GDPR · Regulation (EU) 2016/679
Article 37
Compare the available Commission, Council and Parliament texts and amendments affecting this article.
Article total: 4 parts · 4 Council drafts · 3 Parliament amendments
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
All Commission’s changes to GDPRThe wording proposed by the Commission at the start of this legislative file.
No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to this tracked part.
Article in May Presidency compromise Council text
Comparison basis: Existing law (4 May 2016) compared with May Presidency compromise (21 May 2026)
Article 37
Designation of the data protection officer
- 1.
The controller and the processor shall designate a data protection officer in any case where:
- (a)
the processing is carried out by a public authority or body, except for courts acting in their judicial capacity;
- (b)
the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or
- (c)
the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 or personal data relating to criminal convictions and offences referred to in Article 10.
- (a)
- 2.
A group of undertakings may appoint a single data protection officer provided that a data protection officer is easily accessible from each establishment.
- 3.
Where the controller or the processor is a public authority or body, a single data protection officer may be designated for several such authorities or bodies, taking account of their organisational structure and size.
- 4.
In cases other than those referred to in paragraph 1, the controller or processor or associations and other bodies representing categories of controllers or processors may or, where required by Union or Member State law shall, designate a data protection officer. The data protection officer may act for such associations and other bodies representing controllers or processors.
- 5.
The data protection officer shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39.
- 6.
The data protection officer may be a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract.
- 7.
The controller or the processor shall publish the contact details of the data protection officer
and communicate them to the supervisory authority.
Article 37(7)
May Presidency compromise
The controller or the processor shall publish the contact details of the data protection officer.
Article in June Presidency compromise · 10 June Council text
Comparison basis: Existing law (4 May 2016) compared with June Presidency compromise · 10 June (10 June 2026)
Article 37
Designation of the data protection officer
- 1.
The controller and the processor shall designate a data protection officer in any case where:
- (a)
the processing is carried out by a public authority or body, except for courts acting in their judicial capacity;
- (b)
the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or
- (c)
the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 or personal data relating to criminal convictions and offences referred to in Article 10.
- (a)
- 2.
A group of undertakings may appoint a single data protection officer provided that a data protection officer is easily accessible from each establishment.
- 3.
Where the controller or the processor is a public authority or body, a single data protection officer may be designated for several such authorities or bodies, taking account of their organisational structure and size.
- 4.
In cases other than those referred to in paragraph 1, the controller or processor or associations and other bodies representing categories of controllers or processors may or, where required by Union or Member State law shall, designate a data protection officer. The data protection officer may act for such associations and other bodies representing controllers or processors.
- 5.
The data protection officer shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39.
- 6.
The data protection officer may be a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract.
- 7.
The controller or the processor shall publish the contact details of the data protection officer
and communicate them to the supervisory authority.
Article 37(7)
June Presidency compromise · 10 June
7. The controller or the processor shall publish the contact details of the data protection officer.
Article in June Presidency compromise · 18 June Council text
Comparison basis: Existing law (4 May 2016) compared with June Presidency compromise · 18 June (18 June 2026)
Article 37
Designation of the data protection officer
- 1.
The controller and the processor shall designate a data protection officer in any case where:
- (a)
the processing is carried out by a public authority or body, except for courts acting in their judicial capacity;
- (b)
the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or
- (c)
the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 or personal data relating to criminal convictions and offences referred to in Article 10.
- (a)
- 2.
A group of undertakings may appoint a single data protection officer provided that a data protection officer is easily accessible from each establishment.
- 3.
Where the controller or the processor is a public authority or body, a single data protection officer may be designated for several such authorities or bodies, taking account of their organisational structure and size.
- 4.
In cases other than those referred to in paragraph 1, the controller or processor or associations and other bodies representing categories of controllers or processors may or, where required by Union or Member State law shall, designate a data protection officer. The data protection officer may act for such associations and other bodies representing controllers or processors.
- 5.
The data protection officer shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39.
- 6.
The data protection officer may be a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract.
- 7.
The controller or the processor shall publish the contact details of the data protection officer
and communicate them to the supervisory authority.
Article 37(7)
June Presidency compromise · 18 June
The controller or the processor shall publish the contact details of the data protection officer.
