Article 37 GDPR
Legal Text
1. The controller and the processor shall designate a data protection officer in any case where:
- (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity;
- (b) the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or
- (c) the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 and personal data relating to criminal convictions and offences referred to in Article 10.
2. A group of undertakings may appoint a single data protection officer provided that a data protection officer is easily accessible from each establishment.
3. Where the controller or the processor is a public authority or body, a single data protection officer may be designated for several such authorities or bodies, taking account of their organisational structure and size.
4. In cases other than those referred to in paragraph 1, the controller or processor or associations and other bodies representing categories of controllers or processors may or, where required by Union or Member State law shall, designate a data protection officer. The data protection officer may act for such associations and other bodies representing controllers or processors.
5. The data protection officer shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39.
6. The data protection officer may be a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract.
7. The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority.
Relevant Recitals
Commentary
Article 37 GDPR imposes on the controller or processor the obligation to appoint a Data Protection Officer (DPO) for its organisation. The DPO is a person with expert knowledge of data protection law appointed by the controller or processor in order to, inter alia, advice on data protection related issues and monitor compliance with data protection provisions. Therefore, Article 37 GDPR strongly affirms[1] the importance of the role of the DPO.[2]
The role of the DPO is especially important for demonstrating compliance with data protection principles, which lies at the heart of the principle of accountability (Articles 5(2) and 24 GDPR).[3] Article 37 GDPR is closely connected to the rules stipulating the DPO's position (Article 38 GDPR) and tasks (Article 39 GDPR).
Article 37(1) GDPR imposes on controllers and processors the obligation to appoint a DPO and lists the condition under which this obligation applies.
Article 37(2) GDPR provides for the possibility of appointing a DPO for the entire group of undertakings, while Article 37(3) GDPR establishes a similar rule for public authorities.
Article 37(4) GDPR extends the requirement of appointing a DPO beyond the cases specified in paragraph 1, where this is mandated by the legislation of the Union or Member States.
Article 37(5) GDPR lists the required competences of the DPO, while Article 37(6) GDPR clarifies that the position of a DPO can be be held either by individuals already part of the controller's or processor's staff or external subjects on the basis of a service contract.
Finally, Article 37(7) GDPR mandates the controller to publish the DPO's contact details and communicate them to the relevant data protection authority (DPA).
EDPB and WP29 Guidelines:
- WP29, 'Guidelines on Data Protection Officers (“DPOs”)', WP 243 rev.01, 5 April 2017 (available here);
- EDPS, ‘Supervisory Guidance Role of the Data Protection Officers in EU institutions, bodies, offices and agencies’, 18 December 2025 (available here).
(1) Obligation to designate a data protection officer
Article 37(1) GDPR outlines the cases that mandate the appointment of a DPO. This provision applies to both controllers and processors whose data processing activities entail higher risks compared to other processing operations, necessitating the appointment of a DPO as a safeguard for data subjects and to facilitate potential interventions by DPAs. The DPO plays a crucial role in ensuring compliance with data protection regulations and in proactively addressing data privacy and security concerns within organisations engaged in more sensitive or high-risk data processing activities.
The controller and the processor
Article 37 GDPR concerns the designation of a DPO and applies to both controllers and processors. The obligation to appoint a DPO depends on whether the specific criteria for mandatory designation are met (see below, In any case where). In certain cases, either the controller or the processor alone may be required to appoint a DPO, while in other situations, both the controller and its processor must appoint one and ensure their cooperation.
For example: A small family business active in the distribution of household appliances in a single town uses the services of a processor whose core activity is to provide website analytics services and assistance with targeted advertising and marketing. The activities of the family business and its customers do not generate processing of data on a ‘large scale’, considering the small number of customers and the relatively limited activities. However, the activities of the processor, having many customers like this small enterprise, taken together, are carrying out large-scale processing. The processor must therefore designate a DPO under Article 37(1)(b) GDPR. At the same time, the family business itself is not under an obligation to designate a DPO.
