Does my business need a Data Protection Officer?
Most UK organisations do not need a Data Protection Officer. It is legally mandatory in only three situations, and none of them depend on your size or turnover. The Data (Use and Access) Act 2025 left those rules alone.
Last updated 31 July 2026. This page explains the law as it stands on that date. It is general information, not legal advice.
The bottom line
A Data Protection Officer is mandatory in only three situations, and none of them turn on how many staff you have. The Data (Use and Access) Act 2025 did not replace the DPO with a 'Senior Responsible Individual' — that was a proposal in a different Bill, and it fell in May 2024. The Act also left your records of processing and DPIA duties exactly as they were.
When is a DPO legally mandatory?
Article 37(1) of the UK GDPR sets out three triggers. If none applies to you, you do not have to appoint a DPO. The duty falls on controllers and processors alike.
| Trigger under UK GDPR Article 37(1) | What it means in practice |
|---|---|
| (a) You are a public authority or body, except courts and tribunals acting in their judicial capacity | Defined by section 7 of the Data Protection Act 2018: bodies covered by the Freedom of Information Act 2000 or the Scottish FOI Act, plus the Advanced Research and Invention Agency — and only when carrying out public interest tasks. Parish councils in England, community councils in Wales and Scotland, parish and community meetings and charter trustees are expressly excluded. |
| (b) Your core activities require regular and systematic monitoring of individuals on a large scale | All forms of tracking and profiling, online or offline. The ICO gives behavioural advertising, and a large retail website using algorithms to monitor users' searches and purchases, as examples. |
| (c) Your core activities involve large-scale processing of special category data (Article 9) or criminal convictions and offences data (Article 10) | Health, race, religion, sex life, political opinions, trade union membership, biometrics used for identification — or offence data — at scale. The ICO's example is a health insurance company processing medical conditions and other health information about a large number of people. |
The phrase core activities does a lot of work here. Your core activities are your primary business activities — what you need to process personal data to achieve. Processing you do for secondary purposes, such as payroll and HR records for your own staff, does not count, even though you do it constantly. A shop that keeps staff sickness records is not caught by trigger (c). An occupational health provider almost certainly is.
There is no size threshold
Nothing in the UK GDPR, the Data Protection Act 2018 or the DUAA says you need a DPO once you reach a certain headcount or turnover. A five-person business doing large-scale health data processing needs one. A 300-person manufacturer selling to other businesses probably does not.
There is one separate rule worth knowing. Under section 69 of the Data Protection Act 2018, a controller processing personal data for law enforcement purposes must designate a DPO, unless it is a court or other judicial authority acting in its judicial capacity. There is no large-scale test there — it applies across the board.
You may appoint a DPO voluntarily. If you do, the ICO's position is that the same requirements of position and tasks apply as if the appointment had been mandatory. If you decide you do not need one, the ICO advises recording that decision to help demonstrate compliance with the accountability principle.
No, the DUAA did not create a 'Senior Responsible Individual' duty
This is probably the most widely repeated piece of bad information about UK data protection law in 2026. You will find pages — and AI-generated search summaries — stating that "under Section 15 of the DUAA 2025, all data controllers must appoint a Senior Responsible Individual". That claim is wrong in every particular.
- Section 15 of the Data (Use and Access) Act 2025 is headed "The FCA and financial services interfaces: supplementary". It sits in Part 1 of the Act, "Access to customer data and business data", and has nothing to do with data protection. The Act's data protection provisions are in Part 5, sections 66 to 116.
- The Senior Responsible Individual was a proposal in the Data Protection and Digital Information Bill, a different Bill from the previous Parliament. It never became law. The Bill fell when Parliament was prorogued for the 2024 general election, the wash-up period ending on 24 May 2024.
- The DUAA did not carry the proposal across. Nothing in the Act creates an SRI role, and the term does not appear in it.
- Articles 37, 38 and 39 of the UK GDPR still stand. Designation, position and tasks of the DPO are all in force and substantively unamended.
The DUAA made exactly one change to the DPO rules. Schedule 11, paragraph 11 reads, in full: "In Article 37(1)(a), after "courts" insert "and tribunals"." It came into force on 20 August 2025. The judicial exemption now covers tribunals as well as courts. That is a tidying-up exercise for the justice system. It changes nothing for a business, school or charity.
