If an organization is a "public authority," engages in "large scale systematic monitoring or "large scale processing of sensitive personal data," the regulation requires it to hire a data protection officer.
While it is unclear exactly what "large scale" means, the industry consensus is that it means an organization with more than 250 employees or processes personal data for more than 5,000 subjects over the course of a year. According to the TechRepublic editorial, companies should consider hiring a data protection officer in order to illustrate their commitment to protecting information, even if the regulation doesn’t specifically require one.