Data Protection Officer, When Does My Company Need One?
Introduction
The question ‘do we need a Data Protection Officer?’ is often framed wrongly in Swiss companies, it has two answers depending on the regulatory lens. Under the GDPR, appointment is mandatory in the cases listed in Art. 37; under the FADP, the ‘data protection advisor’ under Art. 10 DSG is a voluntary role with concrete benefits. Companies caught by both regimes, typical for a Swiss SaaS company with EU customers, have the GDPR duty, and the DSG advisor is the natural consolidation into the same person.
This article clarifies:
- The three mandatory GDPR triggers under Art. 37
- What Swiss authorities and courts treat as ‘public body’ and ‘core activity’
- What the DSG data protection advisor delivers under Art. 10 and when it pays off
- Internal vs. external DPO mandates
- Conflict constellations: CISO as DPO, CFO as DPO
- Requirements on qualification, position, independence (Art. 38, 39 GDPR)
We provide a compact decision matrix that we use regularly in mandates and name the typical pitfalls.
The three GDPR triggers under Art. 37
Art. 37(1) GDPR requires the designation of a DPO in three constellations:
- (a) public authorities or bodies: except courts acting in their judicial capacity. Swiss authorities under the GDPR are rare, the DSG has its own rules, but foundations and not-for-profits with EU exposure can be in scope.
- (b) core activity: systematic monitoring of data subjects on a large scale. ‘Core activity’ means the processing belongs to the actual business model, not to a support function (HR tracking by a pure industrial company is not a core activity). ‘Systematic monitoring’ in EDPB guidance covers online tracking, advertising profiling, location tracking, loyalty programmes, video surveillance, behavioural analysis, fitness apps, connected cars and similar.
- (c) core activity: large-scale processing of special categories (Art. 9) or criminal-conviction data (Art. 10). Classically captured: hospitals, insurers, staffing agencies, banking compliance, KYC providers, social services.
The ‘large scale’ threshold is not a fixed number; EDPB WP243 lists criteria including the number of data subjects, data volume, processing duration and geographical reach. Pragmatically: anything above ~5,000 profiles or continuous processing of health, financial or credit data is ‘in suspicion’.
The Swiss data protection advisor under Art. 10 DSG
The DSG has no appointment duty. Art. 10 DSG nonetheless regulates the ‘data protection advisor’ as a voluntary role with clear legal benefits:
- Privilege for internal advice: processing that has been reviewed by the advisor is treated as carefully assessed in any dispute.
- Exemption from FDPIC consultation on the DPIA (Art. 23(4) DSG): if a qualified advisor approves the measures, FDPIC consultation drops away.
- Simpler visibility towards the market and customers.
The role is particularly attractive for SMEs with a DPIA duty (see Art. 22 DSG): instead of submitting every high-risk case to the FDPIC, the appointed advisor keeps the methodology in-house. Personal requirements mirror Art. 38/39 GDPR, expertise, sufficient resources, freedom from instruction in privacy matters, direct access to management. The appointment is not notified to the FDPIC but must be disclosed in the privacy policy.
Companies that are GDPR-bound to appoint a DPO usually combine the function with Art. 10 DSG in the same person, that brings efficiency and closes gaps between the regimes.
Internal vs. external, the pro/con list
The choice between an internal and an external DPO depends on size, complexity and in-house expertise. We share the experience from over 50 mandates:
Internal DPO, pros: deep process knowledge, short paths, constant availability, integration into the line and projects. Cons: frequent role conflicts (see next section), limited experience horizon (only sees the own house), holiday/illness deputy problem, difficult career prospects (promotion typically leads away from the DPO role), often amateur level in small companies.
External DPO, pros: specialist knowledge from 10–50 houses run in parallel, methodological consistency (records, DPIAs, access request templates already tested), clear independence, team substitution guaranteed, fast deployment. Cons: needs a ramp-up phase to understand the specific processes, less visible in daily line work, contract and confidentiality terms must be properly set.
