Glossary/Compliance/Data Protection Officer
Compliance

Data Protection Officer

DPO

Data Protection Officer is the independent advisor a controller or processor must appoint under GDPR Article 37 in defined circumstances, responsible for monitoring data-protection compliance.

What DPO is

The Data Protection Officer (DPO) is a statutory role under Articles 37 to 39 of the GDPR.

The controller or processor must designate a DPO when the processing is carried out by a public authority, when the core activities require regular and systematic monitoring of data subjects on a large scale, or when the core activities involve large-scale processing of special-category data under Article 9 or data on criminal convictions under Article 10.

The DPO's tasks under Article 39 include informing and advising the organisation, monitoring GDPR compliance, advising on Data Protection Impact Assessments, cooperating with the supervisory authority, and acting as the contact point for data subjects.

The role must be independent: the DPO reports to the highest level of management, cannot be dismissed or penalised for performing their duties, and cannot hold a conflicting role such as head of marketing or head of HR.

A DPO can be an employee or an external service provider, and a group of undertakings can share a single DPO if they remain easily accessible from each establishment. Some non-EU jurisdictions have adopted equivalent or analogous roles: the UK GDPR mirrors Articles 37-39, and Brazil's LGPD requires an encarregado.

When you will meet DPO

You will encounter DPO obligations when designing the privacy programme of any organisation processing health data, biometrics, behavioural advertising data at scale, employee monitoring data, or operating as a public authority. The DPO's contact details must be published, typically in the privacy notice, and notified to the supervisory authority.

Where this comes up in our guides

Data Protection Officer FAQ

No. GDPR Article 37 specifies three triggers (public authority, large-scale systematic monitoring, large-scale special-category processing). Outside those triggers, designation is voluntary but if voluntary the same Articles 38 and 39 protections and tasks apply to the appointed person.
At a glance
Category
Compliance
Also written
DPO
Confirm current figures with the official registry or a qualified adviser before relying on them.
Related terms
← All 120 glossary terms
Sources
  1. 1GDPR Articles 37-39, Regulation (EU) 2016/679
  2. 2EDPB Guidelines on Data Protection Officers (WP243 rev.01)
  3. 3ICO guidance on DPOs
Definition reviewed March 2026.
Put it to use

Eight jurisdictions, costed out in full.

See what a company actually costs in year one, and how the jurisdictions compare on tax, capital and timeline.

Tax calculatorEffective rates on your revenue and margin.Country comparisonEleven criteria, side by side.Cost estimatorWhat the first year actually costs.Document checklistWhat each registry will ask for.

New terms as the rules change

Thresholds move, regimes close, new ones open. One email, no pitches.