Your head of legal cannot be your DPO if they also decide how personal data gets processed.
Article 38 requires the data protection officer to receive no instructions on their tasks, to report to the highest management level, and to hold no other duties that create a conflict of interests. An external appointment removes that problem structurally.

- 3 triggersWhen designation is mandatory
- No instructionsOn the exercise of the DPO tasks
- Highest levelWhere the DPO reports
- Service contractAn expressly permitted arrangement
If they decide how personal data is processed, they should not be your DPO.
The conflict of interests provision is short and it disqualifies most of the people organisations instinctively appoint.
- The head of IT decides how systems process personal data. Appointing them as data protection officer means the person monitoring compliance is monitoring their own decisions, which is the definition of the conflict the provision exists to prevent.
- The same applies to heads of HR, marketing and operations, each of whom determines purposes and means for substantial processing activities. General counsel is more arguable and still difficult, since they frequently advise on and approve those same decisions.
- The independence requirement compounds it. The officer must receive no instructions regarding the exercise of their tasks and must not be dismissed or penalised for performing them, which is hard to guarantee for somebody inside an ordinary reporting line.
- An external appointment on a service contract, which the Regulation expressly permits, resolves all three at once. The person has no operational decisions to monitor, no line manager to be instructed by, and no employment to be penalised through.
Eight things that decide whether your arrangement works.
Three situations make designation mandatory
Processing by a public authority or body, core activities requiring regular and systematic monitoring of data subjects on a large scale, or core activities involving large scale processing of special category data or data relating to criminal convictions and offences.
No instructions on the exercise of the tasks
The controller and processor must ensure the data protection officer does not receive any instructions regarding the exercise of those tasks. That is a structural independence requirement, and it is difficult to satisfy with an internal appointment inside a reporting line.
Protection from dismissal or penalty
The officer shall not be dismissed or penalised by the controller or processor for performing their tasks. That protection is meaningful precisely in the situations where a data protection officer gives advice the organisation does not want to hear.
Direct reporting to the highest management level
The data protection officer reports directly to the highest management level. Not through a general counsel, a chief information officer or a compliance director, which is a reporting line most internal appointments quietly fail to establish.
No conflicting duties
Other tasks and duties are permitted provided they do not result in a conflict of interests. In practice that rules out people who decide the purposes and means of processing, which is why heads of IT, HR, marketing and legal are frequently unsuitable.
Involved properly and in a timely manner
The organisation must ensure the officer is involved, properly and in a timely manner, in all issues relating to the protection of personal data. Being told about a new system after it launched does not satisfy that, and it is the most common failure.
A service contract is expressly permitted
The Regulation states the officer may be a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract. An external appointment is not a workaround, it is one of the two arrangements the text contemplates.
Five defined tasks
Inform and advise the organisation and its processing staff, monitor compliance including staff training and audits, advise on data protection impact assessments and monitor their performance, cooperate with the supervisory authority, and act as its contact point.
What Articles 37 to 39 require, and where arrangements fail.
| Requirement | What we typically find | |
|---|---|---|
| Selected on expert knowledge of data protection law and practices | Selected on availability or seniority | |
| Involved properly and in a timely manner in all data protection issues | Told about projects after go live | |
| Provided with resources to carry out tasks and maintain expert knowledge | No budget, no training allowance | |
| Receives no instructions on the exercise of the tasks | Sits inside a normal reporting line | |
| Not dismissed or penalised for performing the tasks | No documented protection | |
| Reports directly to the highest management level | Reports to a functional head | |
| Contactable by data subjects | Contact details not published | |
| Bound by secrecy or confidentiality | Usually satisfied | |
| No conflict of interests from other duties | Holds a role that decides processing | |
| Contact details published and communicated to the supervisory authority | Published sometimes, communicated rarely |
Four things that make the appointment real.
We test for conflicts before anything else
Other tasks are permitted only where they do not result in a conflict of interests. Anybody determining the purposes and means of processing is the wrong choice, and identifying that early prevents an appointment that has to be unwound later.
We establish the reporting line properly
The officer reports directly to the highest management level. Where an existing arrangement routes through a functional head, that is a documented departure from the Regulation and it is usually straightforward to correct once it is noticed.
We insist on early involvement
The organisation must ensure involvement properly and in a timely manner in all issues relating to protection of personal data. Being informed after a system is live is the single most common failure, and it is a process problem rather than a personnel one.
We keep the expert knowledge current
Selection is on professional qualities and expert knowledge of data protection law and practices, and the organisation must provide resources to maintain that knowledge. An external service carries that obligation rather than passing it to a training budget.
Three phases, then an ongoing service.
- 01Weeks 1 to 2
Establish whether designation is required
Against the three triggers, with the reasoning recorded either way. Where designation is not mandatory the analysis still has value, because it is the answer you give if the question is ever asked by a customer or a supervisory authority.
- Assessment against the three mandatory triggers
- Core activities and large scale analysis recorded
- Existing arrangement tested for conflicts
- Recommendation with reasoning documented
- 02Weeks 3 to 6
Appointment and onboarding
Contact details published and communicated to the supervisory authority, the reporting line to the highest management level established, and the officer brought up to speed on processing activities, systems, suppliers and existing documentation.
- Appointment documented with independence terms
- Contact details published and communicated
- Reporting line to highest management established
- Processing landscape reviewed and gaps identified
- 03Ongoing
The Article 39 tasks, continuously
Informing and advising, monitoring compliance including training and audits, advising on and monitoring data protection impact assessments, cooperating with the supervisory authority, and acting as its contact point, with due regard to processing risk.