One thing to watch: the ICO's own DPO guidance page still uses the old "except for courts acting in their judicial capacity" wording and carries a banner saying the guidance is under review following the DUAA. The statute on legislation.gov.uk is the authoritative text.
Do you still need a ROPA and DPIAs?
Yes to both. Because the abandoned DPDI Bill would have narrowed or scrapped these duties, a lot of commentary written in 2023 and 2024 says the paperwork is going away. It did not.
| Governance duty | Status as at 31 July 2026 |
|---|---|
| DPO appointment (UK GDPR Articles 37–39) | Unchanged, apart from "and tribunals" being added to the judicial exemption on 20 August 2025. |
| Records of processing activities (Article 30) | Unchanged. Last amended 31 December 2020. See the note below on the under-250 exemption. |
| Data protection impact assessments (Article 35) | Unchanged. Last amended 31 December 2020. Article 35(2) still requires you to seek your DPO's advice where you have designated one. |
| Personal data breach notification to the ICO (Article 33) | Unchanged. Still 72 hours. |
| Handling data protection complaints (DPA 2018 s.164A) | New. In force 19 June 2026. |
| Children's higher protection in design (Article 25) | Amended by DUAA s.81 from 5 February 2026, for online services likely to be accessed by children. |
On records of processing: Article 30(5) still exempts an organisation employing fewer than 250 people — but only where the processing is *not* likely to result in a risk to rights and freedoms, *is* occasional, and does *not* include special category or criminal offence data. Almost every employer processes staff and customer data routinely rather than occasionally, so in practice the exemption rarely rescues anyone. Assume you need a ROPA.
The ICO's own summary of what the DUAA means for organisations works through the real changes — the new recognised legitimate interests lawful basis, the narrowed automated decision-making rules, children and online services, and data protection complaints. No new governance role appears anywhere on it. The ICO also states plainly that the DUAA "amends, but does not replace" the UK GDPR, the Data Protection Act 2018 and PECR.
If you don't need a DPO, who should be responsible?
The law does not require you to name anyone in particular. But Article 5(2) requires you to be able to demonstrate compliance, and that is hard when nobody owns the subject. The national picture suggests many organisations have not closed this gap. DSIT's UK Business Data Survey 2026 found that 56% of businesses that employ staff and handled digitised personal data had someone whose role includes leading on data protection compliance — 92% of large businesses, but 53% of micro businesses. Some 46% of businesses handling digitised personal data had at least one full-time-equivalent member of staff whose primary role was data protection compliance work. Only 11% had run data protection training for existing staff in the previous 12 months, down from 23% in the 2023–24 survey.
- Step 1 Assign it to a named person in writing A line in a job description or a board minute is enough. The point is that someone can answer for it.
- Step 2 Record why you decided a DPO is not required Note which of the three Article 37(1) triggers you considered and why none applies. This is the ICO's suggested approach.
- Step 3 Do not give them the title 'Data Protection Officer' The ICO is explicit that data protection specialists who are not the DPO should not be referred to as your DPO. The title is a defined role carrying independence and non-dismissal protections you may not have resourced.
- Step 4 Give them time, budget and access Responsibility without authority to see systems and contracts, or without hours in the week, achieves nothing.
- Step 5 Train everyone else Data protection failures usually happen at the desk, not in the policy.
Can you outsource the DPO role?
Yes. Article 37(6) allows the DPO to be a member of your staff or to fulfil the tasks under a service contract. The ICO's position is that an externally appointed DPO should have the same position, tasks and duties as an internal one. Under Article 37(2) and (3) you can also share a single DPO across a group of undertakings, or across several public authorities, provided they can still perform the role effectively given the size and structure of each.
You can have only one DPO. You can build a team around them, but one designated individual holds the role for the purposes of Articles 37 to 39.
Can our lawyer or IT provider do it?
Sometimes, but test the appointment against four things before you make it.
- Expertise. Article 37(5) requires appointment on the basis of professional qualities and expert knowledge of data protection law and practices, proportionate to the risk of your processing. A general commercial solicitor or a managed IT provider may not have it.
- Independence. Article 38(3) says the DPO must not receive instructions on how to carry out their tasks and must report to the highest level of management. A supplier whose contract can be ended for giving unwelcome advice is in a weak position to give it.
