Under the GDPR, some organisations are required to appoint a DPO. This applies to public authorities and organisations whose core activities involve:
- Regular and systematic monitoring of individuals on a large scale.
- Processing special categories of data or data relating to criminal convictions and offences.
The ICO also recommends that other organisations, even if not mandatory, appoint a DPO to demonstrate their commitment to data protection.