Under GDPR, appointing a DPO is mandatory for organizations that:
Are public authorities or bodies (except for courts acting in their judicial capacity). Engage in large-scale, regular, and systematic monitoring of individuals. Process large-scale special categories of data or data relating to criminal convictions and offenses.
Even if not mandatory, having a DPO can be beneficial for organizations involved in extensive email marketing activities.