GDPR requires a DPO in three situations: you are a public authority; your core activities involve regular and systematic monitoring of individuals at large scale; or your core activities involve large-scale processing of special categories of data, health records being the classic case. Plenty of B2B companies fall outside all three — and appoint one anyway, because enterprise customers and supervisory authorities keep asking who holds the role. The wider regulation the officer polices is covered on our GDPR page.
The job has an unusual legal shape. The DPO advises on obligations, monitors compliance, trains staff, supervises data protection impact assessments, and serves as the published contact for regulators and data subjects — while reporting to the highest level of management and taking instructions from nobody on how to do the work. That independence requirement rules out the obvious candidates: whoever decides the purposes of processing, a CEO or CTO for instance, cannot mark their own homework. The officer’s details go in your privacy notice, and inquiries genuinely arrive.
The regulation explicitly permits a DPO engaged under a service contract, and for most startups that is the sensible reading: the seat calls for expert knowledge of data protection law plus enough distance from operations to stay impartial — a combination rarely sitting idle on the payroll. An external DPO pairs naturally with fractional security leadership like a vCISO, and the processor-side paperwork the officer oversees — DPAs and subprocessor registers — usually lives in the same program.