- Conflicts. Article 38(6) permits other tasks only where they do not result in a conflict of interests. An IT provider that designs and runs your systems is helping determine the means of processing, and would then be auditing its own work.
- Accessibility. The DPO must be easily contactable by your staff, by the people whose data you hold, and by the ICO.
The conflict-of-interest traps
The core rule is that the DPO cannot hold a position that leads them to determine the purposes and the means of processing personal data. In a small organisation that rules out more people than you might expect: the owner or managing director, the head of marketing, the head of IT, the head of HR and the finance director are all likely to be conflicted.
- The ICO's worked example: a head of marketing who plans an advertising campaign, decides which customers to target and which personal details to use cannot also be the DPO.
- The ICO's example of an acceptable combination: a public authority appointing its existing FOI officer or records manager, because those roles are about information rights compliance rather than deciding purposes of processing.
- Keeping the ROPA is fine. The ICO says there is nothing preventing that task being allocated to the DPO.
- Article 38(3) protects the DPO from being dismissed or penalised for performing their tasks. Before appointing internally, ask honestly whether that person could tell the chief executive no.
Does the DPO's name appear on the public ICO register?
Their contact details may. Their name appears only if they have agreed to it.
Article 37(7) requires you to publish your DPO's contact details and communicate them to the ICO. You must also include those contact details in the privacy information you give people under Articles 13 and 14, and when consulting the ICO about a DPIA under Article 36. The ICO confirms you are not required to publish the DPO's *name* — contact details are enough, though you may include the name if you find it helpful.
On the ICO's register of fee payers, which holds more than one million fee payers, the published entry shows the controller's name and address, registration reference, fee tier, registration and expiry dates, any trading names, and the DPO's contact details where the ICO has been told of one. The DPO's name is published only where that person has consented.
One place the name is always required
You must give your DPO's name when you report a personal data breach to the ICO under Article 33(3)(b), and to the individuals affected by it under Article 34(2).
- Step 1 Use the ICO's 'Change or update your details' service You will need your registration reference and your security number. The nominated contact can request a security number reminder.
-
Step 2
Or email the ICO
Write to
dataprotectionfee@ico.org.ukwith 'Add a DPO' in the subject line. - Step 3 Say whether the appointment is required or voluntary The ICO asks you to state which, along with the name, address, phone number and email of the individual — or of the external organisation carrying out DPO duties for you.
- Step 4 State clearly whether you want the name published If your DPO is an individual, say in the email whether or not their name should appear on the register.
- Step 5 Allow two working days Changes take up to two working days to show on the register.
What does the DPO do now the complaints duty is live?
Since 19 June 2026, section 164A of the Data Protection Act 2018 — inserted by section 103 of the DUAA, with Schedule 10 making the minor and consequential amendments — requires every controller to facilitate data protection complaints, including by providing a complaint form completable electronically and by other means; acknowledge a complaint within 30 days beginning when it is received; take appropriate steps to respond, including making enquiries; and inform the complainant of the outcome without undue delay. Under the transitional provision in the commencement regulations, the acknowledgement and response duties in section 164A(3) and (4) apply only to complaints received on or after 19 June 2026.
This is a duty on the controller, not on the DPO, and it applies whether or not you have one. Where you do have a DPO, monitoring compliance with it falls squarely within their Article 39(1)(b) task of monitoring compliance with data protection law and your own policies, including staff training and audits.
- You do not need a separate complaints tool. The ICO says you can adapt an existing complaints process, as long as you still meet the obligations.
- However you receive a complaint, you must accept it. People can complain by any route they choose, including to any employee or any part of your organisation.
- The ICO advises making sure all staff can recognise a data protection complaint and know where to direct it internally, and including this in your internal data protection training.
- You must tell people they can complain to you as well as to the ICO — at the point you collect their personal information, and when you respond to a subject access request.
Failing to comply is enforceable. New section 157(4A) of the Data Protection Act 2018 puts an infringement of section 164A — or of regulations made under section 164B — in the *standard* maximum tier: £8,700,000, or, for an undertaking, 2% of total annual worldwide turnover in the preceding financial year if that is higher. The *higher* maximum of £17,500,000 or 4% of turnover is reserved for the infringements listed in section 157(2), which include the UK GDPR breaches for which Article 83 specifies it.
