Do I Need a Data Protection Officer? A Guide for UK Scale-Ups
Quick answer: You need a DPO under UK GDPR if you're a public authority, if your core business involves large-scale, systematic monitoring of people, or if you process special category or criminal offence data at scale. None of those apply? You're not obligated to, but plenty of scale-ups appoint one anyway once data protection has outgrown what one person can track on the side. Run the three-part test below before you decide either way.
Contents
- • What Is a DPO, and What Do They Actually Do?
- • The Three-Part Test: When You're Legally Required to Appoint a DPO
- • When You Might Still Want One, Even If It's Not Mandatory
- • In-House vs Outsourced DPO: Which Fits Your Scale-Up?
- • The Real Cost of Not Appointing a DPO
- • How to Decide: A Quick Framework
- • Frequently Asked Questions
What Is a DPO, and What Do They Actually Do?
Ask five people in your business what a DPO actually does, and you'll probably get five different answers. Somewhere between "writes the privacy policy" and "the person we call if we get hacked."
Neither is quite right, and both miss most of the job.
A Data Protection Officer is the person, or team, responsible for making sure your business handles personal data the way UK GDPR says it should. Strip away the legal language and Article 39 of UK GDPR sets the job out fairly plainly: inform and advise your business on its obligations, monitor compliance, advise on data protection impact assessments, act as the contact point for the ICO, and be the person your team and your customers can actually go to with data protection questions. Not something you can bolt onto someone's existing job title and hope it gets done between meetings.
A good DPO also has to be independent. They report to the top of the business, can't be told what conclusion to reach, and can't be penalised for flagging something uncomfortable. That's exactly why this gets complicated once a business grows past the point where one person can hold the role alongside an operational job without a conflict creeping in.
The Three-Part Test: When You're Legally Required to Appoint a DPO
So, are you actually required to have one? Article 37 of UK GDPR says yes if any of these are true for your business:
- You're a public authority or body: rare for a scale-up, but worth ruling out early.
- Your core activities involve large-scale, regular and systematic monitoring of individuals: think adtech, behavioural profiling, or anything built around watching what people do over time.
- Your core activities involve large-scale processing of special category data, or data about criminal convictions and offences: health data, biometric data, genetic data, that kind of thing.
The word doing the heavy lifting here is "core." Not whether you process personal data at all, because nearly every business does. It's whether processing personal data at scale is central to what you actually do, not incidental to running the business. A HealthTech platform handling patient records at scale almost certainly meets the bar. A small SaaS company that happens to store customer emails almost certainly doesn't.
Not sure which side of that line you're on? The ICO's own guidance on whether you need a DPO is worth running through properly rather than guessing.
When You Might Still Want One, Even If It's Not Mandatory
Plenty of scale-ups that don't technically need a DPO appoint one anyway. It's rarely a compliance-first decision. Usually, the alternative has started to feel risky.
That tends to look like: one person holding all the data protection knowledge in their head, employees who genuinely don't know what to do when something goes wrong, a data map nobody's touched since it was first built, or more and more time spent firefighting instead of managing things properly. None of that is unique to you. It's what growth does to a compliance approach that was fine at twenty people and isn't fine at a hundred and fifty.
Investors and enterprise customers ask about this earlier than most scale-ups expect, too. Due diligence questionnaires increasingly want to know who owns data protection, not just whether a privacy policy exists somewhere on the website. Appointing a DPO, even a non-mandatory one, is often less about the legal requirement and more about having a straight answer ready when that question lands.
In-House vs Outsourced DPO: Which Fits Your Scale-Up?
Once you've decided you want a DPO, there are really only two routes: hire one in-house, or have someone do the role for you on an ongoing basis, externally.
An in-house DPO knows your business inside out and is available whenever you need them. Genuinely valuable. The weakness isn't competence, it's continuity. Independence gets hard to hold onto when the same person also has an operational role, and there's no cover if they go on leave or move on. When they're out, there's usually nobody else who knows the role well enough to step in.
An outsourced DPO brings genuine independence, because they sit outside your day-to-day operational structure. Worth being clear on what "outsourced" actually means here: it's continuous, ongoing work, just like an in-house hire, only external. They act as your DPO on an ongoing basis, not as a one-off project. The honest trade-off is cost and structure. It can be pricier than bringing someone on in-house.
This is where Trust Keith's outsourced DPO service is built a little differently. You get an expert matched specifically to your business, who acts as your DPO and gets to know your processing the way an in-house hire would, but sits outside the business with genuine independence built in. That expert is backed by a full team of DPOs, not working alone, so if they're ever unavailable, someone else can step in immediately. You never lose cover, and you never lose momentum on staying compliant.
