Compliance30 March 2026

DPO mandatory or not? Everything you need to know in 2026

When is the appointment of a DPO mandatory? Required cases, useful cases and good GDPR questions to ask in 2026.

Samuel HAYOT
9 min read

Expert note: This article was written by our chartered accountancy firm. Information is current as of 2026. For a personalised review of your situation, contact us.

DPO mandatory or not? Everything you need to know in 2026

Updated March 30, 2026 - Many companies think that DPO is reserved for large groups. Others, on the contrary, designate a DPO without knowing if this corresponds to a real need. In 2026, the right approach consists of distinguishing between mandatory cases, optional but useful cases and the reality of the data processing carried out by the organization.

When is designation mandatory?

The GDPR provides for cases of mandatory designation, in particular depending on the nature of the organization, the central nature of the processing and certain large-scale monitoring or processing operations.

To complete, see Accounting AI: automate without giving up expertise, How can an independent accountant benefit from a CRM? and Digital accountant.

Why many companies are wrong on the subject

They often think by staff size when the real question concerns:

  • the nature of the treatments;
  • their scale;
  • their regular and systematic nature;
  • the sensitivity of the data processed.

Hayot Expertise Advice: the question is not only “do we need a DPO?” but also “who really manages data compliance in the company?”.

Mandatory, optional, shared DPO: what to do?

Depending on your organization, several options exist:

  • mandatory designation;
  • voluntary designation;
  • external or shared support;
  • internal management without formal designation when the framework does not require it.

Do you want to properly qualify your GDPR need?

We can help you analyze your treatments, your tools and your real level of exposure before choosing the right organizational method.

Quick link: Structuring the governance of your tools and data

Conclusion

The DPO is neither a gadget nor an automatic checkbox. In 2026, the right decision is based on your concrete processing, their scale and your ability to sustainably manage GDPR compliance.

Contact: Want to know if your company should designate a DPO or otherwise strengthen its data governance? Our office can help you make a clear and actionable diagnosis. Make an appointment with Hayot Expertise

(Official sources: GDPR, CNIL)

S

Article written by Samuel HAYOT

Chartered Accountant, registered with the Institute of Chartered Accountants.

Need a quote or personalised advice?

Our accountancy firm supports you through all your steps. Get a free quote to review your situation and receive a bespoke fee proposal, or contact us directly.

Contact us

Quick and clear quote

Response within 24h • Confidential

By submitting, you agree to our privacy policy.