When must a UK organisation appoint a data protection officer?
A DPO is mandatory for public authorities, for organisations whose core activities require regular and systematic monitoring of individuals on a large scale, and for those whose core activities consist of large scale processing of special category or criminal offence data. The DPO must report to the highest level of management, be free from instructions on how to carry out the role and must not be dismissed for performing it. Organisations outside the test may appoint one voluntarily, but then the same requirements apply.
Source
- Source
- UK GDPR Articles 37 to 39
- Acts
- Data Protection Act 2018
- Area
- Data protection and online duties
- Checked
- 2026-09-22
Questions
Nästa steg
Vill ni använda registret i eget arbete finns tre vägar in.
Börja med din uppgift
Advokat, tvist
Hitta stöd i avgörande
Sök i vägledande domar, se vad som vunnit laga kraft och följ ändringar i rättsläget.
Bolagsjurist, transaktion
Kartlägg regelverket i affären
Gå från tema till rättsakt och vidare till artikeln som bär kravet.
Compliance
Bedöm risken i en behandling
Riskklassning per rättsområde, med källorna bakom varje poäng.