Core activities are the processing your business cannot do without, not support functions like payroll or IT.

Article 37(4) lets Member State law require a DPO in more cases. Germany is the best-known example: section 38 of the Federal Data Protection Act (BDSG) requires one where at least 20 people are constantly engaged in the automated processing of personal data. Check the national law of each country where you are established.

The terms are judgement calls. The EDPB-endorsed Guidelines on DPOs (WP243) suggest weighing the number of people concerned, the volume and range of data, the duration of the processing and its geographical extent when deciding what is large scale. If you decide you do not need a DPO, write down why. That analysis is part of your accountability record.

03

Do I need a data protection officer? A quick test

  1. Are you a public authority or body? If yes, you need one.
  2. Is tracking or profiling people central to what you sell? Ad tech, analytics on end users as the product, location or device telemetry at scale: likely yes.
  3. Is health, biometric, genetic or criminal data central to what you do, at scale? Likely yes.
  4. Does a country where you are established add its own threshold? Germany's 20-person rule, for instance.
  5. None of the above? A DPO is optional. Many B2B SaaS companies whose customers' end users are only processed incidentally fall here, but still need someone who owns privacy.

A voluntary DPO carries the same legal protections and duties as a mandatory one, so if you want a privacy lead without those obligations, give the role a different title.

04

DPO roles and responsibilities

Article 39(1) sets the minimum tasks: inform and advise the organisation and its staff on their obligations; monitor compliance, including the assignment of responsibilities, awareness-raising, training and audits; advise on data protection impact assessments and monitor their performance; cooperate with the supervisory authority; and act as its contact point, including for prior consultation. Article 38(4) adds that individuals may contact the DPO about any issue with their data or their rights, so DPOs often oversee data subject requests.

Article 38 protects the role. The organisation must involve the DPO properly and in good time, provide resources and access, and must not instruct the DPO on how to carry out these tasks or dismiss or penalise them for doing so. The DPO reports directly to the highest management level, and is bound by confidentiality. Article 37(5) requires expert knowledge of data protection law and practice; no particular certification is required by the GDPR.

05

Can a DPO be outsourced, or be the CISO?

Outsourced, yes: Article 37(6) allows a staff member or someone under a service contract, and Article 37(2) allows one DPO for a group if each establishment can easily reach them. The same rules apply either way, and the contact details must be published and given to the supervisory authority (Article 37(7)).

Combining roles is where organisations get it wrong. Article 38(6) allows other duties only if they do not create a conflict of interest. WP243 explains that a DPO cannot hold a position that decides the purposes and means of processing, and gives senior roles such as chief executive, chief operating officer, chief financial officer, head of marketing, head of HR and head of IT as likely conflicts. A CISO who decides how personal data is processed will often be conflicted; assess the actual role, not the title. Data protection officer versus data privacy officer is a naming question: only the GDPR DPO is a statutory role.

06

Data protection officer under UK GDPR

The UK GDPR keeps Articles 37 to 39 with the same three triggers, tasks and protections. You publish the DPO's contact details and tell the ICO. The Data (Use and Access) Act 2025, whose data protection provisions the ICO confirmed were all in force on 19 June 2026, did not remove the requirement. A UK organisation that also offers services in the EU must test the EU GDPR separately, and may also need an EU representative under Article 27, which is a different role.

07

DPO-equivalent roles in the UAE, Australia and India

UAE (federal PDPL). Article 10 of Federal Decree-Law No. 45 of 2021 requires controllers and processors to appoint a DPO with sufficient knowledge of the law where processing creates a high risk because of new technologies or data volume, involves a systematic and comprehensive assessment of sensitive personal data including profiling, or covers a large volume of sensitive data. The DPO may sit inside or outside the UAE, and the contact details go to the UAE Data Office. Article 11 lists the tasks, including receiving requests and complaints, and Article 12 forbids dismissing or disciplining the DPO for doing the job. Article 10(4) leaves the technology and volume criteria to the Executive Regulations, and Article 29 gives six months to comply once they are issued. We could not confirm that the Executive Regulations had been published as of October 2026; check before you rely on the timeline.

DIFC. The DIFC Data Protection Law (DIFC Law No. 5 of 2020) is stricter on residence and reporting. Article 16(2) requires a DPO for DIFC Bodies and for anyone performing High Risk Processing Activities on a systematic or regular basis, and the Commissioner can require one in other cases. The DPO must reside in the UAE unless they are a group employee doing the same job internationally, and must carry out an Annual Assessment of the controller's processing for the Commissioner (Article 19). Organisations without a DPO must still allocate responsibility for data protection and be able to name the people (Article 16(4)).