It is essential to note that even if the controller meets the criteria for mandatory DPO designation, its processor may not be obligated to appoint a DPO. Nevertheless, it is considered a best practice for the processor to appoint a DPO voluntarily.[4]
Shall designate a DPO
The designation of a DPO is an action carried out by the controller or the processor. The GDPR does not require a specific form for the designation of a DPA; therefore, the form of the designation is flexible. Consequently, at least in theory, the absence of a written form does not render the designation invalid. However, this lack of a formal record creates evident challenges concerning accountability and the ability to demonstrate compliance as required by Article 24 GDPR.
"Unless it is obvious that an organisation is not required to designate a DPO, the WP29 recommends that controllers and processors document the internal analysis carried out to determine whether or not a DPO is to be appointed, in order to be able to demonstrate that the relevant factors have been taken into account properly."
WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 5.
The DPO does not necessarily need to be a new, additional specialist hired by the controller or processor. Instead, an existing employee can also fulfil this role. Similarly, it is possible to appoint an external DPO (see Article 37(6) GDPR). Also, the role of a DPO does not necessarily be a full-time position but can also be a part-time role.[5] The specific resources allocated to the role of the DPO will depend on the specific situation (e.g. size, type and extend of the processing activities) of the controller or processor.[6]
The GDPR does not specifically regulate the employment or service contract with an external DPO under labour or civil service law, including the establishment and termination of this relationship. Therefore, it should be pointed out that the appointment to the role of DPO should be differentiated from the employment contract; and can, inter alia, be concluded and terminated separately.[7] In particular, it should be noted that the prohibition of dismissal, as stated in Article 38(3) GDPR specifically pertains to the performance of DPO duties and does not extend to unrelated reasons beyond the scope of the DPO's responsibilities.[8]
In any case where
Article 37(1) GDPR specifies three conditions in which the designation of a DPO is mandatory.
- First, when processing is carried out by a public authority or body.
- Second, when the core activities of a controller or processor involve the regular and systematic monitoring of data subjects on a large-scale.
- Third, when the core activities of a controller or processor involve the processing of Article 9 GDPR or Article 10 GDPR data on a large-scale.
The requirement to designate a DPO in case of private organisations is therefore subject to a risk based approach; the requirement only applies in case.[9] However, the controller or processor can also designate a DPO when it is not required to do so, i.e. it is possible to voluntarily appoint a DPO.[10]
(a) Public authorities and bodies
According to Article 37(1)(a) GDPR, a DPO is always required when processing is carried out by a public authority or body. The GDPR does not define what constitutes a public authority or body. The WP29, endorsed by the EDPB, states that the notion is to be determined under national law. In this view, public authorities and bodies may include national, regional, and local authorities, but the term may also stretch to include other bodies that are governed by public law; In such case, the designation of a DPO is mandatory.[11]
However, there are cases where a public task may also be carried out by other natural or legal persons in certain regulated sectors such as public transport services, water and energy supply, road infrastructure, public service broadcasting, public housing or disciplinary bodies for regulated professions. In these cases, data subjects may be in a very similar situation to when their data are processed by a public authority or body. In particular, "data can be processed for similar purposes and individuals often have similarly little or no choice over whether and how their data will be processed and may thus require the additional protection that the designation of a DPO can bring." Here, the designation of a DPO is not mandatory but recommended.[12]
Finally, Article 37(1)(a) GDPR makes clear that judicial authorities are excluded from the requirement to have a DPO, the reason for this being the principle that the judiciary is not subject to the authority of the DPA pursuant to Article 55(3) GDPR.[13] However, this derogation does not apply in instances where personal data processing is carried out by court administrations when they act as public authorities in a way that is linked to their judicial mandate.[14]
(b) Regular and systematic monitoring
Article 37(1)(b) GDPR imposes the obligation of appointing a DPO on controllers or processors whose core activities consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale. For the Commentary regarding these terms, see below.
For example: A company provides employers with a tool allowing for the monitoring of the productivity of employees in a call centre. The company acts as a processor for the involved processing of the personal data of the employees. Such a processing activity will likely be considered to involve the regular and systematic monitoring of data subjects on a large scale. The company, acting as a processor, will therefore be required to appoint a DPO.
