Artificial intelligence
The data protection officer, in a twelve-person business
The question almost never comes from the authority. It comes from a client, in a tender, with a box to fill and a date.
A twelve-person services company in Algiers is filling in a file for a foreign client. One line asks for the name and contact details of the data protection officer. The manager looks at his team: an accountant, two salespeople, six technicians, an assistant, a part-time IT manager. Nobody holds that title and nobody knows whether they need to.
The answer does not depend on headcount, and that is the first thing almost everybody gets wrong. It depends on what the business does with data — which makes it far easier to settle for a business that has written its register, and impossible for one that has not. An artificial intelligence project makes the question urgent because it adds a processing activity, not because it changes the rule.
This article gives the criteria, what the role actually occupies in a week, who can hold it and who cannot. It does not say whether you must designate one: the full framework is elsewhere, your case is settled with a lawyer, and section 1 explains why we stop there.
The question comes from a client, not from the authority
In what we see, the overwhelming majority of businesses asking the question are not asking because they were inspected. They are asking because a client, a foreign partner or a tender asked for a name.
That changes the nature of the problem. A contractual requirement has a date, a form and an immediate consequence — the file passes or it does not — where a legal obligation has a vague deadline and an abstract risk. It is also why the businesses that deal with this early are rarely the ones afraid of a fine.
The second consequence is less pleasant: the box pushes you to designate somebody so there is a name to write, which is exactly how to make the role useless. An officer designated the day before a file is submitted, who has never seen the register and has had nothing taken off their normal work, is a name on a form.
The right response is to treat the client’s request as a deadline and the designation as a separate decision. The first is settled in a week; the second decides how the business will meet its obligations for years.
What the law asks, and of whom
Law 18-07 of 10 June 2018, amended and completed by law 25-11 of 24 July 2025, makes designating a data protection officer compulsory in defined cases. The wording that matters is that the obligation is not assessed by the size of the business: it depends on the nature, volume and sensitivity of the processing carried out.
Three situations are covered. Public administrations and bodies. Organisations whose principal activity involves regular, large-scale monitoring of individuals. And those processing sensitive data — health, biometrics, judicial data, opinions.
The practical consequence is that a twelve-person business can be covered and a two-hundred-person one may not be. A six-person medical practice processes health data; a three-hundred-person trading company holding only supplier contacts is in a different position. The criterion is the processing, not the org chart.
The above describes the state of a regulation as at 21 August 2026 and does not replace a lawyer’s advice. We will not say whether your business must designate an officer, and an IT supplier who settles that question to reassure you is providing a service they do not answer for. What we establish is the list of your processing activities, and it is that which makes the question answerable.
The three criteria, applied to twelve people
Take the services company from the opening and read the criteria against its register rather than its headcount. Its activities: payroll, recruitment, customer file, support tickets, warehouse video surveillance, mailing list, and for six months an assistant connected to the mailbox.
Regular, large-scale monitoring: the video surveillance and the assistant come closest, and the question is neither the number of cameras nor the number of messages but how regular and systematic the observation is. It is the hardest criterion to read alone, and the one where an opinion is worth what it costs.
Sensitive data: a recruitment file sometimes contains a medical certificate, video surveillance produces images of identifiable people, and support tickets contain whatever a customer chose to write. Businesses regularly discover they process some without having decided to, and that discovery happens by reading the register rather than by thinking about it.
The point is that these three readings take an hour when the register exists and are impossible without it. The six columns, filled in on a real case are a separate subject and they are this one’s precondition: the officer question is answered from the register, not from an intuition about the size of the business.
An ordinary week for an officer
The title suggests a post. In a business this size it is a function occupying a few hours a week, and describing those hours is more useful than describing the title.
Five tasks recur. Keeping the register current when a tool changes or an activity starts — usually one row, sometimes nothing. Answering requests from the people concerned: access, correction, deletion. Handling an incident when there is one. Checking the things that erode on their own: a departed employee’s access, logs that switched themselves off, a retention period nobody applies — the same erosion that eventually stops a business, looked at through data rather than through outages.
The fifth is the one that makes the difference and appears on no job description: being consulted before a project starts. An officer who discovers a new tool on the day it goes live spends their time catching up; one told three weeks ahead writes two paragraphs and the project starts straight.
The volume depends on the register and is roughly predictable: a business with twelve stable activities and one project a year takes a few hours a month, one changing tools every quarter far more. What we do not publish is a typical number of hours, because it depends entirely on the length of your register and an average would describe nobody.
