Data protection officer recruitment · Employed, outsourced or fractional DPO
Data protection officer recruitment: how to hire a DPO
Data protection officer recruitment starts with two questions: does the UK GDPR require you to appoint a DPO, and should the seat be employed, outsourced or fractional? To hire a data protection officer, answer both, then test candidates on real data protection work from organisations like yours.
We recruit permanent, interim, fractional, part-time and temporary executives, and non-executive directors. On every brief we send a shortlist of 3–5, each with pay or day rate, availability and IR35 position set out, after five-stage vetting.
How a brief runswhat we undertake
- 01Brief30-MINUTE SCOPING CALLDay 0
- 02Shortlist of 3–5VETTED · RATE BENCHMARK · IR35After the brief
- 03InterviewsYOU MEET THE SHORTLISTYour diary
- 04Scoped startFIRST-MONTH OUTCOMES AGREEDYou set the date
- 05Fractional, interim and permanentIR35 POSITION SET OUTOn every brief
Shortlist3–5
15 minutes · video or phone
Book 15 minutes to hire a data protection officer
Tell us the scope and the days a week. We come back with Data Protection Officer candidates, their day rates and availability.
- 0115 minutes, video or phone
- 02We scope the role and the days a week
- 03A shortlist of 3–5 after the call
- 04Fractional, interim and permanent briefs
Pick a day that suits · live availability
On the board · last 3 months
Data protection officer jobs on the board
No Data protection officer roles on the board in the last three months. Showing legal, privacy and compliance roles instead.
Live data protection, legal and compliance roles
Fractional recruitment works differently from a permanent search — shorter, scoped by days a week, and priced on the engagement. Send a Data Protection Officer brief and we come back with a shortlist of three to five vetted candidates.
01/ the role
When you need a data protection officer, and what the seat is
Article 37 of the UK GDPR makes the appointment mandatory in three cases: you are a public authority or body (courts and tribunals acting judicially excepted); your core activities involve regular and systematic monitoring of people on a large scale; or your core activities involve large-scale processing of special category data or criminal offence data. It applies to processors as well as controllers. The ICO’s guidance on data protection officers explains each test, including what counts as a core activity and as large scale.
If none of those applies you may still appoint a DPO voluntarily, on the same terms, or decide not to and record why. Either way you still need enough people and resources to meet your data protection obligations. Many organisations that are not required to have a DPO appoint a data protection lead instead, under another title.
What the seat is
The DPO informs and advises the organisation, monitors compliance, advises on data protection impact assessments and is the contact point for the ICO and for people whose data you hold. The DPO reports directly to the highest management level, must be involved early in every data protection issue, and cannot be told how to do the job. See what a data protection officer does for the full role.
Those conditions, set out in Article 38, shape the hire. A DPO may hold other duties only if they do not conflict, so the person who decides how personal data is used (a head of marketing, IT or data) is usually the wrong candidate. Write the reporting line and the independence into the role before you advertise it.
02/ scope
How to hire a data protection officer
1. Map the processing and size the work
List what personal data you process, at what scale, and the riskiest uses: special category data, monitoring, AI and automated decisions, transfers abroad. That tells you whether the appointment is mandatory, how many days the role needs and which sector knowledge matters. A DPO for a care provider and one for an adtech business are different hires.
2. Choose employed, outsourced or fractional
An employed DPO suits constant, high-risk processing. An outsourced service or a fractional DPO suits steadier processing, or a group that wants one DPO across several companies. If you want a named senior individual for part of the week, hire a fractional DPO. The comparison below sets out the trade-offs.
3. Assess against casework, not certificates
The law asks for expert knowledge of data protection law and practice, in proportion to the processing, and names no qualification. The BCS Practitioner Certificate in Data Protection and the IAPP’s CIPP/E are common signals. Test the work itself: the CIPD’s guidance on selection favours clear, objective and structured processes, so give every candidate the same DPIA or breach scenario from your own business and score the answers against the same criteria.
4. Run the checks and publish the contact
For an employee, you must check their right to work before they start. Take references from someone the candidate advised, and ask whether they gave unwelcome advice and recorded it. Once appointed, Article 37 requires you to publish the DPO’s contact details and give them to the ICO.
What we do on a DPO brief
We send a shortlist of 3–5 candidates, each with pay or day rate, availability and IR35 position set out. Every candidate goes through our five-stage vetting first.
03/ comparison
Employed, outsourced or fractional DPO?
The law allows all three. An external DPO has the same position, tasks and duties as an internal one.
04/ vetting
How we vet data protection officers
What we undertake on every brief, before a candidate reaches you.
- 01
Qualification screen
Verify Data Protection Officer tenure, sector context and stage fit.
SOURCING - 02
Mandate fit
Match to your situation — stage, board dynamics, timing.
MATCHING - 03
Reference deep-dive
We take references ourselves, from recent past clients — real outcomes, not titles.
VERIFY - 04
Shortlist
Three to five candidates with day rate, availability and IR35 position set out.
SHORTLIST OF 3–5
05/ employed, outsourced or fractional
Internal, outsourced or fractional DPO: which to hire
Article 37 lets the DPO be a member of staff or work under a service contract, and the ICO confirms that an outsourced data protection officer should have the same position, tasks and duties as an internal one. A group of companies may share one DPO if the DPO is easily accessible from each establishment; public bodies may share one too, taking account of their structure and size.
An internal appointment can be an existing employee, if their other duties do not conflict. The ICO’s example of a fit is a public authority’s freedom of information officer or records manager; its example of a conflict is a head of marketing who decides which customers to target. Whichever route you choose, write into the engagement how the DPO is brought into new projects and DPIAs before decisions are made.
For a named individual for part of the week, see fractional DPO jobs and how to hire one. If the wider need is legal cover (contracts, disputes, employment), a fractional general counsel is the better seat; for security operations, see fractional CISO.
06/ what to test for
Data protection officer interview questions: what to test for
Test the four things the role turns on. Judgement: walk through a new processing activity from your business and ask whether it needs a DPIA, what the risks are and what they would advise. Breach handling: give a breach scenario and ask for the first steps, the risk assessment and whether and when to report to the ICO. Independence: ask for a time they advised senior people against a plan, and what they recorded when the advice was declined. Currency: ask what the Data (Use and Access) Act 2025 changed for an organisation like yours, from complaints handling to automated decision-making.
Add sector questions where another regulator sits beside the ICO, and a short written exercise (a privacy notice or a processor contract clause) if the role will draft. Score every answer against the same criteria.
07/ the ICO fee
The ICO data protection fee is not a recruitment fee
Organisations that use personal information, including sole traders, must pay the ICO’s data protection fee under the Data Protection (Charges and Information) Regulations 2018 unless they are exempt. It is a charge paid to the regulator, not to a recruiter or to the DPO, and appointing a DPO neither replaces it nor depends on it.
Keep the two separate in the budget. The fee is set by the ICO; a DPO’s pay or day rate depends on the scale and risk of the processing, the sector and how many days the seat needs. Where an outsourced or fractional DPO works through their own company, the off-payroll working rules (IR35) may apply: status depends on how the engagement runs, and a medium or large client makes the determination. Our IR35 guide sets out the tests.
08/ questions
Data protection officer recruitment FAQ
The questions people ask before bringing in a data protection officer.

Book 15 minutes · shortlist of 3–5
Bring the brief. We architect the team.
A shortlist of 3–5 with day rate, availability and IR35 position set out, after five-stage vetting.
