GDPR Articles 37, 38 & 39:

The Data Protection Officer Framework

Analysis of Governance, Operating Models, Controls, and Organisational Responsibilities

Introduction

Articles 37, 38 and 39 of the GDPR establish the legal framework governing the appointment, position, independence, and tasks of the Data Protection Officer (DPO). Together, these provisions create a specialised governance function intended to embed accountability, privacy-by-design, risk management, and regulatory engagement throughout an organisation's processing activities.

More Than Advisory

The DPO framework is not merely an advisory role. It serves as a structural control mechanism supporting the broader accountability obligations found throughout GDPR, particularly where organisations undertake large-scale, complex, sensitive, or high-risk processing.

A Governance System

For advanced practitioners, Articles 37–39 should be viewed as a governance system rather than three isolated legal provisions. Effective implementation requires organisational design, reporting structures, technical controls, operational processes, audit mechanisms, and executive sponsorship.

Article 37 – Designation of the Data Protection Officer

Mandatory Appointment

Article 37 determines when a DPO must be appointed and establishes qualification requirements. The provision aims to ensure that organisations engaged in significant privacy-risk activities maintain access to expert data protection oversight.

When Appointment is Mandatory

Public Authority

Processing is carried out by a public authority or public body.

Systematic Monitoring

Core activities require regular and systematic monitoring of individuals on a large scale.

Special Category Data

Core activities involve large-scale processing of special category data or criminal offence data.

Key Interpretive Concepts

Core Activities

Core activities are operations necessary to achieve the organisation's primary objectives.

Typically Core

  • Hospital patient treatment
  • Bank customer account management
  • Insurance underwriting
  • Telecommunications service provision
  • Online behavioural advertising

Not Typically Core

  • Payroll processing
  • Employee administration
  • Internal facilities management

Regular and Systematic Monitoring

Includes activities such as:

  • Behavioural profiling
  • Location tracking
  • Credit scoring
  • Loyalty programme analytics
  • Network monitoring
  • Fraud detection systems
  • Digital advertising ecosystems
  • Employee productivity surveillance

Large-Scale Processing & DPO Qualifications

Large-Scale Processing

The GDPR intentionally avoids numerical thresholds. Assessment factors include number of individuals affected, volume of personal data, geographic scope, duration of processing, and processing intensity.

Likely Large-Scale

  • National healthcare systems
  • Large banking platforms
  • Telecom providers
  • Global social media platforms
  • National government databases

Typically Not Large-Scale

  • Single physician practice
  • Small law firm
  • Local accounting office

Qualifications Required

No formal certification is mandated under GDPR. However, the DPO must possess expert knowledge across multiple domains.

Legal & Regulatory

Expert knowledge of data protection law and regulatory engagement capability.

Information Security

Understanding of information security, governance, and risk management expertise.

Business Operations

Knowledge of business operations, independence, and ethical judgement.

Shared and External DPO Models

Article 37 permits flexible DPO arrangements to accommodate organisations of varying sizes and structures.

Internal DPO

A dedicated employee appointed within the organisation, providing deep institutional knowledge and continuous availability.

External DPO

An external service provider engaged under a contract. Suitable for smaller organisations requiring specialist expertise without a full-time hire.

Group DPO

A single DPO serving multiple entities within a corporate group, provided they are easily accessible from each establishment.

Multinational Example

Multinational corporations may establish a centralised global DPO office serving all group entities under a unified governance framework.

SME Example

Small organisations may engage an external DPO service provider, gaining access to specialist expertise on a flexible, cost-effective basis.

Article 38 – Position of the Data Protection Officer

Organisational Support Requirements

Organisations must provide the DPO with the resources necessary to function effectively:

  • Necessary resources and sufficient staffing
  • Appropriate budget allocation
  • Access to information and processing operations
  • Access to senior management

Direct Reporting Requirement

The DPO must report directly to the highest management level:

  • Board of Directors
  • Chief Executive Officer
  • Executive Committee
  • Supervisory Board

Independence & Protection from Penalty

The DPO must not receive instructions regarding investigations, findings, regulatory positions, risk assessments, or compliance recommendations. Organisations may not demote, terminate, reduce compensation, or penalise a DPO solely because they performed GDPR duties.

