Skip to main content
  • About
  • News & Insights
  • Careers
  • International
0808 291 3524
Dialog that contains search functionality
Irwin Mitchell Logo
  • Personal
    • Personal
    • Personal Home
    • Personal Injury Claims
      • Personal Injury Claims
      • Personal Injury Claims Home
      • Abuse Claims
      • Accidents In Public Places Claims
      • Criminal Injury Compensation Claims
      • Accident At Work Claims
      • Air, Rail & Maritime Claims
      • Asbestos & Mesothelioma Claims
      • Changing Solicitors During a Personal Injury Claim
      • Group Claims
      • Holiday Accidents & Illness Claims
      • Illness Compensation Claims
      • Industrial Disease Claims
      • Injury Types
      • Military Injury Compensation Claims
      • No Win No Fee Personal Injury Claims
      • Personal Injury Claims In Scotland
      • How To Claim Compensation For Personal Injury
      • Product Liability Claims
      • Road Traffic Accident Claims
      • Serious Injury Claims
      • Who Can Help?
      • Support Services
    • Medical Negligence Claims
      • Medical Negligence Claims
      • Medical Negligence Claims Home
      • Cancer Misdiagnosis Claims
      • Birth Injury Claims
      • Cauda Equina Syndrome Claims
      • Never Event Claims
      • Ambulance & Paramedic Medical Negligence Claims
      • Cosmetic Surgery Claims
      • Private Healthcare Claims
      • Cerebral Palsy Claims
      • Defective Medical Device Claims
      • Dental Negligence Claims
      • Diabetes Misdiagnosis Claims
      • Fatal Medical Negligence Claims & Inquests
      • GP Negligence Claims
      • Hospital Negligence Claims
      • What Is Medical Negligence?
      • Meningitis Misdiagnosis Claims
      • Failure To Prevent Suicide Claims
      • Misdiagnosis Claims
      • Ophthalmic Negligence Claims
      • Pregnancy & Gynaecology Injury Claims
      • Sepsis Negligence Claims
      • Pharmacy And Medication Negligence Claims
      • Shrewsbury & Telford Hospital NHS Trust Maternity Care Claims
      • Stroke Misdiagnosis Claims
      • Surgery Compensation Claims
    • Counselling
      • Counselling
      • Counselling Home
      • Counselling Myths Dispelled
    • Family Law
      • Family Law
      • Family Law Home
      • Divorce Solicitors
      • Prenuptial & Postnuptial Agreement Solicitors
      • Child Abduction Solicitors
      • Civil Partnership Solicitors
      • LGBT+ Family Law Solicitors
      • Unmarried Couples' Rights
      • Divorce Financial Settlement Solicitors
      • Child Arrangement Orders
      • Family Mediation
      • Out of Court Divorce Solicitors
      • Separation Agreement Solicitors
      • Adoption & Surrogacy Solicitors
    • Wills, Trusts & Estates
      • Wills, Trusts & Estates
      • Wills, Trusts & Estates Home
      • Estate Planning Solicitors
      • Powers Of Attorney
      • Trusts
      • Will Writing Services
      • Will Disputes & Contentious Probate
    • Conveyancing & Property Solicitors
      • Conveyancing & Property Solicitors
      • Conveyancing & Property Solicitors Home
      • Conveyancing Fees Calculator
      • Buying A Property
      • Selling A Property
      • Remortgage
      • Transfer Of Equity
      • Buy To Let
      • Freehold Purchase (Leasehold Enfranchisement) Solicitors
      • Lease Extension Solicitors
      • Conveyancing Guide
      • Residential Property Disputes
    • Tax
      • Tax
      • Tax Home
      • Business Tax
      • Inheritance Tax
      • International Tax
      • Professional Negligence
      • HMRC Tax Investigations
      • Tax Disputes & Litigation
      • Tax Residence
      • Tax Returns & Compliance
      • UK Resident Non-Doms
      • Wealth Structuring
    • Probate
      • Probate
      • Probate Home
      • International Probate
      • Probate Sale Conveyancing
      • What Is Probate & How Does It Work?
    • Will, Trust & Estate Disputes
      • Will, Trust & Estate Disputes
      • Will, Trust & Estate Disputes Home
      • Trust Disputes
      • Inheritance Act Claims
      • Contesting A Will
      • Contentious Probate
      • Pre-Death Agreements
      • Professional Negligence
      • Challenging A Lifetime Gift
      • Financial Abuse
      • Statutory Will Disputes
      • Defending A Contested Will
    • Employment Solicitors
      • Employment Solicitors
      • Employment Solicitors Home
