Skip to content
Legiscope
Menu
Personal Data

DPO or compliance officer ?

Only the DPO is regulated by the GDPR. See how the Data Protection Officer differs from a compliance officer, when it is mandatory, and who appoints one.

Also available in:Français

It’s very important to understand the difference between a Data Protection Officer and all other titles such as Data Privacy Officer, compliance officer, GDPR compliance officer, and for one reason : only the Data Protection Officer (DPO) is regulated by the GDPR. In practical terms this means, the DPO has specific tasks he needs to conduct, specific position and specific safeguards for independence when performing the role.

And that’s not the case with all the other titles.

In an organization, someone might be responsible for GDPR compliance without being a DPO, and provided the organization doesn’t have to designate a DPO, that’s perfectly fine. The Data Protection Officer, however, is appointed through a procedure outlined in the GDPR, which involves distinct responsibilities such as monitoring adherence to the regulation, providing advice on data protection impact assessments, and overseeing their execution.

So in order to determine if your organization needs to appoint a DPO, or if it would be beneficial, let’s look at the cases where a DPO is mandatory.

2026 Update — Recent Developments

The DPO vs Compliance Officer debate has clarified in 2024-2026: DPOs focus on GDPR-specific obligations (Articles 37-39), while Compliance Officers cover broader regulatory landscapes (DORA, NIS2, anti-bribery, ESG). The two roles are complementary, not interchangeable.

Recent companion resources:

Is a GDPR DPO Mandatory?

Organizations are required to ensure compliance with the GDPR, and for sure, this necessitates having at least one person responsible for this task (a “lead” or “mission officer” for the GDPR).

Yet, the appointment of a GDPR DPO is mandatory only in three scenarios (Art. 37 GDPR), as detailed in our article on GDPR DPO designation:

  • If the organization is a public authority or body, except courts acting in their judicial capacity (see the role of the supervisory authority);
  • If its core activities require regular and systematic monitoring of individuals on a large scale;
  • If the organization’s core activities involve large-scale processing of sensitive GDPR data (Art. 9 and 10), such as health data — see our guide on what is personal data.

Union or Member State law can impose additional designation requirements under Article 37(4), so check the applicable national rules before concluding that appointment is optional.

Is It Advisable to Appoint a DPO?

It is absolutely essential to have someone within the organization who is trained, and whose mission is to ensures the obligations imposed by the GDPR are being met.

The DPO can partially play this role, or it can also be a person who has undergone GDPR training to ensure that the organization complies with data protection regulations.

In cases where the desgination of a DPO is mandatory the situation is simple : the organization will have to appoint a DPO. However do not expect the DPO to handle the GDPR compliance of the organization, that’s not his role at all! Yes, this adds to the confusion of the reality of the role of the DPO, but there’s a fundamental segmentation of responsibilities : the DPO is not the controller, and he is independant from him. Therefore it’s not his role to ensure the compliance of the organization, that’s the controller role! Do not confuse that. Article 38(3) provides the relevant independence safeguard:

Art. 38.3 The controller and processor shall ensure that the data protection officer does not receive any instructions regarding the exercise of those tasks. He or she shall not be dismissed or penalized by the controller or the processor for performing his tasks.

The role of the controller is defined in article 4 :

‘controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data

Therefore, the controller has to handle its own GDPR compliance, independently from the DPO, as he will be the one liable for it.

The DPO may be an employee or an external provider, but is not an employee or agent of the supervisory authority. The organisation must provide resources, access and independence. The DPO can coordinate work while maintaining the distinction between advice and management decisions on purposes and means.

Beyond the 3 cases where the organization has to appoint a DPO, it’s designation through the procedure outlined in the GDPR is to the choice of the controller. Can it be beneficial ? Sure. In particular in very large organizations (fortune 500, CAC40…) where a legal team is in charge of compliance, and the DPO will offer indenpendant assessement of the work and quality control. Additional compliance responsibilities require a conflict-of-interest assessment. Do not assume that another regulation creates a universal role called an AI compliance officer or that combining titles resolves the allocation of decisions.

Two important requirements for the DPO

If the organization decides to appoint a DPO, two important requirements will need to be met (Art. 37.5), specifically:

  • Knowledge of data protection law and practices
  • Ability to fulfill their responsibilities

How is the GDPR DPO Appointed?

If an organization wishes to appoint a DPO in accordance with GDPR requirements, it must publish the DPO’s contact details and communicate them to the supervisory authority under Article 37(7) - in France, for example, the CNIL, who has an online procedure.