Rule of thumb: up to about 300 employees, a part-time external DPO (4–10 days per month) is more efficient and of higher quality. From around 500 employees an internal DPO pays off, ideally backed by an external sparring partner. Groups typically run internal DPO structures with expert committees per business segment.
Conflict constellations: CISO-DPO and CFO-DPO
Art. 38(6) GDPR allows the DPO to be given further duties, but they must not cause a conflict of interest with the DPO role. Supervisory practice (CNIL, BayLDA, DSK) has condemned typical constellations in recent years:
- CISO as DPO: conflict presumed. The CISO decides operationally on technical and organisational measures, the same person cannot independently supervise those same measures. ECJ ruling C-453/21 (2023) confirmed this line: anyone co-determining purposes and means of processing cannot be the DPO.
- CFO/COO as DPO: conflict presumed, since these roles are directly involved in processing decisions (accounting, HR, procurement).
- IT manager as DPO: conflict presumed, analogous to the CISO.
- HR head as DPO: conflict presumed, since HR processes personal data extensively.
- Compliance officer / legal counsel as DPO: in principle compatible, provided privacy is not lost in a dual role (for example, being the contract negotiator on outsourcing at the same time).
Pragmatically: in smaller houses that want to stay internal, the DPO role is best placed with a staff person outside of IT and line management, often in compliance or legal, with a clear support clause and a direct reporting line to management.
Qualification and position
Art. 37(5) GDPR requires ‘professional qualities and, in particular, expert knowledge of data protection law and practice’ and the ability to fulfil the tasks under Art. 39. In our practice that means:
- Solid knowledge of GDPR, DSG, ePrivacy and where relevant sector-specific law
- Understanding of IT and security architectures (at minimum bridge-builder to the CISO)
- Experience with DPIAs, international data transfers and the access request workflow
- Communication ability towards management, marketing and engineering
- A relevant certification (CIPP/E, CIPM, IAPP, Swiss diploma) is indicative, not a substitute for experience
Art. 38 GDPR defines the position of the DPO:
- Early involvement in all data protection matters (para. 1)
- Necessary resources and access to data and processing (para. 2)
- Freedom from instruction (para. 3)
- Reporting line to the highest management level (para. 3)
- Protection against dismissal or penalty for performing the role (para. 3)
The DPO's contact details must be published in the privacy policy and notified to the competent supervisory authority (Art. 37(7)).
Decision matrix for Swiss SMEs
The following simplified matrix walks a Swiss SME through the decision. Where several cases apply, the stricter duty wins.
- Pure CH business, < 250 FTE, no special categories, no systematic tracking: no mandatory DPO. Voluntary Art. 10 advisor recommended for the DPIA privilege.
- CH business with EU customers, no profiling, no special character: GDPR applies territorially; DPO mandatory only if a Art. 37 trigger is present. In practice almost always recommended due to contractual pressure or reputation.
- Online marketplace, loyalty programme, advertising profiling: Art. 37(b) highly likely, DPO mandatory.
- Insurer, hospital, staffing agency, banking compliance: Art. 37(c) highly likely, DPO mandatory.
- AI company with profiling and/or special categories (health-tech, HR-tech, credit): DPO mandatory; additionally AI Act compliance.
- Industrial group, > 500 FTE, ordinary HR/customer data: no Art. 37 trigger, but Art. 10 DSG plus a voluntary GDPR DPO for EU subsidiaries makes sense.
This matrix does not replace a legal opinion but in 90% of our advisory cases it gives a correct first orientation.
How SIDD supports you
SIDD takes on DPO mandates fully or as a co-DPO model with an internal counterpart. Our GDPR DPO mandate meets all requirements under Art. 37–39 GDPR including notification to the supervisory authority. In parallel we are happy to take on the Swiss data protection advisor role under Art. 10 DSG; the Swiss data protection advisory covers ongoing compliance management.
If you additionally need an EU representative under Art. 27 GDPR or a UK representative, we provide these roles from the same hand, this simplifies communication, deadlines and documentation consistency considerably. We support employees and the line through our privacy workshops. For a first clarification of your DPO duty and a compact proposal, reach us via the contact form or directly via the offer.
