Skip to content
+370 5 212 1506 info@dat.lt

Does our organisation need a data protection officer — and what happens when we appoint one of our own

23 September 2026 · Good to know

In most cases a private company does not need to appoint a data protection officer (DPO). Article 37(1) GDPR sets out three cases in which appointment is mandatory, and an ordinary trading, manufacturing, IT or services company meets none of them. HR records, accounting, a client list and video cameras at the entrance do not create the obligation. If you are a private company and nobody has explained to you which of the three cases applies to you, it is likely that none does.

This is not the answer people expect from a company that provides data protection services. But it is accurate, and it shapes everything that follows.

When a DPO is actually mandatory

Under Article 37(1) GDPR, the obligation is tied to three things: the processing is carried out by a public authority or body; the core activities require regular and systematic monitoring of individuals on a large scale; or the core activities consist of processing special categories of data on a large scale. The decisive word is “core”. It means the activity the organisation exists for, not the data processing that supports it.

That is why a school, a health clinic, a museum or a municipal institution usually falls within the obligation, while a construction company with twenty employees does not.

Article 37(4) GDPR also allows a DPO to be appointed where there is no obligation to do so. This is a lawful and increasingly common choice, most often prompted by public procurement or a large customer’s questionnaire. It is important to understand the consequence: a voluntarily appointed DPO is subject to exactly the same requirements as a mandatory one. Article 37(4) GDPR does not say this directly, but the Article 29 Working Party Guidelines on Data Protection Officers (WP243 rev.01), which the European Data Protection Board (EDPB) endorsed on 25 May 2018, state it: the requirements of Articles 37–39 GDPR on the designation, position and tasks of the DPO apply as if the appointment were mandatory. A voluntary appointment is not a lighter version.

Why “we will appoint one of our own” is often the worst of the three options

In practice we see the same decision again and again. An organisation decides that it does not need a DPO, or that buying one in is expensive, and by internal order appoints one of its employees as the “person responsible for personal data protection”. Most often this is an administrator, an HR specialist or someone from IT.

Such an employee often lacks the knowledge needed to ensure compliance with either the internal rules or the other GDPR requirements. Not through negligence — simply because it is not their field, and nobody has given them the time to make it so.

The risk of breaches and sanctions then barely goes down. Only one thing changes: the organisation believes it has reduced it. There are three possible options, and this one is the worst, because it costs money, costs the employee’s time and gives no protection. Doing nothing and knowing that you are doing nothing is a more honest position, because at least it does not create a false sense of security.

Article 39(1)(b) GDPR gives the DPO the task of monitoring compliance with the GDPR and with the organisation’s own internal policies. A person who does not know what to look for does not perform this function, even though the order appointing them remains in force.

Conflict of interest: the second most common mistake

The first mistake is a lack of knowledge. The second is combining roles.

Article 38(6) GDPR allows the DPO to carry out other tasks as well, but requires that these do not give rise to a conflict of interest. Article 38(3) GDPR requires that the DPO does not receive instructions regarding the exercise of their tasks and reports directly to the highest level of management.

A simple conclusion follows. A person who decides on the purposes and means of the processing cannot be the DPO. A chief executive, a head of IT or a head of HR cannot supervise their own decisions. In a small organisation there is often not a single available candidate left after this filter — and that is a fact better seen before the order is issued than during an inspection.

A third duty, consistently forgotten: Article 38(1) GDPR requires the DPO to be involved properly and in a timely manner in all issues relating to the protection of personal data. A DPO who learns about a new system only once it is already running exists formally, but not in practice. The dates on the correspondence show this at once.

And one more step that is not optional: Article 37(7) GDPR requires the DPO’s contact details to be published and communicated to the supervisory authority. An appointment without these two steps is incomplete.

The question worth asking any provider

If you decide to buy in the DPO function, there is one question that tells you more about the service than the price does.

Ask whether the contract sets a cap on hours and what happens once it is used up.

An hours cap is a risk for the buyer, not the provider. Once the cap is used up, unless the organisation pays extra, it is left without a DPO exactly when one is needed: during an inspection, during an incident, during a data subject request. A year in which nothing happens does not use up the cap. A year in which something does happen uses it up in a single week.

So it is worth buying the service by function, not by the hour. The question to the provider goes like this: do you perform the DPO function all year round, or are you selling me a certain number of hours? These are two different products at the same price.

What to do if you are not required to have a DPO

Your GDPR obligations do not disappear. You still have records of processing activities, privacy notices, contracts with service providers, retention periods and breach response. The only difference is that none of this work is assigned to a person with a title.

For many private companies the most honest solution is not to appoint a DPO, but to put the documents in order once and know whom to call when a question comes up.

How to start

We will tell you free of charge whether you are required to have a DPO — all we need is your field of activity and a short description of the data you process. If the answer is “not required”, that is exactly what we will write.

You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).

Email: info@linden.lt

More about this service: external data protection officer service.

Get a free assessment

Related articles