(c) Special category or data relating to criminal convictions and offences
In a similar fashion to Article 37(1)(b) GDPR, Article 37(1)(c) GDPR imposes the obligation of appointing a DPO on controllers or processors whose core activities involve, on a large scale, the processing of special categories of data under Article 9 GDPR or data relating to criminal convictions and offences under Article 10 GDPR. See also Commentary below on the terms "core activities" and "on a large scale"; see Commentary on Article Article 9 GDPR and Article 10 GDPR for more information on special categories of data and data relating to criminal convictions.
Core activities
Article 37(1)(b) GDPR as well as Article 37(1)(c) GDPR refer to the core activity of the controller or processor regarding the requirement to appoint a DPO. In case of Article 37(1)(b) GDPR, the appointment of a DPO is required in case the controller's or processor's core activity consist of the regular and systematic monitoring of data subjects on a large scale, while Article 37(1)(c) GDPR applies in case of the core activity consists of large scale processing of special categories of data related to criminal convictions and offences.
In both cases, it is essential to consider whether the described processing constitute a core activity of the controller or processor. Recital 97 GDPR clarifies that the core activities of a controller are those relating to “primary activities and do not relate to the processing of personal data as ancillary activities”. The WP29 has clarified that the notion of core activities can be considered as “the key operations necessary to achieve the controller’s or processor’s goals”.[15]
"However, ‘core activities’ should not be interpreted as excluding activities where the processing of data forms an inextricable part of the controller’s or processor’s activity. For example, the core activity of a hospital is to provide health care. However, a hospital could not provide healthcare safely and effectively without processing health data, such as patients’ health records. Therefore, processing these data should be considered to be one of any hospital’s core activities and hospitals must therefore designate DPOs."
WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 7.
Mere support functions (e.g. maintaining time employees' time records) do not constitute core activities of the controller or processor and do not trigger the obligation to appoint a DPO.[16]
Regular and systematic monitoring
Article 37(1)(b) GDPR refers to the concept of regular and systematic monitoring of data subjects. This concept is mentioned in Recital 24 GDPR, and includes all forms of tracking and profiling on the internet, including for the purposes of behavioral advertising.[17] Monitoring of data subjects can also take place outside of the context of an online environment. Specifically, the WP29 has interpreted “regular” to mean:
- Ongoing or occurring at particular intervals for a particular period;
- Recurring or repeated at fixed times; or
- Constantly or periodically taking place.[18]
“Systematic”, according to the WP29 should be interpreted as meaning
- Occurring according to a system;
- Pre-arranged, organized or methodical;
- Taking place as part of a general plan for data collection; or
- Carried out as part of a strategy.[19]
"Examples of activities that may constitute a regular and systematic monitoring of data subjects: operating a telecommunications network; providing telecommunications services; email retargeting; data-driven marketing activities; profiling and scoring for purposes of risk assessment (e.g. for purposes of credit scoring, establishment of insurance premiums, fraud prevention, detection of money-laundering); location tracking, for example, by mobile apps; loyalty programs; behavioural advertising; monitoring of wellness, fitness and health data via wearable devices; closed circuit television; connected devices e.g. smart meters, smart cars, home automation, etc."
WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 9.