Article in September Presidency compromise Council text
Comparison basis: Existing law (4 May 2016) compared with September Presidency compromise (3 September 2026)
Article 37
Designation of the data protection officer
- 1.
The controller and the processor shall designate a data protection officer in any case where:
- (a)
the processing is carried out by a public authority or body, except for courts acting in their judicial capacity;
- (b)
the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or
- (c)
the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 or personal data relating to criminal convictions and offences referred to in Article 10.
- (a)
- 2.
A group of undertakings may appoint a single data protection officer provided that a data protection officer is easily accessible from each establishment.
- 3.
Where the controller or the processor is a public authority or body, a single data protection officer may be designated for several such authorities or bodies, taking account of their organisational structure and size.
- 4.
In cases other than those referred to in paragraph 1, the controller or processor or associations and other bodies representing categories of controllers or processors may or, where required by Union or Member State law shall, designate a data protection officer. The data protection officer may act for such associations and other bodies representing controllers or processors.
- 5.
The data protection officer shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39.
- 6.
The data protection officer may be a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract.
- 7.
The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority.
Article 37(7)
September Presidency compromise
Proposed change withdrawn
The 3 September Council text marks this proposed change as withdrawn and supplies no replacement wording. This does not by itself remove text from existing law.
Article 37(7) 4 Council drafts
Article 37(7)
21 May 2026 · May Presidency compromise
The controller or the processor shall publish the contact details of the data protection officer.
Article 37(7)
10 June 2026 · June Presidency compromise · 10 June
7. The controller or the processor shall publish the contact details of the data protection officer.
Article 37(7)
18 June 2026 · June Presidency compromise · 18 June
The controller or the processor shall publish the contact details of the data protection officer.
Article 37(7)
3 September 2026 · September Presidency compromise
Proposed change withdrawn
The 3 September Council text marks this proposed change as withdrawn and supplies no replacement wording. This does not by itself remove text from existing law.
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Additional proposed wording Amendment 1237 · Angelika Niebler, Monika Hohlmeier ITRE · LIBE
9a. Article 37, paragraph 7, is amended as follows
The controller or the processor shall publish the contact details of the data protection officer.
against:
Article 37
Designation of the data protection officer
- 1.
The controller and the processor shall designate a data protection officer in any case where:
- (a)
the processing is carried out by a public authority or body, except for courts acting in their judicial capacity;
- (b)
the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or
- (c)
the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 or personal data relating to criminal convictions and offences referred to in Article 10.
- (a)
- 2.
A group of undertakings may appoint a single data protection officer provided that a data protection officer is easily accessible from each establishment.
- 3.
Where the controller or the processor is a public authority or body, a single data protection officer may be designated for several such authorities or bodies, taking account of their organisational structure and size.
- 4.
In cases other than those referred to in paragraph 1, the controller or processor or associations and other bodies representing categories of controllers or processors may or, where required by Union or Member State law shall, designate a data protection officer. The data protection officer may act for such associations and other bodies representing controllers or processors.
- 5.
The data protection officer shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39.
- 6.
The data protection officer may be a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract.
- 7.
The controller or the processor shall publish the contact details of the data protection officer
and communicate them to the supervisory authority.
Alternative wording Amendment 1238 · Axel Voss ITRE · LIBE
Justification
DPO Package #2: The amendment strengthens accountability by recognising DPOs as practical governance safeguards and first points of contact for complaints. DPOs already advise controllers and processors, monitor compliance and support data subjects; giving them an explicit complaint-handling role makes resolution faster, less bureaucratic and closer to the facts. Voluntary or shared DPOs are encouraged. Supervisory authorities remain available where the complaint is not addressed or not fully remedied within one month.
against:
Article 37
Designation of the data protection officer
- 1.
The controller and the processor shall designate a data protection officer in any case where:
- (a)
the processing is carried out by a public authority or body, except for courts acting in their judicial capacity;
- (b)
the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or
- (c)
the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 or personal data relating to criminal convictions and offences referred to in Article 10.
- (a)
- 2.
A group of undertakings may appoint a single data protection officer provided that a data protection officer is easily accessible from each establishment.
- 3.
