A person signing a formal document at a desk, representing the decision to appoint a Data Protection Officer

Do You Actually Need a Data Protection Officer?

September 06, 20269 min read

"We've got a DPO. It's Sarah in HR. She does it alongside payroll."

I hear a version of that sentence most months. The business owner is usually relieved to have ticked the box. Then I ask two questions, and the relief goes.

Does Sarah decide how you process personal data? And did anyone check whether you needed a DPO in the first place?

The answer to the first is normally yes, which means Sarah cannot lawfully be your DPO. The answer to the second is normally no, which means you may have appointed someone to a role you were never required to fill, and in doing so you have taken on legal obligations you did not know existed.

So let's sort it out. This article covers when UK GDPR forces you to appoint a Data Protection Officer, when it doesn't, what the role involves once you have one, and what to do if you fall in the gap between the two.

The three triggers that make a DPO mandatory

Article 37 of UK GDPR is short. You must appoint a DPO if any one of these applies:

  • You are a public authority or public body (courts and tribunals acting in their judicial capacity are the only exception).

  • Your core activities involve regular and systematic monitoring of individuals on a large scale.

  • Your core activities involve large scale processing of special category data, or data about criminal convictions and offences.

That is the whole list. There is no headcount threshold. There is no turnover threshold. A six person company can be caught. A 600 person company can be exempt.

The words doing the heavy lifting are "core activities" and "large scale", and the ICO has been clear about what they mean.

What counts as a "core activity"

Core activities are the things your business exists to do. Processing personal data as a side effect of running a company does not count.

Every employer holds staff records, sickness absence, bank details and emergency contacts. Some of that is special category data. None of it makes HR a core activity, because you are not in the business of employing people. You are in the business of selling widgets, or fixing boilers, or giving financial advice.

Compare that with a private GP practice, a dental group, an occupational health provider, or a recruitment agency handling right to work and DBS checks at volume. For those businesses, processing health data or criminal records data is the job. That is core.

The test I use with clients: if you stopped this processing tomorrow, could you still deliver your service? If the answer is no, it is a core activity.

A desk with paperwork, a laptop and a coffee, where a business owner is working through compliance documents

What counts as "large scale"

UK GDPR does not give a number. The ICO tells you to weigh up:

  • how many people are affected;

  • the volume and range of data you hold on each of them;

  • how long you keep it;

  • how wide the geographical reach is.

A single dentist with 1,800 patients on the books is processing health data as a core activity, but the regulatory guidance the ICO follows treats an individual practitioner as not large scale. A chain with 14 practices and 60,000 patient records is a different conversation.

The same logic applies to monitoring. A local gym with a swipe in system is tracking attendance. That is monitoring, and it is regular and systematic, but it is not large scale. A fitness app with 200,000 users and location tracking switched on is all three at once.

"Regular and systematic monitoring" is wider than you think

This one catches marketing led businesses out. The ICO includes all forms of tracking and profiling, online and offline, and names behavioural advertising as an example.

If your business model relies on retargeting pixels, profiling customers to score them, telematics in vehicles, wearable data, loyalty schemes that track purchases to predict behaviour, or CCTV across multiple sites, you are monitoring. Whether it is large scale depends on the factors above.

Most small firms running a Facebook pixel on a brochure website are nowhere near the threshold. An adtech company, a data broker, or a lead generation business almost always is.

Did the Data (Use and Access) Act change any of this?

Not for the DPO rules.

The earlier bill, the one that fell before the 2024 election, was going to scrap the DPO role and replace it with a "senior responsible individual". That idea did not survive. The Data (Use and Access) Act 2025 kept the DPO regime, and Articles 37, 38 and 39 still stand. The only change the Act made to them was a minor tidy up in August 2025, adding tribunals alongside courts to the judicial exemption. It changes nothing for a business, school or charity.

The Act as a whole is being brought into force in stages, and other parts of it do change UK data protection law. But the rules on whether you need a DPO, and what a DPO must do, read as they did before. So if someone told you in 2023 that DPOs were being abolished, they were describing a bill, not a law.

What you take on when you appoint one

This is the part that gets missed when a business appoints a DPO because it sounded like the responsible thing to do.

Once you have a DPO, whether required or voluntary, the same rules apply. The ICO says so in its own guidance. Your DPO must:

  • report to the highest level of management;

  • act independently, with no instructions from you on how to do the job;

  • be protected from dismissal or penalty for doing the job;

  • have the budget, time and access to data needed to do it;

  • be involved, early, in every issue that touches personal data;

  • be the contact point for the ICO and for individuals;

  • have their contact details published and sent to the ICO.

