Data Protection Officer Requirements by Country (2026)
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 37 primary sources cited on this page. How we verify our legal content
A Data Protection Officer (DPO) is a designated compliance professional required by law in dozens of jurisdictions worldwide. Under the EU General Data Protection Regulation (GDPR), Articles 37 through 39 set the foundational rules that most national frameworks have since adopted or adapted. This guide explains who must appoint a DPO, what the role requires, and how the obligation varies across major global regimes as of 10 September 2026.
Information last verified on 2026-09-10. This article has not yet been reviewed by a licensed lawyer.
Jurisdiction scope: This article covers DPO and DPO-equivalent requirements under the EU GDPR, including the national variations in Germany, France, Romania, Poland and Spain, under the UK GDPR, and under selected national privacy laws in Brazil, Canada (PIPEDA and Quebec Law 25), China, India, South Korea, Singapore, Malaysia, Thailand, South Africa, the UAE (federal PDPL, DIFC, ADGM), Indonesia and Vietnam. The comparison table also covers Japan and Australia, neither of which imposes a DPO duty. Statutes are cited as in force on 10 September 2026.
What Is a Data Protection Officer?
A Data Protection Officer is an individual designated by an organisation to serve as the internal authority on data protection compliance. Article 39 of the GDPR defines the DPO's core tasks: informing and advising the controller and processor (and their employees) of data protection obligations; monitoring compliance with the GDPR and with the controller's own policies; advising on data protection impact assessments (DPIAs); cooperating with the supervisory authority; and acting as the contact point for data subjects and the supervisory authority.
The concept gained global traction after the GDPR took effect on 25 May 2018. Regulators across South America, Asia, and Africa have since built DPO-equivalent requirements into national privacy statutes, though the specific triggers, qualifications, and reporting lines differ substantially by jurisdiction.
Not every organisation needs a DPO. The obligation typically turns on the type of data processed, the scale of processing activities, and whether the organisation is a public body. For multinational organisations, overlapping obligations can arise simultaneously under two or more regimes.
The GDPR DPO Rules: Articles 37, 38, and 39
The GDPR establishes the foundational DPO framework that most other jurisdictions have used as a reference. Articles 37 through 39 of Regulation (EU) 2016/679 set out the appointment triggers, qualifications, operational requirements, and tasks.
The Three Mandatory Appointment Triggers (Article 37)
Under Article 37(1) of the GDPR, a data controller or processor must designate a DPO when any one of three conditions is met:
Trigger 1: Public authority or body. The processing is carried out by a public authority or body, except for courts acting in their judicial capacity. This covers government departments, municipalities, public universities, state-owned enterprises, and similar entities across the EU and EEA.
Trigger 2: Large-scale regular and systematic monitoring. The controller's or processor's core activities consist of processing operations that require regular and systematic monitoring of data subjects on a large scale. The WP29 guidelines (WP243rev.01, endorsed by the EDPB) give geolocation tracking via mobile applications and systematic CCTV monitoring of public spaces as examples. The GDPR does not define "large scale" by a precise number; the WP29 guidance instructs controllers to consider the number of data subjects, volume of data, geographic extent, duration, and the nature of the processing. A single hospital processing health data for its patient population qualifies; a sole-practitioner doctor treating individual patients does not.
Trigger 3: Large-scale processing of special-category or criminal data. The controller's or processor's core activities consist of large-scale processing of special categories of data under Article 9 (including racial or ethnic origin, health data, biometric data, and data concerning sexual orientation) or of personal data relating to criminal convictions and offences under Article 10.
The term "core activities" is critical. The EDPB clarifies that it refers to the primary business operations, not ancillary support functions. An insurer processing health data to assess risk is engaged in a core activity; a law firm processing employee payroll data is not, even though payroll involves personal data.
"'Core activities' can be considered as the key operations necessary to achieve the controller's or processor's goals." -- WP29, Guidelines on Data Protection Officers (WP243rev.01), 5 April 2017
The same guidelines add that a hospital could not provide healthcare safely and effectively without processing health data such as patients' records, so processing that data is one of any hospital's core activities and hospitals must designate DPOs.
DPO Qualifications (Article 37(5))
Article 37(5) of the GDPR requires the DPO to possess "expert knowledge of data protection law and practices." No specific academic degree or professional certification is mandated at the EU level. The required level of expertise scales with the complexity of the organisation's data processing operations. For a large-scale processor of sensitive data, a high level of specialist knowledge is expected. For a smaller public body with straightforward processing, a proportionate level of knowledge suffices.
In practice, certifications such as the CIPP/E (Certified Information Privacy Professional/Europe) and CIPM (Certified Information Privacy Manager) from the International Association of Privacy Professionals (IAPP) are widely treated as evidence of the required expertise, though they remain voluntary under EU law.
Position and Independence (Article 38)
Article 38 establishes the operational requirements that protect the DPO's independence:
- The DPO must be involved, properly and in a timely manner, in all matters relating to the protection of personal data.
- The controller and processor must support the DPO by providing resources necessary to carry out their tasks, maintain expert knowledge, and access to personal data and processing operations.
- The DPO must report directly to the highest level of management of the controller or processor.
- The DPO cannot be dismissed or penalised for performing their tasks.
- The DPO may fulfil other tasks, but there must be no conflict of interest.
The conflict-of-interest requirement has been a focus of significant enforcement action. The EDPB confirms that roles which determine the purposes and means of data processing inherently conflict with the DPO position. This includes: Chief Executive Officer, Chief Operating Officer, Chief Technology Officer, Head of IT, Head of Human Resources, Head of Marketing, and in most contexts, Head of Legal (where legal counsel advises on the very processing decisions the DPO must independently oversee).
By decision of 18 December 2024, the Polish data protection authority (UODO) fined Toyota Bank Polska S.A. a total of EUR 132,000. Of that, EUR 60,000 concerned the DPO's lack of independence: the DPO sat in the security department and reported to its director, who also managed the bank's data processing operations, rather than to the highest level of management. The remaining EUR 72,000 related to undocumented profiling used for creditworthiness assessment and to missing impact assessments.
On 20 September 2022 the Berlin Commissioner for Data Protection (BlnBDI) fined the subsidiary of a Berlin e-commerce group EUR 525,000 under Article 38(6). Its DPO was at the same time managing director of two group service companies that processed personal data on behalf of the very company he was supposed to oversee. The authority had issued a warning in 2021 and imposed the fine only after a further inspection found the conflict still in place; the fine was not final when announced.
The DPO's Tasks (Article 39)
Article 39 defines five categories of mandatory tasks:
- Informing and advising the controller, processor, and their employees of their data protection obligations under the GDPR and other EU or member-state data protection law.
- Monitoring compliance, including the assignment of responsibilities, awareness-raising, training of staff involved in processing operations, and related audits.
- Providing advice where requested on DPIAs and monitoring their performance under Article 35.
- Cooperating with the supervisory authority.
- Acting as the contact point for the supervisory authority on processing issues and consulting them where appropriate.
Penalties for DPO Non-Compliance (Article 83(4))
Failure to designate a required DPO, interfering with the DPO's independence, or failing to publish DPO contact details falls under Article 83(4)(a), which permits fines of up to EUR 10 million or 2% of total worldwide annual turnover of the preceding financial year, whichever is higher.
The EDPB's DPO Guidance and the 2024 Coordinated Enforcement Action
The WP29 Guidelines on Data Protection Officers (WP243rev.01), adopted in December 2016 and revised in April 2017, remain the primary interpretive authority on Articles 37 through 39. The EDPB endorsed these guidelines at its first plenary meeting in May 2018.