Conflict of Interest Requirements & Accessibility

The DPO cannot determine purposes and means of processing. Certain senior roles present inherent conflicts with the DPO function.

Roles Commonly Presenting Conflicts

Chief Information Officer

Chief Technology Officer

Chief Information Security Officer (context dependent)

Head of Human Resources

Chief Marketing Officer

Head of Data Analytics

Accessibility Requirements

The DPO must be accessible to all relevant stakeholders. Organisations commonly implement:

Dedicated Email

A dedicated privacy email address for data subjects and employees.

Privacy Portal

A self-service portal for rights requests and privacy enquiries.

Regulatory Contact

Formal procedures for supervisory authority engagement.

Case Management

Systems to track and manage privacy cases and requests.

Article 39 – Tasks of the Data Protection Officer

Article 39 defines the operational responsibilities of the DPO. These responsibilities are advisory, oversight, governance, and coordination functions rather than direct ownership of compliance activities.

Informing & Advising

Advises executive management, business units, data owners, technology teams, procurement, HR, and security functions on lawful basis, international transfers, privacy notices, AI governance, and data retention.

Monitoring Compliance

Monitors compliance with GDPR, internal policies, data governance standards, privacy programmes, and security obligations through audits, control assessments, gap analysis, and policy reviews.

Awareness & Training

Oversees privacy training, awareness campaigns, role-based education, executive briefings, and developer privacy training across the organisation.

DPIA Advisory

Advises on DPIAs, reviews methodologies, assesses completeness, and monitors implementation. The DPO advises but does not own business risk acceptance decisions.

Supervisory Authority Cooperation

Manages regulatory engagement, investigation support, audit responses, breach communications, and consultation processes as the primary contact point.

GDPR Articles Intersecting with Articles 37–39

The DPO framework intersects extensively with other GDPR provisions. The DPO must maintain working knowledge across the full regulatory landscape.

Twenty Cross-Cutting Governance and Technical Controls

The following controls collectively support Articles 37–39 compliance across governance, operational, and technical dimensions.

Governance Controls

  • Board-approved DPO charter defining independence and authority
  • Formal DPO appointment procedure
  • Conflict-of-interest assessment framework
  • DPO reporting directly to executive leadership
  • Annual DPO independence review
  • Enterprise privacy governance committee
  • Regulatory engagement management process
  • Privacy risk management framework
  • DPO budget governance process
  • Enterprise privacy training programme

Operational Controls

  • Record of Processing Activities (ROPA) governance
  • DPIA workflow and approval process
  • Data subject rights management process
  • Vendor privacy due diligence process
  • Privacy incident escalation procedures

Technical Controls

  • Automated data discovery and classification
  • Privacy management platform
  • Data lineage and mapping capability
  • Consent management technology
  • Data retention automation
  • Identity and access management controls
  • Audit logging and monitoring
  • Encryption governance
  • Cross-border transfer monitoring
  • Continuous privacy compliance monitoring

Large Organisation Operating Models

Article 37 permits flexible DPO structures. Advanced organisations select operating models based on their size, complexity, regulatory exposure, and geographic footprint.

1

Centralised DPO Office

Single global DPO with a central privacy team, unified standards, and centralised investigations. Best suited for highly regulated industries and global organisations seeking standardisation. Offers consistency and strong governance but may face scalability challenges.

2

Federated Privacy Model

Central DPO supported by regional privacy leads and embedded business privacy managers. Best suited for multinational enterprises and complex matrix organisations. Provides local expertise and scalable governance but requires strong coordination.

3

Hub-and-Spoke Model

Central DPO office with business unit privacy officers operating under a shared governance framework. Delivers strong oversight and local accountability but is resource intensive and requires robust governance coordination.

4

Regional DPO Model

Multiple DPOs organised by geography with coordinated global governance. Provides jurisdiction-specific expertise and strong regulator relationships but carries higher cost and potential fragmentation risk.

Roles and Responsibilities within the DPO Ecosystem

Effective GDPR governance requires clear delineation of responsibilities across multiple organisational functions. The DPO does not operate in isolation.

