Do you need a DPO for a small salon, clinic, or shop? Clear criteria, no panic
When GDPR actually forces you to appoint a data protection officer, and when it is just a cost you do not need.
Has someone told you that "if you have customers you must appoint a DPO or you will be fined"? For most small salons, small clinics, or corner shops, that is simply not true. GDPR does require a data protection officer, but only in a few clearly defined situations, not for every business that keeps a customer list.
The trouble is that this topic sells through fear. You will see "mandatory DPO packages" offered for hundreds of euros a year to businesses that legally have no obligation to appoint anyone. In this article I will explain, in plain terms for a busy owner, when you genuinely need a DPO, when you do not, and what you must do anyway regardless of the answer.
What a DPO actually is
DPO stands for Data Protection Officer. This is the person who oversees how your business follows data protection rules: they check, advise, handle requests from people who want their data, and act as the point of contact with the supervisory authority.
A few things to get straight from the start:
- A DPO can be internal (an employee) or external (a contractor or a firm).
- The role can be part-time and can be shared across several businesses.
- It does not replace your obligations. You remain legally responsible even with a DPO.
- Having a DPO is not the same as "being GDPR compliant." Those are two different things.
The three cases where GDPR truly requires a DPO
The rule comes from Article 37 of GDPR. You must appoint a DPO only in one of these three situations:
- You are a public authority or body (a town hall, a state school, a public hospital).
- Your core activity involves regular and systematic monitoring of people on a large scale, such as extensive video surveillance, large-scale online tracking, or profiling.
- Your core activity involves large-scale processing of sensitive data: health data, ethnic origin, sexual orientation, biometric data, or criminal records.
The key words are "core activity" and "large scale." If processing data is not the heart of your business but simply a normal consequence of having customers, you most likely fall outside these cases.
What this means for a real salon, clinic, or shop
Let us take them one by one, the way they show up in real life:
- Beauty salon, barber, nail salon: you keep appointments, names, phone numbers, maybe photos. That is not large-scale monitoring or a surveillance business. Normally you do not need a DPO.
- Small shop or small online store: names, delivery addresses, orders. Again, ordinary, small-scale processing. Normally you do not need a DPO.
- Small medical or dental practice: here you process health data, which is sensitive. But the law talks about processing "on a large scale." A single or small practice, where health data is kept by the professional treating their own patients, is normally not considered large scale.
In short: most small businesses of this kind have no legal duty to appoint a DPO. A large clinic chain, a retail network with tracking, or a platform with many users is a different conversation.
What you must do anyway, even without a DPO
Here is the part nobody mentions when they are selling you fear. GDPR applies regardless, DPO or not. Whether or not you are required to appoint someone, you still must:
- Have a clear privacy policy on your site and at reception, saying what data you collect and why.
- Ask for proper consent where it is needed, for example a newsletter or photos used in advertising.
- Keep data secure: passwords, limited access, do not leave the appointment book in plain sight.
- Delete data when you no longer need it, and respond when a customer asks to be removed.
- Have a legal basis for each type of data you use.
That is the real "GDPR compliance" for a small business, and it costs far less than a pointless DPO subscription.
How we can help, without the scare tactics
At MPO Web Studio we build websites for small businesses across the country, remotely, and it comes naturally to set up the data side correctly too: a privacy policy written in plain language, a booking form that asks only for what is needed, clear consent where it belongs, and a cookie banner that does not annoy your customer.
We do not sell "mandatory DPO packages" to businesses that do not need one. If you run a salon, a small clinic, or a shop, in most cases you need a clean website and correct legal text, not a monthly subscription with fear baked in.
If you want to see what that looks like, we build you a ready-made demo for free before you pay anything. Message us on WhatsApp and we will tell you honestly whether you need a DPO in your case.
Frequently asked questions
Will I be fined if I do not have a DPO?+
You are not fined for lacking a DPO as long as you are not legally required to appoint one. You are fined for breaking data protection rules, for example having no privacy policy, using customer photos without consent, or leaving data unsecured. The real duty is to comply with GDPR, not necessarily to have a DPO.
My dental practice processes health data. Surely I need a DPO?+
Not automatically. Yes, health data is sensitive, but the law only requires a DPO when processing is on a large scale. A single or small practice, where the professional keeps records for their own patients, normally does not count as large scale. A large clinic network is a different story. If in doubt, a one-off check is safer than an open-ended subscription.
Can I be my own DPO?+
If you are required to have a DPO, you can appoint an employee or a contractor, but there must be no conflict of interest, meaning it cannot be the person who alone decides how data is used. In practice, the owner who makes every decision is a poor choice for DPO. But remember: most small businesses are not required to have one at all.
Do I have to notify anyone if I appoint a DPO?+
Yes. If you formally appoint a DPO, you must communicate their contact details to the supervisory authority and publish those contact details, usually on your website. But this step only applies if you actually have a DPO.
How much should GDPR compliance cost for a small salon?+
Far less than some try to scare you into paying. For a small business, we are generally talking about correct legal text on the site, a clean form, and a few sensible internal rules, not an expensive monthly subscription. Be wary of offers that tell you it is "mandatory" without explaining why in your specific case.
7 mistakes that drive clients away from your website
Leave your email and get the guide right here, instantly. No spam.
Want to see what your business's website could look like?
Message us on WhatsApp and we'll build you a free demo website with your business name on it. See it first, then decide — no strings attached.