Data protection officer recruitment · Employed, outsourced or fractional DPO

Data protection officer recruitment: how to hire a DPO

Data protection officer recruitment starts with two questions: does the UK GDPR require you to appoint a DPO, and should the seat be employed, outsourced or fractional? To hire a data protection officer, answer both, then test candidates on real data protection work from organisations like yours.

We recruit permanent, interim, fractional, part-time and temporary executives, and non-executive directors. On every brief we send a shortlist of 3–5, each with pay or day rate, availability and IR35 position set out, after five-stage vetting.

How a brief runswhat we undertake

  1. 01Brief30-MINUTE SCOPING CALLDay 0
  2. 02Shortlist of 3–5VETTED · RATE BENCHMARK · IR35After the brief
  3. 03InterviewsYOU MEET THE SHORTLISTYour diary
  4. 04Scoped startFIRST-MONTH OUTCOMES AGREEDYou set the date
  5. 05Fractional, interim and permanentIR35 POSITION SET OUTOn every brief

Shortlist3–5

3–5
Shortlist · with pay or day rate, availability and IR35 set out
5
Vetting · stages before a candidate reaches you

15 minutes · video or phone

Book 15 minutes to hire a data protection officer

Tell us the scope and the days a week. We come back with Data Protection Officer candidates, their day rates and availability.

  1. 0115 minutes, video or phone
  2. 02We scope the role and the days a week
  3. 03A shortlist of 3–5 after the call
  4. 04Fractional, interim and permanent briefs
Prefer email? Use the booking page →

Pick a day that suits · live availability

On the board · last 3 months

Data protection officer jobs on the board

0 Data protection officer · 2 legal, privacy and compliance

No Data protection officer roles on the board in the last three months. Showing legal, privacy and compliance roles instead.

Live data protection, legal and compliance roles

Fractional recruitment works differently from a permanent search — shorter, scoped by days a week, and priced on the engagement. Send a Data Protection Officer brief and we come back with a shortlist of three to five vetted candidates.

01/ the role

When you need a data protection officer, and what the seat is

Article 37 of the UK GDPR makes the appointment mandatory in three cases: you are a public authority or body (courts and tribunals acting judicially excepted); your core activities involve regular and systematic monitoring of people on a large scale; or your core activities involve large-scale processing of special category data or criminal offence data. It applies to processors as well as controllers. The ICO’s guidance on data protection officers explains each test, including what counts as a core activity and as large scale.

If none of those applies you may still appoint a DPO voluntarily, on the same terms, or decide not to and record why. Either way you still need enough people and resources to meet your data protection obligations. Many organisations that are not required to have a DPO appoint a data protection lead instead, under another title.

What the seat is

The DPO informs and advises the organisation, monitors compliance, advises on data protection impact assessments and is the contact point for the ICO and for people whose data you hold. The DPO reports directly to the highest management level, must be involved early in every data protection issue, and cannot be told how to do the job. See what a data protection officer does for the full role.

Those conditions, set out in Article 38, shape the hire. A DPO may hold other duties only if they do not conflict, so the person who decides how personal data is used (a head of marketing, IT or data) is usually the wrong candidate. Write the reporting line and the independence into the role before you advertise it.

02/ scope

How to hire a data protection officer

1. Map the processing and size the work

List what personal data you process, at what scale, and the riskiest uses: special category data, monitoring, AI and automated decisions, transfers abroad. That tells you whether the appointment is mandatory, how many days the role needs and which sector knowledge matters. A DPO for a care provider and one for an adtech business are different hires.

2. Choose employed, outsourced or fractional

An employed DPO suits constant, high-risk processing. An outsourced service or a fractional DPO suits steadier processing, or a group that wants one DPO across several companies. If you want a named senior individual for part of the week, hire a fractional DPO. The comparison below sets out the trade-offs.

3. Assess against casework, not certificates

The law asks for expert knowledge of data protection law and practice, in proportion to the processing, and names no qualification. The BCS Practitioner Certificate in Data Protection and the IAPP’s CIPP/E are common signals. Test the work itself: the CIPD’s guidance on selection favours clear, objective and structured processes, so give every candidate the same DPIA or breach scenario from your own business and score the answers against the same criteria.

4. Run the checks and publish the contact

For an employee, you must check their right to work before they start. Take references from someone the candidate advised, and ask whether they gave unwelcome advice and recorded it. Once appointed, Article 37 requires you to publish the DPO’s contact details and give them to the ICO.

What we do on a DPO brief

We send a shortlist of 3–5 candidates, each with pay or day rate, availability and IR35 position set out. Every candidate goes through our five-stage vetting first.

03/ comparison

Employed, outsourced or fractional DPO?

The law allows all three. An external DPO has the same position, tasks and duties as an internal one.

Employed DPOOutsourced DPO serviceFractional DPO
Who does the workA member of staff designated as DPOA firm, under a service contract, with a named DPOA named senior individual for an agreed number of days
IndependenceMust be protected in the reporting line and the job descriptionEasier to show; the risk is distance from decisionsEasier to show; needs a seat in project and board meetings
SuitsConstant, high-risk or large-scale processingSteady processing with a defined service scopeGrowing businesses, programme work, groups sharing one DPO
Watch forConflicting duties added laterBeing told about projects after decisions are madeIR35 status, decided by how the engagement runs

04/ vetting

How we vet data protection officers

What we undertake on every brief, before a candidate reaches you.