Who can hold it internally
The starting competence is neither legal nor technical: it is the ability to describe what the business does, to ask people for answers without being brushed off, and to write. In businesses this size that often points to whoever handles administration, quality or human resources.
What has to be added is training and access. Training exists and is short; access is the part businesses forget — an officer who has to ask permission to open a screen or read a contract will not exercise the role.
Genuinely freed time is also needed, written down somewhere. “On top of their job” means the function yields to any urgency, and the register is exactly the kind of thing that yields without anybody noticing for eight months.
The last point is duration. A designation that changes every six months cancels the benefit, because the role’s value is cumulative: the useful officer is the one who knows in February what they saw in November.
Who cannot: the IT manager
This is the designation that comes naturally to mind and the most problematic. The IT manager is the one who puts the processing in place, chooses the tools and configures access. Handing them oversight of those choices amounts to asking them to audit their own work.
The conflict is not theoretical and shows in a simple case: an officer has to be able to say a project cannot start as it stands. When the project is theirs, the sentence will not be spoken — not out of dishonesty, but because nobody stops themselves as easily.
There is a nuance that matters in a small organisation: the IT manager is often the person who best knows where the data is, and they are indispensable to the officer’s work. The right configuration is for them to be the officer’s first source of information, not the officer.
The same reasoning applies to an external supplier who built the system, and it applies to us. That is why we do not take this role at our clients, and section 11 returns to it.
The manager, and the conflict nobody sees
The second instinctive designation is the manager or director, on the grounds that they have the authority to make things happen. The authority is real and that is precisely the problem: the director decides the purposes of the processing, which makes them the person whose decisions have to be examined.
The conflict is less visible than in the IT case because it is not about technology. It is about commercial trade-offs: keeping a prospect file longer, using a database for a campaign, accepting an unbalanced clause to sign a contract. Those are exactly the decisions an officer has to be able to discuss.
In a very small organisation there is sometimes no other option, and it is better said than dressed up. A four-person business where the manager holds the function is in an imperfect position it can honestly document; a twelve-person one making the same choice for convenience has deprived itself of the only counterweight the arrangement provides.
The simple test is to ask who in the business can say no to the manager without it becoming an incident. If the answer is nobody, an internal designation will not produce what is expected of it, and the external route deserves a look.
The external officer: what they cost in access
The law allows the function to be given to somebody outside, and it is often the most realistic solution at this size. Independence comes by construction and competence can be bought.
What is bought less easily is knowledge of the business, and that is where most external designations fail. An external officer who sees nobody for eleven months and produces a report in December is describing a business they do not know. The real cost of that arrangement is not what it invoices, it is the access you have to open.
Three things make it work, and they cost you time rather than money: an internal person who answers them, a regular appointment however short, and the rule that they are told before a project starts. Without the third they are an auditor; with it they are what the function provides for.
We publish no price range for that service, and not only because it is not ours: it depends on the number of activities, the sector and how often things change, and an amount written here would be read as a rate by businesses none of which resemble each other.
The designation, and what it commits you to
A designation is a written act, not a verbal mention in a meeting. It names the person, describes their mission, states who they report to and what they have access to. That document is short — one page is enough — and it is what distinguishes a function from an intention.
The officer then becomes the point of contact with the authority. They prepare declarations and authorisation requests, handle a breach notification, answer information requests and accompany a documentary or on-site inspection — the four documents an inspection asks for are what they have to be able to produce without a preparatory meeting.
Their contact details circulate, and that is intended: somebody wanting to exercise a right has to know who to write to. Arrange a functional address rather than a personal one, so that the person leaving does not cut the channel.
Finally, the designation does not transfer responsibility. It stays with the business as controller, and the officer is not an insurance policy: they are what makes the business able to answer. A designation made to move a risk moves nothing.
Independence in practice, and the day they say no
Independence is not declared in the designation document, it is verified by three signs. The officer reports at the highest level rather than to a department head. They receive no instruction on how to carry out their mission. And they cannot be penalised for having carried it out.
The third sign is the one that gets tested, and it gets tested once: the day the officer says a project cannot go ahead as it stands. What happens that day determines everything else, because the business learns in one meeting whether the function is real.
