When A DPO Is Mandatory

When A DPO Is Mandatory

The GDPR does not ask whether a data protection officer would be useful. It asks three questions, and where the answer to any of them is yes, a mandatory DPO follows. Candidates lose marks here by reasoning from company size or sector instead of from the text. The CIPP/E Body of Knowledge, the blueprint the IAPP publishes to define what the exam covers, places this in Domain IV with the rest of accountability.

When a mandatory DPO is required

Article 37(1) sets out three triggers. A DPO is required where the processing is carried out by a public authority or body, except for courts acting in their judicial capacity. It is required where the core activities of the controller or processor consist of processing operations which, by their nature, scope or purposes, require regular and systematic monitoring of data subjects on a large scale. And it is required where the core activities consist of large-scale processing of the special categories in Article 9, or of criminal conviction and offence data under Article 10.

Read the second and third triggers side by side. Both need core activities and large scale; only the second needs regular and systematic monitoring. The first needs neither: a municipal body appoints a DPO for what it is, not for how much it processes.

Article 37(4) leaves room for Union or Member State law to require a DPO in other cases, which is why a German controller can be caught by a national threshold with no equivalent in the Regulation.

Core activities, not the support functions

Core activities are the operations through which an organisation achieves its objectives, not everything it does. The Article 29 Working Party guidelines on DPOs, endorsed by the EDPB, give the example that reads best in an exam. A hospital's core activity is healthcare, and it cannot deliver healthcare without processing patient health records, so that processing is a core activity, not an ancillary one.

The counter-example matters as much. Payroll and routine IT support happen in every organisation and both involve personal data. Both are support functions, so neither makes a DPO mandatory on its own. A scenario that dwells on the size of the HR database is often testing that distinction.

Large scale, with no number attached

The Regulation sets no threshold, and the exam rewards nobody for inventing one. The guidelines give four factors instead: the number of data subjects, as a number or a proportion; the volume and range of the data; the duration or permanence of the processing; and its geographical extent.

That is a judgement, and meant to be. What you can rule out is arithmetic. An option that makes a mandatory DPO turn on a stated number of records is almost always wrong, because the Regulation contains no such number.

The DPO independence rule

Appointing the DPO is the easy half. Article 38 is where organisations come unstuck. The DPO must be involved properly and in good time in all issues relating to personal data protection, must take no instructions on those tasks, must not be dismissed or penalised for performing them, and must report to the highest management level.

Article 39 lists the tasks: inform and advise, monitor compliance including awareness raising and staff training, advise on data protection impact assessments and monitor their performance, cooperate with the supervisory authority, and act as its contact point. Notice what is absent. Nothing there makes the DPO responsible for compliance. Article 24 keeps that with the controller, which is why an option that fines the DPO personally is a distractor.

The conflict of interest test

Article 38(6) allows the DPO to hold other tasks and duties provided they create no conflict of interests. The Court of Justice addressed that in X-FAB Dresden, decided on 9 February 2023. A DPO cannot be entrusted with tasks that involve determining the purposes and means of processing, and the conflict is assessed case by case, in particular against the organisational structure.

That is why the head of IT, the head of HR and the head of marketing make poor candidates. Each decides how personal data gets used, then would be asked to audit that decision.

The traps this topic sets

Three recur. A voluntary DPO is not a lighter DPO; once appointed, Articles 37 to 39 apply in full. A group of undertakings may appoint a single DPO under Article 37(2), but only where that person is easily accessible from each establishment, so accessibility rather than headcount is the test. And the contact details must be published and communicated to the supervisory authority under Article 37(7), the administrative step organisations forget.

The EDPB ran a coordinated enforcement action across the EEA on the designation and position of DPOs, reporting in January 2024. Regulators are watching.

Why the exam keeps asking about the DPO

Domain IV is about accountability, and the mandatory DPO is accountability in its most testable form: defined triggers, a defined position, defined tasks. Work the trigger first and the position second. If you cannot name which limb of Article 37(1) applies, the scenario has not handed you a DPO obligation, whatever its size suggests.

For the enforcement side of the same domain, how GDPR enforcement really works covers what follows when accountability fails. Then work the Domain IV material at 22academy.com/study and recite the three triggers from memory.

Share this Post

Exam Question Masterclass



Ready to kick-start your career?

GET STARTED NOW



About The Blog


Stay up to date with the latest news, background articles, and tips for your study.


Our latest video





22Academy

Tailored Training Solutions

Let's find the best education solution for your situation. We will contact you for Free Support!

Success! Your message has been sent to us.
Error! There was an error sending your message.
It’s for:
We will only use your email address to contact you regarding your education needs. We do not sell your personal data to third parties.