Skip to main content
Praxikon

Article 37: Designation of the data protection officer

Praxikon tracks Article 37 (Designation of the data protection officer) under the GDPR, alongside the EU AI Act, citing the source for every statement.

Chapter IVIn force since 25-05-2018

What does Article 37 govern?

Article 37 determines when an organisation must designate a data protection officer (DPO). Under paragraph 1 this is mandatory for public authorities and bodies (except courts acting in their judicial capacity), for organisations whose core activities consist of regular and systematic monitoring of people on a large scale, and for organisations whose core activities consist of large-scale processing of special categories of data (Article 9) and criminal data (Article 10). The duty applies to the controller and to the processor alike. The DPO is chosen for expert knowledge of data protection law and practice (paragraph 5), may be an employee or an external person (paragraph 6), and the DPO's contact details are published and communicated to the supervisory authority (paragraph 7). The article exists because organisations with risky processing need someone with expertise who monitors compliance with the GDPR internally and independently (recital 97).

Key term: Core activities: the primary activities of an organisation, not the processing of personal data as an ancillary matter; only core activities count for the DPO duty in paragraph 1(b) and (c) (recital 97)

Directly affects:controllerprocessordata protection officersupervisory authoritymember state

Praxikon’s reading of the text and the recitals; the official text below prevails.

Official text

/
The controller and the processor shall designate a data protection officer in any case where: (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; (b) the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or (c) the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 and personal data relating to criminal convictions and offences referred to in Article 10.
A group of undertakings may appoint a single data protection officer provided that a data protection officer is easily accessible from each establishment.
Where the controller or the processor is a public authority or body, a single data protection officer may be designated for several such authorities or bodies, taking account of their organisational structure and size.
In cases other than those referred to in paragraph 1, the controller or processor or associations and other bodies representing categories of controllers or processors may or, where required by Union or Member State law shall, designate a data protection officer. The data protection officer may act for such associations and other bodies representing controllers or processors.
The data protection officer shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39.
The data protection officer may be a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract.
The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority.

Source: EUR-Lex, Regulation (EU) 2016/679. Official text, reproduced without modification.

What does this mean for you?

Controller

You check whether you fall under one of the three cases in paragraph 1: a public authority, large-scale regular and systematic monitoring as a core activity, or large-scale processing of special categories of data and criminal data as a core activity. If so, you designate a DPO with demonstrable expertise (paragraph 5), internal or external (paragraph 6), and you publish the contact details and communicate them to the supervisory authority (paragraph 7). If you do not fall under paragraph 1, you may designate a DPO voluntarily, unless Union or national law requires it anyway (paragraph 4).

Processor

The duty in paragraph 1 applies to you as processor too: if your core activities consist of large-scale processing of special categories of data and criminal data, or of large-scale monitoring of people on behalf of your clients, you designate a DPO yourself. The requirements on expertise (paragraph 5) and the publication of contact details (paragraph 7) apply to you as well.

Data Protection Officer

You are designated on the basis of your professional qualities, your expert knowledge of data protection law and practice and your ability to fulfil the tasks in Article 39 (paragraph 5). You may be an employee or work under a service contract (paragraph 6), and within a group of undertakings you may act for several establishments as long as you are easily accessible from each of them (paragraph 2). Recital 97 expects you to be able to perform your tasks independently.

Data Subject

The DPO's contact details are published (paragraph 7), so you can see whether an organisation has a DPO and how to reach that person.

Compliance checklist

Related recitals

Cross-references

Frequently asked questions

Connections

What connects to Article 37 GDPR

Themes where this returns

The counterpart in the other law

Legislation in motion