SecurSentry
← All notes
UK GDPR

Does a Small Business Need a Data Protection Officer (DPO)?

The honest answer for most small businesses is no — a statutory DPO is mandatory in only three situations. Here is how to tell which side of the line you're on, and what to do either way.

The short version

If you’ve come across “you might need a Data Protection Officer” and felt a flicker of worry, you can probably relax. The question do I need a DPO has a reassuring answer for most small businesses: almost certainly not, at least not the formal, legally-required version. UK GDPR makes a statutory DPO mandatory in only three specific situations, and ordinary trading businesses rarely fall into any of them. The trick is knowing the difference between the legal role and the sensible everyday practice that every business should follow.

What a Data Protection Officer actually is

A DPO is a specific statutory role under UK GDPR, an independent expert who oversees how an organisation handles personal data, not just a job title you can hand to whoever has spare time.

The term gets used loosely, which is where the confusion starts. A Data Protection Officer in the legal sense is a defined position with defined duties: monitoring compliance with data protection law, advising the organisation, training staff, and acting as the contact point for the ICO (the Information Commissioner’s Office, the UK’s data protection regulator) and for the people whose data you hold.

Crucially, the role carries protections and conditions. A statutory DPO must be able to act independently, report to your most senior level, and avoid any conflict of interest. That’s a real commitment, which is exactly why the law only requires it where the risk to people genuinely warrants it. For most small businesses, calling someone your ‘data protection lead’ is the right move. Calling them a DPO when the law doesn’t require one means signing up to obligations you don’t actually have.

Article 37 of the UK GDPR makes a DPO mandatory in exactly three situations, and unless your business clearly fits one, you are not legally required to appoint one.

Here are the three, stripped of the legal phrasing:

  1. You are a public authority or body. Councils, schools, NHS bodies and similar public organisations must appoint a DPO, whatever data they handle. Courts acting in their judicial capacity are the one carve-out. If you run a private business, this one doesn’t apply to you.
  2. Your core activities require large-scale, regular and systematic monitoring of people. This is about businesses whose main purpose involves tracking or profiling individuals at scale: think continuous behavioural tracking, large-scale location monitoring, or profiling for targeted advertising as the actual product.
  3. Your core activities involve large-scale processing of special-category or criminal-offence data. Special-category data is the sensitive stuff: health, racial or ethnic origin, religious or philosophical beliefs, sex life or sexual orientation, and biometric and genetic data. A large private hospital or a national health-screening service would be in this bracket. A café that keeps a note of a customer’s nut allergy is not.

Two ideas do almost all the heavy lifting in triggers two and three: core activities and large scale. Get those right and the answer usually becomes obvious.

Why “core activities” lets most small businesses off

Processing you do as a routine side-effect of running a business — payroll, a customer list, staff HR files — is not a ‘core activity’, so it doesn’t trigger the DPO requirement.

This is the single most misunderstood part of the test, and it’s the part that reassures most owners once they grasp it.

The ICO draws a clear line. Your core activities are the things you do to achieve your primary objectives, the heart of what your business is for. A debt-recovery firm’s core activity is processing debtor data. A market-research company’s core activity might be profiling consumers. By contrast, processing you do all the time but only to keep the lights on (paying your staff, holding a list of customers so you can invoice them, keeping HR records) is a secondary purpose, not a core activity.

So a plumber, an accountancy practice, a small marketing agency, a corner shop, a builder, a local solicitor: they all process personal data daily, but that processing is incidental to the trade itself, not the trade itself. None of them is in the business of large-scale monitoring or large-scale sensitive-data processing. None of them needs a statutory DPO.

A QUICK GUT CHECK

Ask yourself one question: is large-scale tracking of people, or large-scale handling of sensitive data, the actual thing my business sells or does? If the honest answer is no, and you just hold normal customer and staff records to run a normal business, you almost certainly don't need a statutory DPO. If you're genuinely unsure because monitoring or sensitive data is central to your model, that's the moment to take proper advice.

Who does need one: a few real examples

A handful of business types do cross the line, and they’re the ones where tracking people or handling sensitive data at scale is the point of the business.

It helps to see both sides. Businesses that genuinely do tend to need a DPO include:

Businesses that almost never need one include the everyday majority: retailers, trades, professional services, hospitality, small agencies, e-commerce shops selling ordinary goods. They hold personal data, sometimes a fair amount of it, but it’s the ordinary plumbing of doing business, not large-scale monitoring or large-scale sensitive processing.

The DPO question isn’t really ‘how much data do I hold?’. It’s ‘is watching or handling people’s most sensitive data the actual job?’. For most small businesses, the answer is a clear no.

What to do instead: name a data protection lead

Even when the law doesn’t require a DPO, you should still give one named person clear responsibility for data protection. It’s good practice, and it’s where real protection actually comes from.

