Data Protection Officer Requirements by Country (2026)

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 37 primary sources cited on this page. How we verify our legal content

Data Protection Officer Requirements by Country (2026)

Frequently Asked Questions

Under the GDPR, what are the three triggers that make DPO appointment mandatory?

Article 37(1) of the GDPR requires DPO appointment for: (1) public authorities or bodies (except courts in their judicial capacity); (2) controllers or processors whose core activities require regular and systematic monitoring of data subjects on a large scale; and (3) controllers or processors whose core activities involve large-scale processing of special-category data (Article 9) or criminal-conviction data (Article 10). Satisfying any one trigger makes appointment mandatory.

Does every company need a Data Protection Officer?

No, not universally. Under the GDPR, only organisations meeting at least one of the three Article 37 triggers must appoint a DPO. However, Singapore's PDPA applies to every organisation handling personal data regardless of size. South Korea's PIPA requires CPO appointment by all personal information controllers and processors. South Africa's POPIA requires all responsible parties to register an Information Officer. Brazil's LGPD requires all controllers to appoint an encarregado, subject to small-business exemptions.

What qualifications does a DPO need under the GDPR?

Article 37(5) requires 'expert knowledge of data protection law and practices.' No specific degree or certification is mandated. The required level scales with the complexity of the processing. CIPP/E and CIPM certifications from the IAPP are widely treated as indicators of the required expertise but remain voluntary. No EU member state requires a specific DPO certification: Spain's LOPDGDD Article 35 treats certification as voluntary evidence of expertise, and Romania's ANSPDCP applies the GDPR standard without prescribing a credential.

Can a DPO be dismissed for performing their duties?

No. Article 38(3) of the GDPR provides that the DPO cannot be dismissed or penalised for performing their tasks. This protection ensures the DPO can raise compliance concerns without retaliation. Similar job-protection provisions appear in Brazil's LGPD and Thailand's PDPA. A DPO may be dismissed for reasons wholly unrelated to their DPO duties, provided those reasons are demonstrably independent of compliance work.

Can one DPO serve multiple group companies?

Yes. Under GDPR Article 37(2), a group of undertakings may designate a single DPO provided the DPO is 'easily accessible from each establishment.' This is widely used by multinational groups for EU operations. However, India's DPDPA requires an India-based individual responsible to the SDF's board, so a Europe-based group DPO cannot satisfy it, and China's PIPL Article 53 requires a handler established outside China to set up an in-China entity or designate a representative there. South Korea requires a CPO with internal decision-making authority, limiting the use of group-level or external DPOs.

What is the penalty for failing to appoint a required DPO under the GDPR?

Under Article 83(4)(a), failure to designate a DPO when required can result in fines of up to EUR 10 million or 2% of total worldwide annual turnover. In the UK the matching standard maximum is GBP 8.7 million or 2%. The Polish UODO fined a public body EUR 5,814 in October 2024 for failing to designate a DPO, and fined Toyota Bank Polska EUR 132,000 in December 2024, of which EUR 60,000 concerned the DPO's independence. Elsewhere: China PIPL -- up to CNY 1 million ordinarily, rising to a ceiling of CNY 50 million or 5% of turnover only where the circumstances are serious; South Korea PIPA -- an administrative fine of up to KRW 30 million for failing to designate a CPO once the 2026 amendment takes effect on 11 September 2026, and up to KRW 10 million before that; the 10% of total revenue introduced by that amendment is a separate Art. 64-2(2) surcharge for an intentional or grossly negligent repeat of one of the nine Art. 64-2(1) violation types within three years, for such a violation harming 10 million or more data subjects, or for a leak that follows non-compliance with a corrective order, not a penalty for the designation duty.

Is a DPO personally liable for the organisation's data protection violations?

No. The GDPR and most other frameworks place legal liability on the data controller or processor, not on the DPO. The DPO advises, monitors, and cooperates but does not personally authorise processing decisions. The controller remains responsible for ensuring the DPO's advice is followed. DPO liability for breach of confidentiality or personal conflicts of interest is a separate matter governed by national employment and contract law.

What roles create a conflict of interest that prevents someone from serving as DPO?

The EDPB's WP243rev.01 guidance identifies any role determining the purposes and means of data processing as incompatible with the DPO position. This typically includes: CEO, COO, CTO, Head of IT, Head of Human Resources, Head of Marketing, and Head of Legal. In September 2022 the Berlin DPA fined the subsidiary of a Berlin e-commerce group EUR 525,000 under Article 38(6) because its DPO was also managing director of two group companies processing data on its behalf. In December 2024 the Polish UODO fined Toyota Bank Polska EUR 60,000, within a total of EUR 132,000, because its DPO reported to a department director who also ran data processing operations.

Can an external consultant or law firm serve as DPO?

Yes, under the GDPR, Brazil's LGPD, and Thailand's PDPA, the DPO function may be outsourced to an external service provider, provided the provider meets the same independence and expertise standards as an internal DPO. Malaysia permits outsourcing where the DPO is either resident for 180 days or easily contactable, and is proficient in Bahasa Melayu and English. China's PIPL and South Korea's PIPA expect an internal individual with organisational authority. A law firm also advising the same client on processing decisions should maintain a strict scope separation to avoid conflicts.