Where the controller or the processor is a public authority or body, a single data protection officer may be designated for several such authorities or bodies, taking account of their organisational structure and size.
- 4.
In cases other than those referred to in paragraph 1, the controller or processor or associations and other bodies representing categories of controllers or processors may
or, where required by Union or Member State law shall,designate a data protection officer. The data protection officer may act for such associations and other bodies representing controllers or processors." - 5.
The data protection officer shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39.
- 6.
The data protection officer may be a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract.
- 7.
The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority.
Additional proposed wording Amendment 1239 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
In Article 37, paragraphs 2a and 4a are inserted:
Microenterprises, small and medium-sized enterprises within the meaning of Recommendation 2003/361/EC, and small mid-cap enterprises may jointly designate a single data protection officer, whether or not they are partner or linked enterprises, provided that the data protection officer is easily accessible from each of them and is able to perform his or her tasks effectively in respect of each participating enterprise, taking into account the nature, scope, context and purposes of their respective processing operations. The participating enterprises shall specify, in a written arrangement, the allocation of responsibilities and the resources made available to the shared data protection officer.';
Member States may provide that a public body designated for that purpose makes available data protection officers acting for a pool of microenterprises, small and medium-sized enterprises or small mid-cap enterprises. A data protection officer made available under this paragraph shall perform the tasks referred to in Article 39 independently, in accordance with Article 38, and shall not receive instructions regarding the exercise of those tasks. This paragraph shall not apply to the supervisory authorities referred to in Article 51, so as to avoid any conflict of interest.';
Justification
The cost of a dedicated data protection officer is prohibitive for small structures. The amendment allows micro, small and medium-sized enterprises and small mid-caps which are not related undertakings to designate a single data protection officer jointly, provided that the officer is easily accessible from each establishment and that the conditions of independence and absence of conflict of interest are met in respect of each controller concerned. Pooling reduces compliance costs without lowering the level of protection.
against:
Article 37
Designation of the data protection officer
- 1.
The controller and the processor shall designate a data protection officer in any case where:
- (a)
the processing is carried out by a public authority or body, except for courts acting in their judicial capacity;
- (b)
the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or
- (c)
the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 or personal data relating to criminal convictions and offences referred to in Article 10.
- (a)
- 2.
A group of undertakings may appoint a single data protection officer provided that a data protection officer is easily accessible from each establishment.
- 2a.
Microenterprises, small and medium-sized enterprises within the meaning of Recommendation 2003/361/EC, and small mid-cap enterprises may jointly designate a single data protection officer, whether or not they are partner or linked enterprises, provided that the data protection officer is easily accessible from each of them and is able to perform his or her tasks effectively in respect of each participating enterprise, taking into account the nature, scope, context and purposes of their respective processing operations. The participating enterprises shall specify, in a written arrangement, the allocation of responsibilities and the resources made available to the shared data protection officer.';
- 3.
Where the controller or the processor is a public authority or body, a single data protection officer may be designated for several such authorities or bodies, taking account of their organisational structure and size.
- 4.
In cases other than those referred to in paragraph 1, the controller or processor or associations and other bodies representing categories of controllers or processors may or, where required by Union or Member State law shall, designate a data protection officer. The data protection officer may act for such associations and other bodies representing controllers or processors.
- 4a.
Member States may provide that a public body designated for that purpose makes available data protection officers acting for a pool of microenterprises, small and medium-sized enterprises or small mid-cap enterprises. A data protection officer made available under this paragraph shall perform the tasks referred to in Article 39 independently, in accordance with Article 38, and shall not receive instructions regarding the exercise of those tasks. This paragraph shall not apply to the supervisory authorities referred to in Article 51, so as to avoid any conflict of interest.';
- 5.
The data protection officer shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39.
- 6.
The data protection officer may be a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract.
- 7.
The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority.
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.
Article 37 – paragraph 4
Wording reproduced in the amendment → Amendment 1238 · ITRE–LIBE amendments 1053–1260 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1238 · ITRE–LIBE amendments 1053–1260 to the draft report
Article 37(7)
Council Presidency text · ST 9547/26 → Council Presidency text · ST 10426/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 9547/26
Council Presidency text · ST 10426/26
Article 37(7)
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
RemovedAdded