      • Employment Contract Solicitors
      • Employment Disputes
      • Dismissal & Redundancy Solicitors
      • Employment Discrimination Solicitors
      • Employment Lawyers for Legal Expenses Insurance
      • Harassment & Bullying At Work Solicitors
      • Parental & Family Friendly Employment Rights
      • Professional Discipline Solicitors
      • Recruitment & Promotion
      • Senior Executive Employment Lawyers
      • Settlement Agreements
      • Whistleblowing Solicitors
    • Elderly Legal Services
    • Protecting Your Rights
      • Protecting Your Rights
      • Protecting Your Rights Home
      • Actions Against The Police
      • Inquests
      • Environmental & Planning Law
      • Assessment & Treatment Unit Solicitors
      • Data Protection Breach Claims
      • Education Law
      • Healthcare & Social Services
      • Human Rights
      • Judicial Review
      • Mental Capacity
      • Professional Regulation & Discipline
      • Dispute Resolution
      • Legal Aid
    • Immigration Solicitors
      • Immigration Solicitors
      • Immigration Solicitors Home
      • British Citizenship & Naturalisation Solicitors
      • EU & EEA Immigration Solicitors
      • Indefinite Leave To Remain Solicitors
      • Spouse Visa Solicitors
      • Innovator Visa
      • Permanent Residence Solicitors
      • Business Immigration Solicitors
    • Crime & Investigations
      • Crime & Investigations
      • Crime & Investigations Home
      • Crime
      • Fraud & Financial Crime
      • Court Martial Solicitors
      • Motoring Offences Legal Advice
      • Regulatory Investigations & Enforcement
    • Insolvency
      • Insolvency
      • Insolvency Home
      • Business Restructuring & Insolvency
      • Debt Consultancy
      • Insolvency Disputes & Litigation
    • Court Of Protection
      • Court Of Protection
      • Court Of Protection Home
      • Court Of Protection Deputyship
      • Personal Injury Trusts
      • Court Of Protection Problems & Disputes
      • Healthcare and Social Services
      • Court of Protection Frequently Asked Questions
      • Powers Of Attorney Disputes
      • Statutory Wills Solicitors
  • Wealth Management
    • Wealth Management
    • Wealth Management Home
    • Asset Management For Personal Injury
    • Charity & Philanthropy
    • Estate Planning
    • Ethical & Sustainable Investing
    • Financial Planning
    • Intergenerational Wealth Management
    • Investment Management
    • Retirement Financial Planning
    • Family Offices
    • Succession Planning
    • Tax Planning
  • Business
    • Business
    • Business Home
    • Sectors
      • Sectors
      • Sectors Home
      • Agriculture & Rural Business
      • Retail, Leisure & Hospitality
      • Education
      • Financial & Professional Services
      • Landed Estates
      • Manufacturing
      • Real Estate
      • Sport
      • Technology & Communications
    • Banking & Finance
      • Banking & Finance
      • Banking & Finance Home
      • Corporate Banking
      • Leveraged & Acquisition Finance
      • Real Estate Finance
      • Receivables Finance & Asset Based Lending
    • Environmental, Social & Governance
      • Environmental, Social & Governance
      • Environmental, Social & Governance Home
      • Cyber Security
      • Environment
      • Net Zero
      • Social
      • Diversity & Inclusion
      • Governance
      • International
      • ESG Legal Advisory Services
      • Legislation Library
      • Manufacturing Sector
      • Real Estate
      • Retail, Leisure and Hospitality Sector
      • Sports Sector
    • Business Crime
      • Business Crime
      • Business Crime Home
      • Anti-Bribery & Corruption
      • Asset Tracing & Recovery
      • Cartels & Illegal Price Fixing
      • Cybercrime
      • Dawn Raids
      • Deferred Prosecution Agreements
      • Extradition
      • INTERPOL Red Notices
      • Mutual Legal Assistance
      • Private Prosecution
      • Proceeds Of Crime Act
      • Unexplained Wealth Orders
      • Fraud Lawyers
      • Insider Trading & Market Abuse
      • Corporate Internal Investigations
    • Business Immigration
      • Business Immigration
      • Business Immigration Home
      • Business Visitor Visa
      • Global Business Mobility Visas
      • Innovator Visa
      • Prevention Of Illegal Working
      • Skilled Worker Visas
