DPO: should you appoint a data protection officer?
The Data Protection Officer, or DPO, is responsible for ensuring GDPR compliance within an organization. Appointing one is mandatory in specific cases set out by the regulation, and recommended in many other situations, even without a strict legal obligation. The CNIL keeps a public register of appointed DPOs, which every organization subject to the obligation must notify.
When is appointing a DPO mandatory?

- The organization is a public authority or body.
- The organization's core activity involves the regular and systematic large scale monitoring of individuals.
- The organization's core activity involves large scale processing of sensitive data (health, racial origin, political opinions...) or data relating to criminal convictions.
The DPO's role
| Mission | Description |
|---|---|
| Advice | Informing and advising the organization on its GDPR obligations |
| Oversight | Checking compliance with the regulation and internal policies |
| Point of contact | Acting as the contact point for the data protection authority and data subjects |
| Impact assessment | Advising on the completion of data protection impact assessments (DPIA) |
Internal or external DPO?
An SME can appoint an internal employee, provided they have the necessary skills and are not in a conflict of interest: a DPO cannot, for example, also be the IT manager who alone decides on processing activities, which in practice rules out this option in many small organizations where IT and compliance sit with the same person. Using a shared external DPO solves that problem, but comes with a recurring cost that needs to be weighed against the actual volume of high risk processing: for a company with simple processing activities, that expense can be disproportionate to the real risk.
Conflict of interest red flags to avoid
- The prospective DPO is also the person who alone decides on the means and purposes of processing (often the HR director, the marketing director or the IT manager).
- The DPO reports hierarchically to a function whose practices they are meant to oversee.
- The DPO combines the role with operational responsibilities that force them to trade off commercial performance against data protection.
- No direct reporting line to senior management is provided for the DPO.
How much does a DPO cost, internal or external
A shared external DPO is most often billed as an annual flat fee, proportionate to the volume and sensitivity of processing activities: a few thousand euros a year for an SME with simple processing, up to tens of thousands for an organization processing health data at scale. An internal DPO represents a different kind of cost, made up of dedicated time (rarely full time in an SME) and ongoing training, since the role requires regularly updated legal and technical knowledge. Comparing the two options therefore means first estimating the actual volume of high risk processing, not just headcount.
GDPR Diagnostic·See a diagnostic preview
Steps to appoint and onboard a DPO
- Assess whether the organization falls under a mandatory appointment case, or whether an internal contact person would suffice.
- Choose between an internal DPO, a shared external DPO, or a non-mandatory contact person based on the volume and sensitivity of processing.
- Check for the absence of conflicts of interest and confirm the reporting line to management.
- Notify the appointment to the CNIL, which adds it to its public register.
- Provide the DPO with the necessary means: access to information, a training budget, and the authority to be consulted before any new processing activity.
- Communicate their contact details internally and in legal notices, so data subjects can reach them directly.
What if appointing one is not mandatory?
Even without a legal obligation, appointing an internal GDPR contact person, trained in the basics of the regulation, helps structure compliance and avoids the topic being handled by no one. This is often a first step before, where relevant, appointing a full DPO.
Establishing whether the organization genuinely falls under a mandatory appointment case avoids two opposite pitfalls: going without a DPO when the regulation requires one, or appointing one out of excessive caution when a simple internal contact person would largely suffice.
Related diagnostic
Ready to assess your organization?
Try for free