Australia. The Privacy Act 1988 does not require private-sector organisations to appoint a DPO. APP 1.2 requires reasonable steps to implement practices, procedures and systems that ensure compliance with the APPs and handle enquiries and complaints, and the OAIC's APP guidelines list designated privacy officers and regular reporting to the governing body among those steps. In practice an Australian business answering APP 1 names a privacy officer. Australian Government agencies have a firmer duty under the agencies' privacy governance code.

India. Under the DPDP Act, only a Significant Data Fiduciary must appoint a DPO, who must be based in India, be responsible to the board and be the grievance contact (section 10(2)(a)). Every other fiduciary must publish the business contact of a person who can answer questions about its processing (section 8(9)). The substantive duties under the DPDP Rules apply from 13 May 2027. See the Significant Data Fiduciary guide.

RegimeWhen the role is requiredNotable conditions
EU GDPRPublic bodies; core activities of large-scale regular and systematic monitoring; core activities of large-scale special category or criminal data (Art. 37(1)); plus Member State lawEmployee or contractor; one DPO for a group if easily accessible; publish contact details and tell the supervisory authority
UK GDPRThe same three triggers (Art. 37)Publish contact details and tell the ICO
UAE PDPL (Decree-Law 45 of 2021)High-risk processing from new technologies or data volume; systematic and comprehensive assessment of sensitive data, including profiling; large volumes of sensitive data (Art. 10)May be inside or outside the UAE; notify the UAE Data Office (the Bureau); volume and technology criteria left to Executive Regulations
DIFC Data Protection Law 2020DIFC Bodies, and controllers or processors carrying out High Risk Processing Activities on a systematic or regular basis (Art. 16(2)); or if the Commissioner requiresMust reside in the UAE unless a group DPO with an international role; Annual Assessment to the Commissioner
Australia, Privacy Act 1988No statutory DPO for businesses. APP 1.2 requires reasonable steps to implement practices, procedures and systemsThe OAIC lists designated privacy officers as one such step; Australian Government agencies must have a Privacy Officer under the agencies' governance code
India, DPDP Act 2023Significant Data Fiduciaries only (s.10(2)(a))Based in India, responsible to the board, grievance contact. Every other fiduciary publishes a contact who can answer questions (s.8(9))

A summary to plan with, not legal advice. Check the current text with your counsel.

08

How TryTrustable supports a DPO

A DPO's work is mostly evidence: what the organisation processes, which controls run, which requests are open, what went wrong and what was done. TryTrustable keeps that in one place. The shared control library maps each control across GDPR, UK GDPR, the UAE PDPL, the DIFC and ADGM data protection rules, the Australian Privacy Act and the DPDP Act, so one review answers several regimes. The rights request queue gives each request a deadline set at receipt; incident management tracks breaches; and the evidence ledger, policies, risk register and vendor register hold the records an Annual Assessment or a regulator's question needs. We do not act as your DPO.

Questions

The things people ask us

Do I need a data protection officer?

Under the GDPR, only if you are a public body, or your core activities involve large-scale regular and systematic monitoring of people or large-scale processing of special category or criminal data, or national law requires one. Otherwise it is optional.

What does a data protection officer do?

Advises the organisation on its obligations, monitors compliance including training and audits, advises on DPIAs, cooperates with the supervisory authority and acts as its contact point (Article 39).

Can the DPO be an external consultant?

Yes. Article 37(6) allows a DPO under a service contract. The same independence, resourcing and reporting rules apply.

Who should the DPO report to?

Directly to the highest management level of the organisation (Article 38(3)). The DPO must not receive instructions on how to carry out the DPO tasks.

Does the UAE PDPL require a DPO?

In three cases under Article 10: high-risk processing from new technologies or volume, systematic and comprehensive assessment of sensitive data including profiling, or large volumes of sensitive data. The DIFC and the federal law are separate regimes with different rules.

Does India's DPDP Act require a DPO?

Only for Significant Data Fiduciaries, whose DPO must be based in India and answer to the board. Other fiduciaries publish a contact who can answer questions about their processing.

Is a DPO required in Australia?

Not by statute for private-sector organisations. APP 1.2 requires reasonable governance steps, and naming a privacy officer is the usual way to meet it.

Book a walkthrough

Give your DPO one place for the evidence.

Thirty minutes on your controls, rights requests and the GDPR, UK GDPR, UAE, Australian or DPDP duties you answer to.