Group DPO for International Companies: A Jurisdiction Decision Guide
One group privacy contact can simplify coordination, but each entity and legal role still needs its own assessment. Use this matrix to define the mandate, capacity and country-specific work before appointing a provider.

Map the group before choosing the title
Start with the legal entities, establishments, people affected, processing activities and decision owners in each market. The same brand may contain several controllers and processors, each with different reasons to appoint a Data Protection Officer or obtain privacy advice. A group chart should show who is covered by a proposed mandate and who remains outside it.
Under GDPR Article 37(2), a group of undertakings may appoint one DPO if that person is easily accessible from each establishment. The UK ICO also allows a shared DPO when the role can be performed effectively across the organisations. Neither rule turns one name on an organisational chart into unlimited capacity; access, language, workload, independence and local contact routes need a practical plan.
Four-market role comparison
Use the matrix as a scoping aid, then check the current rules and facts for each entity. It separates a formal DPO appointment from advisory and representative roles; it does not decide that every group needs all of them.
| Market | Role to assess | Group appointment question | Separate contact or adviser question |
|---|---|---|---|
| European Union | GDPR Articles 37–39 DPO | Can one DPO remain easily accessible to every covered establishment and carry out the tasks with enough resources? | A non-EU entity may separately need an Article 27 representative after a territorial-scope and exception assessment. |
| United Kingdom | UK GDPR DPO | Can a shared DPO perform the UK role effectively, with a clear route to the ICO, staff, individuals and senior management? | A non-UK entity may separately need a UK Article 27 representative; an EU representative is not the UK appointment. |
| Switzerland | FADP Article 10 data protection adviser for private entities is generally voluntary | Which Swiss entity or processing needs FADP advice, and how will it be coordinated with any EU or UK DPO? | A foreign private controller must separately assess the cumulative Article 14 representative conditions. |
| Türkiye | KVKK compliance support is not an automatic GDPR DPO appointment | Which Turkish controller duties and operating decisions require local expertise and an accountable owner? | A foreign controller should separately assess VERBİS registration and representative requirements under the applicable rules. |
Test whether one DPO can actually cover the group
Count the activities rather than only the entities: product launches, DPIAs, incidents, rights requests, vendor reviews, authority correspondence, audits, training and management meetings. Identify periods when work peaks in several countries at once. A shared DPO may need supporting staff or specialist advisers while retaining a clear, independent oversight role.
Review conflicts of interest for internal and external candidates. A person who decides the purposes or means of the processing should not monitor their own decisions as DPO. Agree a direct reporting route to the highest management level of the relevant controller or processor, access to information and people, cover during absence, and how advice and management responses are recorded.
- List the entities, processing and markets included in the written mandate.
- Name the senior reporting contact and operational liaison for each covered entity.
- Estimate case volume, recurring reviews, urgent escalation and language needs.
- Record other duties and possible conflicts for every proposed DPO.
- Agree authority and individual contact channels, absence cover and secure handover.
- Define how country specialists support the DPO without replacing the statutory role.
Keep DPOs and representatives separate
A DPO advises, monitors and serves as a supervisory-authority contact within the statutory DPO role. An EU or UK Article 27 representative, or a Swiss Article 14 representative, is a distinct local contact arrangement assessed under different conditions. An organisation may require one, both or neither in a particular market. The same provider label does not merge the legal tests or automatically create the written appointments.
For Türkiye, a foreign controller's representative and VERBİS position also need their own assessment. A group DPO mandate written for the EU or UK is not evidence that Turkish designation or registration steps have been completed. Record the controller that makes decisions and the contact that receives and routes local correspondence.
A practical first-month handover
In week one, collect the entity chart, current appointments, privacy notices and authority contacts. In week two, review the processing inventory and open DPIAs, incidents and requests. In week three, agree the reporting and escalation routes with management and the internal owners. By the end of the first month, the group should have a written coverage map, capacity assumptions, unresolved role questions and a dated action register.
This is a planning sequence, not a promise that every legal question can be resolved in 30 days. Complex establishments, local sector rules and incomplete evidence may require further specialist review. Keep the decision record current when a new entity, product, acquisition or country is added.
Frequently asked questions
Can one person be the DPO for several EU group companies?
GDPR Article 37(2) permits a group of undertakings to appoint a single DPO when the person is easily accessible from each establishment. The group still needs sufficient capacity, independence and a clear mandate.
Does an EU group DPO appointment cover the UK automatically?
No. Assess the UK entities and their UK GDPR DPO position separately, even if the same qualified person may serve both roles under a workable arrangement.
Is a Swiss data protection adviser the same as a GDPR DPO?
No. Swiss FADP Article 10 provides a distinct data protection adviser framework. Private-sector appointment is generally voluntary and must be assessed on its own terms.
Does a group DPO replace EU, UK, Swiss or Turkish representatives?
No. Each representative requirement has a separate territorial, entity and role assessment. A DPO or adviser appointment does not itself create the local representative mandate.
What should a group send before requesting a proposal?
Share the entity chart, countries, processing types, existing privacy roles, approximate workload, open incidents or assessments, languages, senior reporting contacts and any known representative arrangements.
Keep researching
Related resources
A practical next step
Make the next privacy decision clearer
Bring your organisation, processing, jurisdictions, current documents, internal owners, and deadline. We can help identify the right scope before an appointment or wider workstream begins.
This guide provides general information, not legal advice or a conclusion that a particular organisation is required to appoint a role. Final scope, responsibilities, capacity, and deliverables should be confirmed against the organisation's facts.
Sources: EUR-Lex: GDPR Articles 27 and 37–39, EDPB: DPO designation and accessibility, ICO: data protection officers, FDPIC: Swiss data protection adviser, FDPIC: Article 14 representative, KVKK: Data Controllers Registry By-Law
