← All postsHow-to

Data protection officer: whether you need one, and what the role actually does

Appointing a data protection officer is a legal requirement for some organisations and a bad idea for others — because the role carries independence obligations that a part-time volunteer cannot meet.

How-toD

A data protection officer is a designated person responsible for overseeing how an organisation handles personal data — advising on obligations, monitoring compliance, and acting as the contact point for individuals and for the supervisory authority. Under the GDPR and equivalent regimes the role is defined, and in specific circumstances it is mandatory.

The question most small businesses actually have is simpler than the literature suggests: do we have to appoint one, and if not, what should we do instead? Both answers are usually clear once the triggers are known.

When one is required

  • Public authorities and bodies, essentially always.
  • Organisations whose core activities involve regular and systematic monitoring of people on a large scale — tracking, profiling, behavioural advertising at scale.
  • Organisations whose core activities involve large-scale processing of special category data: health, biometrics, political or religious views, criminal records.
  • Anywhere national law adds its own trigger, which several countries have done — Germany, for example, historically set a headcount threshold well below anything in the GDPR itself.
  • Core activities is the operative phrase. A shop that keeps staff health records is not processing them as a core activity; a company whose product is health data is.

Most small businesses meet none of these and are not required to appoint anyone. That is a finding worth writing down with the reasoning, because the question comes back — from a customer questionnaire, an insurer, or a prospective client's procurement form — and answering it from a note beats re-deciding each time.

What the role involves when it applies

  1. Advising the organisation on its obligations, and documenting that advice.
  2. Monitoring compliance, including assigning responsibilities and running awareness activity.
  3. Advising on data protection impact assessments where they are required.
  4. Cooperating with the supervisory authority and acting as its contact point.
  5. Being reachable by individuals whose data you hold, which means the contact details are published — commonly in the privacy policy.

The obligation people underestimate is independence. A data protection officer must not be instructed on how to perform the role, cannot be dismissed for doing it properly, and must not hold a position that creates a conflict of interest — which usually rules out the head of IT, the head of marketing, the head of HR, and the owner of a small company. Appointing somebody who cannot be independent is worse than not appointing at all, because it creates an obligation you are visibly failing.

What to do if you do not need one

Name somebody responsible anyway, without calling them a data protection officer — the title carries the legal role with it. Someone should own the record of what data you hold, answer requests within the deadline, and be the person who thinks about it before a new tool is adopted. In practice that means the register of processing, the retention position and the request procedure have an owner. Those pieces are covered in record of processing activities, data retention policy and subject access request.

Where the work lives

Ettex Records holds the processing register, retention positions and request log as structured entries with owners and dates, which is what the role — formal or informal — actually needs to do its job. The published disclosure sits in privacy policy and the surrounding rules in information security policy.

To be direct: this is not legal advice, we do not provide a data protection officer service, and whether you are required to appoint one depends on your jurisdiction and on facts about your processing that only you know. Where the answer is genuinely unclear — and it sometimes is — an hour of specialist advice is cheaper than either mistake.

Frequently asked

Does a small business need a data protection officer?

Usually not. The requirement applies to public authorities, to large-scale systematic monitoring, and to large-scale special category data — plus any additional trigger in national law.

Can the business owner be the data protection officer?

Rarely, because the role requires independence and freedom from conflict of interest. An owner, or a head of IT, marketing or HR, generally cannot meet that test.

What does a data protection officer do?

Advises on obligations, monitors compliance, advises on impact assessments, acts as contact point for the supervisory authority, and is reachable by individuals whose data you hold.

What should you do if you are not required to appoint one?

Give the responsibility a named owner without using the title, and make sure the processing register, retention position and request procedure are actually owned by somebody.

EP
Written by Elena P.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.