Many small and medium businesses worry they must formally appoint a Data Protection Officer (DPO). In fact, most do not have to. A DPO is mandatory only in specific situations under the UK GDPR. Here is how to tell whether your company needs one, and what to do if it does not.
When a DPO is mandatory
Under Article 37 of the UK GDPR, you must appoint a DPO if any of the following applies:
- you are a public authority or body (other than courts acting judicially);
- your core activities consist of large-scale, regular and systematic monitoring of individuals (for example, large-scale tracking or behavioural profiling); or
- your core activities consist of large-scale processing of special category data (such as health, ethnicity or religious data) or data about criminal convictions and offences.
The key words are core activities and large scale. Processing personal data that is just incidental to your business (like running payroll or a customer list) usually does not trigger the requirement. Most ordinary SMEs fall outside it.
If you don't legally need one
Even where a DPO is not mandatory, you still have to comply with data protection law. Good practice is to:
- appoint a privacy lead (not a formal DPO) to own day-to-day compliance;
- keep a record of your processing (what data, why, lawful basis, retention);
- have a privacy notice and an internal data protection policy;
- train staff, control access, and have a plan for breaches and individuals' rights requests.
You can give someone responsibility for data protection without using the formal "DPO" label and its specific legal requirements.
If you do appoint a DPO (mandatory or voluntary)
A DPO carries legal protections and responsibilities:
- they must be able to act independently, report to the highest level of management, and must not have a conflict of interest (UK GDPR, Article 38), so they should not also be the person who decides how and why data is processed;
- they advise on and monitor compliance, act as a contact point for individuals and the ICO, and advise on Data Protection Impact Assessments.
Because of the independence rule, many businesses that need a DPO use an external/outsourced DPO to avoid conflicts and ensure expertise.
Practical guidance
- Assess whether your core activities involve large-scale monitoring or sensitive-data processing, if not, you likely don't need a DPO.
- Either way, comply with the UK GDPR and document your processing.
- If you do appoint a DPO, make sure they are independent and conflict-free (consider an external DPO).
Key takeaways
- A DPO is mandatory only for public authorities, or where core activities involve large-scale monitoring or special category/criminal data (UK GDPR, Article 37).
- Most SMEs do not need a formal DPO, but must still comply with data protection law.
- A non-mandatory privacy lead can own compliance without the formal DPO role.
- Any DPO must be independent and conflict-free (Article 38); an external DPO is a common solution.
Sources
- UK GDPR, Articles 37–39 (when a DPO is required; position and tasks)
- Data Protection Act 2018
- ICO guidance on Data Protection Officers
--- This article is general information about the law of England & Wales as at 2026, not legal advice. For advice on your circumstances, consult a qualified solicitor.