On a large scale
The term ‘large-scale’ with regards to processing is also not defined in the GDPR. However, Recital 91 GDPR sheds some light on it, noting that large-scale processing operations might aim to “process a considerable amount of personal data at regional, national, or supranational level” and might “affect a large number of data subjects”. In this regard, the WP29 Guidelines mention four criteria with which the large-scale nature of processing operations can be assessed:
- the number of data subjects concerned,
- the volume and range of data being processed,
- the duration or permanence of the processing, and
- the geographical extent of the processing activities.[20]
Examples of large-scale processing include:
- processing of patient data in the regular course of business by a hospital;
- processing of travel data of individuals using a city’s public transport system (e.g. tracking via travel cards);
- processing of real time geo-location data of customers of an international fast food chain for statistical purposes by a processor specialised in providing these services;
- processing of customer data in the regular course of business by an insurance company or a bank;
- processing of personal data for behavioural advertising by a search engine;
- processing of data (content, traffic, location) by telephone or internet service providers[21]
(2) Group of undertakings
Article 37(2) GDPR allows for the designation of a single DPO for a group of undertakings ("Group DPO") as long as the DPO is easily accessible from each establishment. This enables the undertakings in the group to leverage synergy effects and ensure consistent handling of data protection issues.[22] The Group DPO acts as a DPO for different controllers, each of which has to inform the competent DPA about the appointment of the DPA and publish the DPO's contact details in accordance with Article 37(7) GDPR.[23]
The accessibility specifically required in Article 37(2) GDPR must be read in conjunction with the other provisions relating to the tasks and position of the DPO; therefore, it must be recalled that the DPO serves as a contact point for data subjects (see Article 38(4) GDPR, DPAs (see Article 39(1)(e) GDPR) and internally for the organisation itself (see Article 39(1)(a) GDPR).[24]
It is therefore compliant for a group of undertakings to appoint a single DPO as a Group DPO in case they are, first and foremost, reachable. The contact details of the Group DPO must therefore be available both externally and internally.[25] While it is unclear what specific requirements have to be fulfilled in order to assume the DPO's accessibility, simply disclosing the Group DPO's contact information alone cannot be considered to be sufficient. Rather, it must be possible for the controller, the data subjects and the DPA, to engage in a genuine exchange with the DPO which implies a physical proximity to the organisation as well as a short-term availability in case (e.g. in case of a personal data breach in accordance with Article 33 GDPR).[26]
To be "accessible" also implies that any communication should occur in the language(s) utilized by the supervisory authorities, the affected data subjects and controller or processor's staff.[27] The DPO must act as a primary point of contact. While the language proficiency of the DPO's employees can provide some support, it cannot fully replace the language competence of the DPO. This is because the DPO must have the ability to grasp the overall situation and possess at least a basic understanding of all relevant national laws, including a basic knowledge of the respective languages.[28]
"He or she, with the help of a team if necessary, must be in a position to efficiently communicate with data subjects and cooperate with the supervisory authorities concerned. This also means that this communication must take place in the language or languages used by the supervisory authorities and the data subjects concerned. The availability of a DPO (whether physically on the same premises as employees, via a hotline or other secure means of communication) is essential to ensure that data subjects will be able to contact the DPO."
It should be recalled that in accordance with Article 38(2) GDPR, the DPO has to be provided with the necessary resources to carry out their tasks; for a Group DPO, this regularly means that they must be provided with a team supporting them in their role.[29]
(3) Multiple public authorities or bodies
Similar to the preceding paragraph 2, Article 37(3) GDPR allows for the designation of a single DPO for several public authorities or bodies, taking into account their organisational structure and size. If a single DPO is to be appointed for a variety of tasks and across such entities, it is the task of the controller or processor (i.e. public authority or body) to ensure that the DPO can perform their activities efficiently. In other words, their acting in capacity for multiple entities must not hinder the effective execution of their tasks (see Commentary on Article 37(2) GDPR above).
"According to Article 37(3), a single DPO may be designated for several public authorities or bodies, taking account of their organisational structure and size. The same considerations with regard to resources and communication apply. Given that the DPO is in charge of a variety of tasks, the controller or the processor must ensure that a single DPO, with the help of a team if necessary, can perform these efficiently despite being designated for several public authorities and bodies."
[WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 6 (available here). WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 10.]
To ensure that a DPO is effective, the WP29 recommends that they be located within the European Union, regardless of whether the controller or processor themselves is also established in the Union.[30]
(4) Other circumstances in which to designate a data protection officer
The first part of Article 37(4) GDPR clarifies that a controller, processor, association and other bodies representing categories of controllers or processors can also appoint a DPO in case it is not obliged to do so. In other words, it is possible to voluntarily designate a DPO even if the obligation in Article 37(1) GDPR does not apply.[31] A voluntarily appointed DPO has the same rights and obligations as a required one; therefore, as an alternative to this voluntary appointed DPO some controllers appoint a person monitoring compliance with the GDPR but not formally acting as a DPO (sometimes referred to as data protection manager).[32]
For instance, an association or other body representing controllers or processors could appoint a DPO in this context in order to advise the group of controllers or processors on frequently encountered issues, and could also serve as a communication channel between the represented controllers and processors, and the competent DPAs.[33] However, it is debated whether this provisions allows for such an association representing controllers or processors to appoint one DPO for those controllers or processors, acting as the (external) DPO for all those controllers or rather only as the DPO for the association; without interfering with the potential obligation of the represented controllers or processors to appoint a DPO themselves.[34]
Further, Article 37(4) GDPR stipulates that Union or Member State law can provide for additional situations in which the designation of a DPO is required.[35]
(5) Expertise and skills of the DPO
Article 37(5) GDPR specifies that the DPO shall be designated on the basis of their professional qualities and in particular expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39 GDPR.
