Do I Need a Data Protection Officer (DPO)?
A Data Protection Officer is only legally required in three situations under the UK GDPR: you're a public authority, your core work involves large-scale monitoring of people, or you routinely handle special-category or criminal-offence data at scale. Most small businesses don't meet this test — but you still need a named, competent person responsible for data protection. Here's how to tell which side of the line you're on.
The short answer
Most small businesses do not need to appoint a formal Data Protection Officer. The role is only legally required in specific circumstances, and running a shop, agency, practice or trades business rarely triggers them. But there is an important catch: even when a DPO is not mandatory, someone in your business still needs to own data protection. Getting this distinction right saves you from both over-engineering and quiet non-compliance.
When a DPO is legally required
Under Article 37 of the UK GDPR, you must appoint a Data Protection Officer in only three situations:
- You are a public authority or public body (courts acting in their judicial capacity are the exception). This covers organisations like councils, schools, NHS bodies and government departments.
- Your core activities involve regular and systematic monitoring of individuals on a large scale. Think of an organisation whose main business is tracking behaviour — large-scale profiling, ad-tech, location tracking or behavioural advertising networks.
- Your core activities involve large-scale processing of special category data, or data about criminal convictions and offences. Special category data includes health, race, religion, sexual orientation, biometric and genetic data.
If none of these apply, the law does not require you to appoint a DPO.
What “core activities” and “large scale” really mean
Two phrases do a lot of work here, so it’s worth being precise.
Core activities are the primary things you do to deliver your service — not routine back-office admin. Every business processes staff payroll and holds some customer contact details, but that is ancillary, not core. A private hospital’s core activity is delivering healthcare (which needs health data); a security firm’s core activity may be systematic CCTV monitoring. A café’s core activity is selling coffee.
Large scale has no fixed number in the legislation. Regulators look at things like the number of people affected, the volume and range of data, how long the processing lasts, and its geographical reach. A single GP surgery is generally treated as not large scale; a hospital or a national health app is. When you’re genuinely unsure, the safe move is to document your reasoning.
Most small businesses need a responsible person, not a DPO
Here’s the part that trips people up. Not being legally required to appoint a DPO is not the same as having no one responsible for data protection.
The UK GDPR still expects you to comply with all its principles — lawfulness, transparency, security, accountability and the rest. In practice that means naming a person (often the owner, a director or an office manager) who:
- knows what personal data you hold and why
- keeps your privacy notice, records and policies up to date
- handles data subject requests and any personal data breaches
- is the point of contact for staff questions and, if needed, the ICO
This person is not a statutory DPO. They can be fully involved in business decisions, they have no special legal protections, and you can call the role whatever you like — just don’t call them your “Data Protection Officer”, because that specific title carries legal duties (more on that below).
What a statutory DPO actually involves
If you do fall within Article 37, the role is more than a job title. A formal DPO comes with obligations under Articles 38 and 39:
- Independence. They must be free to act without instruction on how to carry out their tasks and cannot be dismissed or penalised for doing the job properly.
- No conflict of interest. They can’t also be the person who decides the purposes and means of processing — so your IT director, head of marketing or managing director usually can’t double up as DPO.
- A direct line to the top. They report to the highest level of management.
- Expert knowledge of data protection law and practice, proportionate to your processing.
- Published contact details. You must publish the DPO’s contact details and provide them to the ICO.
A DPO does not have to be an employee. Many organisations that need one appoint an external, outsourced DPO on a contract — which can be more practical and cost-effective than hiring in-house.
Appointing a DPO voluntarily — a word of caution
You can choose to appoint a DPO even when you’re not required to. But be aware: if you formally designate someone as your DPO, the ICO expects the same legal requirements to apply — independence, no conflict of interest, the statutory tasks and protections. So don’t hand the title to your busy office manager as a nice-sounding label. If you only want someone accountable for data protection, give them a different job title (for example, “data protection lead”) and keep the flexibility.
A quick decision checklist
Work through these:
- Are you a public authority or public body? If yes — you need a DPO.
- Is large-scale, regular, systematic monitoring of people one of the main things your business does? If yes — you likely need a DPO.
- Is large-scale handling of health, biometric, criminal-offence or other special category data one of your core activities? If yes — you likely need a DPO.
- If you answered no to all three, you probably don’t need a formal DPO — but you do need a named, competent person responsible for data protection.
If any answer is “maybe”, write down your reasoning and the data you process. That record is itself part of good accountability.
Getting it right
The goal isn’t to appoint the grandest-sounding role you can; it’s to make sure someone competent genuinely owns data protection and that you can show your reasoning. For most small businesses in Leeds and across Yorkshire, that means a clear internal owner, sensible policies and good security — not a statutory DPO.
If you’d like a hand working out where your business sits, or getting your data protection housekeeping in order, talk to our team. We help small businesses keep compliance proportionate and practical — see how we approach managed IT and cyber security, and if you’re still finding your feet with the rules, start with our GDPR basics for UK small business guide.
Frequently asked questions
Does every business that handles personal data need a DPO?
No. Nearly every business processes some personal data, but a formal DPO is only mandatory in three cases: you're a public authority, large-scale monitoring of people is a core activity, or large-scale handling of special-category or criminal-offence data is a core activity. Most small businesses meet none of these.
Can the business owner be the Data Protection Officer?
If a statutory DPO is required, usually not — the DPO can't also be the person who decides the purposes and means of processing, which is a conflict of interest. If a DPO isn't required, the owner can absolutely be the responsible person for data protection, just under a different job title rather than 'DPO'.
Can we outsource the DPO role?
Yes. A DPO does not have to be an employee. Many organisations that need one appoint an external, outsourced DPO under a contract, which is often more practical and cost-effective than hiring in-house.
What's the difference between a DPO and a 'data protection lead'?
A DPO is a statutory role with legal protections and duties under the UK GDPR — independence, no conflict of interest, and published contact details. A data protection lead is an informal internal owner you appoint voluntarily; they carry no special legal status, so you keep more flexibility.
Dacros — led by Jordan Gilbert
Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.
Related guides
The backup password on the laptop you're backing up
Recovery controls fail in a way audits miss: the control quietly depends on the very thing it is meant to recover you from. We found five in our own systems in a week — here's the one question that finds them, and a two-hour fix.
Read → GuideIT and Cyber Security for Charities and Non-Profits in the UK
A plain-English guide to IT and cyber security for UK charities: protecting donor and beneficiary data, controlling volunteer access, and Cyber Essentials on a tight budget.
Read → GuideIT & Cyber Security for Solicitors and Law Firms: A Plain-English Guide
A practical guide to IT security for UK law firms: client confidentiality, SRA-aligned controls, secure email and documents, DMARC, backups and staying compliant.
Read →Want this handled for you?
Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.