Article 37: Designation of the data protection officer
Praxikon tracks Article 37 (Designation of the data protection officer) under the GDPR, alongside the EU AI Act, citing the source for every statement.
What does Article 37 govern?
Article 37 determines when an organisation must designate a data protection officer (DPO). Under paragraph 1 this is mandatory for public authorities and bodies (except courts acting in their judicial capacity), for organisations whose core activities consist of regular and systematic monitoring of people on a large scale, and for organisations whose core activities consist of large-scale processing of special categories of data (Article 9) and criminal data (Article 10). The duty applies to the controller and to the processor alike. The DPO is chosen for expert knowledge of data protection law and practice (paragraph 5), may be an employee or an external person (paragraph 6), and the DPO's contact details are published and communicated to the supervisory authority (paragraph 7). The article exists because organisations with risky processing need someone with expertise who monitors compliance with the GDPR internally and independently (recital 97).
Key term: Core activities: the primary activities of an organisation, not the processing of personal data as an ancillary matter; only core activities count for the DPO duty in paragraph 1(b) and (c) (recital 97)
Directly affects:controllerprocessordata protection officersupervisory authoritymember state
Praxikon’s reading of the text and the recitals; the official text below prevails.
Official text
Source: EUR-Lex, Regulation (EU) 2016/679. Official text, reproduced without modification.
What does this mean for you?
Controller
You check whether you fall under one of the three cases in paragraph 1: a public authority, large-scale regular and systematic monitoring as a core activity, or large-scale processing of special categories of data and criminal data as a core activity. If so, you designate a DPO with demonstrable expertise (paragraph 5), internal or external (paragraph 6), and you publish the contact details and communicate them to the supervisory authority (paragraph 7). If you do not fall under paragraph 1, you may designate a DPO voluntarily, unless Union or national law requires it anyway (paragraph 4).
Processor
The duty in paragraph 1 applies to you as processor too: if your core activities consist of large-scale processing of special categories of data and criminal data, or of large-scale monitoring of people on behalf of your clients, you designate a DPO yourself. The requirements on expertise (paragraph 5) and the publication of contact details (paragraph 7) apply to you as well.
Data Protection Officer
You are designated on the basis of your professional qualities, your expert knowledge of data protection law and practice and your ability to fulfil the tasks in Article 39 (paragraph 5). You may be an employee or work under a service contract (paragraph 6), and within a group of undertakings you may act for several establishments as long as you are easily accessible from each of them (paragraph 2). Recital 97 expects you to be able to perform your tasks independently.
Data Subject
The DPO's contact details are published (paragraph 7), so you can see whether an organisation has a DPO and how to reach that person.
Compliance checklist
Related recitals
Cross-references
Frequently asked questions
Connections
What connects to Article 37 GDPR
Themes where this returns
The counterpart in the other law
Legislation in motion
- Council: Cyprus Presidency tables negotiating mandate, Coreper vote of 26 June 2026 cancelled
2026-06-22 · under negotiation, Raad van de Europese Unie, Antici-groep (vereenvoudiging) en Coreper