Professional qualities
While Article 37(5) GDPR does not explicitly outline the specific professional qualifications for appointing the DPO, it is crucial that DPOs possess expertise in both national and European data protection laws; in particular, a comprehensive understanding of the GDPR is required, alongside with an understanding of the controller and their tasks. Furthermore, having knowledge of the business sector and the organisation's structure is valuable. The DPO should also demonstrate a throughout comprehension of the processing activities conducted, information systems, and the controller's data security and data protection requirements. In the context of a public authority or body, the DPO should also possess a sound understanding of the organisation's administrative rules and procedures.[36]
For example: The DPO of a financial institution with numerous branches in different Member States should have not only a thorough understanding of data protection law but should also understand the organisation and the processes of the financial institution. Further, the DPO should have some level of understanding regarding the regulatory background of the financial industry.
Expert knowledge
The required level of expertise is not strictly defined but it must be commensurate with the sensitivity, complexity and amount of data an organisation processes. Recital 97 GDPR states that the necessary level of expert knowledge that the DPO should have should be determined according to what processing operations are being carried out, and what level of protection is necessary for the data that is being processed. The more complex the processing activities are, and the more measures of protection are needed, the more ‘knowledgeable’ the DPO will have to be.
"The required level of expertise is not strictly defined but it must be commensurate with the sensitivity, complexity and amount of data an organisation processes. For example, where a data processing activity is particularly complex, or where a large amount of sensitive data is involved, the DPO may need a higher level of expertise and support. There is also a difference depending on whether the organisation systematically transfers personal data outside the European Union or whether such transfers are occasional. The DPO should thus be chosen carefully, with due regard to the data protection issues that arise within the organisation."
WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 11.
Ability to fulfil its tasks
The data protection officer shall be designated on the basis of, among the others, the ability to fulfil the tasks referred to in Article 39 GDPR. These include, but are not limited to, tasks such as informing and advising the controller and processor of their obligations under the GDPR, monitoring compliance with the GDPR and assisting in assigning responsibilities and training staff involved in processing operations, providing assistance with Data Protection Impact Assessments (DPIAs) where needed and monitoring compliance with them, and finally, cooperating with the DPA and acting as a channel of communication. The WP29 recalls that the ability to fulfil the responsibilities entrusted to the DPO should be understood to encompass both their personal qualities and knowledge, as well as their position within the organization.[37]
For example, the Luxembourg DPA fined a logistics company €15,000 for failing to ensure that its DPO could exercise its tasks as outlined in Articles 39(1)(b) GDPR, inter alia because the DPO was not invited to all relevant meetings, and did not report directly to the highest level of management.[38]
Personal qualities should encompass attributes such as integrity and a strong commitment to professional ethics. The character and track record of a person designated as a data protection officer play a crucial role in their suitability for the role. Past breaches of confidentiality obligations, a known history of careless work, issues with alcohol or drug use, or relevant criminal convictions such as embezzlement or bribery are significant factors that need to be considered. Personal reliability can be seen as part of the broader requirement that the DPO is capable of effectively carrying out their responsibilities. Moreover, the data protection officer's personality traits are also important, ranging from the ability to collaborate constructively to the willingness to address data protection violations with management when necessary.[39]
(6) Internal or External DPO
Article 37(6) GDPR allows a designated DPO to be either a controller or processor’s staff member (i.e. internal DPO), or to alternatively be appointed on the basis of a service contract (i.e. external DPO). This provision can be interpreted as providing added flexibility to the controller or processor in deciding how to best employ a DPO for their organisation. Importantly, it does not require that the DPO is an entirely impartial body who is not associated with the controller or processor, much like an independent auditor might be. However, it is essential that the DPO fulfils the applicable requirements of Section 4 Chapter IV of the GDPR – for instance, that they have no conflict of interests. In particular, see Commentary on Article 37(5) and 38 GDPR for more information on the requirements.
