Compliance6 min read

Does Your Company Need a DPO to Use AI?

Using AI doesn't automatically require a DPO: it's mandatory in 3 cases (GDPR art. 37). The move you can make today: anonymise your data before AI.

By Pierre de ONYRI

The answer lives in a nuance. No, using AI does not, on its own, force you to appoint a DPO (data protection officer). Yes, your use can trigger it in some cases. It all depends on the nature and the scale of the data you process. Not on the tool. Article 37 of the GDPR sets three cases where a DPO is mandatory. Outside them, the CNIL still encourages appointment. And in every case, one duty is immediate: minimise and anonymise your data before you hand it to AI.

A DPO is mandatory in three cases

Article 37 of the GDPR is precise. Appointing a DPO is mandatory only in three situations. Meeting a single one is enough to be concerned.

  • The processing is carried out by a public authority or body.
  • Your core activities consist of regular and systematic monitoring of individuals on a large scale.
  • Your core activities consist of large-scale processing of special-category data (health, biometrics, opinions, origin…) or criminal data.

Two words deserve attention: “core activities”. The test targets the heart of your business. Not a side task. A company whose main activity is neither monitoring people nor handling sensitive data often falls outside the three cases. The CNIL, for its part, does enforce this: it has issued formal notices to French municipalities to appoint a DPO. Local authorities are public bodies, so they fall under the first case.

SituationDPO mandatory?
Public authority or bodyYes — first case of article 37
Regular and systematic monitoring at large scale (core activity)Yes — second case
Large-scale processing of special-category or criminal data (core activity)Yes — third case
SME using AI for everyday tasksUsually no — but the GDPR still applies
The three cases of GDPR article 37. Meeting a single one is enough to make a DPO mandatory.

Using AI does not create the duty

AI on its own triggers no DPO duty. What matters is what you process and at what scale. Analysing health data at large scale through an AI can tip you into the third case. Using an AI assistant to draft emails does not. Most SMEs that turn to AI for everyday tasks stay outside the three cases.

Still, the CNIL goes further. Even without a duty, it encourages appointing a DPO. A single point of reference helps steer compliance across all your processing. It is a recommendation, not a hidden obligation. Weigh the benefit against your maturity.

“No DPO, no constraints”: that is false

The objection comes up often. No mandatory DPO, so no constraint. That is false. The GDPR applies whatever your DPO status. Several duties remain intact for any professional use of AI.

A legal basis for your processing (article 6). Data minimisation (article 5). Informing individuals. Keeping the record of processing. Security. And a DPIA (data protection impact assessment, article 35) as soon as processing presents a high risk.

The DPIA is a mechanism separate from the DPO. It is required, for instance, for large-scale processing of sensitive data or automated profiling. Some AI uses create exactly those set-ups. DPO and DPIA are two separate duties. One never exempts you from the other.

The lever you can pull today

DPO mandatory or not, one lever cuts the risk right away. Minimisation. Send AI only the data strictly needed. Remove or anonymise personal and sensitive data first. Before it leaves your environment. This move answers article 5 of the GDPR directly, and you wait for no organisational decision to apply it.

  1. 1Map the personal and sensitive data present in your prompts.
  2. 2Remove or anonymise what the answer does not need.
  3. 3Send the AI only the anonymised text.
  4. 4Restore the real values in the reply, locally.
Decision diagram: an organisation node leads to a branch gate; one path ends at a DPO badge with a person glyph, the other at a plain path. Beside it, a data record in the clear (amber) is carried into a lower lane where it becomes cobalt token chips with a checkmark — the fix that applies either way.
After article 37 of the GDPR (EUR-Lex) and the CNIL's guidance on the data protection officer.

That is what ONYRI Sanitize is for. The engine detects sensitive data — names, contact details, identifiers, health data, technical secrets — and replaces it with reversible tokens before sending. Detection and the mapping stay in your browser. Only anonymised text reaches the model. Let's be clear: ONYRI is neither a DPO nor a substitute for your GDPR compliance. It is a technical minimisation control that cuts the risk upstream, whether you have a DPO or not.

Frequently asked questions

Does your company need a DPO to use AI?
Not automatically. Using AI does not, on its own, create the duty to appoint a DPO. GDPR article 37 makes it mandatory in three cases only. A public authority or body. Regular and systematic monitoring at large scale. Or large-scale processing of special-category or criminal data. If your AI use involves one of those, the duty can trigger. Otherwise the CNIL still encourages appointment, without imposing it.
In which cases is a DPO mandatory?
GDPR article 37 sets three cases. One: the processing is carried out by a public authority or body. Two: your core activities consist of regular and systematic monitoring of individuals at large scale. Three: your core activities consist of large-scale processing of special-category or criminal data. Meeting a single one is enough. The test is about your core activities, not a side task.
Without a mandatory DPO, do you still have GDPR duties with AI?
Yes, fully. The absence of a mandatory DPO removes no obligation. A legal basis (article 6), minimisation (article 5), informing individuals, the record of processing and security all still apply. A DPIA (impact assessment) is required whenever processing presents a high risk, which some AI uses can create. The immediate lever: minimise and anonymise data before you hand it to AI.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Anonymize my prompt

Read next