Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Articles 37-39 (DPO)
Resources
🇫🇷 FR 🇬🇧 EN 🇳🇱 NL
EU Legal Reference⚖️ GDPR Regulatory Text⚖️ Binding Legal Force

Articles 37 to 39 GDPR : Status, Designation and Tasks of the DPO

Official EU Regulation (EU) 2016/679 legal analysis · Controlled official sources

⚡ In 30 seconds:

Articles 37 to 39 GDPR and EDPB Guidelines WP243 define mandatory criteria for appointing a DPO (public authorities, large-scale regular monitoring, large-scale sensitive data) and guarantee their strict independence.

Mandatory Designation Criteria for the DPO (Art. 37(1) GDPR)

In accordance with EDPB/WP29 Guidelines WP243, designating a Data Protection Officer (DPO) is mandatory in three specific situations:

  • Public sector (Art. 37(1)(a)): The processing is carried out by a public authority or body, except for courts acting in their judicial capacity;
  • Regular and systematic monitoring on a large scale (Art. 37(1)(b)): The core activities of the controller or the processor require regular and systematic monitoring of data subjects on a large scale (e.g. telecommunications, credit scoring, ad tracking, video surveillance);
  • Sensitive data on a large scale (Art. 37(1)(c)): The core activities consist of processing on a large scale of special categories of data (Art. 9) or data relating to criminal convictions and offences (Art. 10) (e.g. hospitals, medical laboratories, health insurance).

Article 37(4) explicitly allows Member States or organisations to designate a DPO on a voluntary or sector-specific basis.

Independent Position and Core Statutory Tasks (Arts. 38 & 39 GDPR)

Article 38 strictly guarantees the independence of the DPO: they are involved in all data protection matters, receive no instructions regarding the exercise of their tasks, and cannot be dismissed or penalised for performing their statutory duties.

Article 39 defines their core missions: informing and advising the controller and processor, monitoring compliance with the GDPR, providing advice on data protection impact assessments (DPIA, Art. 35), and acting as the contact point for the supervisory authority and data subjects.

Verified Official Sources

⚖️ Binding Source
Regulation (EU) 2016/679 (GDPR) · CELEX: 32016R0679 · 2016-04-27

General Data Protection Regulation — EU Reference Legal Framework

Consult official source →
🇪🇺 WP29 / EDPB Guidelines
Guidelines on Data Protection Officers ('DPOs') (WP243 rev.01)

DPO (Art. 37-39), critères de désignation obligatoire, missions, indépendance

Consult official source →

Associated Operational Micro-Tools

🛡️
Art. 37-39 GDPR
DPO Check (Designation Criteria)

Analyze mandatory DPO designation criteria (public authority, large scale core processing, special categories of data).

Launch interactive tool →

See Also in the Legal Framework

Article 35 GDPR Official Text

Article 35 GDPR : Criteria and Methodology of the DPIA

Legal framework of the Data Protection Impact Assessment (Art. 35 GDPR): mandatory cases, WP248 high-risk criteria, asse...

View document
Article 30 GDPR Official Text

Article 30 GDPR : Maintaining Records of Processing Activities

Records of processing activities obligations under Article 30 GDPR: mandatory content for controllers and processors, li...

View document
← Explore this topic in the interactive RGPD.click knowledge base
Reviewed date: 2026-08-23 Last modified: 2026-08-23

Independent legal reference documentation on Regulation (EU) 2016/679 (GDPR).

Home · Resources Index · Privacy Policy · Legal Notice