What does Malaysia's 2024 PDPA amendment require for DPOs?

The Personal Data Protection (Amendment) Act 2024, in force from June 2025, inserted section 12A. The regulator's guideline requires a DPO where processing involves personal data of more than 20,000 data subjects, sensitive personal data including financial information of more than 10,000 data subjects, or activities requiring regular and systematic monitoring. The DPO must either be resident in Malaysia for at least 180 days in one calendar year or be easily contactable by any means, and in both cases must be proficient in Bahasa Melayu and English. The appointment must be registered with the Commissioner through the SPDP portal within 21 days, and changes updated within 14 days. Outsourced DPOs are permitted. Section 12A itself creates no offence.

What does South Korea's 2026 PIPA amendment change for DPOs?

The amendment, passed 12 February 2026 and effective 11 September 2026, designates the CEO or business representative as the ultimate person responsible for data protection. CPO appointment, reassignment, or removal now requires formal board resolution and must be reported to the PIPC for qualifying organisations. The CPO must report directly to both the CEO and the board. The Art. 64-2 surcharge ceiling rises from 3% to 10% of total revenue for an intentional or grossly negligent repeat of one of the nine Art. 64-2(1) violation types within three years of an earlier surcharge, for such a violation harming 10 million or more data subjects, or for a leak that follows non-compliance with a corrective order. Failing to designate a CPO is not among those violation types.

Updates

Corrected DPO rules across the comparison: Malaysia's residency rule is an alternative to being easily contactable and the Bahasa Melayu and English requirement was missing, with the regulator's 20,000 and 10,000 thresholds and 21-day registration added; China's PIPL Article 52 sets no number (the 10 million figure in State Council Decree 790 is a different officer) and its penalties are ceilings, not a whichever-is-higher test; India's SDF status comes only from a Central Government notification and the section 10 penalty is INR 150 crore, not 250; the UK's DPO maximum is GBP 8.7 million or 2% and the Data (Use and Access) Act 2025 dropped the senior responsible individual model; Canada already requires an accountable individual under PIPEDA and Bill C-27 died in January 2025; Indonesia's Constitutional Court ruling binds directly; Singapore's DPO filing dates from 2020 and its penalty cap includes a 10 percent turnover limb; South Africa's Information Officer duty is section 55 and carries no imprisonment; Thailand's failure-to-appoint fine is THB 1 million; Germany's BDSG catches small firms regardless of headcount; a misquoted WP29 passage was replaced with the verbatim text; Romania imposes no DPO certification; three enforcement actions were redated to 2022 and 2024 with their real facts; the French DPO figures were replaced with the CNIL's own; and Brazil's governing 2024 encarregado regulation was added. Corrected the Indonesia entry in the comparison table: failure to appoint a DPO under Article 53 of Law No. 27 of 2022 is an administrative matter under Article 57, capped at 2% of annual revenue, and the IDR 60 billion fine and six-year prison term previously shown belong to the criminal offences of unlawfully collecting, disclosing or falsifying personal data. The Japan and Australia rows no longer show a general privacy-law maximum against jurisdictions that impose no DPO duty. Added Brazil's requirement that the encarregado be able to communicate with data subjects and the ANPD in Portuguese, qualified Thailand's public-authority trigger to the bodies the Committee has announced, and updated the jurisdiction-scope note to list Canada, Japan, Australia and the EU member-state variations the article covers. Corrected the South Korea entry: failing to designate a Chief Privacy Officer carries an administrative fine under PIPA Article 75 (up to KRW 30 million once the 2026 amendment takes effect on 11 September 2026), while the 10 percent of turnover figure introduced by that amendment is a punitive surcharge for repeated or serious data leaks; restated the EDPB's 2023 coordinated enforcement findings to the report's own numbers, including that the vast majority of surveyed organisations had designated a DPO; and completed the Japanese and Indonesian penalty descriptions. Corrected how the page describes South Korea's 10% of turnover surcharge under the amended PIPA: it applies under Art. 64-2(2) to an intentional or grossly negligent repeat of any of the nine violation types in Art. 64-2(1) within three years, to any of those violations harming 10 million or more data subjects, or to a leak that follows non-compliance with a corrective order, rather than to data leaks generally, and it never applies to the CPO designation duty. Also repointed the South Korea statute reference to the consolidated-text permalink, added APPI Art. 179 to the Japan citation, and removed an unsourced 2025-2026 timeframe from the EDPB coordinated enforcement summary.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

AI Act dates updated for the July 2026 Digital Omnibus (Regulation (EU) 2026/1744): high-risk obligations now apply 2 December 2027 for Annex III systems and 2 August 2028 for AI built into regulated products, while the 2 August 2026 transparency date is unchanged.

