Analysis of Governance, Operating Models, Controls, and Organisational Responsibilities
Articles 37, 38 and 39 of the GDPR establish the legal framework governing the appointment, position, independence, and tasks of the Data Protection Officer (DPO). Together, these provisions create a specialised governance function intended to embed accountability, privacy-by-design, risk management, and regulatory engagement throughout an organisation's processing activities.
The DPO framework is not merely an advisory role. It serves as a structural control mechanism supporting the broader accountability obligations found throughout GDPR, particularly where organisations undertake large-scale, complex, sensitive, or high-risk processing.
For advanced practitioners, Articles 37–39 should be viewed as a governance system rather than three isolated legal provisions. Effective implementation requires organisational design, reporting structures, technical controls, operational processes, audit mechanisms, and executive sponsorship.
Article 37 determines when a DPO must be appointed and establishes qualification requirements. The provision aims to ensure that organisations engaged in significant privacy-risk activities maintain access to expert data protection oversight.
Processing is carried out by a public authority or public body.
Core activities require regular and systematic monitoring of individuals on a large scale.
Core activities involve large-scale processing of special category data or criminal offence data.
Core activities are operations necessary to achieve the organisation's primary objectives.
Includes activities such as:
The GDPR intentionally avoids numerical thresholds. Assessment factors include number of individuals affected, volume of personal data, geographic scope, duration of processing, and processing intensity.
No formal certification is mandated under GDPR. However, the DPO must possess expert knowledge across multiple domains.
Expert knowledge of data protection law and regulatory engagement capability.
Understanding of information security, governance, and risk management expertise.
Knowledge of business operations, independence, and ethical judgement.
Article 37 permits flexible DPO arrangements to accommodate organisations of varying sizes and structures.
A dedicated employee appointed within the organisation, providing deep institutional knowledge and continuous availability.
An external service provider engaged under a contract. Suitable for smaller organisations requiring specialist expertise without a full-time hire.
A single DPO serving multiple entities within a corporate group, provided they are easily accessible from each establishment.
Multinational corporations may establish a centralised global DPO office serving all group entities under a unified governance framework.
Small organisations may engage an external DPO service provider, gaining access to specialist expertise on a flexible, cost-effective basis.
Organisations must provide the DPO with the resources necessary to function effectively:
The DPO must report directly to the highest management level:
The DPO must not receive instructions regarding investigations, findings, regulatory positions, risk assessments, or compliance recommendations. Organisations may not demote, terminate, reduce compensation, or penalise a DPO solely because they performed GDPR duties.
The DPO cannot determine purposes and means of processing. Certain senior roles present inherent conflicts with the DPO function.
Chief Information Officer
Chief Technology Officer
Chief Information Security Officer (context dependent)
Head of Human Resources
Chief Marketing Officer
Head of Data Analytics
The DPO must be accessible to all relevant stakeholders. Organisations commonly implement:
A dedicated privacy email address for data subjects and employees.
A self-service portal for rights requests and privacy enquiries.
Formal procedures for supervisory authority engagement.
Systems to track and manage privacy cases and requests.
Article 39 defines the operational responsibilities of the DPO. These responsibilities are advisory, oversight, governance, and coordination functions rather than direct ownership of compliance activities.
Advises executive management, business units, data owners, technology teams, procurement, HR, and security functions on lawful basis, international transfers, privacy notices, AI governance, and data retention.
Monitors compliance with GDPR, internal policies, data governance standards, privacy programmes, and security obligations through audits, control assessments, gap analysis, and policy reviews.
Oversees privacy training, awareness campaigns, role-based education, executive briefings, and developer privacy training across the organisation.
Advises on DPIAs, reviews methodologies, assesses completeness, and monitors implementation. The DPO advises but does not own business risk acceptance decisions.
Manages regulatory engagement, investigation support, audit responses, breach communications, and consultation processes as the primary contact point.
The DPO framework intersects extensively with other GDPR provisions. The DPO must maintain working knowledge across the full regulatory landscape.

The following controls collectively support Articles 37–39 compliance across governance, operational, and technical dimensions.
Article 37 permits flexible DPO structures. Advanced organisations select operating models based on their size, complexity, regulatory exposure, and geographic footprint.
Single global DPO with a central privacy team, unified standards, and centralised investigations. Best suited for highly regulated industries and global organisations seeking standardisation. Offers consistency and strong governance but may face scalability challenges.
Central DPO supported by regional privacy leads and embedded business privacy managers. Best suited for multinational enterprises and complex matrix organisations. Provides local expertise and scalable governance but requires strong coordination.
Central DPO office with business unit privacy officers operating under a shared governance framework. Delivers strong oversight and local accountability but is resource intensive and requires robust governance coordination.
Multiple DPOs organised by geography with coordinated global governance. Provides jurisdiction-specific expertise and strong regulator relationships but carries higher cost and potential fragmentation risk.
Effective GDPR governance requires clear delineation of responsibilities across multiple organisational functions. The DPO does not operate in isolation.
The distinction between oversight and ownership is fundamental to the GDPR accountability framework.
Advise and inform
Monitor and challenge
Escalate concerns
Educate and train
Report to leadership
Coordinate and engage regulators
Process personal data
Implement controls
Own risks and execute remediation
Maintain records
Allocate resources
Accept residual risk
This separation is one of the most important governance concepts underpinning Articles 37, 38 and 39 and is frequently examined by supervisory authorities when assessing organisational accountability under the GDPR.
One of the most persistent misconceptions in GDPR governance is the belief that a DPO loses independence by providing advice, guidance, recommendations, or subject matter expertise to the business. This interpretation is incorrect and is inconsistent with both the text and purpose of Articles 38 and 39.
Article 39(1)(a) states that the DPO shall "inform and advise" the controller, processor, and employees who carry out processing regarding their obligations under the GDPR. Advisory activity is not merely permissible — it is a mandatory statutory obligation.
The critical distinction is not between advice and oversight. Rather, it is between advice and operational decision-making.
An effective teaching analogy is that the DPO performs both an architectural and inspection role — helping design privacy controls whilst remaining independent of their operation.
DPO advises that customer analytics requires a DPIA.
Business performs the DPIA.
DPO reviews methodology and recommends additional safeguards.
Management accepts or rejects recommendations.
DPO performs the DPIA themselves.
DPO approves deployment.
DPO signs risk acceptance.
DPO becomes accountable for implementation.
The question is not whether the DPO provides advice. The question is whether the DPO ultimately controls decisions that they later monitor.
Articles 38 and 39, interpreted alongside EDPB and supervisory authority guidance, imply a broad set of oversight obligations spanning strategic governance, processing activities, privacy-by-design, and DPIAs.
The DPO's oversight mandate extends across data subject rights, security incidents, vendor management, international transfers, training, and regulatory engagement.
The DPO should maintain evidence demonstrating oversight. A mature interpretation of Articles 38 and 39 recognises that the DPO simultaneously performs two complementary functions.
The DPO advises because the GDPR requires expertise to be embedded into organisational decision-making.
The DPO oversees because the GDPR requires independent monitoring of those same decisions.
The boundary is crossed only when the DPO moves from advising and challenging decisions to making and owning those decisions. At that point, the DPO ceases to function as an independent oversight mechanism and begins to create the very conflict of interest that Article 38 seeks to prevent. For advanced practitioners, maintaining this distinction is one of the most important governance principles in the entire GDPR accountability framework.
The material within this site is provided for general guidance only and does not constitute legal, regulatory, or professional advice. Datari accepts no liability for any actions taken or not taken based on this content. Organisations should seek their own independent advice before making decisions.
GDPR Articles 37, 38 & 39: