Blog

Does your company need a Data Protection Officer? Technology & GDPR changes in 2025

According to the General Data Protection Regulation (GDPR), every organization that processes personal data is required to regularly assess whether the appointment of a Data Protection Officer (DPO) is necessary.

Many data controllers carried out such an assessment in 2018, shortly after the GDPR came into force. However, since then, both the technologies used and the scale of data processing in business have changed significantly. That’s why, in 2025, a new evaluation of whether a DPO is required is not only recommended — in many cases, it is legally required.

hy Reassess the Need for a DPO in 2025?

In 2025, companies are using advanced technologies that were rarely seen just a few years ago. The following tools and practices may increase the risk and scope of personal data processing:

  • Artificial intelligence (AI) for analyzing user behavior
  • Profiling and marketing automation
  • Internet of Things (IoT) devices collecting real-time data
  • Video surveillance systems with facial recognition features

Using such technologies may mean that the company meets the criteria under Article 37 of the GDPR, which requires the appointment of a DPO.

Examples of Companies That May Be Required to Appoint a DPO in 2025

  • E-commerce businesses analyzing customer purchase behavior
  • Courier and logistics companies using geolocation and tracking
  • Marketing agencies engaged in retargeting and profiling
  • Financial and insurance institutions using AI to assess risk
  • Surveillance operators using facial recognition systems

The Accountability Principle – “We Don’t Need One” Isn’t Enough

It is important to note that the GDPR introduces the principle of accountability (Article 5(2)), meaning every company must be able to demonstrate that it has conducted an assessment regarding the need to appoint a DPO. Failing to make or document this decision may be considered a breach of data controller obligations.

In 2025, appointing a Data Protection Officer is no longer just a formality — it is a genuine legal obligation for many businesses engaged in large-scale or high-risk data processing. Conducting an up-to-date assessment not only reduces legal risk but is also a key part of responsible data governance.

Latest blog posts

Does your company need a Data Protection Officer? Technology & GDPR changes in 2025

EU Court publishes overview of landmark rulings on data protection

Incorrect processing of personal data after a cyberattack can result in fine!