  1. 01

    Qualification screen

    Verify Data Protection Officer tenure, sector context and stage fit.

    SOURCING
  2. 02

    Mandate fit

    Match to your situation — stage, board dynamics, timing.

    MATCHING
  3. 03

    Reference deep-dive

    We take references ourselves, from recent past clients — real outcomes, not titles.

    VERIFY
  4. 04

    Shortlist

    Three to five candidates with day rate, availability and IR35 position set out.

    SHORTLIST OF 3–5

05/ employed, outsourced or fractional

Internal, outsourced or fractional DPO: which to hire

Article 37 lets the DPO be a member of staff or work under a service contract, and the ICO confirms that an outsourced data protection officer should have the same position, tasks and duties as an internal one. A group of companies may share one DPO if the DPO is easily accessible from each establishment; public bodies may share one too, taking account of their structure and size.

An internal appointment can be an existing employee, if their other duties do not conflict. The ICO’s example of a fit is a public authority’s freedom of information officer or records manager; its example of a conflict is a head of marketing who decides which customers to target. Whichever route you choose, write into the engagement how the DPO is brought into new projects and DPIAs before decisions are made.

For a named individual for part of the week, see fractional DPO jobs and how to hire one. If the wider need is legal cover (contracts, disputes, employment), a fractional general counsel is the better seat; for security operations, see fractional CISO.

06/ what to test for

Data protection officer interview questions: what to test for

Test the four things the role turns on. Judgement: walk through a new processing activity from your business and ask whether it needs a DPIA, what the risks are and what they would advise. Breach handling: give a breach scenario and ask for the first steps, the risk assessment and whether and when to report to the ICO. Independence: ask for a time they advised senior people against a plan, and what they recorded when the advice was declined. Currency: ask what the Data (Use and Access) Act 2025 changed for an organisation like yours, from complaints handling to automated decision-making.

Add sector questions where another regulator sits beside the ICO, and a short written exercise (a privacy notice or a processor contract clause) if the role will draft. Score every answer against the same criteria.

07/ the ICO fee

The ICO data protection fee is not a recruitment fee

Organisations that use personal information, including sole traders, must pay the ICO’s data protection fee under the Data Protection (Charges and Information) Regulations 2018 unless they are exempt. It is a charge paid to the regulator, not to a recruiter or to the DPO, and appointing a DPO neither replaces it nor depends on it.

Keep the two separate in the budget. The fee is set by the ICO; a DPO’s pay or day rate depends on the scale and risk of the processing, the sector and how many days the seat needs. Where an outsourced or fractional DPO works through their own company, the off-payroll working rules (IR35) may apply: status depends on how the engagement runs, and a medium or large client makes the determination. Our IR35 guide sets out the tests.

08/ questions

Data protection officer recruitment FAQ

The questions people ask before bringing in a data protection officer.

Check whether the law requires one, map your processing to size the role, choose employed, outsourced or fractional, test candidates on the same DPIA or breach scenario, take references, and check right to work for an employee. Then publish the DPO’s contact details and give them to the ICO. For part of the week, hire a fractional DPO instead.
It depends on the scale and risk of your processing, the sector and how many days the role needs. We do not quote a figure we cannot verify at source. On every brief we set out pay or day rate for each candidate on the shortlist, so you can compare like with like. The ICO’s data protection fee is a separate charge paid to the regulator.
When you are a public authority or body, or your core activities involve large-scale regular and systematic monitoring of people, or large-scale processing of special category or criminal offence data (Article 37). Otherwise appointment is voluntary, on the same terms.
Internal for constant, high-risk processing; outsourced or fractional for steadier processing or a group sharing one DPO. The law treats them the same: an external DPO has the same position, tasks and duties as an internal one. See the comparison above.
A DPIA scenario from your business, a breach scenario with the reporting decision, a time they gave unwelcome advice to senior people, and what the Data (Use and Access) Act 2025 changed. Score each answer against the same criteria.
No. The data protection fee is paid to the ICO by organisations that use personal information unless they are exempt. It is not paid to a recruiter or a DPO, and appointing a DPO does not replace it.
Yes, if their other duties do not create a conflict of interests. Someone who decides why and how personal data is processed, such as a head of marketing or IT, is usually unsuitable. See what a data protection officer does.

Book 15 minutes · shortlist of 3–5

Bring the brief. We architect the team.

A shortlist of 3–5 with day rate, availability and IR35 position set out, after five-stage vetting.

For hiring managers

Bring the brief. We bring the shortlist.

Sign up now →Book a call

  1. A shortlist of 3–5, each with day rate, availability and IR35 position
  2. Fractional, interim, part-time, temporary or permanent — and non-executive directors
  3. Every candidate through our five-stage vetting
  4. Your briefs and their candidates, in one room
Fractional Quest logo — how to hire a data protection officer, data protection officer recruitment