In January 2024, the EDPB published the report of its 2023 Coordinated Enforcement Action (CEF 2023) on DPO designation and position. The investigation involved 25 data protection authorities across the EEA, which reviewed over 17,000 responses from organisations and DPOs across the private and public sectors. Key findings included:
- The vast majority of responding organisations had designated a DPO. Twelve respondents from seven member states, out of 15,108 organisations surveyed, admitted they had not designated one where designation was compulsory, and the report cautions that this figure is unlikely to reflect the true extent of non-compliance with Article 37(1).
- Resourcing gaps sat mainly in the public sector. Resources were judged sufficient in 91% of private-sector cases against 66% in the public sector, and public-sector DPOs were less likely to have a deputy DPO (36.4% against 56.3%) or a budget (26.6% against 56.8%).
- A median of 90.91% of respondents said their DPO had data protection experience or expert knowledge, but only a median of 74.97% treated expert knowledge of data protection law as a requirement for the role. The EDPB's concern is the gap between experience and the expert knowledge Article 37(5) actually demands, and the fact that most DPOs receive 24 hours of training a year or less.
- A median of 13.82% of respondents said their DPO receives instructions on how to carry out their tasks. The report calls that a minority of DPOs, while noting that eight member states returned results above 20%.
- DPOs were not consistently consulted. Only a median of 22.54% of respondents said their DPO was involved or consulted on personal data issues all of the time.
The EDPB's own summary of the action calls the overall results encouraging: the majority of DPOs surveyed report the necessary skills, clearly defined tasks and freedom from instructions, though the EDPB adds that there are still too many DPOs who are not in that position. The EDPB recommended that data protection authorities increase awareness-raising activity and targeted enforcement. The full report is available at edpb.europa.eu.
EU Member State Variations
While the GDPR sets a minimum floor, member states may impose additional requirements through national implementing legislation.
Germany. Section 38(1) of the Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG) has two limbs. The first requires DPO appointment by any organisation that as a rule permanently employs at least 20 persons in the automated processing of personal data, a threshold substantially lower than the GDPR's large-scale standard.
The second limb has no headcount at all. A controller or processor that carries out processing subject to a data protection impact assessment under GDPR Article 35, or that commercially processes personal data for the purpose of transfer, anonymised transfer, or market or opinion research, must appoint a DPO irrespective of how many people it employs. A three-person German market-research firm is therefore in scope.
France. The CNIL recommends broad DPO adoption but does not add mandatory appointment triggers beyond the GDPR. The CNIL reports that 109,249 organisations had designated a data protection officer, and that 39,174 DPOs were designated, as of 2025. That is strong institutional adoption, but note the two figures differ: many organisations share a DPO.
Romania. The National Supervisory Authority (ANSPDCP) applies the GDPR's own standard, not a national credential. Its published guidance says a DPO is designated on the basis of professional qualities and in particular expert knowledge of data protection law and practice, with the level of expertise scaled to the processing. Romanian law prescribes no certification for individual DPOs. The accreditation regime that does exist concerns certification bodies under GDPR Article 43, which certify processing operations rather than people.
Poland. The Polish data protection authority (UODO) requires notification of DPO appointment within 14 days and publishes a public register. By decision of 18 October 2024 the UODO fined the District Building Supervision Inspectorate in Czestochowa EUR 5,814 for three Article 37 failures: no effective designation of a DPO in writing, failure to publish the DPO's contact details, and failure to notify the supervisory authority. An oral instruction assigning DPO duties was held not to be an effective designation.
Spain. Article 34(1) of the LOPDGDD lists sixteen categories of entity that must appoint a DPO in every case, whatever the Article 37(1) tests would produce. They include professional associations, schools and universities, credit institutions, insurers and reinsurers, investment firms, electricity and gas retailers, operators of shared solvency and anti-fraud files, advertising and market-research firms that profile individuals, private security companies, and healthcare centres legally obliged to keep clinical records. Article 34(3) requires designations, appointments and removals to be communicated to the AEPD, or to the relevant regional authority, within ten days, for voluntary as well as mandatory designations. Article 35 treats certification as voluntary evidence of expertise, not a requirement.
United Kingdom (UK GDPR and DPA 2018)
Since Brexit, the UK operates under the UK GDPR and the Data Protection Act 2018 (DPA 2018). The DPO appointment triggers mirror the EU GDPR's three-part Article 37 structure. The Information Commissioner's Office (ICO) provides guidance at ico.org.uk.
The Data Protection and Digital Information Bill, introduced in 2023, proposed replacing the mandatory DPO requirement with a more flexible "senior responsible individual" (SRI) model. That Bill fell at the 2024 dissolution. Parliament replaced it with the Data (Use and Access) Act 2025, which received Royal Assent on 19 June 2025 and did not adopt the senior responsible individual model. The UK GDPR Article 37 DPO regime therefore remains in force.
The 2025 Act did make one DPO-relevant change. Schedule 11, paragraph 11 inserted the words "and tribunals" into UK GDPR Article 37(1)(a), so the carve-out from the public-authority trigger now covers courts and tribunals acting in their judicial capacity. That amendment took effect on 20 August 2025.
UK penalties for DPO failures sit in the standard tier, not the higher one. Infringements of Articles 37 to 39 fall under Article 83(4), and section 157(6) of the Data Protection Act 2018 sets the standard maximum at GBP 8.7 million or 2% of total annual worldwide turnover, whichever is higher. The GBP 17.5 million / 4% higher maximum in section 157(5) applies to other infringements.
DPO-Equivalent Requirements in Other Jurisdictions
Brazil (LGPD) -- Encarregado
Brazil's Lei Geral de Proteção de Dados (LGPD), Law 13.709/2018, effective September 2020, requires every data controller to appoint an encarregado under Article 41. Unlike the GDPR, Brazil's obligation applies to all controllers regardless of size or processing type. The encarregado accepts complaints from data subjects, provides information to data subjects and the ANPD, cooperates with the ANPD, and guides internal compliance efforts.
The ANPD's Resolution CD/ANPD No. 2 of January 2022 relaxed the obligation for small businesses and microenterprises classified under Brazilian law, allowing voluntary rather than mandatory designation. Small agents excused from designating an encarregado must still provide data subjects with a communication channel.
Resolution CD/ANPD No. 18 of 16 July 2024, in force on publication, is now the governing regulation on how the encarregado is appointed and operates. Designation must be by a formal act: a written, dated and signed document that sets out the encarregado's forms of action and activities, to be produced to the ANPD on request. A formally designated substitute must cover absences, impediments and vacancies. Public bodies must publish the designation in the relevant Official Gazette and should prefer public servants of unblemished reputation. Designation by processors (operadores) is optional and counts as a good-governance practice.
The treatment agent, not the ANPD, sets the professional qualifications. The encarregado's identity and contact details must be kept up to date and published clearly, prominently and accessibly on the agent's website, giving the full name if a natural person, or the business name plus the full name of the responsible natural person if a legal entity. The role may be performed by an individual, internal or external, or by a legal entity; there is no local-presence requirement, and the regulation states expressly that no registration with any body and no certification or specific professional training is presupposed. Article 13 sets one personal requirement: the encarregado must be able to communicate with data subjects and with the ANPD clearly and precisely in Portuguese.
China (PIPL) -- Person Responsible for Personal Information Protection
China's Personal Information Protection Law (PIPL), effective 1 November 2021, requires a personal information protection officer under Article 52 where a handler processes personal information reaching "the quantity provided by the State cyberspace and informatization department." Article 52 itself contains no number, and the Cyberspace Administration of China (CAC) has not published a figure specific to that officer. The responsible person's name and contact information must be publicly disclosed and reported to the department that performs personal information protection duties.
