# Designation of the data protection officer — GDPR — context bundle

> Focused context for a single provision, curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/laws/gdpr/art-37
> Every item cites its source. Verify against the official text (EUR-Lex / wetten.overheid.nl) before relying on it.

## Provision

### Designation of the data protection officer — Designation of the data protection officer

*GDPR, gdpr-art-37-en — https://overview.legal/laws/gdpr/art-37*

1. The controller and the processor shall designate a data protection officer in any case where:
   a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity;
   b) the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or
   c) the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 and personal data relating to criminal convictions and offences referred to in Article 10.

2. A group of undertakings may appoint a single data protection officer provided that a data protection officer is easily accessible from each establishment.

3. Where the controller or the processor is a public authority or body, a single data protection officer may be designated for several such authorities or bodies, taking account of their organisational structure and size.

4. In cases other than those referred to in paragraph 1, the controller or processor or associations and other bodies representing categories of controllers or processors may or, where required by Union or Member State law shall, designate a data protection officer. The data protection officer may act for such associations and other bodies representing controllers or processors.

5. The data protection officer shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39.

6. The data protection officer may be a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract.

7. The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority.

## Enforcement

62 decision(s) on record cite Article 37, totalling approximately €6,709,620 in fines (median €6,000).

Top fines:
- **Foodinho s.r.l.: Non-compliance with general data processing principles** (ITALY, €2,600,000) — https://overview.legal/posts/46858
- **Deliveroo Italy s.r.l.: Non-compliance with general data processing principles** (ITALY, €2,500,000) — https://overview.legal/posts/46905
- **Telenor ASA.: Non-compliance with general data processing principles** (NORWAY, €338,000) — https://overview.legal/posts/48688
- **Amiu S.p.A.: Insufficient legal basis for data processing** (ITALY, €200,000) — https://overview.legal/posts/47782
- **Setúbal municipality: Non-compliance with general data processing principles** (PORTUGAL, €180,000) — https://overview.legal/posts/47613

## Guidance

### Template for Cross-Regulatory Cooperation Agreements

*EDPB — https://overview.legal/posts/125669*

1 | Adopted Template for Cross-Regulatory Cooperation Agreements Adopted by the EDPB on July 7 th 2026 2 | Adopted Explanatory note Cross-regulatory cooperation between data protection supervisory authorities (DPAs) and other national and EU competent authorities has become increasingly important as legal and practical challenges emerge at the intersection of different regulatory fields. Cooperation agreements can be an important basis to organise and strengthen cooperation and dialogue between…

### Opinion 21/2026 on the draft decision of the Irish Supervisory Authority regarding the Controller Binding Corporate Rules of the Flutter Group

*EDPB — https://overview.legal/posts/125670*

Opinion 21/2026 on the draft decision of the Irish Supervisory Authority regarding the Controller Binding Corporate Rules of the Flutter Group Adopted on 07 July 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

### Opinion 20/2026 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the Fluor Group

*EDPB — https://overview.legal/posts/125671*

Opinion 20/2026 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the Fluor Group Adopted on 07 July 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

### Opinion 19/2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Rubrik Group

*EDPB — https://overview.legal/posts/125672*

Opinion 19/2026 on the draft decision of the Dutch Supervisory Authority regarding the Processor Binding Corporate Rules of the Rubrik Group Adopted on 08 June 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

### Opinion 18/2026 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the Rubrik Group

*EDPB — https://overview.legal/posts/125673*

Opinion 18/2026 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the Rubrik Group Adopted on 08 June 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

## Related topics

- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  ## Legal Framework

---
Generated by overview.legal · https://overview.legal/laws/gdpr/art-37 · 2026-08-22
