CHAPTER IV . Section 4
GDPR Article 37: Designation of the data protection officer
1. The controller and the processor shall designate a data protection officer in any case where:
(a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity;
(b) the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or
(c) the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 and personal data relating to criminal convictions and offences referred to in Article 10.
2. A group of undertakings may appoint a single data protection officer provided that a data protection officer is easily accessible from each establishment.
3. Where the controller or the processor is a public authority or body, a single data protection officer may be designated for several such authorities or bodies, taking account of their organisational structure and size.
4. In cases other than those referred to in paragraph 1, the controller or processor or associations and other bodies representing categories of controllers or processors may or, where required by Union or Member State law shall, designate a data protection officer. The data protection officer may act for such associations and other bodies representing controllers or processors.
5. The data protection officer shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39.
6. The data protection officer may be a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract.
7. The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority.
What this article means in practice
Written by Engage Compliance. The text above is the article itself, reproduced from its official source and unchanged. Everything in this section is ours, and last read against the current text on 2026-09-07.
Article 37 sets out who has to have a Data Protection Officer and what kind of person that has to be. The test is not your headcount and not your revenue. It is whether your core activities require regular and systematic monitoring of people on a large scale, or consist of large-scale processing of special category or criminal conviction data.
Who it binds
- Public authorities and bodies, except courts acting in their judicial capacity (Article 37(1)(a)).
- Controllers and processors whose core activities require regular and systematic monitoring of data subjects on a large scale (Article 37(1)(b)).
- Controllers and processors whose core activities consist of large-scale processing of Article 9 special category data, or of criminal conviction and offence data under Article 10 (Article 37(1)(c)).
- Anyone else may appoint one voluntarily, and Union or Member State law can require one in cases Article 37(1) does not reach (Article 37(4)). Germany's national threshold is the best known example.
What it makes somebody do
- You, the controller or processor. Designate the officer on the basis of professional qualities, in particular expert knowledge of data protection law and practice, and the ability to carry out the Article 39 tasks (Article 37(5)).
- You, the controller or processor. Publish the officer's contact details (Article 37(7)). Published means on a surface a data subject can find, not held internally.
- You, the controller or processor. Communicate those contact details to the supervisory authority (Article 37(7)). This is a notification to the authority, and it is separate from publishing them.
What it does not say
- It does not require an employee. Article 37(6) allows the tasks to be carried out on the basis of a service contract, which is what an outsourced or fractional DPO is.
- It does not require one officer per company. A group of undertakings may appoint a single officer under Article 37(2), as long as the officer is easily accessible from each establishment.
- It does not set a staff-count threshold anywhere. The core activities test is about what your business does, so a twelve-person company built on behavioral analytics can be caught while a five-hundred-person manufacturer is not.
- It does not name a qualification. Article 37(5) requires expert knowledge proportionate to the processing, not a specific certification.
- Registering the officer with an authority is not the phrase the Regulation uses. Article 37(7) is a communication of contact details to the supervisory authority, which is why a competent appointment is described as notified rather than registered.
How it sits beside the other mandates
- Article 37 is not Article 27. A company with no EU establishment can need an Article 27 representative and no DPO, or a DPO and no representative, or both. The two tests share no criterion.
- Articles 38 and 39 are what make this appointment real: 38 protects the officer's independence and reporting line, 39 lists the tasks. An appointment under 37 that ignores 38 is the common failure.
Source text: EUR-Lex, Official Journal consolidated HTML (CELEX 32016R0679). Recital short titles are editorial labels from gdpr-info.eu editorial short titles (not official). Cross-checked against gdpr-info.eu (independent reproduction).