While it is subject to some debate,[40] the WP29 seems to consider it possible to designate a legal person as DPO:
"When the function of the DPO is exercised by an external service provider, a team of individuals working for that entity may effectively carry out the DPO tasks as a team, under the responsibility of a designated lead contact and ‘person in charge’ of the client. In this case, it is essential that each member of the external organisation exercising the functions of a DPO fulfils all applicable requirements of the GDPR."
WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 23.
(7) Contact details of the DPO
Finally, Article 37(7) GDPR requires that the controller or processor (i) publishes the contact details of the DPO, and (ii) communicates them to the competent DPA.
"The objective of these requirements is to ensure that data subjects (both inside and outside of the organisation) and the supervisory authorities can easily and directly contact the DPO without having to contact another part of the organisation. Confidentiality is equally important: for example, employees may be reluctant to complain to the DPO if the confidentiality of their communications is not guaranteed."
WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 12.
Publish contact details of the DPO
The publication of the DPO's contact details will often be part of the information provided under Article 13 and 14 GDPR, i.e. in the controllers privacy policy. See therefore commentary on Article 13(1)(b) GDPR. In general, the published contact details must make it possible to reach the DPO in an easy way (e.g. a postal address, telephone number, and/or a dedicated e-mail address).[41] Since a postal address alone does not provide for an easy way to reach the DPO, in particular when the controller interacts with data subjects in an online context (e.g. providing services online), the contact details should at least contain a designated e-mail address.[42] While, it is not necessary to publish the DPO's name, internally, the employees of an organisation should be informed not just about the contact details of the DPO but also about the DPO's identity.[43]
Controllers might also provide a contact form addressed to the DPO, but since this cannot be considered as "contact details" in the literal sense, it should only be provided in addition to the controller's contact details. The WP29 pointed out that, "when appropriate, for purposes of communications with the public, other means of communications could also be provided, for example, a dedicated hotline, or a dedicated contact form addressed to the DPO on the organisation's website”.[44] Hence, the use of alternative forms, although not excluded by the GDPR, is not sufficient to fulfil the legal obligation if the contact details of the DPO are not provided in the first place. The contact form may, however, be provided in addition to the contact details.
Communicate contact details to the DPA
Regarding the communication of the DPO's contact details to the DPA, the WP29 points out that the communication of the DPO's name can be considered necessary since the DPO serves as the contact point between the organisation and the supervisory authority (see Article 39(1)(e) GDPR); the communication of a mere department mail address could therefore be considered insufficient.[45] In case a group of undertakings jointly appoint one DPO in accordance with Article 37(2) GDPR, each undertaking has to communicate the contact details to the respective competent DPA.[46]
Decisions
→ You can find all related decisions in Category:Article 37 GDPR
References
- ↑ The notion of appointing a DPO has its roots in Article 18(2) of the Data Protection Directive 1995 (Directive 95/46/EC) (DPD). However, although the DPD spoke about the designation of a DPO, it did not make this mandatory. With the GDPR’s introduction of the requirement to appoint a DPO in certain instances, the importance of the role embodied by the DPO can be said to have become pivotal.
- ↑ Indeed, the importance of appointing a DPO was confirmed by the European Data Protection Supervisor when they stated that “the Data Protection Officer is fundamental in insuring the respect of data protection principles within institutions/bodies”. EDPS, ‘Position Paper on the Role of Data Protection Officers in Ensuring Effective Compliance with Regulation (EC) 45/2001’, 28 November 2005, p. 3 (available here).
- ↑ EDPS, ‘Position paper on the role of Data Protection Officers of the EU institutions and bodies’, 30 September 2018, p. 14 (available here).
- ↑ WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 9 (available here).
- ↑ Baumgartner, in Ehmann, Selmayr, DS-GVO, Article 37 GDPR, margin number 17 (C.H. Beck 2024, 3rd Edition).
- ↑ See Commentary on Article 38(2) GDPR.
- ↑ König, in Knyrim, DatKomm, Article 37 GDPR, margin number 56 (Manz 2023).