The one quantified threshold in the binding implementing instrument attaches to a different role. Article 28 of the Network Data Security Management Regulations (State Council Decree No. 790, in force 1 January 2025) provides that a network data handler processing the personal information of 10 million or more people must additionally comply with Articles 30 and 32, and Article 30 requires designation of a network data security officer and a security management body. That role is the network data security officer created by Decree 790, a separate appointment from the Article 52 personal information protection officer.
Article 52 imposes no China-residency requirement. The duty to establish a dedicated entity or designate a representative inside China sits in Article 53 and binds only handlers established outside China that are caught by Article 3(2).
On penalties, an ordinary failure falls under the first paragraph of Article 66: an order to correct, a warning, confiscation of unlawful gains and, where the handler refuses to correct, a fine of up to CNY 1 million, plus CNY 10,000 to CNY 100,000 on the directly responsible personnel. Only where the circumstances are serious may a provincial-level or higher authority impose a fine of up to CNY 50 million or up to 5% of the previous year's turnover. Those are two ceilings the regulator chooses between. The PIPL has no "whichever is higher" formula.
India (DPDPA 2023) -- DPO for Significant Data Fiduciaries
India's Digital Personal Data Protection Act, 2023 (DPDPA), enacted 11 August 2023, requires "Significant Data Fiduciaries" (SDFs) to appoint a Data Protection Officer based in India under Section 10(2)(a). SDF status is not a threshold an organisation can measure itself against. Under Section 10(1) it arises only where the Central Government notifies a Data Fiduciary, or a class of them, as an SDF, on an assessment of the factors listed there: volume and sensitivity of personal data processed, risk to the rights of data principals, potential impact on the sovereignty and integrity of India, risk to electoral democracy, security of the State, and public order.
The DPDP Rules, notified by MeitY on 13 November 2025 as G.S.R. 846(E), set no SDF threshold and do not mention the Data Protection Officer anywhere. Rule 13 presupposes SDF status and adds a twelve-monthly data protection impact assessment and audit, algorithmic due diligence, and a localisation restriction on data the Central Government specifies. Rule 13 comes into force eighteen months after publication of the Rules.
The Act prescribes no seniority grade. Section 10(2)(a) requires an individual who represents the SDF, is based in India, is responsible to its Board of Directors or similar governing body, and is the point of contact for the grievance redressal mechanism. SDFs must also conduct periodic DPIAs and appoint an independent data auditor. Breach of the Section 10 obligations, the DPO duty included, attracts a penalty of up to INR 150 crore under item 4 of the Act's Schedule. Item 1 of the Schedule, which carries the higher INR 250 crore penalty, covers failure to take reasonable security safeguards under Section 8(5).
Singapore (PDPA) -- Universal Mandatory DPO
Singapore's Personal Data Protection Act 2012 (PDPA), administered by the Personal Data Protection Commission (PDPC), requires every organisation subject to the PDPA to designate at least one individual as its DPO under Section 11(3). There is no minimum processing threshold. The obligation extends to holding companies, dormant companies, and organisations ceasing operations while they continue handling personal data.
Organisations must also file the DPO's business contact information. That filing dates from July 2020, when it ran through ACRA's BizFile+ portal. ACRA closed its channel on 1 December 2024, and registration now goes through the PDPC's own form, with the details published in the PDPC's public DPO Registry. No specific qualifications are mandated by law, though the DPO must possess adequate knowledge of the PDPA to guide the organisation effectively.
Malaysia (PDPA as amended 2024)
Malaysia's Personal Data Protection Act 2010 (PDPA) was substantially amended by the Personal Data Protection (Amendment) Act 2024, which inserted a new section 12A requiring data controllers and data processors to appoint one or more data protection officers. The amendment came into force in stages between January and June 2025.
The regulator's Guideline on the Appointment of Data Protection Officer sets numeric thresholds. A DPO is required where the processing involves personal data of more than 20,000 data subjects, sensitive personal data including financial information of more than 10,000 data subjects, or activities that require regular and systematic monitoring of personal data. An organisation holding sensitive data on a few hundred people is below the threshold.
On the person: the DPO must either be resident in Malaysia, meaning physically present for at least 180 days in one calendar year, or be easily contactable by any means, and in either case must be proficient in Bahasa Melayu and English. Residency is one of two alternatives, not a hard condition, so an outsourced or non-resident DPO is permitted provided accessibility and language proficiency are met. Language proficiency is the requirement that is genuinely mandatory in every case.
The appointment must be registered and the DPO's business contact information submitted to the Commissioner through the SPDP portal within 21 days of appointment, and any change updated within 14 days. The DPO advises on PDPA obligations, monitors compliance, conducts impact assessments, and serves as the contact point with the Commissioner.
Section 12A creates no offence and prescribes no penalty of its own; it is enforced through the Commissioner's enforcement powers. Penalties sit elsewhere in the Act: RM1 million or three years' imprisonment for contravening the Personal Data Protection Principles under section 5(2), and RM250,000 or two years for failure to notify a data breach under section 12B(3).
South Korea (PIPA) -- CPO and 2026 CEO Accountability Amendment
South Korea's Personal Information Protection Act (PIPA), significantly amended in 2023, requires all personal information controllers and processors to designate a Chief Privacy Officer (CPO) under Article 31. The CPO must hold decision-making authority within the organisation. Public institutions must designate the CPO at senior executive officer level. The CPO's name, department, and contact details must be publicly disclosed.
On 12 February 2026, the National Assembly passed a further amendment to PIPA, promulgated 10 March 2026 and effective 11 September 2026. The 2026 amendment: designates the CEO or business representative as the "ultimate person responsible for data protection"; requires CPO appointment, reassignment, or removal by formal board resolution with notification to the Personal Information Protection Commission (PIPC) for organisations above a size threshold; requires the CPO to report directly to both the CEO and the board; and raises the top surcharge ceiling under Art. 64-2(2) to 10% of total revenue. That 10% tier applies to an intentional or grossly negligent repeat of one of the nine violation types listed in Art. 64-2(1) within three years of an earlier surcharge, to an intentional or grossly negligent violation of any of those types that harms 10 million or more data subjects, and to a leak that follows non-compliance with a corrective order under Art. 64(1). The ordinary ceiling for those nine types stays at 3% of total revenue, and failing to designate a CPO is not among them.
Thailand (PDPA)
Thailand's Personal Data Protection Act B.E. 2562 (2019), fully effective from 1 June 2022, requires DPO appointment by public authorities prescribed and announced by the Committee, by organisations whose activities require regular monitoring of personal data by reason of holding a large volume of it as prescribed and announced by the Committee, and by organisations whose core activity is the processing of sensitive personal data (Sections 41-42 PDPA). The PDPC's Notification on Appointment of Data Protection Officers, effective 13 December 2023, provides detailed implementation guidance.
A further PDPC notification, No. 2 of B.E. 2568 issued on 9 October 2025, enlarged the schedule of state agencies that must appoint a DPO, adding provincial and local government bodies. It expands that list rather than covering every state agency. The DPO may be an employee or an external contractor. The DPO's contact information must be provided to the PDPC. In March 2026, the PDPC opened a public consultation on updated PDPA guidelines, with DPO obligations among the priority areas.
Failure to appoint a required DPO carries an administrative fine of up to THB 1 million, under section 82 for a data controller and section 85 for a data processor. Sections 84 and 87 set the higher ceiling of THB 5 million for violations involving sensitive personal data.
South Africa (POPIA) -- Information Officer
South Africa's Protection of Personal Information Act 4 of 2013 (POPIA), fully effective from 1 July 2021, does not have private bodies designate an Information Officer at all: read with the Promotion of Access to Information Act, the Information Officer of a private body is the head of that body by definition. Section 55(2) is the registration rule, providing that officers may take up their duties under the Act only after the responsible party has registered them with the Information Regulator. Section 56 governs something different and optional, the designation of deputy information officers, in such number "if any" as is necessary.
