Is a DPO mandatory? Internal or outsourced?
What the texts actually say about the obligation to designate a data protection officer — and the honest comparison between an in-house position and an outsourced function, costs included.
The three cases where the GDPR requires a DPO
Article 37(1) of Regulation (EU) 2016/679 makes designation mandatory in three situations. In healthcare, the third captures most of the sector.
You are a public authority or body
Public hospitals, hospital groups (GHT), local authorities, agencies: designation is mandatory whatever the nature of the processing (only courts acting in their judicial capacity are exempt).
Your core activities require regular and systematic monitoring on a large scale
Patient-monitoring platforms, teleconsultation at significant volume, connected health devices, support programmes: whenever the ongoing observation of individuals is at the heart of the activity.
Your core activities involve large-scale processing of sensitive data
This is the case that captures most of the sector: health data falls under Article 9 GDPR. Facilities, coordinated-care structures, data warehouses and software vendors processing patient data are directly concerned.
The decisive criterion
What counts as “large-scale” processing?
The GDPR sets no numerical threshold. The European guidelines on DPOs (WP243) retain four assessment criteria — and give two healthcare reference points: the processing of patient data by a hospital is large-scale; that of an individual physician is not. In between, everything is assessed case by case.
Reference text: Regulation (EU) 2016/679, Articles 37 to 39.
- The number of data subjects concerned, in absolute terms or as a proportion of the population
- The volume and variety of the data processed
- The duration or permanence of the processing
- The geographical extent of the processing
Internal DPO or outsourced DPO: both columns, without caricature
Both models are legitimate — the GDPR expressly recognises fulfilment on the basis of a service contract (Article 37(6)). The real question is economic and organisational: how much capacity do you actually need, and at what full cost?
Internal DPO
Its strengths
Daily physical presence and intimate knowledge of the organisation
Immediate on-site availability for the teams
Relevant when the volume justifies a full-time position — large facilities, multi-site groups
Its constraints
Full cost of a senior profile: gross salary plus employer contributions, continuing training, regulatory watch, tools — in the region of €70k to €100k per year
Expertise to build and maintain alone: healthcare regulation evolves constantly (GDPR, AI Act, EHDS, NIS 2, HDS)
Risk of conflict of interests (Article 38(6)) when the role is combined with IT, HR, quality or management — the Berlin authority fined such a combination €525,000 in 2022
Fragile continuity: holidays, absences, departure — compliance stops with the person
Independence that is delicate to exercise towards one’s own hierarchy
Outsourced DPO specialised in healthcare
Its strengths
Controlled, scalable cost: a defined capacity, from €690 excl. VAT/month — no payroll charges, no recruitment, no training to fund
Immediate, pooled healthcare expertise: regulatory watch, methods and lessons learned shared across comparable engagements
Reinforced independence: outside the hierarchy and with no internal operational role — the absence of conflict of interests (Article 38(6)) is verified and documented for each engagement
Organised continuity: a networked team providing cover — the function does not rest on a single person
Credibility with purchasers, partners and the CNIL: a documented outside perspective
Clear contractual framework: capacity, timelines, deliverables and service level in writing
Its limits — and how we address them
Less day-to-day physical presence — offset by an identified internal relay and a defined governance rhythm
Requires rigorous organisation of information flows (which is precisely what the contract organises)
The trade-off, in one sentence
Below a genuine half-time need, an in-house position costs up to ten times more than a specialised outsourced DPO — for expertise built alone and independence that is harder to guarantee.
And for large organisations whose volume justifies an in-house position, the hybrid model — an internal DPO backed by outsourced healthcare expertise for regulatory watch, DPIAs and specialist topics (AI, EHDS, research) — combines the advantages of both columns.
Obligation, combined roles, shared DPOs: what we are asked
Does a small private organisation have to designate a DPO?
It all depends on large scale: the European guidelines cite the processing of patient data by a hospital as large-scale, and processing by an individual physician as not. Between these two extremes — multidisciplinary health centres, care centres, nursing homes (EHPAD), software vendors — the analysis is made case by case, in light of the processing actually carried out. That is exactly what we qualify during a first conversation, free of charge.
Is an outsourced DPO recognised by the GDPR and the CNIL?
Yes, expressly: Article 37(6) GDPR provides that the data protection officer may fulfil the tasks on the basis of a service contract. The designation is declared to the CNIL exactly as for an internal DPO, and the outsourced officer has the same tasks and the same independence obligations.
Can an employee combine the DPO role with another position?
It is possible, but Article 38(6) GDPR requires the absence of conflict of interests: the DPO cannot hold a position that leads them to determine the purposes or means of processing — which in practice rules out general management, IT, HR or quality management in most configurations. European authorities have already sanctioned this type of combination.
Can a DPO be shared between several organisations?
Yes. A group of undertakings may designate a single DPO (Article 37(2)), public bodies may share one (Article 37(3)), and independent organisations may use the same external officer under a service contract (Article 37(6)) — provided, in all cases, that the DPO is easily reachable and effectively able to perform their tasks for each of them. It is this requirement of effectiveness, more than the arrangement itself, that makes the model compliant.
And if we are not in a case of mandatory designation?
The CNIL encourages designating a DPO even where there is no obligation: the substantive obligations of the GDPR (records of processing, security, information, DPIAs) apply in all cases, and identified stewardship remains the surest way to meet them. A light arrangement — a few hours per month — is often enough.
Your situation deserves better than a general rule
Describe your processing activities: we qualify your designation obligation and the level of capacity actually required — frankly, including if a light arrangement is enough.
Reply within 24 business hours · No commitment