The right way through that moment is to separate the opinion from the decision. The officer says what is missing and why; management decides, including deciding to override, and that decision is written down. Management carrying a documented risk is in a far stronger position than management nobody ever flagged anything to.
The bad scenario does not look like a conflict, it looks like silence. An officer who was not overruled but has simply stopped being told has been neutralised without any decision having been taken, and it shows in one thing: the date they were last consulted before a project.
The test for the person you have in mind
Here is the exercise, and it is done before designating anybody. Take the person you are considering, alone, unprepared, and ask them to name every place in the business where data about people sits. Let them finish without correcting.
Write the list down. Then compare it with what you would get by asking the same question of three people from three different trades — it is the same exercise a register requires, and it costs half an hour.
What you are measuring is not the person’s legal knowledge, which can be acquired, but two things that cannot be acquired quickly: their cross-cutting knowledge of the business, and their willingness to say “I do not know” rather than fill in. The second matters more in this role.
If the list stops at software, the person sees the business through IT. If it includes the notebook at reception, the drivers’ messaging group and the salesperson’s spreadsheet, you have found your officer, whatever their current job title.
What we do, and what we refuse
We build the register with your teams, which is the precondition for reading the criteria at all, and we train the person you designate: what they keep, what they check, in what order and at what rhythm. We also prepare the designation document and the list of what has to be opened to them, because that is the part businesses forget and it decides everything.
We answer their technical questions afterwards, and that is the right position: they need to know where the data is and how a flow works, and that is what we do. A well-equipped officer asks precise questions and costs us little time.
We are not your officer, and the refusal is structural rather than commercial. The function assumes being able to contradict whoever built the system, and when that system came from us we would be both the audited and the auditor. A supplier who accepts both roles sells the second by cancelling the first.
And we will not tell you whether the obligation applies to you. That is a reading of a text applied to your situation, done with a lawyer and with the register in front of you, and a reassuring answer from an IT supplier binds nobody on the day it is questioned.
Frequently asked questions
Does a twelve-person business have to designate an officer?
That is not decided by headcount. The obligation depends on the nature, volume and sensitivity of the processing — public administrations, organisations whose principal activity involves regular large-scale monitoring of individuals, and those processing sensitive data. Reading those three criteria against your register takes an hour; applying them to your case is a lawyer’s work.
Can our IT manager hold the role?
It is the commonest designation and the most fragile: they put the processing in place, choose the tools and configure access, so overseeing those choices means auditing their own work. The right configuration is for them to be the officer’s first source of information rather than the officer, which preserves their real value in the arrangement.
Can we designate somebody external?
Yes, and it is often the most realistic solution at this size: independence comes built in and competence can be bought. What decides whether it works is not their rate but the access you open — an internal person who answers them, a regular appointment, and the rule that they are told before a project starts.
How many hours a week does this take?
We publish no average, because it depends entirely on the length of your register and how often you change tools. What is predictable is the shape: a few hours a month for a business with stable activities, clearly more in the year three projects start. The workload can only be estimated honestly once the register exists.
What happens if the officer objects to a project?
They give an opinion, management decides, and the decision is written down — including when it overrides them. Management carrying a documented risk is far better placed than management nobody ever flagged anything to. What does not hold is the third scenario, where people simply stop telling them.
Does designating one protect us if something goes wrong?
No: responsibility for the processing stays with the business, and the officer is not an insurance policy. What they bring is the ability to answer — a current register, an incident procedure, somebody who knows the file. A designation made to move a risk moves nothing, and it shows immediately.
Where we come in
The person you have in mind gave you a list. What counts is not its length but whether it includes the notebook at reception and the messaging group, or only software.
- The inventory happens trade by trade at your end: without it the three criteria have nothing to be read against.
- We put your candidate in a position to exercise the role — the routine, the things that erode, the cadence.
- We write the act and, beside it, what must be opened so the function exists other than on paper.
We refuse to take the role on — our own position rules it out — and whether the obligation covers you belongs to a lawyer, not to us.
Read next
IT audit: start by opening the cupboard
An audit is done standing up, on the premises, opening doors. What is found there decides everything else, and it is written down nowhere.The second audit: what moved, and the findings that never will
A first audit describes. The second compares — and comparison says things about a business that no description can.The processing register, filled in on a real case
A twelve-person firm loses a tender on a document it had never heard named. Here are the six columns, filled in on a real assistant.
Let us talk about your project
A free audit, no commitment: we look at your online presence and tell you what is holding it back.