Reviewed and approved by an editor

Sources and References

  1. GDPR Regulation (EU) 2016/679, Arts. 37-39, 83(4)(eur-lex.europa.eu).gov
  2. WP29 Guidelines on Data Protection Officers (WP243rev.01)(ec.europa.eu).gov
  3. EDPB CEF 2023 DPO Report, January 2024(edpb.europa.eu).gov
  4. Germany BDSG Section 38 - Data Protection Officers(gesetze-im-internet.de).gov
  5. UK ICO Guidance on Data Protection Officers(ico.org.uk).gov
  6. Brazil LGPD Article 41(planalto.gov.br).gov
  7. China PIPL, Arts. 52, 53 and 66 (Cyberspace Administration of China publication)(cac.gov.cn).gov
  8. India DPDP Act 2023, s. 10 and the Schedule (Gazette text, MeitY)(meity.gov.in).gov
  9. Malaysia Personal Data Protection (Amendment) Act 2024(pdp.gov.my).gov
  10. South Korea, Personal Information Protection Act, Arts. 31, 64-2 and 75 (Law No. 21445, promulgated 10 March 2026, in force 11 September 2026), Korea Law Information Center(law.go.kr).gov
  11. South Korea 2026 PIPA amendment (promulgated 10 March 2026, effective 11 September 2026), Korean Government policy briefing(korea.kr)
  12. Thailand PDPA B.E. 2562 (2019), ss. 41-42, 82 and 85 (MDES English text)(mdes.go.th).gov
  13. South Africa POPIA, Act 4 of 2013, ss. 55, 56, 107 and 109(gov.za).gov
  14. UAE Federal Decree-Law No. 45 of 2021 (PDPL), Art. 10(uaelegislation.gov.ae).gov
  15. DIFC Data Protection Law No. 5 of 2020(difc.ae).gov
  16. ADGM Office of Data Protection Guidance(adgm.com).gov
  17. Singapore PDPA Section 11(3)(pdpc.gov.sg).gov
  18. Polish UODO, decision of 18 December 2024, Toyota Bank Polska S.A., EUR 132,000 in total (EUR 60,000 for the DPO's lack of independence)(edpb.europa.eu).gov
  19. Polish UODO, decision of 18 October 2024, District Building Supervision Inspectorate in Czestochowa, EUR 5,814 for failure to designate a DPO(edpb.europa.eu).gov
  20. BlnBDI (Berlin), press release of 20 September 2022, EUR 525,000 fine for DPO conflict of interest(datenschutz-berlin.de)
  21. Regulation (EU) 2026/1744 of 8 July 2026 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI), OJ L 2026/1744, 24.7.2026(eur-lex.europa.eu).gov
  22. Malaysia JPDP, Guideline on the Appointment of Data Protection Officer, paras 4.2, 6.10, 7.1 and 7.4(pdp.gov.my).gov
  23. Malaysia Personal Data Protection (Amendment) Act 2024 (Act A1727), ss. 4 and 6 (new ss. 12A and 12B)(pdp.gov.my).gov
  24. China, Network Data Security Management Regulations (State Council Decree No. 790), Arts. 28 and 30, in force 1 January 2025(gov.cn).gov
  25. India Digital Personal Data Protection Rules 2025 (G.S.R. 846(E), 13 November 2025), rules 1(4) and 13(meity.gov.in).gov
  26. UK Data (Use and Access) Act 2025 (c. 18), Royal Assent 19 June 2025, Sch. 11 para. 11(legislation.gov.uk).gov
  27. UK Data Protection Act 2018, s. 157 (standard maximum GBP 8.7M / 2%)(legislation.gov.uk).gov
  28. Brazil, Resolucao CD/ANPD n. 18, de 16 de julho de 2024 (Regulamento sobre a atuacao do encarregado)(gov.br).gov
  29. Spain, Ley Organica 3/2018 (LOPDGDD), Arts. 34 and 35(boe.es).gov
  30. Canada PIPEDA, Schedule 1, Principle 4.1 and cl. 4.1.2(laws-lois.justice.gc.ca).gov
  31. Indonesia Constitutional Court, Decision No. 151/PUU-XXII/2024, pronounced 30 July 2025(s.mkri.id).gov
  32. Thailand PDPC, Notification on state-agency controllers and processors required to have a DPO (No. 2), B.E. 2568, 9 October 2025(mdes.go.th).gov
  33. Singapore PDPC, Guide on Active Enforcement (revised 1 October 2022), PDPA s. 48J penalties(pdpc.gov.sg).gov
  34. ACRA, DPO registration on BizFile+ unavailable from 1 December 2024; file with the PDPC instead(acra.gov.sg).gov
  35. CNIL, DPO designation figures (109,249 organisations, 39,174 DPOs, 2025)(cnil.fr).gov
  36. Vietnam Government policy portal, Law No. 91/2025/QH15: five-year option for small enterprises and start-ups, full exemption for household and micro-enterprises(xaydungchinhsach.chinhphu.vn).gov
  37. Indonesia Law No. 27 of 2022 on Personal Data Protection, Arts. 53, 57 and 67-70(peraturan.bpk.go.id).gov
  38. Japan, Act on the Protection of Personal Information, Arts. 178, 179 and 184 (Ministry of Justice official translation)(japaneselawtranslation.go.jp).gov
  39. Australia Privacy Act 1988, s. 13G (civil penalty for a serious interference with privacy)(legislation.gov.au).gov
Share: