Skip to main content
Praxikon

Direct answer · GDPR

When must an organisation designate a data protection officer?

Short answer

A data protection officer is mandatory for a public authority or body, except courts acting in their judicial capacity, and where the core activities consist of regular and systematic monitoring of data subjects on a large scale, or of large-scale processing of special categories of data or data relating to criminal convictions (Article 37(1)). The size of the organisation plays no role.

Direct answer · GDPR

Data protection officer

A data protection officer is mandatory (Article 37(1)): (a) for a public authority or body, except courts acting in their judicial capacity; (b) where the core activities consist of processing operations which, by virtue of their nature, scope or purposes, require regular and systematic monitoring of data subjects on a large scale; (c) where the core activities consist of processing on a large scale of special categories of data, such as health data, or of data relating to criminal convictions and offences. The size of the organisation plays no role. According to the guidelines, core activities are the key operations necessary to achieve the goals of the organisation, not supporting tasks such as payroll.

For you to establish

  • Is the large-scale processing a core activity or a supporting task?

Articles

Guidelines and decisions

Read the article Check your own case General interpretation, not legal advice. The official source remains authoritative.

Check your own situation

Describe your system or project in the free case check and get a reasoned first assessment of, among other things, the DPIA obligation, Article 22 GDPR and the AI Act, with the source for every conclusion.

Go to the free case check
Zahed Ashkara, jurist and freelance AI & Privacy Consultant

Behind this page

Zahed Ashkara

Freelance AI & Privacy Consultant, jurist