- ↑ Heberlein, in Ehmann, Selmayr, DS-GVO, Article 37 GDPR, margin number 18 (C.H. Beck 2024, 3rd Edition); fore more information regarding the termination of the appointment of a DPO see e.g. König, in Knyrim, DatKomm, Article 37 GDPR, margin number 56 (Manz 2023).
- ↑ Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 37 GDPR, margin number 18 (C.H. Beck 2024, 4th Edition).
- ↑ WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 6 (available here); see also Commentary on Article 37(4) GDPR.
- ↑ WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 6 (available here); for a more differentiated opinion, see Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 37 GDPR, margin number 16 (C.H. Beck 2024, 4th Edition).
- ↑ WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 6 (available here). The WP29 also rightfully points out that "Such a DPO’s activity covers all processing operations carried out, including those that are not related to the performance of a public task or exercise of official duty (e.g. the management of an employee database)."
- ↑ Alvarez Rigaudias, Spinas, in Kuner et al., The EU General Data Protection Regulation (GDPR), Article 37 GDPR, p. 692 (Oxford University Press 2020).
- ↑ Alvarez Rigaudias, Spinas, in Kuner et al., The EU General Data Protection Regulation (GDPR), Article 37 GDPR, p. 692 (Oxford University Press 2020), see also Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 37 GDPR, margin number 17 (C.H. Beck 2024, 4th Edition).
- ↑ WP29, ‘Guidelines on Data Protection Officers (‘DPOs’)’, 16/EN WP 243 rev.01, 5 April 2017, p. 7 (available here).
- ↑ WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 7 (available here).
- ↑ WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 8 (available here).
- ↑ WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 8 et seq. (available here).
- ↑ WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 9 (available here).
- ↑ WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 8 (available here).
- ↑ WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 8 (available here).
- ↑ Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 35 GDPR, margin number 27 (C.H. Beck 2024, 4th Edition); see also Drewes, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 35 GDPR, margin numbers 30 (NOMOS 2025, 2nd Edition).
- ↑ Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 35 GDPR, margin number 27 (C.H. Beck 2024, 4th Edition).
- ↑ WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 10 (available here).
- ↑ See also the requirement in Articles 37(7), 13(1)(b) and 14(1)(b) GDPR.
- ↑ Compare Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 35 GDPR, margin number 28 and 29a (C.H. Beck 2024, 4th Edition) with reference to opposing opinions.
- ↑ WP29, ‘Guidelines on Data Protection Officers (‘DPOs’)’, 16/EN WP 243 rev.01, 5 April 2017, p. 10 (available here).
- ↑ Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 35 GDPR, margin number 29 (C.H. Beck 2024, 4th Edition).
- ↑ Drewes, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 35 GDPR, margin numbers 34 (NOMOS 2025, 2nd Edition).
- ↑ WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 11 (available here).
- ↑ Drewes, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 37 GDPR, margin numbers 38 (NOMOS 2025, 2nd Edition).
- ↑ Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 37 GDPR, margin number 26 (C.H. Beck 2024, 4th Edition).
- ↑ Alvarez Rigaudias, Spinas, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 37 GDPR, p. 695 (Oxford University Press 2020).
- ↑ For this interpretation see Drewes, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 37 GDPR, margin numbers 39 (NOMOS 2025, 2nd Edition); see also Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 37 GDPR, margin number 31 (C.H. Beck 2024, 4th Edition).
- ↑ WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 5 (available here).
- ↑ WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 11 (available here).
- ↑ WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 12 (available here).
- ↑ CNPD (Luxembourg) - Délibération n° 20FR/2021 (available here).
- ↑ Bergt, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 37 GDPR, margin number 35 (C.H. Beck 2024, 4th Edition).
- ↑ For an overview of this discussion see Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 37 GDPR, margin number 36 (C.H. Beck 2024, 4th Edition).
- ↑ WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 13 (available here).
- ↑ Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 37 GDPR, margin number 37 (C.H. Beck 2024, 4th Edition).
- ↑ WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 13 (available here).
- ↑ WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 12 (available here).
- ↑ WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 13 (available here).
- ↑ Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 37 GDPR, margin number 38b (C.H. Beck 2024, 4th Edition); oppising opinion Drewes, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 37 GDPR, margin numbers 69 (NOMOS 2025, 2nd Edition).




