The question isn't "what diploma do they need", but "who actually meets the conditions the law sets". Let's clarify the requirements, the conflict of interest, and the choice between an in-house and an outsourced DPO.
When an organisation has to — or chooses to — appoint a data protection officer, the first instinct is often to look for "someone suitable" in-house, frequently the person who "handles GDPR anyway". The right question, though, is not who has the time, but who meets the conditions the GDPR imposes. And those conditions are more precise than they look.
For clarity: if you first want to understand what a DPO does, we cover that separately in what a DPO is and its responsibilities. Here we deal strictly with eligibility — who may lawfully hold the role.
The starting point is Art. 37(5) GDPR: the data protection officer is designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices, and the ability to fulfil the tasks set out in Art. 39.
Two things follow. First, what counts is actual expertise, not hierarchical position or seniority. Second, the law requires no particular diploma and no mandatory certificate. A person can be a perfectly valid DPO without holding any certificate, provided they have the knowledge and the genuine ability to do the job. Certificates may evidence training, but they do not replace it and are not, in themselves, an eligibility condition — we return to this point at the end.
In practice, the level of expertise expected rises in proportion to the complexity and sensitivity of the processing. An organisation processing health data on a large scale needs a DPO with a markedly higher level of knowledge than one sufficient for a business with routine processing.
Art. 37(6) GDPR states clearly that the DPO may be either a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract. In other words, outsourcing is an option expressly provided by the law, just as valid as appointing an employee.
For small and medium businesses, the outsourced option is often more practical: it brings up-to-date expertise and a structural independence that an employee in a relationship of subordination achieves with more difficulty. For how this works in practice, we wrote at length in our Outsourced DPO article.
The GDPR also allows, in Art. 37(2), a group of undertakings to appoint a single DPO, provided that the DPO is easily accessible from each establishment. "Easily accessible" means, in practice, accessible to the data subjects, to the authority and to internal staff — including in linguistic and geographic terms.
Eligibility is not only about knowledge; it is also about the position the person can hold inside the organisation. Art. 38 GDPR sets out a set of safeguards without which the role remains purely formal:
From this follows a useful eligibility test: if the proposed person cannot realistically say "no" to management without fear of consequences, then they cannot be a DPO, however well they know the law.
This is where most appointment mistakes happen. Art. 38(6) GDPR allows the DPO to fulfil other tasks and duties, but only on condition that they do not give rise to a conflict of interests.
The WP29 guidelines, endorsed by the European Data Protection Board (EDPB), explain the core rule: the DPO cannot be a person who determines the purposes and means of processing. The reason is simple — you cannot independently review and advise on decisions that you yourself make. You would be reviewing your own work.
As a rule, management roles that decide on processing are incompatible with the DPO role, such as:
How do you test, in concrete terms, whether a conflict exists? You check whether the role in question decides what data is processed, for what purpose and by what means. If the answer is yes, the person would be in the position of assessing their own decisions — and cannot be the DPO for that organisation. The conflict is not cured by a formal declaration of impartiality; it is cured only by an effective separation of roles.
The ideal profile combines three qualities: solid legal knowledge of data protection, an understanding of the IT and security side (enough to assess technical and organisational measures), and an independent position, with no duties that decide on processing. The same person need not be both a lawyer and an engineer; they need to be able to hold a competent dialogue with both worlds.
That is why "the office manager who also keeps the GDPR folder" is rarely a real DPO: even in good faith, they usually lack the expertise, the resources and, above all, the independence and access to management. Such an arrangement creates a false impression of compliance — which is itself a risk, because it delays the discovery of the real problems.
If you are still unsure whether you are obliged to appoint a DPO, the legal threshold is detailed in our article on when a DPO is mandatory. Whatever the answer, the eligibility criteria above apply equally to a DPO appointed voluntarily.
Who can be the data protection officer? The person — internal or external — who has the expertise required by Art. 37(5), can benefit from the independent position in Art. 38, and is not in a conflict of interests under Art. 38(6). Title, seniority or a certificate replace none of these conditions. A sound appointment starts here, not with the question "who has the time".
No. Under Art. 37(5) GDPR, the DPO is designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices, and the ability to fulfil the Art. 39 tasks. An employee who lacks that expertise and the necessary independence is not a real DPO, only a name on a form.
As a rule, no. Art. 38(6) GDPR allows the DPO to hold other tasks only if they do not give rise to a conflict of interests. People who determine the purposes and means of processing — the managing director, head of IT, head of HR, head of marketing, operations director — would end up reviewing their own decisions, which WP29/EDPB guidance treats as incompatible with the DPO role.
Both are valid. Art. 37(6) GDPR provides that the DPO may be a staff member or may fulfil the tasks on the basis of a service contract (outsourced). For small and medium businesses, outsourcing brings up-to-date expertise and independence without the cost of a dedicated employee.
No. The GDPR requires no mandatory diploma or certificate. The legal test is genuine data protection expertise and the ability to perform the Art. 39 tasks. A certificate may evidence training, but it does not replace expertise and is not, in itself, an eligibility condition.
We assess whether you are obliged to appoint a data protection officer, check for any conflicts of interest, and provide an outsourced DPO — independent, with up-to-date expertise and without the cost of an extra employee.