Practical summary
The GDPR requires appointment of a Data Protection Officer (DPO) in three main cases: public bodies, regular and systematic monitoring on a large scale, or large-scale processing of sensitive/criminal-offence data. The role can be outsourced (firm, independent professional, shared DPO). Even when not mandatory, many businesses choose an outsourced DPO for expertise, independence and cost control.
Outsourced DPO: definition and legal framework
The DPO is the expert responsible for advising, monitoring and liaising with the supervisory authority. The legal bases are Articles 37 to 39 of the GDPR (EUR-Lex). The appointment can be internal or external (service contract): Article 37(6) expressly permits this. CNIL details the tasks, safeguards for independence and DPO notification arrangements (CNIL).
Key points:
- Who is concerned? Controllers and processors when the Article 37(1) criteria are met (EUR-Lex).
- Common myth: the “250 employees” threshold is not a DPO criterion; it mainly concerns the record of processing activities (Art. 30), not DPO appointment (Legifrance).
- Independence and absence of conflicts of interest: requirements set out in Article 38 GDPR and the EDPB guidelines on DPOs (EDPB).
- Notify the DPO’s contact details to the competent supervisory authority (Art. 37(7)); in France, through CNIL’s online service (CNIL).
When must you appoint a DPO? Typical cases
The general obligation (Art. 37 GDPR)
- Public authority or public body (excluding courts acting in their judicial capacity);
- Core activity involving regular and systematic monitoring of individuals on a large scale (e.g. adtech, remote monitoring, apps with extensive profiling);
- Core activity consisting of large-scale processing of sensitive data (Art. 9) or criminal-offence data (art. 10).
Practical examples (startups/scale-ups)
- B2C analytics/marketing SaaS tracking millions of users (profiling, scoring, retargeting): regular and systematic large-scale monitoring → DPO required.
- Healthtech processing health records for thousands of patients: sensitive data on a large scale → DPO required.
- Fintech fighting fraud using overall scoring: large-scale monitoring + potentially sensitive data → DPO required.
- HRtech managing multi-customer HR records (SSO, payroll, absences) on a large scale → DPO required for the processor.
Optional but worthwhile appointment
Many businesses appoint a DPO voluntarily to structure compliance (records, DPIAs, breaches, rights requests). This is particularly relevant for SaaS vendors and AI products. In practice, the DPO also oversees consistency between your privacy policy and contracts. On these topics, see our guide to drafting a GDPR privacy policy and our advice on a processing agreement compliant with Article 28 GDPR.
Why outsource the DPO role?
- Immediately available expertise: monitoring developments, audits, DPIAs and incident management. CNIL recalls the “expert knowledge” requirement (Art. 37(5)) (CNIL).
- Greater independence: outsourcing helps avoid conflicts of interest (EDPB DPO guidelines) (EDPB).
- Controlled costs and flexibility: a package suited to size/risk, without the costs of an internal position; see the analysis of this approach on France Num and the benefits identified by Actecil (Actecil).
- Multidisciplinary coverage: legal, security, product and team training.
- Liability: the DPO advises and monitors; the controller remains legally responsible for GDPR compliance (Art. 24, 39) (EUR-Lex).
How to select and structure an outsourced DPO engagement
Selection criteria
- Verifiable experience in GDPR audits, DPIAs, breach management and dealings with authorities.
- Sector knowledge (SaaS, health, fintech, adtech, AI) and knowledge of processing chains.
- Accessibility for data subjects and authorities (Art. 38(4)).
- Independence documented, with a conflict-of-interest management procedure (EDPB).
- Languages and cross-border expertise (EEA/UK, international transfers).
Essential clauses in an external DPO contract
- Purpose and scope: Article 39 GDPR tasks, annual roadmap and KPIs (incidents handled, DPIAs, training).
- Resources and access: access rights to information, business contacts, tools and budget (Art. 38(2)).
- Independence: no instructions on how tasks are performed, and an escalation channel to management.