And the one that rules out most internal appointments: the DPO cannot hold a role where they decide the purposes or means of processing personal data.

That excludes the owner. It excludes the MD, the finance director and the head of marketing. It excludes the head of HR, because HR decides how staff data is used. It excludes the IT manager, because IT decides how data is stored and secured. The ICO's position is that the DPO monitors those decisions. They cannot mark their own homework.

"Sarah in HR" fails on independence, on conflict of interest, and on resourcing. Naming her DPO does not make you compliant. It creates a compliance problem that did not exist before.

A team meeting around a table, discussing who holds responsibility for data protection in the business

What happens if you get it wrong

Failing to appoint a DPO when you are required to, or appointing one who cannot do the job, sits in the lower tier of UK GDPR penalties: up to £8.7 million or 2% of global annual turnover.

Nobody expects the ICO to fine a small UK firm £8.7m for a missing DPO on its own. That is not how the ICO uses its powers. The way it plays out in practice is that something else goes wrong, a breach or a complaint, and the ICO's investigation turns up that the organisation had no DPO, or a DPO who was also the IT manager and had never been given a day to do it. The missing DPO then becomes evidence of a wider accountability failure, and the penalty for the original problem goes up.

"We didn't think we needed one" is not a defence. The ICO expects you to have done the assessment and written down the result.

The middle ground most UK SMEs sit in

After more than ten years in data protection, my read is that most UK businesses under 250 staff are not legally required to appoint a DPO. Most of them still have a data protection problem.

They hold customer data, staff data, supplier data and marketing lists. They get subject access requests they do not recognise as subject access requests. They have a privacy notice copied from a competitor's website in 2018. They have had at least one "does anyone know if we're allowed to do this?" moment in the last quarter, and nobody knew.

The law does not require a DPO for that business. It does require the business to comply with everything else in UK GDPR, and somebody has to own that.

You have three sensible options:

  • Nominate a data protection lead internally. Do not call them a DPO. Give them a clear remit and some training. Document that you assessed the DPO requirement and concluded it did not apply, and why.

  • Appoint a voluntary DPO, but only if you are prepared to meet the full Article 38 and 39 obligations. Half a DPO is worse than none.

  • Appoint an outsourced DPO. UK GDPR allows the role to be filled under a service contract. You get the independence and the expertise without a full time salary, and the conflict of interest problem disappears because the person is not making your business decisions.

The third route is the one I provide, so weigh that when you read it. It is also the one the ICO recognises as valid, and for a business that processes sensitive data at any real volume it is the cheapest way I know of to meet the requirement in full.

Three questions to answer this week

  • Is processing health, biometric, criminal records or other special category data part of what your business sells, and if so, at what volume?

  • Does your business track, profile or monitor people as part of how it makes money, beyond basic analytics?

  • If you already have someone called a DPO, can they say no to the MD and keep their job?

If the answer to either of the first two is yes, you need to do the formal assessment now, and you should expect the answer to be that you need one. If the answer to the third is no, you have a DPO in name only, and the ICO will treat it that way.

If you are not sure where you land, that is normal. The test was written for a regulation covering the whole of Europe and it was never going to be crisp for a 40 person firm in Leeds.

I work with UK businesses as their outsourced DPO, and I can run the assessment for you and give you a written conclusion you can show the ICO. If you want a straight answer on whether you need one, get in touch. No obligation, no jargon.

Alex Goodman
Alex Goodman|DPO and GDPR expert|LinkedIn logo icon
Alex Goodman has over 10 years of experience in data protection. He has handled compliance for organisations across financial services, SaaS, healthcare, enforcement, charity, and children's data, first inside large regulated businesses and now as an independent adviser. He holds practitioner certifications in Data Protection Impact Assessments and Subject Access Requests, and is an accredited Counter Fraud Investigator.
Back to Blog

Alex Goodman is an experienced GDPR consultant and outsourced Data Protection Officer working with UK businesses to improve their DPO and GDPR compliance.

© 2026 - GDPR Consultant - All Rights Reserved.

Driven by expertise and personalised service, we’re here to guide you towards GDPR compliance every step of the way.

© 2026 - GDPR Consultant - All Rights Reserved.