Failure to designate or register an Information Officer is not an offence under POPIA and carries no fine or term of imprisonment of its own. The Regulator enforces through an enforcement notice, and it is non-compliance with that notice that becomes an offence. POPIA's 10-year maximum term applies only to the offences listed in section 107(a), which concern obstructing the Regulator, breach of confidentiality and the account-number offences. The ZAR 10 million figure is the ceiling on administrative fines under section 109(2)(c).
UAE (Federal PDPL, DIFC, ADGM)
The United Arab Emirates has three overlapping but distinct data protection frameworks with different DPO requirements:
Federal PDPL. UAE Federal Decree-Law No. 45 of 2021 (PDPL) requires controllers to appoint a DPO when: processing involves systematic large-scale handling of sensitive personal data; processing poses a high risk to the privacy and confidentiality of personal data; or processing involves large-scale, sensitive, or systematically automated profiling. Once appointed, the controller or processor must notify the UAE Data Office of the DPO's contact details. The DPO may be an internal employee or an external service provider.
DIFC. The Dubai International Financial Centre operates under DIFC Law No. 5 of 2020 (Data Protection Law). DPO appointment is mandatory for DIFC bodies and for any controller or processor conducting High Risk Processing Activities on a systematic or regular basis. The DPO must reside in the UAE, unless the individual is employed within the organisation's group and performs an equivalent function internationally. The organisation must publish the DPO's contact details. Amended Data Protection Regulations enacted in September 2023 further aligned the framework with international standards.
ADGM. The Abu Dhabi Global Market operates under the ADGM Data Protection Regulations 2021. A DPO must be appointed for firms whose core activities involve regular and systematic processing of personal data on a large scale, or large-scale processing of special categories of personal data. The controller or processor must notify the ADGM Commissioner of Data Protection of the DPO's appointment within one month of appointment.
Indonesia (PDP Law 2022)
Indonesia's Law No. 27 of 2022 on Personal Data Protection took full effect on 17 October 2024. Article 53 requires appointment of a DPO where the processing is carried out for the interest of public services, the core activities require regular and systematic monitoring of personal data on a large scale, or the core activities involve large-scale processing of special categories of personal data.
On 30 July 2025, Indonesia's Constitutional Court (Decision No. 151/PUU-XXII/2024) held that the word "and" in Article 53(1)(b) of Law No. 27 of 2022 is unconstitutional and without binding force unless read as "and/or". That turns the three limbs from cumulative into alternative: an organisation must appoint a DPO if it meets any one of them. The ruling binds from the moment it was pronounced and does not wait on implementing regulations.
Vietnam (PDPL 2025)
Vietnam's Law No. 91/2025/QH15 on Personal Data Protection, enacted 26 June 2025 and effective 1 January 2026, requires controllers and processors to appoint an internal data protection department or personnel, or to engage external data protection service providers. Business households and micro-enterprises are exempt outright from designating data protection personnel or a department and from impact assessment obligations. Small enterprises and start-ups are not permanently exempt: they may choose whether to carry out those two obligations for five years from the Law's entry into force, so the option lapses on 1 January 2031.
Global DPO Requirements: Comparison Table
| Jurisdiction | Law | Role Title | Who Must Appoint | Local Presence Required | Outsourced DPO Permitted | Max Penalty |
|---|---|---|---|---|---|---|
| EU/EEA | GDPR Art. 37 | Data Protection Officer | Public bodies; large-scale systematic monitoring; large-scale special-data processing | No (must be accessible) | Yes | EUR 10M / 2% revenue |
| Germany | BDSG s. 38 | Data Protection Officer | 20 or more persons in automated processing; or, at any headcount, processing needing a DPIA or commercial transfer, anonymised transfer, market or opinion research (plus GDPR triggers) | No | Yes | EUR 10M / 2% revenue |
| UK | UK GDPR / DPA 2018 | Data Protection Officer | Same as GDPR (SRI model dropped; DUAA 2025 kept the DPO) | No | Yes | GBP 8.7M / 2% revenue |
| Brazil | LGPD Art. 41 | Encarregado | All controllers (SME exemption via ANPD Resolution 2/2022) | No | Yes | 2% revenue (max BRL 50M/violation) |
| China | PIPL Art. 52 | Person Responsible for PI Protection | Handlers reaching a quantity the CAC has not yet set; Decree 790 sets 10M+ for a separate network data security officer | No under Art. 52 (Art. 53 in-China entity or representative binds offshore handlers) | No (internal expected) | Up to CNY 1M ordinarily; ceiling of CNY 50M or 5% revenue only if serious |
| India | DPDPA s. 10 | Data Protection Officer | Significant Data Fiduciaries, only once notified as such by the Central Government (no threshold in the Rules) | Yes (India-based) | No (individual responsible to the SDF's board) | INR 150 crore for s. 10 breaches (Schedule item 4) |
| Singapore | PDPA s. 11(3) | Data Protection Officer | All organisations handling personal data | No | Yes | SGD 1M or 10% of Singapore turnover, whichever is higher (turnover limb once Singapore turnover passes SGD 10M) |
| Malaysia | PDPA (amended 2024) s. 12A | Data Protection Officer | More than 20,000 data subjects; or sensitive data on more than 10,000; or regular and systematic monitoring | No (180-day residency OR easily contactable; Bahasa Melayu and English required) | Yes | None for s. 12A itself (MYR 1M / 3 yrs attaches to the Principles, s. 5(2)) |
| South Korea | PIPA Art. 31 (2023 + 2026 amdt.) | Chief Privacy Officer | All PI controllers and processors | No | No (internal, decision-making authority) | Administrative fine of up to KRW 30 million for failing to designate a CPO (PIPA Art. 75(2), item 14-2, from 11 September 2026; KRW 10 million under Art. 75(4), item 9, before that). The turnover-based surcharge in Art. 64-2 is a separate regime: up to 3% of total revenue for the nine violation types listed in Art. 64-2(1), rising to up to 10% under Art. 64-2(2) for an intentional or grossly negligent repeat of the same violation type within three years of an earlier surcharge, for an intentional or grossly negligent violation of any of those types that harms 10 million or more data subjects, or for a leak that follows non-compliance with a corrective order. Failing to designate a CPO is not among those violation types |
| Thailand | PDPA ss. 41-42 / Dec 2023 Notification | Data Protection Officer | Public authorities announced by the Committee; large-volume regular monitoring; sensitive-data core activity | No | Yes | THB 1M for failure to appoint (ss. 82, 85) |
| South Africa | POPIA s. 55 | Information Officer (head of a private body) | All responsible parties; must be registered with the Regulator before taking up duties | No | Deputy IO may be designated (s. 56) | No penalty for the IO duty itself; enforcement-notice route |
| UAE (Federal) | PDPL / Exec. Regs. | Data Protection Officer | High-risk or sensitive large-scale processing | No | Yes | Pending secondary regulations |
| DIFC | DIFC DPL No. 5/2020 | Data Protection Officer | DIFC bodies; High Risk Processing entities | Yes (UAE resident, group exception) | Subject to DPL | Regulatory action by DIFC Commissioner |
| ADGM | ADGM DP Regs 2021 | Data Protection Officer | Large-scale systematic or special-data processing | No | Subject to Regs | Regulatory action by ADGM Commissioner |
| Indonesia | PDP Law No. 27/2022 Art. 53 | Data Protection Officer | Public-service; large-scale monitoring; large-scale special-data processing | No | Pending Regs | Administrative sanctions under Art. 57, including a fine of up to 2% of annual revenue or income (the criminal fines and prison terms in Arts. 67-70 attach to unlawfully obtaining, disclosing, using or falsifying personal data, not to the DPO duty) |
| Vietnam | PDPL No. 91/2025 | Data Protection Personnel/Dept. | All controllers/processors; household businesses and micro-enterprises exempt; small enterprises and start-ups may opt out for 5 years | No | Yes (external providers) | Pending secondary regulations |
| Japan | APPI | No formal DPO required | N/A (voluntary best practice) | N/A | N/A | None for a DPO duty (the JPY 100M corporate maximum in APPI Art. 184(1)(i) attaches to breach of a Commission order under Art. 178 and to misappropriation of a personal information database for illegal profit under Art. 179) |
| Australia | Privacy Act 1988 | No formal DPO required | N/A (voluntary; reform proposals ongoing) | N/A | N/A | None for a DPO duty (AUD 50M is one limb of the s. 13G penalty for a serious interference with privacy) |
| Canada | PIPEDA Sch. 1, Principle 4.1; Quebec Law 25 | Accountable individual / person in charge | Already mandatory for all organisations under PIPEDA; Bill C-27 died with the 44th Parliament in January 2025 | No | Yes | Complaint to the Privacy Commissioner and Federal Court; no fine for the designation duty |
Internal vs. External DPO
Most major privacy frameworks permit the DPO role to be filled by an external contractor or shared-service DPO, provided independence and expertise standards are met. The GDPR Article 37(2) explicitly allows a group of undertakings to designate a single DPO, provided that person is "easily accessible from each establishment."