      • Sole Representative Of An Overseas Business
      • UK Visa Sponsor License
    • Commercial
      • Commercial
      • Commercial Home
      • Commercial Contracts
      • Competition Law
      • GDPR & Data Protection
      • Information Technology
      • Sourcing
      • Notary Public Solicitors
    • Commercial Litigation & Dispute Resolution
      • Commercial Litigation & Dispute Resolution
      • Commercial Litigation & Dispute Resolution Home
      • Banking & Finance Litigation
      • Business Interruption Insurance Lawyers
      • Contract Disputes
      • Defamation & Reputation Management
      • International & Cross-Border Disputes
      • Commercial Debt Recovery
      • Litigation Funding
      • Professional Negligence
    • Corporate
      • Corporate
      • Corporate Home
      • Corporate Advisory
      • Equity Capital Markets
      • Mergers & Acquisitions (M&A)
      • Private Equity
      • Search Funds and Entrepreneurship Through Acquisition Lawyers
    • Costs Team
    • Employment Law
      • Employment Law
      • Employment Law Home
      • Business Immigration
      • Employment Contracts, Policies & Procedures
      • Disciplinary & Grievance
      • Employee & Industrial Relations
      • Employment Lawyers for Legal Expenses Insurance
      • Employment Litigation & Resolution Lawyers
      • Equality, Diversity & Discrimination
      • Flexible Working Arrangements
      • Health & Safety
      • HR Advice Service - IMhrplus
      • Managing Sickness Absence
      • Pensions
      • Recruitment
      • Restrictive Covenants
      • Restructuring & Redundancy
      • Self Employment, Contractors & Agency Workers
      • Employment Seminars, Training & Updates
      • TUPE
    • In-House Counsel
    • Intellectual Property and Media
      • Intellectual Property and Media
      • Intellectual Property and Media Home
      • Defamation & Reputation Management
      • Copyright Lawyers
      • Design Rights Lawyers
      • Image Rights Lawyers
      • Online Marketplace Seller Account Or Listing Suspensions
      • Stopping IP Infringement By Sellers On Online Marketplaces
      • Patent Lawyers
      • Trade Mark Lawyers
      • Trade Secrets Lawyers
    • Legal Helpline
    • Licensing
      • Licensing
      • Licensing Home
      • Betting & Gaming Licensing
      • Event Licences
      • Alcohol Licensing
    • Pensions
      • Pensions
      • Pensions Home
      • Employment
      • Managing Death Benefit Trusts
    • Regulatory & Compliance
      • Regulatory & Compliance
      • Regulatory & Compliance Home
      • Road Transport & Operator Compliance
      • GDPR & Data Protection
      • Regulatory Investigations
      • Account Freezing Orders
      • Anti-Money Laundering
      • Companies House Prosecutions
      • Environment & Safety Regulatory Compliance
      • Financial Services Regulation
    • Real Estate
      • Real Estate
      • Real Estate Home
      • Corporate Occupiers
      • Real Estate Development and Regeneration
      • Construction & Engineering
      • Environmental
      • Real Estate Finance
      • Real Estate Investment
      • Later Living & Care
      • Planning
      • Property Litigation & Real Estate Disputes
      • Real Estate Tax
      • Residential Development
      • Strategic Land
      • Structured Real Estate
    • Restructuring & Insolvency
      • Restructuring & Insolvency
      • Restructuring & Insolvency Home
      • Corporate Insolvency
      • Partnership Insolvency
      • Directors' Duties
      • Restructuring Plans
      • Debt Recovery (up to £100,000) – Pricing
      • Restructuring
    • Tax
      • Tax
      • Tax Home
      • Corporate Tax
      • Real Estate Tax
      • Tax Investigations
  • People
    • People
    • People Home
    • Search By Name
    • Search By Location
    • Search By Expertise
    • Business Management
  • Offices
    • Offices
    • Offices Home
    • Birmingham
    • Brighton
    • Bristol
    • Cambridge
    • Cardiff
    • Chichester
    • Edinburgh
    • Gatwick
    • Glasgow
    • Leeds
    • Liverpool
    • London
    • Manchester
    • Middlesbrough
    • Newbury
    • Newcastle
    • North Yorkshire
    • Nottingham
    • Reading
    • Sheffield
    • Southampton
  • Contact
  • About
  • News & Insights
  • Careers
  • International
Irwin Mitchell Logo
Dialog with Irwin Mitchell phone number
Call us on 0808 291 3524

