Articles 37 to 39 GDPR : Status, Designation and Tasks of the DPO
Articles 37 to 39 GDPR and EDPB Guidelines WP243 define mandatory criteria for appointing a DPO (public authorities, large-scale regular monitoring, large-scale sensitive data) and guarantee their strict independence.
Mandatory Designation Criteria for the DPO (Art. 37(1) GDPR)
In accordance with EDPB/WP29 Guidelines WP243, designating a Data Protection Officer (DPO) is mandatory in three specific situations:
- Public sector (Art. 37(1)(a)): The processing is carried out by a public authority or body, except for courts acting in their judicial capacity;
- Regular and systematic monitoring on a large scale (Art. 37(1)(b)): The core activities of the controller or the processor require regular and systematic monitoring of data subjects on a large scale (e.g. telecommunications, credit scoring, ad tracking, video surveillance);
- Sensitive data on a large scale (Art. 37(1)(c)): The core activities consist of processing on a large scale of special categories of data (Art. 9) or data relating to criminal convictions and offences (Art. 10) (e.g. hospitals, medical laboratories, health insurance).
Article 37(4) explicitly allows Member States or organisations to designate a DPO on a voluntary or sector-specific basis.
Independent Position and Core Statutory Tasks (Arts. 38 & 39 GDPR)
Article 38 strictly guarantees the independence of the DPO: they are involved in all data protection matters, receive no instructions regarding the exercise of their tasks, and cannot be dismissed or penalised for performing their statutory duties.
Article 39 defines their core missions: informing and advising the controller and processor, monitoring compliance with the GDPR, providing advice on data protection impact assessments (DPIA, Art. 35), and acting as the contact point for the supervisory authority and data subjects.
Verified Official Sources
General Data Protection Regulation — EU Reference Legal Framework
Consult official source →DPO (Art. 37-39), critères de désignation obligatoire, missions, indépendance
Consult official source →Associated Operational Micro-Tools
Analyze mandatory DPO designation criteria (public authority, large scale core processing, special categories of data).
See Also in the Legal Framework
Article 35 GDPR : Criteria and Methodology of the DPIA
Legal framework of the Data Protection Impact Assessment (Art. 35 GDPR): mandatory cases, WP248 high-risk criteria, asse...
Article 30 GDPR : Maintaining Records of Processing Activities
Records of processing activities obligations under Article 30 GDPR: mandatory content for controllers and processors, li...