Alternatively, if an organization simply wants someone to handle these matters without formal DPO designation, no procedure is required beyond ensuring that their responsibilities are included in the job description of the employee or in the service contract with the chosen provider.

Can the DPO be an External Party, or Must They Be Internal?

The DPO can be either an internal employee or an external service provider. Article 37.6 of the GDPR specifically allows for this:

  1. The data protection officer may be a staff member of the data controller or processor, or fulfill their tasks on the basis of a service contract.

FAQ

What is the difference between a DPO and a Compliance Officer?

A DPO (GDPR Articles 37-39) has a specific legal status: independent, cannot be dismissed for DPO tasks, and reports to senior management. A Compliance Officer is a general business role with no statutory definition or protections under GDPR.

Can the same person be both DPO and Compliance Officer?

Yes, if there is no conflict of interest. A Compliance Officer who also sets compliance policy should not be DPO if that policy includes data protection decisions — this would conflict with the DPO’s independence requirement under Article 38(6).

Is a DPO mandatory for all companies in the EU?

No. Article 37(1) mandates a DPO only for public authorities, organisations doing large-scale systematic monitoring, and those processing large-scale special category data. All other organisations may appoint one voluntarily and are encouraged to.

Can a DPO be shared between multiple organisations?

Yes. Article 37(2) allows a group of undertakings to designate a single DPO. Public authorities may also share a DPO. The DPO must be accessible to all entities and to supervisory authorities and data subjects at all times.

Document the role boundary before combining appointments

Create a short decision record showing which designation triggers were examined, who approved the conclusion and when the assessment should be revisited. For a combined DPO and compliance role, list the actual decisions the person makes. A title is less useful than knowing whether they choose monitoring tools, determine retention purposes or approve how employee data is used.

In a hypothetical organisation, the compliance manager selects a new employee monitoring system and decides what the employer will measure. Giving that same person the DPO title without changing those responsibilities creates an independence problem to examine. A workable arrangement might allocate the operational decision to management and obtain independent DPO advice before approval. The analysis should cover the real authority exercised, not only the organisation chart.

Keep the DPO’s recommendation, management’s decision and the implementation owner as separate entries. If management departs from the advice, record its reasons and the measures taken. Give the DPO a route to the highest management level and a way to obtain information without seeking permission from the team being reviewed. Revisit the arrangement after a promotion, acquisition or new service changes the person’s responsibilities.

The governing requirements are in GDPR Articles 37–39. This role record supports the assessment; it does not transfer the controller’s obligations to the DPO.

L
Written by
Legiscope
Legiscope

Put this guidance into operation

See how Legiscope connects privacy records, source material and review-controlled work.

Book a tailored demo
Continue reading

Related articles

01Personal Data

Article 28 of the GDPR: Obligations Imposed on Processors

Article 28 of the GDPR is arguably one of the most important provisions in practical terms, as it imposes a series of practical obligations on data controllers (DC) in managing the processors (PR)…

02Personal Data

EU Representative GDPR Compliance Guide 2024

Navigating the complexities of the European Union's General Data Protection Regulation (GDPR) is essential for businesses operating within or targeting the EU market. GDPR, which came into effect on…

03Personal Data

GDPR and AML: 5 Compliance Conflicts + Resolution Guide 2026

In one sentence. GDPR and AML (Anti-Money Laundering) regulations pull in opposite directions: AML mandates 5-10 year retention of identity and transaction data, sanctions screening of every…

November 29, 2022
04Personal Data

GDPR and Outbound sales : €500,000 fines for non-compliance

Commercial prospecting is undoubtedly one of the risk areas of the GDPR, where it is important to be rigorous to ensure compliance with the law. Enforcement in this area continues to intensify: by Q1…

05Personal Data

GDPR Audit Guide: Step-by-Step Compliance Checklist

- A GDPR audit is essential for identifying compliance gaps and mitigating data protection risks. - Comprehensive data mapping and inventory are foundational steps in the GDPR audit process. -…

06Personal Data

GDPR Data Storage Requirements: Retention, Security and Hosting

GDPR data storage requirements cover lawful purpose, limited retention, appropriate security and accountability. The Regulation does not prescribe one retention period, one encryption algorithm or a…

07Personal Data

GDPR DPO Designation: Article 37 Requirements Explained

Under GDPR Article 37, a DPO is mandatory for public authorities or bodies other than courts acting judicially; for core activities requiring regular and systematic monitoring on a large scale; and…

February 19, 2024
08Personal Data

GDPR Information notices, a few things you need to know

GDPR information notices are among the mandatory mentions that are important to comply with. Indeed, they will demonstrate whether an organization is in compliance or not with the European…