- Conflicts of interest: incompatible roles (e.g. CIO, product CPO, marketing) and removal procedure.
- Confidentiality and security: technical clauses (access logs, retention, encryption).
- Breach management: on-call arrangements, analysis and notification SLAs (Art. 33/34), incident register.
- Use of substitutes and business continuity, professional insurance.
- International transfers: if access occurs outside the EU, use Standard Contractual Clauses (SCCs) and a country assessment (EDPB, EUR-Lex).
If your product incorporates AI, align the GDPR roadmap with our good practice on GDPR obligations applicable to AI systems.
Step-by-step appointment and notification procedure
- Assess the obligation: apply the Article 37 criteria and document the decision (signed internal memo, “large-scale”, “core activity” and “regular and systematic monitoring” criteria). CNIL and EDPB guidance is useful (CNIL, EDPB).
- Appoint the DPO (internal/external, potentially shared within a group: Art. 37(2)-(3)) and document tasks, resources and position in writing.
- Notify CNIL of the DPO (Art. 37(7)) through the online service; provide identity/contact details and those of the controller/processor (Service Public Pro, CNIL).
- Inform individuals: identify the DPO and provide contact details in your privacy policy (Art. 13/14). Drafting support: GDPR privacy policy.
- Launch the first 100 days: processing map, Article 30 record, DPIA plan, review of processing agreements, breach-management policy and training.
DPO outside the EU: feasibility and precautions
The GDPR does not formally require the DPO to be established in the EU; they must be easily accessible (Art. 37(2), 38(4)) to the authority and individuals (EDPB). However, if an external DPO accesses data from a “third” country, that access constitutes an international transfer: implement Standard Contractual Clauses and an assessment of the destination country (SCCs + supplementary measures) (EDPB, EUR-Lex).
Penalties and business implications
Failure to appoint a DPO when mandatory is punishable by a fine of up to €10m or 2% of worldwide turnover (Art. 83(4)(a) GDPR: EUR-Lex). Beyond CNIL risk, having a DPO and robust documentation has become a prerequisite in investor audits. Prepare ahead by preparing your legal data room.
Short FAQ
Is a DPO mandatory from 250 employees?
No. This threshold mainly concerns the record of processing activities (Art. 30). DPO appointment depends on the Article 37 criteria (large-scale monitoring, sensitive data, public body).
Must a processor also appoint a DPO?
Yes, if it meets the Article 37 criteria (e.g. large-scale processing on behalf of many customers).
Is the DPO liable for non-compliance?
No. They advise and monitor (Art. 39). Liability rests with the controller/processor (Art. 24, 28).
Can a DPO be shared?
Yes, within a group or a set of organisations, if the DPO is easily reachable from each establishment (Art. 37(2)-(3)).
For product and AI leaders, also see our practical advice on GDPR and AI and our contractual good practice for GDPR processing arrangements.
Further reading
Related resources
Frequently asked questions
FAQ
When is a DPO mandatory under the GDPR?
For public bodies, core activities involving regular and systematic monitoring on a large scale, or large-scale processing of sensitive or criminal-offence data (Art. 37 GDPR).
Is an outsourced DPO permitted?
Yes. Article 37(6) GDPR permits appointment of an external DPO under a service contract, with the same tasks and safeguards for independence as an internal DPO.
Must CNIL be notified of the DPO?
Yes. Whenever a DPO is appointed (mandatorily or voluntarily), their contact details must be communicated to the competent supervisory authority (Art. 37(7) GDPR).
Can the DPO be located outside the EU?
Yes, if easily accessible to the authority and data subjects. However, any access to data from a third country must be safeguarded (SCCs, country assessment).
Who is liable for GDPR non-compliance?
The controller (or processor) remains liable. The DPO advises, monitors and cooperates with the authority (Art. 39 GDPR).
References
Sources used
Training · Audit · Support
Put what you read into practice
Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.