Data Protection Officer

  • Independent oversight
  • Monitoring compliance
  • Regulatory liaison
  • DPIA advisory
  • Executive reporting
  • Training oversight

Privacy Office

  • Programme execution
  • Policy management
  • Privacy operations
  • Metrics
  • Control implementation
  • Risk coordination

Information Security

  • Security architecture
  • Access controls
  • Vulnerability management
  • Incident response
  • Encryption

Legal Department

  • Legal interpretation
  • Litigation support
  • Contractual controls
  • Regulatory analysis

Risk Management

  • Risk methodologies
  • Enterprise risk reporting
  • Risk acceptance governance

Internal Audit

  • Independent assurance
  • Control testing
  • Governance reviews
  • Audit findings

Business Data Owners

  • Processing decisions
  • Lawful basis selection
  • Data quality
  • Retention decisions

HR & Procurement

  • Employee data processing
  • Workforce monitoring governance
  • Third-party assessments
  • Processor oversight

Comparing DPO Responsibilities with Business Responsibilities

The distinction between oversight and ownership is fundamental to the GDPR accountability framework.

DPO Responsibilities

Advise and inform

Monitor and challenge

Escalate concerns

Educate and train

Report to leadership

Coordinate and engage regulators

Business Responsibilities

Process personal data

Implement controls

Own risks and execute remediation

Maintain records

Allocate resources

Accept residual risk

The Three-Lines Governance Model

This separation is one of the most important governance concepts underpinning Articles 37, 38 and 39 and is frequently examined by supervisory authorities when assessing organisational accountability under the GDPR.

Advisory Functions and Oversight Functions Under Articles 38 and 39

One of the most persistent misconceptions in GDPR governance is the belief that a DPO loses independence by providing advice, guidance, recommendations, or subject matter expertise to the business. This interpretation is incorrect and is inconsistent with both the text and purpose of Articles 38 and 39.

Article 39(1)(a) states that the DPO shall "inform and advise" the controller, processor, and employees who carry out processing regarding their obligations under the GDPR. Advisory activity is not merely permissible — it is a mandatory statutory obligation.

The critical distinction is not between advice and oversight. Rather, it is between advice and operational decision-making.

A DPO May:

  • Provide recommendations
  • Interpret legal requirements
  • Advise on risk mitigation
  • Recommend controls
  • Review proposed processing
  • Recommend DPIA outcomes
  • Suggest lawful bases
  • Recommend transfer mechanisms
  • Challenge management decisions
  • Escalate concerns

A DPO Should Not:

  • Decide business strategy
  • Determine purposes of processing
  • Determine means of processing
  • Approve risk acceptance
  • Own operational controls
  • Sign off processing on behalf of management
  • Authorise system deployment
  • Accept residual privacy risk
  • Own remediation actions
  • Become accountable for compliance outcomes

The "Architect Versus Inspector" Analogy

An effective teaching analogy is that the DPO performs both an architectural and inspection role — helping design privacy controls whilst remaining independent of their operation.

Appropriate DPO Conduct

01

DPO advises that customer analytics requires a DPIA.

02

Business performs the DPIA.

03

DPO reviews methodology and recommends additional safeguards.

04

Management accepts or rejects recommendations.

Inappropriate DPO Conduct

01

DPO performs the DPIA themselves.

02

DPO approves deployment.

03

DPO signs risk acceptance.

04

DPO becomes accountable for implementation.

The Second-Line Challenge Model

First Line — Business

  • Processing activities
  • Data management
  • Control operation
  • Risk ownership
  • Compliance execution

Second Line — DPO & Privacy Governance

  • Advice and challenge
  • Monitoring
  • Escalation
  • Reporting
  • Independent assessment

Third Line — Internal Audit

  • Independent assurance
  • Audit testing
  • Board reporting

What Creates a Conflict of Interest?

The question is not whether the DPO provides advice. The question is whether the DPO ultimately controls decisions that they later monitor.

Conflicts Arise When the DPO:

  • Determines processing purposes
  • Determines processing means
  • Owns technology systems
  • Owns privacy operations
  • Owns marketing decisions
  • Owns HR processing decisions
  • Owns security architecture decisions
  • Approves business risk acceptance

Conflicts Do NOT Arise Merely Because the DPO:

  • Advises on controls
  • Recommends safeguards
  • Reviews projects
  • Participates in governance meetings
  • Provides training
  • Reviews contracts
  • Reviews DPIAs
  • Advises senior management

Required Oversight Activities Under Articles 38 and 39

Articles 38 and 39, interpreted alongside EDPB and supervisory authority guidance, imply a broad set of oversight obligations spanning strategic governance, processing activities, privacy-by-design, and DPIAs.