External DPO services are commercially available in most jurisdictions and are popular among small and mid-sized businesses. Under the GDPR, the LGPD, and Thailand's PDPA, an external DPO must meet the same independence requirements as an internal one: they cannot simultaneously advise on the processing decisions they are supposed to oversee, and the organisation remains fully liable for compliance.
Jurisdictions that require internal appointment include: China (the responsible person must be an internal individual with authority within the organisation), South Korea (the CPO must hold internal decision-making authority), and India (the SDF's DPO must be an individual responsible to its board of directors, which in practice rules out a detached external provider).
Watch out: Using a law firm or a data privacy consultant as your DPO does not automatically satisfy independence requirements. The EDPB has noted that a legal adviser who also provides processing recommendations to the same client may hold a conflict of interest. Maintain a clear scope-of-work separation between advisory services and DPO oversight functions when using external providers.
How to Appoint and Position a DPO Effectively
Based on the EDPB's WP243rev.01 guidelines and the findings of the January 2024 CEF report, the following steps reduce compliance risk:
Step 1: Determine whether appointment is mandatory. Map all jurisdictions in which your organisation is established or processes personal data. Apply each jurisdiction's triggers. Document the analysis and review it annually or when operations change materially.
Step 2: Select a qualified candidate. The level of "expert knowledge" required scales with the complexity of the organisation's processing. A hospital DPO requires deeper expertise than a small municipality's. Certifications (CIPP/E, CIPM, CDPSE) are common evidence of expertise but are not legally required under EU law.
Step 3: Conduct a conflict-of-interest review. Identify every role the candidate holds or will hold that involves setting the purposes or means of data processing. Under the 2026 South Korea PIPA amendment, CPO appointment, reassignment, or removal requires formal board resolution. Consider similar governance mechanisms in other jurisdictions as a best practice.
Step 4: Provide adequate resources. The CEF 2023 report treated insufficient resources as one of its central concerns, with the shortfall concentrated in the public sector. The DPO must have protected time, budget, and access to processing operations and relevant staff. Part-time DPOs are permissible but must have time sufficient for the role.
Step 5: Establish direct reporting lines. The DPO must report to the highest level of management under GDPR Article 38(3). Section 10(2)(a) of India's DPDP Act and South Korea's 2026 PIPA amendment require board-level accountability by statute.
Step 6: Register and notify where required. Across the EU and EEA this is universal rather than a national extra. GDPR Article 37(7) requires every controller and processor that designates a DPO, mandatorily or voluntarily, to publish the DPO's contact details and communicate them to its supervisory authority.
National timing rules sit on top of that: Spain within ten days to the AEPD or the relevant regional authority, Poland within 14 days to the UODO. Outside the EEA, notification duties run to Singapore (PDPC), Malaysia (SPDP portal within 21 days, changes within 14 days), South Africa (registration with the Information Regulator before the officer takes up duties), Brazil (publish the encarregado's identity and contact details prominently on the website), ADGM (Commissioner, within one month), and UAE federal (UAE Data Office). Publish DPO contact details in the organisation's privacy notice and on its website.
Recent Developments (2024-2026)
EDPB CEF 2023 report (January 2024). The EDPB's coordinated enforcement action examined over 17,000 responses from DPOs and organisations across 25 EEA authorities. It found that the vast majority of respondents had designated a DPO, and identified resourcing gaps concentrated in the public sector along with independence concerns in a minority of cases. National authorities were recommended to raise awareness of the designation obligation, issue further guidance, and pursue enforcement action.
EU AI Act expansion of DPO workload. The EU AI Act (Regulation (EU) 2024/1689) has obligations for high-risk AI systems entering full application on 2 December 2027 for Annex III systems and 2 August 2028 for AI built into regulated products, moved by the July 2026 Digital Omnibus. Many organisations are assigning AI compliance oversight to existing DPOs, particularly for high-risk AI systems that also process personal data and therefore require DPIAs under the GDPR.
Malaysia mandatory DPO (June 2025). The Personal Data Protection (Amendment) Act 2024 came fully into force by June 2025, and the regulator's guideline set the thresholds: more than 20,000 data subjects, sensitive personal data on more than 10,000, or regular and systematic monitoring. The DPO must be resident in Malaysia or easily contactable, and in either case proficient in Bahasa Melayu and English, with registration through the SPDP portal within 21 days.
India DPDP Rules (November 2025). MeitY notified the DPDP Rules on 13 November 2025, and the provisions establishing the Data Protection Board of India took effect on publication. The Rules set no Significant Data Fiduciary threshold and do not mention the DPO; SDF status still depends on a Central Government notification under Section 10(1) of the Act, and the SDF additional obligations in Rule 13 commence eighteen months after publication.
South Korea 2026 PIPA amendment (effective September 2026). Passed 12 February 2026, promulgated 10 March 2026. Introduces CEO as ultimate responsible person, board-resolution requirement for CPO changes, a 10% of total revenue surcharge ceiling under Art. 64-2(2) for an intentional or grossly negligent repeat of one of the nine Art. 64-2(1) violation types within three years, for such a violation harming 10 million or more data subjects, or for a leak that follows non-compliance with a corrective order, and mandatory ISMS-P certification for large controllers from 1 July 2027.
Vietnam PDPL (January 2026). Vietnam's first standalone data protection law entered into force, requiring data protection personnel or departments across most organisations. Household businesses and micro-enterprises are exempt outright; small enterprises and start-ups may opt out for the first five years only.
Indonesia Constitutional Court ruling (July 2025). Decision No. 151/PUU-XXII/2024, pronounced 30 July 2025, read the "and" in Article 53(1)(b) of the 2022 PDP Law as "and/or", so meeting any one of the three conditions now triggers the DPO duty. The ruling binds directly and needs no implementing regulation.
Singapore DPO registration moved to the PDPC (December 2024). DPO contact filing has existed since July 2020, originally through ACRA's BizFile+ portal. ACRA closed that channel on 1 December 2024, and registration now runs through the PDPC's own form, with entries published in its public DPO Registry.
United Kingdom, Data (Use and Access) Act 2025 (June 2025). The Act replaced the DPDI Bill, declined to adopt the senior responsible individual model, and amended UK GDPR Article 37(1)(a) so the judicial carve-out covers courts and tribunals from 20 August 2025.
Where to Learn More
For organisations subject to the GDPR, the foundational reference is the EDPB's endorsed WP29 Guidelines on Data Protection Officers (WP243rev.01), available at edpb.europa.eu. For the broader GDPR compliance framework in which the DPO obligation sits, see the GDPR compliance checklist and the EU data privacy laws hub on this site.
