Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Fiches
  4. Data Protection Officer (DPO) (Art. 37–39)
Courses Guides Blog Resources News
Français English Nederlands
Fiche 44/54 Part 5 — Operational Obligations & Sanctions Intermediate Reviewed 2026-08-23

Data Protection Officer (DPO) (Art. 37–39)

Article 37 mandates the designation of a Data Protection Officer (DPO) in three strict cases: public authorities, regular and systematic monitoring of individuals on a large scale, or large-scale proc

Open in interactive reader
⚖️ Statutory Designation 📋 Independence & Tasks (Art. 37–39)

Data Protection Officer (DPO) (Art. 37–39)

⚡ In 30 seconds

Under Article 37(1), designating a DPO is mandatory where: (a) Processing is carried out by a public authority, (b) Core activities require regular and systematic monitoring of individuals on a large scale, or (c) Core activities consist of processing on a large scale of sensitive data (Art. 9) or criminal data (Art. 10).

Statutory Dimension Legal Requirement Operational Reality
Status & Position (Art. 38) Reports directly to highest management; protected against dismissal for performing tasks. Direct board access; no instructions on how to interpret law; zero conflict of interest.
Core Tasks (Art. 39) Inform, advise, monitor compliance, oversee DPIAs, act as contact point for DPA. Reviewing vendor DPAs; organizing staff training; auditing RoPA records.
Legal Liability The DPO is personally not liable for corporate GDPR non-compliance. The controller alone bears legal responsibility and risk of administrative fines.
⚡ Key Takeaways
  • A single DPO may be designated for a corporate group provided they are easily accessible (Art. 37.2).
  • The DPO may be a staff member or an external consultant under a service contract (Art. 37.6).
  • Mandatory notification: contact details must be published and communicated to the national supervisory authority.
⚠️ Common Pitfall

Instructing the DPO on what conclusions to reach or punishing them for advising against high-risk business deployments.

🛠️ In Practice

Notify your DPO's credentials to the national DPA (via the online portal) and publish their contact email on your website.

⚖️ Official Sources: Articles 37 to 39 GDPR · Recital 97 · WP29 Guidelines on Data Protection Officers (WP243) ✓ Legal review: 23 August 2026

✓ Key takeaways

  • Mandatory in 3 statutory cases (Art. 37.1); voluntary appointment permitted under identical status (Art. 37.4).
  • Absolute operational independence: must report to the highest management tier without conflict of interest.
  • The DPO is an adviser and monitor; legal liability for compliance remains solely with the controller.

⚠ Common pitfall: Designating the Head of IT, CEO, or Marketing Director as DPO, creating an unlawful conflict of interest (Art. 38.6).

→ Actionable practice: Formalize the DPO appointment letter, ensure sufficient dedicated budget, and officially notify contact details to the national DPA.

← Data Protection Impact Assessment (DPIA) (Art. 35) Security of Processing: Technical Measures (Art. 32) →