Strategic Governance Oversight

  • Monitor overall GDPR compliance programme
  • Assess accountability effectiveness
  • Monitor privacy risk trends
  • Review board-level privacy reporting
  • Assess adequacy of privacy resources
  • Monitor organisational compliance culture

Processing Activity Oversight

  • Monitor Records of Processing Activities
  • Review new processing activities
  • Review lawful basis determinations
  • Monitor purpose limitation compliance
  • Monitor data minimisation practices
  • Assess special category processing

Privacy-by-Design Oversight

  • Review privacy-by-design implementation
  • Monitor privacy-by-default controls
  • Assess product development governance
  • Monitor AI governance controls
  • Review automated decision-making activities
  • Monitor profiling activities

DPIA Oversight

  • Monitor DPIA trigger identification
  • Review DPIA methodologies
  • Assess DPIA quality
  • Review mitigation plans
  • Monitor implementation of recommendations
  • Track DPIA completion metrics

Extended Oversight Responsibilities

The DPO's oversight mandate extends across data subject rights, security incidents, vendor management, international transfers, training, and regulatory engagement.

Data Subject Rights Oversight

  • Monitor rights request processes and response timelines
  • Assess response quality and request volumes
  • Review complaint trends and transparency obligations
  • Monitor consent withdrawal and objection handling
  • Monitor portability processes
  • Review automated decision-making challenges

Security & Incident Oversight

  • Monitor personal data breach processes
  • Review breach classifications and notification decisions
  • Monitor Article 33 reporting compliance
  • Monitor Article 34 communication decisions
  • Assess recurring breach patterns
  • Review security control effectiveness

Vendor & Processor Oversight

  • Monitor processor governance and contractual compliance
  • Assess Article 28 implementation
  • Review subprocessor governance
  • Monitor processor incidents and remediation
  • Assess outsourcing risks

International Transfer Oversight

  • Monitor cross-border transfers
  • Review transfer impact assessments
  • Assess SCC implementation
  • Monitor adequacy decisions
  • Review supplementary safeguards
  • Monitor geopolitical developments
  • Assess cloud-hosting arrangements

Training & Awareness Oversight

  • Review training strategy and completion rates
  • Monitor awareness effectiveness
  • Review role-based and developer privacy training
  • Assess executive education
  • Monitor contractor training
  • Review awareness campaigns

Regulatory Oversight

  • Monitor regulatory developments and enforcement actions
  • Manage supervisory authority interactions
  • Monitor emerging guidance and new legal obligations
  • Coordinate consultation activities
  • Monitor corrective action programmes
  • Review regulator commitments

Independent Assurance Activities & Advanced Practitioner Conclusion

The DPO should maintain evidence demonstrating oversight. A mature interpretation of Articles 38 and 39 recognises that the DPO simultaneously performs two complementary functions.

Evidence of Oversight

  • Privacy monitoring plans
  • Compliance review schedules
  • Independent assessments
  • Formal recommendations
  • Escalation records
  • Governance committee reports
  • Executive reporting packs
  • Compliance dashboards
  • Risk assessments
  • Annual DPO reports

Two Complementary Functions

Trusted Advisor

The DPO advises because the GDPR requires expertise to be embedded into organisational decision-making.

Independent Overseer

The DPO oversees because the GDPR requires independent monitoring of those same decisions.

The boundary is crossed only when the DPO moves from advising and challenging decisions to making and owning those decisions. At that point, the DPO ceases to function as an independent oversight mechanism and begins to create the very conflict of interest that Article 38 seeks to prevent. For advanced practitioners, maintaining this distinction is one of the most important governance principles in the entire GDPR accountability framework.

Datari Home

The material within this site is provided for general guidance only and does not constitute legal, regulatory, or professional advice. Datari accepts no liability for any actions taken or not taken based on this content. Organisations should seek their own independent advice before making decisions.