We're here 24/7, 365 days a year.

  • Home
  • News & Insights
  • Newsletters
  • In-house Update
  • The role of a Data Protection Officer

The role of a Data Protection Officer

Does your business need to appoint one and who should it be?

The General Data Protection Regulation (GDPR) will come into force on 25 May 2018 and represents a complete overhaul of the current data protection regime. In-house counsel teams are likely to be at the forefront of advising the business on the requirements of the GDPR.

One of those requirements is the accountability principle, which requires you to demonstrate your compliance with the GDPR. Not only do you have to do the right thing but must demonstrate that you are doing it. You can demonstrate compliance by implementing a range of different measures, one of which includes appointing a data protection officer (DPO) where appropriate.

The practice of appointing a DPO is not new, and has already developed over many years in several countries (e.g. Germany and Sweden), but there is now a statutory obligation in the GDPR for businesses to appoint a DPO in certain circumstances.

There is a popular misconception that this obligation requires all organisations to appoint a DPO in all situations in order to be compliant with the GDPR. This is not the case, and it is only a mandatory obligation in certain circumstances. You should therefore assess your collection and use of personal data to understand whether you will be required to appoint a DPO under the GDPR or not.

Who needs to appoint a DPO?

The appointment of a DPO applies to both data controllers and processors. If the business meets the criteria set out below, it will be required to appoint a DPO.

The GDPR requires the compulsory appointment of a DPO where:

(a) the processing is carried out by a public authority or body

(b) the core activities of the controller or the processor consist of processing operations which require regular and systematic monitoring of data subjects on a large scale

(c) the core activities of the controller or the processor consist of processing on a large scale of sensitive personal data or personal data relating to criminal convictions and offences

Given the lack of clarity in the above provisions, the Article 29 Working Party (A29 WP) has adopted guidelines to explain what constitutes ‘regular and systematic monitoring’ and at what point processing can be defined as ‘large scale’.

Regular and systematic monitoring

Regular and systematic monitoring is not defined in the GDPR but according to the A29 WP, the concept of ‘“regular monitoring” includes ongoing, recurring or repeated at fixed times and the concept of “systematic monitoring” includes pre-arranged, organised, methodical and occurring according to a system. Examples include tracking and profiling on the internet, including for the purposes of behavioural advertising, e.g. profiling and scoring for the purpose of risk assessment including credit scoring or fraud protection and location tracking.

Large-scale processing

The A29 WP recommends that a number of factors are taken into consideration when determining whether processing is carried out on a “large scale”, which includes having regard to:

  • the number of individuals concerned
  • the volume of data and/or the range of different data items being processed
  • the duration of the data processing activity and the geographical extent of the processing activity

An example of such large-scale processing given by the A29 WP is processing of customer data in the course of business by an insurance company or bank.

Where the GDPR does not require the mandatory appointment of a DPO, you can nevertheless appoint one on a voluntary basis – this is a decision that should be considered, as there are clear benefits to a voluntary appointment. This is encouraged by the A29 WP. It will also show the ICO and your customers that you are committed to complying with your data protection obligations. You can’t be wrong for appointing a DPO, but you can be wrong for taking the decision not to do so.

You should, however, bear in mind that if you appoint a DPO voluntarily, you must still comply with the full range of compliance obligations as if the appointment had been mandatory. You must therefore ensure that your business is able to comply with all the obligations that come with the role; if not, you should not use the title of DPO within your business and should clearly document that you have decided not to appoint a DPO and the reasons for that decision. If you decide that having a formal DPO appointment is not necessary, it is still a good idea to have someone who is the focus of GDPR compliance within the business, who can deal with such things as subject access requests and communication from the ICO.

What does a DPO do?

The DPO’s tasks include:

  • informing the business and its employees who carry out processing of their obligations under the GDPR
  • monitoring compliance with the GDPR, and with the policies in place for the protection of personal data, including staff training and audits
  • providing advice in relation to data protection impact assessments
  • co-operating with the ICO and acting as its contact point.

Who should be appointed as a DPO?

Whilst there are currently no mandatory qualifications for who can be a DPO, there are certain requirements to follow, and you should consider carefully who should be appointed and whether they should be an employee or a consultant under a contract for services.

A key requirement for a DPO is that they have to be independent. This can rule out a number of roles internally who are suitable. It can also raise issues as to whether the external appointment of a consultant will work.

From an internal perspective, individuals who determine what personal data is collected and how it is used cannot be a DPO, because they don’t have the requisite independence. If, in a nutshell, you are ‘marking your own homework’ from a data protection perspective, you are not suitable to be a DPO. According to the A29 WP, the following cannot be a DPO:

  • chief executive
  • chief financial officer
  • head of IT
  • head of marketing department
  • chief operating officer
  • head of HR

This makes it likely that someone from in-house legal or compliance will be a popular choice.