- Advice on processing decisions before they are taken
- Compliance monitoring with training and audit programme
- DPIA advice and performance monitoring
- Supervisory authority and data subject contact handled
Six situations that make the question live.
A UAE technology company tracking user behaviour
Where core activities involve regular and systematic monitoring of data subjects on a large scale, designation becomes mandatory. Analytics, personalisation, location features and behavioural advertising all sit near that line and deserve a documented assessment.
A healthcare or wellness business
Large scale processing of special categories of data under Article 9 is the third trigger, and health data is the clearest example of it. Organisations handling it at scale should treat designation as expected rather than optional.
A group wanting one appointment across entities
A group of undertakings may appoint a single data protection officer provided that officer is easily accessible from each establishment. That accessibility condition is what determines whether a single appointment is workable in practice.
A firm whose head of legal currently holds the role
This is the most common arrangement we are asked to review. It usually fails on conflict of interests, on independence from instructions, or on the reporting line, and it is generally straightforward to restructure once the specific failure is identified.
An organisation facing a supervisory authority question
The officer cooperates with the supervisory authority and acts as its contact point, including for prior consultation. Having somebody who has done that before, and who is genuinely independent, materially changes how that interaction proceeds.
A business where data subjects have nowhere to write
Data subjects may contact the data protection officer about all issues relating to processing of their personal data and the exercise of their rights. Contact details must be published, and that publication is missing more often than not.
How UAE organisations staff the role.
| Feature | External on a service contract | Internal, added to an existing role | Nobody appointed |
|---|---|---|---|
Free of conflicting duties | Yes | Usually not | Not applicable |
Independent of instructions | Structurally | Hard to guarantee | Not applicable |
Protected from penalty | By contract | By assertion | Not applicable |
Reports to highest management | Yes | Rarely | No |
Expert knowledge maintained | Continuously | Occasional training | None |
Available for data subject contact | Yes | In principle | No |
Time actually allocated | Defined | Whatever is left | None |
Cost profile | Predictable service | Hidden inside a salary | None until a problem |
Permitted by the Regulation | Expressly | Yes, if conflicts avoided | Only where not required |
Position if a supervisory authority asks | Defensible | Questionable | Depends on the triggers |
Two of the three triggers turn on the words core activities and large scale.
Those phrases do most of the work, and organisations reach opposite conclusions about themselves depending on how carefully they read them.
- Core activities means the processing is integral to what the organisation does, rather than ancillary support like paying its own staff. A company whose product depends on tracking user behaviour is in a different position from one that merely runs payroll.
- Regular and systematic monitoring of data subjects on a large scale is the second trigger. Behavioural advertising, location tracking, connected devices, fraud scoring and loyalty analytics all sit close to this, and many UAE technology businesses do at least one.
- The third trigger is large scale processing of special categories of data under Article 9, or personal data relating to criminal convictions and offences under Article 10. Health, biometric and background screening data all fall inside that description.
- Where none of the three applies, designation is voluntary. That is a legitimate position, and it is worth recording the reasoning rather than leaving it unexamined, because the analysis is what you would produce if a supervisory authority asked.
Five steps, and the first may conclude you do not need one.
- 1
Assess against the three mandatory triggers
Public authority or body, core activities requiring regular and systematic monitoring of data subjects on a large scale, or core activities involving large scale processing of special category or criminal offence data. The reasoning is recorded either way.
- 2
Test any existing arrangement
For conflicts of interests, for independence from instructions, for the reporting line to the highest management level, for published contact details and for whether the person is involved properly and in a timely manner in data protection issues.
- 3
Appoint and formalise
Whether internal or on a service contract, both of which the Regulation permits. The appointment documents the independence terms, the protection from penalty for performing the tasks, and the resources available to carry them out.
- 4
Publish and communicate the contact details
Published so data subjects can exercise their right to contact the officer, and communicated to the supervisory authority as the Regulation requires. Both steps are quick and both are frequently missed after an otherwise sound appointment.
- 5
Perform the Article 39 tasks continuously
Informing and advising, monitoring compliance with training and audits, advising on and monitoring data protection impact assessments, cooperating with the supervisory authority and acting as contact point, with due regard to the risk of the processing.
What UAE organisations ask about the DPO role.
Fifteen questions about your current appointment.
Independence
- Do they receive instructions on their tasks?They must not.
- Who do they report to?Highest management level.
- Are they protected from penalty?For performing the tasks.
- Do they decide how data is processed?That is the conflict.
- Would they disagree with the CEO in writing?The practical test.
Capability
- Do they have expert knowledge?The stated standard.
- Is there a training budget?Resources are required.
- Do they have time for it?Often a fraction of a job.
- Can they access processing operations?Required to do the work.
- Do they handle DPIAs?An Article 39 task.
Formalities
- Are contact details published?A stated obligation.
- Communicated to the supervisory authority?Also stated.
- Can data subjects reach them?They are entitled to.
- Are they involved before decisions?Timely means before.
- Is the appointment documented?With its independence terms.
Ask whether your data protection officer could formally disagree with a board decision.
Without professional consequence, and in writing. If the honest answer is no, the arrangement does not meet the independence the Regulation describes.
Related Services
Explore more solutions that work great with this service
GDPR for UAE Businesses
When EU law actually reaches a UAE business, and when it does not
Privacy Impact Assessment
DPIA done at design stage, necessity tested properly
Records of processing activities
The Article 30 record, complete and producible on request.
UAE PDPL Compliance
Federal Decree-Law 45 of 2021 readiness and operations
Virtual CISO Dubai
Security governance and accountability, not more tools
Compliance as a Service
Keeping the position true between assessments
Breach notification readiness
Who declares a breach, and how the 72 hours is spent.
Security Policy Development
Policies you can actually comply with