Organisations operating across multiple jurisdictions should obtain advice from qualified data protection counsel in each relevant territory before finalising their DPO structure.
Disclaimer
This article provides general legal information about data protection officer requirements across multiple jurisdictions as of 10 September 2026. It is not legal advice. The laws and regulations described change frequently and may have been amended after the date of verification. Readers should not rely on this article as a substitute for advice from a lawyer qualified and licensed in the specific jurisdictions relevant to their operations. No attorney-client relationship is formed by reading this article.
Authorities Cited
- Regulation (EU) 2016/679 (GDPR), Arts. 37-39, 83(4). https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
- WP29, Guidelines on Data Protection Officers (WP243rev.01), 5 April 2017 (endorsed by EDPB). https://ec.europa.eu/newsroom/article29/items/612048
- EDPB, CEF 2023 Report on Designation and Position of DPOs, 16 January 2024. https://www.edpb.europa.eu/our-work-tools/our-documents/other/coordinated-enforcement-action-designation-and-position-data_en
- Bundesdatenschutzgesetz (BDSG) 2018, s. 38. https://www.gesetze-im-internet.de/bdsg_2018/__38.html
- ICO (UK), Guide to Accountability and Governance: Data Protection Officers. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/guide-to-accountability-and-governance/accountability-and-governance/data-protection-officers/
- Brazil LGPD, Law 13.709/2018, Art. 41. https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htm
- ANPD Resolution CD/ANPD No. 2, 27 January 2022, and Resolution CD/ANPD No. 18, 16 July 2024 (Regulation on the acting of the encarregado). https://www.gov.br/anpd/pt-br/acesso-a-informacao/institucional/atos-normativos/regulamentacoes_anpd
- China PIPL, effective 1 November 2021, Arts. 52, 53 and 66 (Cyberspace Administration of China publication). https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm
- India DPDP Act 2023, s. 10 and the Schedule. https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
- India DPDP Rules 2025 (G.S.R. 846(E)), notified 13 November 2025, rules 1(4) and 13. https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf
- Singapore PDPA 2012 (rev. 2021), s. 11(3). https://www.pdpc.gov.sg/Overview-of-PDPA/The-Legislation/Personal-Data-Protection-Act
- Malaysia Personal Data Protection (Amendment) Act 2024. https://www.pdp.gov.my/ppdpv1/en/akta/personal-data-protection-amendment-act-2024/
- South Korea, Personal Information Protection Act, Arts. 31, 64-2 and 75 (Law No. 21445, promulgated 10 March 2026, in force 11 September 2026), Korea Law Information Center. https://www.law.go.kr/%EB%B2%95%EB%A0%B9/%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%EB%B3%B4%ED%98%B8%EB%B2%95
- South Korea PIPA Amendment (promulgated 10 March 2026, effective 11 September 2026), Korean Government policy briefing. https://www.korea.kr/news/policyNewsView.do?newsId=148960564
- Thailand PDPA B.E. 2562 (2019), ss. 41-42, 82 and 85 (MDES English text); PDPC Notification on DPO Appointment (effective 13 December 2023). https://www.mdes.go.th/uploads/tinymce/source/%E0%B8%AA%E0%B8%84%E0%B8%AA/Personal%20Data%20Protection%20Act%202019.pdf
- South Africa POPIA, Act 4 of 2013, ss. 55, 56, 107 and 109. https://www.gov.za/sites/default/files/gcis_document/201409/3706726-11act4of2013protectionofpersonalinforcorrect.pdf
- UAE Federal Decree-Law No. 45 of 2021 (PDPL), Art. 10. https://uaelegislation.gov.ae/en/legislations/1972
- DIFC Data Protection Law No. 5 of 2020. https://www.difc.ae/business/laws-regulations/legal-database/data-protection-law-difc-law-no-5-2020/
- ADGM Data Protection Regulations 2021. https://www.adgm.com/operating-in-adgm/office-of-data-protection/guidance
- Indonesia Law No. 27 of 2022 on Personal Data Protection, Arts. 53, 57 and 67-70. https://peraturan.bpk.go.id/Details/229798/uu-no-27-tahun-2022
- Vietnam Law No. 91/2025/QH15 on Personal Data Protection (effective 1 January 2026). https://vanban.chinhphu.vn/?pageid=27160&docid=214590&classid=1&typegroupid=3
- Polish UODO, decision of 18 December 2024, Toyota Bank Polska S.A., EUR 132,000 in total, of which EUR 60,000 for the DPO's lack of independence. https://www.edpb.europa.eu/news/national-news/2025/polish-sa-administrative-fine-132-000-eu-improper-positioning-dpo-and_en
- Polish UODO, decision of 18 October 2024, District Building Supervision Inspectorate in Czestochowa, EUR 5,814 for failure to designate a DPO. https://www.edpb.europa.eu/news/national-news/2025/polish-sa-administrative-fine-5-814-eu-failure-designate-data-protection_en
- BlnBDI (Berlin), press release of 20 September 2022, EUR 525,000 fine for DPO conflict of interest (Art. 38(6) GDPR). https://www.datenschutz-berlin.de/fileadmin/user_upload/pdf/pressemitteilungen/2022/20220920-BlnBDI-PM-Bussgeld-DSB.pdf
- UK Data (Use and Access) Act 2025 (c. 18), Sch. 11 para. 11; Data Protection Act 2018, s. 157. https://www.legislation.gov.uk/ukpga/2025/18/contents
- Malaysia JPDP, Guideline on the Appointment of Data Protection Officer, paras 4.2, 6.10, 7.1 and 7.4. https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2025/02/GARIS-PANDUAN-PERLINDUNGAN-DATA-PERIBADI_PELANTIKAN-PEGAWAI-PERLINDUNGAN-DATA.pdf
- Malaysia Personal Data Protection (Amendment) Act 2024 (Act A1727), ss. 4 and 6 (new ss. 12A and 12B). https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2024/11/Act-A1727.pdf
- China, Network Data Security Management Regulations (State Council Decree No. 790), Arts. 28 and 30, in force 1 January 2025. https://www.gov.cn/zhengce/content/202409/content_6977766.htm
- Spain, Ley Organica 3/2018 (LOPDGDD), Arts. 34 and 35. https://www.boe.es/buscar/act.php?id=BOE-A-2018-16673
- Canada, PIPEDA, Schedule 1, Principle 4.1 and cl. 4.1.2. https://laws-lois.justice.gc.ca/eng/acts/P-8.6/FullText.html
- Indonesia, Constitutional Court Decision No. 151/PUU-XXII/2024, pronounced 30 July 2025. https://s.mkri.id/public/content/persidangan/putusan/putusan_mkri_12970_1753859809.pdf
- Thailand PDPC, Notification on data controllers and processors that are state agencies required to have a DPO (No. 2), B.E. 2568, 9 October 2025. https://www.mdes.go.th/law/detail/10069
- Singapore PDPA 2012, s. 48J, as applied by the PDPC Guide on Active Enforcement (revised 1 October 2022). https://www.pdpc.gov.sg/-/media/files/pdpc/pdf-files/other-guides/active-enforcement/guide-on-active-enforcement_oct2022.pdf
- ACRA, "DPO registration on BizFile+ unavailable from 1 December 2024". https://www.acra.gov.sg/news-events/news-announcements/834/
- CNIL, DPO designation figures (109,249 organisations, 39,174 DPOs, 2025). https://www.cnil.fr/fr/missions/mission-2-accompagner-la-conformite-conseiller
- Vietnam Government policy portal, summary of Law No. 91/2025/QH15 including the five-year option for small enterprises and start-ups. https://xaydungchinhsach.chinhphu.vn/quoc-hoi-da-thong-qua-luat-bao-ve-du-lieu-ca-nhan-119250626153701582.htm
- Japan, Act on the Protection of Personal Information, Arts. 178, 179 and 184 (Japanese Law Translation, Ministry of Justice). https://www.japaneselawtranslation.go.jp/en/laws/view/4241/en
- Australia, Privacy Act 1988, s. 13G (civil penalty for serious interference with privacy). https://www.legislation.gov.au/C2004A03712/latest/text
Last updated: 2026-09-10. Statutes cited reflect their in-force version as of 10 September 2026.