External appointments

Some businesses have expressed an interest in appointing one of their external legal advisers as DPO. Whilst this is possible, you should give the issue careful thought because there is a concern that being a law firm and acting as DPO for a client may cause conflict issues. From the point of view of DPO independence, there is an argument that if a law firm takes on the role, it may conflict them from assisting on other matters, e.g. litigation. Question marks have also been raised over the negotiation of contracts, which involve substantial data protection issues.

The other issue in relation to an external appointment is ensuring that the external lawyer is sufficiently embedded in the business to carry out the role. If you go down this route, the external firm will need to be able to demonstrate that it can monitor compliance and things such as staff training effectively.

In a nutshell, an external appointment can work – you just need to give thought to how to avoid the issues raised above.

Another popular misconception about the role of DPO is that they must have legal or specialist privacy qualifications. This is not the case – mandatory qualifications have not been set. The DPO should have expertise in national and European data protection laws and a sufficient understanding of what the business does with personal data. An external appointment of an individual with data protection legal expertise would mean that this requirement is met, but does not take away from the potential conflict issue.

DPO policy

We would recommend that, as with other compliance issues under the GDPR, your decisions in relation to a DPO are recorded in writing. It is a good idea to have a policy in place that records what the role of the DPO is in the context of the organisation, who cannot be a DPO and set out ground rules to avoid conflicts of interest.

Consequences for organisations

Breaches of the GDPR can result in fines of a maximum of €20 million or 4% annual worldwide turnover, whichever is greater. Where an organisation fails to adhere to the full range of DPO compliance obligations under the GDPR, the maximum fines it may face are up to €10 million or 2 per cent annual worldwide turnover, whichever is greater.

Although the appointment of a DPO may seem like a burden, it can in fact be advantageous, and there are many positives in that the DPO facilitates compliance with data protection obligations in a centralised manner. Getting compliance right and demonstrating that you comply with the GDPR can give you a competitive advantage, enabling you to develop a relationship of trust and confidence, both internally with your employees and externally with your customers and suppliers.

Joanne Bone – Partner

Published: 13 October 2017


IM Connect Newsletter - Update for In-house Counsel

Sign up to receive quarterly updates >

Autumn 2017

  • The role of a Data Protection Officer (“DPO”) – Does your business need to appoint one and who should it be?
  • Has mediation had its heyday?
  • Sense and severability – when does a restrictive covenant become totally unenforceable?
  • A third of UK firms failing to publish modern slavery statements

For general enquiries

0808 291 3524

Or we can call you back at a time of your choice

Phone lines are open 24/7, 365 days a year

Contact us today

For a free initial consultation

Freephone

0808 291 3524

Prefer not to call?

Use our form

This data will only be used by Irwin Mitchell for processing your query and for no other purpose.

Joanne Bone
Joanne Bone Partner Meet the team

About Irwin Mitchell

Founded in Sheffield in 1912, Irwin Mitchell has always been a bit different. Our advisers really get to know the people and business that we help.

We have offices around the UK so wherever you are, our experts can help.

Contact Us

Give us a ring to speak to a member of our team in the strictest confidence. Or you can fill out our contact form and we'll ring you back.

0370 1500 100

Our phone lines are open 24/7, 365 days a year

Get a call back

Fill in your details below and we'll be in touch as soon as possible

This data will only be used by Irwin Mitchell for processing your query and for no other purpose.

  • Contact
  • 0370 1500 100
  • Contact Irwin Mitchell
  • Social Media
  • Twitter
  • Facebook
  • YouTube
  • LinkedIn
  • Instagram
  • About Irwin Mitchell
  • About Us
  • Responsible Business
  • Careers
  • Business Management
  • Alumni Programme
  • Pay A Bill
  • Complaints Procedure
  • SRA Regulated
  • Terms & Conditions
  • Accessibility
  • Privacy & Security
  • Hoaxes
  • Modern Slavery Act Statement
  • Manage Cookie Settings

© 2025  Irwin Mitchell LLP

Irwin Mitchell LLP is authorised & regulated by the Solicitors Regulation Authority. Our Regulatory Information

Dialog that contains a form to request a callback.

Request A Callback

Enter your details below and a member of our team will contact you within 24 hours

This data will only be used by Irwin Mitchell for processing your query and for no other purpose.