The Real Cost of Not Appointing a DPO
If you're legally required to appoint a DPO and don't, that's a straightforward compliance gap, and one the ICO can act on. But even where it isn't mandatory, going without clear ownership of data protection costs you well before a fine ever does.
Breaches are the obvious one. The government's Cyber Security Breaches Survey puts the share of UK businesses reporting a breach or attack in the past year at 43%. Almost without exception, the businesses that handle that well already knew who owned the response before it happened. Without a DPO, or someone doing an equivalent job, that question gets answered in a panic instead of in advance.
Slower deals are the less obvious cost. A vague answer to a data protection question in due diligence, or worse, one that gets bounced between three different people before anyone responds, won't kill a deal outright. It just adds weeks. And weeks matter when you're trying to close a funding round or land an enterprise customer on a deadline.
How to Decide: A Quick Framework
Still weighing it up? Work through it in this order:
- Run the three-part test first: meet any of the Article 37 criteria, and the decision's made for you. Appoint a DPO.
- Don't meet the criteria? Check for the symptoms: one person holding all the knowledge, an out-of-date data map, or due diligence questions that make your team nervous are all signs it's worth appointing one anyway.
- Need one? Decide in-house or outsourced based on continuity, not just cost: ask what happens to data protection at your business the day your DPO is unreachable.
- Headcount the blocker? That's not a reason to do nothing. An outsourced DPO gets you the role without adding a full-time salary to your headcount plan.
None of this needs solving in one afternoon, but it does need an owner. "Nobody, officially" is the one answer that tends to catch up with a business at the worst possible time.
Frequently Asked Questions
Do small businesses need a DPO?
Only if they meet one of the three Article 37 criteria: public authority status, large-scale systematic monitoring, or large-scale special category data processing. Size alone isn't the test. A small business built around sensitive data can meet the bar, while a much bigger one that doesn't process sensitive data at scale might not.
Can one DPO cover more than one company?
Yes. UK GDPR allows a single DPO to act for multiple organisations, as long as they're still genuinely accessible to each one and there's no conflict of interest between them. It's exactly how an outsourced DPO service typically works.
Can our existing legal counsel or ops lead just take on the role?
They can, but think through the independence requirement first. A DPO can't mark their own homework, so if the same person is making operational decisions about how data gets processed, taking on the DPO role too can create the exact conflict of interest the rules are trying to avoid.
What happens if we're required to appoint a DPO and don't?
You're non-compliant with Article 37, and it's the kind of gap the ICO can raise directly, whether that's prompted by a complaint, a breach, or a routine enquiry. It also tends to surface in investor or customer due diligence long before the ICO ever gets involved.
Is an outsourced DPO cheaper than hiring one in-house?
Not always, so go in with realistic expectations rather than assuming outsourcing is automatically the budget option. What it usually avoids is the cost of a full-time salary, benefits, and the gap in cover when an in-house hire is away or leaves. The right comparison is cost against continuity, not just against a salary line.
Working through this doesn't mean overhauling how your business runs. Most scale-ups get here because "someone will figure it out" has stopped being a good enough answer, and the real question becomes who that someone is, and whether they'll still be around when it matters.
Want the fuller picture of what the role looks like day to day? What Does a DPO Actually Do? A Practical Breakdown is a good next read, and What Is GDPR? The Plain-English Guide for UK Business Leaders is worth a look if you want the wider regulatory picture first. If any of the symptoms above sounded familiar, 5 Signs Your Scale-Up Has Outgrown Its Data Protection Approach goes into more detail on what that looks like in practice.
Leaning towards outsourcing and want to compare what's out there? How do I choose the right DPO service provider? and I'm Interested in a Data Protection Officer Service with 24/7 Support - What Should I Know? both cover what to look for. Heading into a funding round or a customer's procurement process? How to Prepare for GDPR/Privacy Due Diligence is worth reading alongside this one. And if headcount is genuinely what's holding you back, both I need to hire a DPO but don't want to add headcount, what are my options and how do I get ongoing GDPR compliance support without a full-time data protection officer both tackle that directly.
If any of this still feels uncertain, or you'd like to talk it through with someone who's handled this before, you're welcome to book some time with our team. We're happy to see how we can help.


.png?width=2048&height=400&name=Blog%20Banners%20(21).png)
.png?width=3584&height=700&name=Blog%20Banners%20(12).png)
.png?width=228&height=57&name=CTAs%20(14).png)
.png?width=3450&height=1150&name=blog%20cta%20(5).png)