Common questions
How many employees do you need before you need a DPO?
There is no employee threshold. The three triggers in UK GDPR Article 37(1) are about what you are (a public authority or body) and what your core activities involve (large-scale monitoring, or large-scale special category or criminal offence data). A five-person business can need a DPO while a 300-person one does not. The only place headcount appears in this area is the separate Article 30(5) records exemption for organisations employing fewer than 250 people, and that exemption falls away in most real situations.
Is a 'Senior Responsible Individual' the same thing as a DPO?
No, and there is no Senior Responsible Individual role in UK data protection law. It was a proposal in the Data Protection and Digital Information Bill, which fell in the wash-up before the 2024 general election, Parliament being prorogued on 24 May 2024. The Data (Use and Access) Act 2025 did not include it. If a page tells you that section 15 of the DUAA requires you to appoint an SRI, it is wrong — section 15 of that Act sits in Part 1 and is about FCA financial services interfaces.
Does our school need a data protection officer?
Maintained schools and academy proprietors are public authorities under the Freedom of Information Act 2000, which makes them public authorities for UK GDPR purposes under section 7 of the Data Protection Act 2018. So they fall within Article 37(1)(a) and must appoint a DPO. Independent schools are not FOIA public authorities, so they need a DPO only if one of the other two triggers applies to their core activities.
Can the business owner or managing director be the DPO?
Usually not. Article 38(6) allows a DPO to hold other roles only where they do not create a conflict of interests, and the DPO cannot hold a position that leads them to determine the purposes and means of processing. An owner or managing director generally does exactly that. The ICO lists senior roles such as chief executive, chief operating officer, chief financial officer, head of marketing, head of HR and head of IT as likely to be conflicted for the same reason.
Do we have to put our DPO's name on our website or the ICO register?
No. You must publish your DPO's contact details and give them to the ICO under Article 37(7), but the ICO confirms you are not required to include the name. On the ICO's register of fee payers, the DPO's contact details appear where the ICO has been told of a DPO, and the name appears only where that person has consented. You must, however, give the DPO's name when reporting a personal data breach to the ICO and to affected individuals.
Did the DUAA get rid of the ROPA and DPIA requirements?
No. Both UK GDPR Article 30 (records of processing activities) and Article 35 (data protection impact assessments) were last amended on 31 December 2020 and were untouched by the Data (Use and Access) Act 2025. The claim that the paperwork has gone usually comes from commentary written about the abandoned DPDI Bill, which would have changed them. The ICO's own summary of what the DUAA means for organisations covers new lawful bases, automated decision-making, children's online services and complaints — records of processing and DPIAs are not among the changes.
Sources
This page summarises the following primary sources. Where they disagree with this summary, they take precedence.
- UK GDPR Article 37: Designation of the data protection officer (legislation.gov.uk, showing the 20 August 2025 amendment)
- Data (Use and Access) Act 2025, Schedule 11, paragraph 11 — the only DUAA change to the DPO rules
- Data (Use and Access) Act 2025 — contents, showing section 15 and Part 5
- Data Protection Act 2018, section 7 — meaning of 'public authority' and 'public body'
- Data Protection Act 2018, section 164A — complaints to controllers, in force 19 June 2026
- Data Protection Act 2018, section 157 — penalty maximums, including new subsection (4A)
- The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 — 5 February and 19 June 2026 dates and the complaints transitional
- UK GDPR Article 25 — children's higher protection matters inserted by DUAA s.81 from 5 February 2026
- ICO — Data protection officers (accountability and governance guidance)
- ICO — Register of fee payers: what is published
- ICO — Add a Data Protection Officer (DPO)
- ICO — How do we prepare to handle data protection complaints?
- DSIT — UK Business Data Survey 2026
Related guidance
-
Do I need to register with the ICO, and how much is the data protection fee in 2026?
Do you need to register with the ICO? The 2026 data protection fee is £52, £78 or £3,763 — unchanged since February 2025. Who pays, who's exempt.
-
New rule from 19 June 2026: every UK organisation must have a data protection complaints process
From 19 June 2026 every UK controller must accept data protection complaints, acknowledge them within 30 days and give an outcome. No size exemption.