Not needing a statutory DPO is not the same as no one being responsible. The opposite, in fact. The ICO encourages every organisation to make sure someone has clear ownership of data protection, even where a formal DPO isn’t required.

This person is sometimes called a data protection lead or manager — a deliberately lighter role than the statutory DPO: no formal independence requirement, no obligation to report to board level, no rule against conflicts of interest. In a small business it’s often the owner, the office manager, or whoever already keeps an eye on systems and records. What matters is that the responsibility is named and understood, not floating vaguely across everyone and therefore nobody.

A good data protection lead does the practical work that actually keeps you compliant: knowing what personal data you hold and where, keeping your privacy notice and basic GDPR housekeeping up to date, handling any requests or incidents calmly, and making sure your policies aren’t just sitting in a drawer. Much of that becomes far simpler with a GDPR policy starter pack to build from, rather than starting with a blank page.

If you do appoint a DPO, voluntarily or because you must

Once you appoint a statutory DPO, real conditions attach to the role, and you have to meet them whether you appointed one by choice or by law.

It’s worth knowing this, because some businesses appoint a DPO voluntarily and are surprised that the legal requirements then apply in full. The ICO is explicit that a voluntary DPO must be treated exactly as a mandatory one. If you give someone the formal DPO title, UK GDPR expects you to:

The role can be filled internally by an existing employee, or outsourced to an external provider on a service contract. Plenty of small organisations that do need one choose the outsourced route, because it brings independent expertise without a full-time hire. Either way, the conditions above still apply.

Don’t let the DPO question stall the basics

Whether or not you need a DPO, the foundations of data protection are the same, and they’re what genuinely reduce your risk.

Here’s the honest bit. “Do I need a DPO?” can quietly become an excuse to do nothing, as if the answer changes everything. It doesn’t. Whether you’re legally required to appoint a DPO or not, the same fundamentals apply to every business: know what personal data you hold, hold only what you need, keep it secure, be straight with people about how you use it, and be ready to respond if something goes wrong.

For the overwhelming majority of small businesses, the answer to the DPO question is simply “no, but make sure someone owns this.” Settle that quickly, point that person at the practical work, and you’ve spent your energy where it actually counts — on protecting data, not on a job title most of you don’t need.

SecurSentry is launching soon to help UK SMEs build genuine, evidence-backed data protection — including naming who’s responsible and getting the everyday basics in place — without needing a DPO or a legal team to do it. Join the waitlist to be first to know when we open.


This article is general information, not legal or compliance advice. If your business involves large-scale monitoring or sensitive data, or you’re unsure which side of the line you fall on, seek qualified guidance from a data protection professional or solicitor.

Frequently asked questions

When is a DPO legally required for a small business?

Under UK GDPR Article 37, a DPO is mandatory in only three situations: you are a public authority or body; your core activities require regular and systematic monitoring of individuals on a large scale; or your core activities involve large-scale processing of special-category data or criminal-offence data. Most small businesses meet none of these and so do not need a statutory DPO.

What does 'core activities' mean for the DPO test?

Core activities are your primary business activities, the things you do to achieve your main objectives. The ICO is clear that processing you do all the time for secondary purposes, such as payroll or staff HR records, is not a core activity. A DPO is only triggered when the large-scale monitoring or special-category processing is central to what your business actually does.

Do I need a DPO if I don't meet the three triggers?

No. If none of the three Article 37 conditions apply, you are not legally required to appoint a DPO. The ICO still recommends giving someone clear responsibility for data protection, sometimes called a data protection lead or manager, but this is good practice, not the formal statutory role. It is worth recording your decision that a DPO is not required, to help demonstrate accountability.

Can a small business outsource the DPO role?

Yes. If you do need or choose to appoint a DPO, it can be an existing employee or an external provider on a service contract. Either way the DPO must be able to act independently, be properly resourced, report to your most senior level, and have no conflict of interest with their other duties. Note that a voluntary DPO carries the same legal requirements as a mandatory one.

Written by The SecurSentry Team

We write plain-English notes on security and compliance for small businesses — the things we wish someone had explained to us. Read more notes →

More from the blog

Cyber Essentials

How to Get ISO 27001 Certified: The Process, Step by Step

21 Aug 2026 · 9 min
Cyber Essentials

ISO 27001 Risk Assessment, Without Overcomplicating It

18 Aug 2026 · 9 min
Cyber Essentials

ISO 27001 Annex A Controls, in Plain English

14 Aug 2026 · 8 min

Be first to know when we launch.

Leave your email and we'll let you know the moment SecurSentry is ready. One email — no newsletters, no spam.

Just one email, at launch. We never share your data. Privacy policy.

You're on the list — we'll be in touch at launch.