Frequently Asked Questions
Under the GDPR, what are the three triggers that make DPO appointment mandatory?
Article 37(1) of the GDPR requires DPO appointment for: (1) public authorities or bodies (except courts in their judicial capacity); (2) controllers or processors whose core activities require regular and systematic monitoring of data subjects on a large scale; and (3) controllers or processors whose core activities involve large-scale processing of special-category data (Article 9) or criminal-conviction data (Article 10). Satisfying any one trigger makes appointment mandatory.
Does every company need a Data Protection Officer?
No, not universally. Under the GDPR, only organisations meeting at least one of the three Article 37 triggers must appoint a DPO. However, Singapore's PDPA applies to every organisation handling personal data regardless of size. South Korea's PIPA requires CPO appointment by all personal information controllers and processors. South Africa's POPIA requires all responsible parties to register an Information Officer. Brazil's LGPD requires all controllers to appoint an encarregado, subject to small-business exemptions.
What qualifications does a DPO need under the GDPR?
Article 37(5) requires 'expert knowledge of data protection law and practices.' No specific degree or certification is mandated. The required level scales with the complexity of the processing. CIPP/E and CIPM certifications from the IAPP are widely treated as indicators of the required expertise but remain voluntary. No EU member state requires a specific DPO certification: Spain's LOPDGDD Article 35 treats certification as voluntary evidence of expertise, and Romania's ANSPDCP applies the GDPR standard without prescribing a credential.
Can a DPO be dismissed for performing their duties?
No. Article 38(3) of the GDPR provides that the DPO cannot be dismissed or penalised for performing their tasks. This protection ensures the DPO can raise compliance concerns without retaliation. Similar job-protection provisions appear in Brazil's LGPD and Thailand's PDPA. A DPO may be dismissed for reasons wholly unrelated to their DPO duties, provided those reasons are demonstrably independent of compliance work.
Can one DPO serve multiple group companies?
Yes. Under GDPR Article 37(2), a group of undertakings may designate a single DPO provided the DPO is 'easily accessible from each establishment.' This is widely used by multinational groups for EU operations. However, India's DPDPA requires an India-based individual responsible to the SDF's board, so a Europe-based group DPO cannot satisfy it, and China's PIPL Article 53 requires a handler established outside China to set up an in-China entity or designate a representative there. South Korea requires a CPO with internal decision-making authority, limiting the use of group-level or external DPOs.
What is the penalty for failing to appoint a required DPO under the GDPR?
Under Article 83(4)(a), failure to designate a DPO when required can result in fines of up to EUR 10 million or 2% of total worldwide annual turnover. In the UK the matching standard maximum is GBP 8.7 million or 2%. The Polish UODO fined a public body EUR 5,814 in October 2024 for failing to designate a DPO, and fined Toyota Bank Polska EUR 132,000 in December 2024, of which EUR 60,000 concerned the DPO's independence. Elsewhere: China PIPL -- up to CNY 1 million ordinarily, rising to a ceiling of CNY 50 million or 5% of turnover only where the circumstances are serious; South Korea PIPA -- an administrative fine of up to KRW 30 million for failing to designate a CPO once the 2026 amendment takes effect on 11 September 2026, and up to KRW 10 million before that; the 10% of total revenue introduced by that amendment is a separate Art. 64-2(2) surcharge for an intentional or grossly negligent repeat of one of the nine Art. 64-2(1) violation types within three years, for such a violation harming 10 million or more data subjects, or for a leak that follows non-compliance with a corrective order, not a penalty for the designation duty.
Is a DPO personally liable for the organisation's data protection violations?
No. The GDPR and most other frameworks place legal liability on the data controller or processor, not on the DPO. The DPO advises, monitors, and cooperates but does not personally authorise processing decisions. The controller remains responsible for ensuring the DPO's advice is followed. DPO liability for breach of confidentiality or personal conflicts of interest is a separate matter governed by national employment and contract law.
What roles create a conflict of interest that prevents someone from serving as DPO?
The EDPB's WP243rev.01 guidance identifies any role determining the purposes and means of data processing as incompatible with the DPO position. This typically includes: CEO, COO, CTO, Head of IT, Head of Human Resources, Head of Marketing, and Head of Legal. In September 2022 the Berlin DPA fined the subsidiary of a Berlin e-commerce group EUR 525,000 under Article 38(6) because its DPO was also managing director of two group companies processing data on its behalf. In December 2024 the Polish UODO fined Toyota Bank Polska EUR 60,000, within a total of EUR 132,000, because its DPO reported to a department director who also ran data processing operations.
Can an external consultant or law firm serve as DPO?
Yes, under the GDPR, Brazil's LGPD, and Thailand's PDPA, the DPO function may be outsourced to an external service provider, provided the provider meets the same independence and expertise standards as an internal DPO. Malaysia permits outsourcing where the DPO is either resident for 180 days or easily contactable, and is proficient in Bahasa Melayu and English. China's PIPL and South Korea's PIPA expect an internal individual with organisational authority. A law firm also advising the same client on processing decisions should maintain a strict scope separation to avoid conflicts.
What does Malaysia's 2024 PDPA amendment require for DPOs?
The Personal Data Protection (Amendment) Act 2024, in force from June 2025, inserted section 12A. The regulator's guideline requires a DPO where processing involves personal data of more than 20,000 data subjects, sensitive personal data including financial information of more than 10,000 data subjects, or activities requiring regular and systematic monitoring. The DPO must either be resident in Malaysia for at least 180 days in one calendar year or be easily contactable by any means, and in both cases must be proficient in Bahasa Melayu and English. The appointment must be registered with the Commissioner through the SPDP portal within 21 days, and changes updated within 14 days. Outsourced DPOs are permitted. Section 12A itself creates no offence.
What does South Korea's 2026 PIPA amendment change for DPOs?
The amendment, passed 12 February 2026 and effective 11 September 2026, designates the CEO or business representative as the ultimate person responsible for data protection. CPO appointment, reassignment, or removal now requires formal board resolution and must be reported to the PIPC for qualifying organisations. The CPO must report directly to both the CEO and the board. The Art. 64-2 surcharge ceiling rises from 3% to 10% of total revenue for an intentional or grossly negligent repeat of one of the nine Art. 64-2(1) violation types within three years of an earlier surcharge, for such a violation harming 10 million or more data subjects, or for a leak that follows non-compliance with a corrective order. Failing to designate a CPO is not among those violation types.
Updates
Corrected DPO rules across the comparison: Malaysia's residency rule is an alternative to being easily contactable and the Bahasa Melayu and English requirement was missing, with the regulator's 20,000 and 10,000 thresholds and 21-day registration added; China's PIPL Article 52 sets no number (the 10 million figure in State Council Decree 790 is a different officer) and its penalties are ceilings, not a whichever-is-higher test; India's SDF status comes only from a Central Government notification and the section 10 penalty is INR 150 crore, not 250; the UK's DPO maximum is GBP 8.7 million or 2% and the Data (Use and Access) Act 2025 dropped the senior responsible individual model; Canada already requires an accountable individual under PIPEDA and Bill C-27 died in January 2025; Indonesia's Constitutional Court ruling binds directly; Singapore's DPO filing dates from 2020 and its penalty cap includes a 10 percent turnover limb; South Africa's Information Officer duty is section 55 and carries no imprisonment; Thailand's failure-to-appoint fine is THB 1 million; Germany's BDSG catches small firms regardless of headcount; a misquoted WP29 passage was replaced with the verbatim text; Romania imposes no DPO certification; three enforcement actions were redated to 2022 and 2024 with their real facts; the French DPO figures were replaced with the CNIL's own; and Brazil's governing 2024 encarregado regulation was added. Corrected the Indonesia entry in the comparison table: failure to appoint a DPO under Article 53 of Law No. 27 of 2022 is an administrative matter under Article 57, capped at 2% of annual revenue, and the IDR 60 billion fine and six-year prison term previously shown belong to the criminal offences of unlawfully collecting, disclosing or falsifying personal data. The Japan and Australia rows no longer show a general privacy-law maximum against jurisdictions that impose no DPO duty. Added Brazil's requirement that the encarregado be able to communicate with data subjects and the ANPD in Portuguese, qualified Thailand's public-authority trigger to the bodies the Committee has announced, and updated the jurisdiction-scope note to list Canada, Japan, Australia and the EU member-state variations the article covers. Corrected the South Korea entry: failing to designate a Chief Privacy Officer carries an administrative fine under PIPA Article 75 (up to KRW 30 million once the 2026 amendment takes effect on 11 September 2026), while the 10 percent of turnover figure introduced by that amendment is a punitive surcharge for repeated or serious data leaks; restated the EDPB's 2023 coordinated enforcement findings to the report's own numbers, including that the vast majority of surveyed organisations had designated a DPO; and completed the Japanese and Indonesian penalty descriptions. Corrected how the page describes South Korea's 10% of turnover surcharge under the amended PIPA: it applies under Art. 64-2(2) to an intentional or grossly negligent repeat of any of the nine violation types in Art. 64-2(1) within three years, to any of those violations harming 10 million or more data subjects, or to a leak that follows non-compliance with a corrective order, rather than to data leaks generally, and it never applies to the CPO designation duty. Also repointed the South Korea statute reference to the consolidated-text permalink, added APPI Art. 179 to the Japan citation, and removed an unsourced 2025-2026 timeframe from the EDPB coordinated enforcement summary.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
AI Act dates updated for the July 2026 Digital Omnibus (Regulation (EU) 2026/1744): high-risk obligations now apply 2 December 2027 for Annex III systems and 2 August 2028 for AI built into regulated products, while the 2 August 2026 transparency date is unchanged.
Reviewed and approved by an editor
Sources and References
- GDPR Regulation (EU) 2016/679, Arts. 37-39, 83(4)(eur-lex.europa.eu).gov
- WP29 Guidelines on Data Protection Officers (WP243rev.01)(ec.europa.eu).gov
- EDPB CEF 2023 DPO Report, January 2024(edpb.europa.eu).gov
- Germany BDSG Section 38 - Data Protection Officers(gesetze-im-internet.de).gov
- UK ICO Guidance on Data Protection Officers(ico.org.uk).gov
- Brazil LGPD Article 41(planalto.gov.br).gov
- China PIPL, Arts. 52, 53 and 66 (Cyberspace Administration of China publication)(cac.gov.cn).gov
- India DPDP Act 2023, s. 10 and the Schedule (Gazette text, MeitY)(meity.gov.in).gov
- Malaysia Personal Data Protection (Amendment) Act 2024(pdp.gov.my).gov
- South Korea, Personal Information Protection Act, Arts. 31, 64-2 and 75 (Law No. 21445, promulgated 10 March 2026, in force 11 September 2026), Korea Law Information Center(law.go.kr).gov
- South Korea 2026 PIPA amendment (promulgated 10 March 2026, effective 11 September 2026), Korean Government policy briefing(korea.kr)
- Thailand PDPA B.E. 2562 (2019), ss. 41-42, 82 and 85 (MDES English text)(mdes.go.th).gov
- South Africa POPIA, Act 4 of 2013, ss. 55, 56, 107 and 109(gov.za).gov
- UAE Federal Decree-Law No. 45 of 2021 (PDPL), Art. 10(uaelegislation.gov.ae).gov
- DIFC Data Protection Law No. 5 of 2020(difc.ae).gov
- ADGM Office of Data Protection Guidance(adgm.com).gov
- Singapore PDPA Section 11(3)(pdpc.gov.sg).gov
- Polish UODO, decision of 18 December 2024, Toyota Bank Polska S.A., EUR 132,000 in total (EUR 60,000 for the DPO's lack of independence)(edpb.europa.eu).gov
- Polish UODO, decision of 18 October 2024, District Building Supervision Inspectorate in Czestochowa, EUR 5,814 for failure to designate a DPO(edpb.europa.eu).gov
- BlnBDI (Berlin), press release of 20 September 2022, EUR 525,000 fine for DPO conflict of interest(datenschutz-berlin.de)
- Regulation (EU) 2026/1744 of 8 July 2026 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI), OJ L 2026/1744, 24.7.2026(eur-lex.europa.eu).gov
- Malaysia JPDP, Guideline on the Appointment of Data Protection Officer, paras 4.2, 6.10, 7.1 and 7.4(pdp.gov.my).gov
- Malaysia Personal Data Protection (Amendment) Act 2024 (Act A1727), ss. 4 and 6 (new ss. 12A and 12B)(pdp.gov.my).gov
- China, Network Data Security Management Regulations (State Council Decree No. 790), Arts. 28 and 30, in force 1 January 2025(gov.cn).gov
- India Digital Personal Data Protection Rules 2025 (G.S.R. 846(E), 13 November 2025), rules 1(4) and 13(meity.gov.in).gov
- UK Data (Use and Access) Act 2025 (c. 18), Royal Assent 19 June 2025, Sch. 11 para. 11(legislation.gov.uk).gov
- UK Data Protection Act 2018, s. 157 (standard maximum GBP 8.7M / 2%)(legislation.gov.uk).gov
- Brazil, Resolucao CD/ANPD n. 18, de 16 de julho de 2024 (Regulamento sobre a atuacao do encarregado)(gov.br).gov
- Spain, Ley Organica 3/2018 (LOPDGDD), Arts. 34 and 35(boe.es).gov
- Canada PIPEDA, Schedule 1, Principle 4.1 and cl. 4.1.2(laws-lois.justice.gc.ca).gov
- Indonesia Constitutional Court, Decision No. 151/PUU-XXII/2024, pronounced 30 July 2025(s.mkri.id).gov
- Thailand PDPC, Notification on state-agency controllers and processors required to have a DPO (No. 2), B.E. 2568, 9 October 2025(mdes.go.th).gov
- Singapore PDPC, Guide on Active Enforcement (revised 1 October 2022), PDPA s. 48J penalties(pdpc.gov.sg).gov
- ACRA, DPO registration on BizFile+ unavailable from 1 December 2024; file with the PDPC instead(acra.gov.sg).gov
- CNIL, DPO designation figures (109,249 organisations, 39,174 DPOs, 2025)(cnil.fr).gov
- Vietnam Government policy portal, Law No. 91/2025/QH15: five-year option for small enterprises and start-ups, full exemption for household and micro-enterprises(xaydungchinhsach.chinhphu.vn).gov
- Indonesia Law No. 27 of 2022 on Personal Data Protection, Arts. 53, 57 and 67-70(peraturan.bpk.go.id).gov
- Japan, Act on the Protection of Personal Information, Arts. 178, 179 and 184 (Ministry of Justice official translation)(japaneselawtranslation.go.jp).gov
- Australia Privacy Act 1988, s. 13G (civil penalty for a serious interference with privacy)(legislation.gov.au).gov