Article 37
Designation of a Data Protection Officer
GDPR · Regulation (EU) 2016/679 · Last verified August 2026
Objective
Designate a data protection officer when required by public-authority status or qualifying core activities, publish contact details, and notify the supervisory authority.
Points of focus
- Assess DPO designation triggers against actual core activities
- Ensure expertise, independence, resources, and direct senior access
- Avoid conflicts between DPO monitoring and operational decisions
Implementation notes
Document designation analysis as products evolve, give the DPO direct board access and budget, publish reachable contact routes, and separate advisory monitoring from ownership of processing decisions. Operationalize assess dpo designation triggers against actual core activities in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain documented dpo applicability assessment with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that the privacy lead is named dpo while also deciding the purposes of processing Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample documented dpo applicability assessment with dates and named reviewers. Be ready to walk through how you detect and correct: the privacy lead is named dpo while also deciding the purposes of processing
Evidence auditors typically request:
- Documented DPO applicability assessment
- DPO charter, reporting line, and resource plan
- Published contact details and supervisory-authority notification
Common gaps
- The privacy lead is named DPO while also deciding the purposes of processing
- A group DPO exists on paper but is inaccessible to local data subjects
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| GDPR | Article 37 | This control |
| SOC 2 | CC3.2, CC6.1 | Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness. |
| ISO 27001 | A.5.34, A.8.10 | ISO privacy and security controls can implement parts of this duty when mapped to processing. |
| HIPAA | 164.308(a)(1) | HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data. |
Primary sources
- EUR-Lex GDPR Article 37: Regulation (EU) 2016/679, Article 37 — Designation of a Data Protection Officer