DAT-018 Data Protection Officer
Description
A recorded assessment states whether the organisation's processing triggers a statutory duty to designate a data protection officer, naming the criteria tested, the conclusion, the date and the author. The assessment is repeated when the processing changes materially. Where it concludes the duty applies, a written appointment record names the officer and states the tasks the officer performs, which cover advice on obligations, monitoring of compliance, advice on impact assessments and acting as the contact point for data subjects and the supervisory authority. The record shows that the officer reports to the highest management level and takes no instruction on the exercise of those tasks. The officer's contact details are published and notified to the supervisory authority. A conflict of interest check against the officer's other duties is recorded.
Rationale
The old wording applied "where required", so an organisation that had never asked the question answered it the same way as one that had asked and concluded no. The assessment is the first observable and it is what a supervisory authority asks for first. Under GDPR the criteria are Article 37(1), the position and independence requirements are Article 38 and the tasks are Article 39; the publication and notification duty is Article 37(7). The conflict check is missed most often: the officer cannot also decide the purposes and means of the processing they oversee, which rules out several plausible internal candidates. DAT-006 holds the record of processing activities the officer monitors and DAT-013 the impact assessments they advise on.
Applicability (9 profiles)
Framework Mappings (5)
| GDPR-Art.37 | Designation of Data Protection Officer | partial |
| GDPR-Art.38 | Data Protection Officer — Position and Independence | full |
| GDPR-Art.39 | Data Protection Officer — Tasks | full |
| PM-19 | Privacy Program Leadership Role | partial |
| P8.1 | Privacy Compliance | informative |
Evidence (2)
Applicability assessment recording whether a data protection officer must be designated, with the appointment record and supervisory authority notification where the assessment concludes the duty applies.
Example: DPO appointment letter (signed by CEO or board), DPO contact details published on the company website privacy page, and DPO registration confirmation from the relevant supervisory authority (e.g. ICO registration certificate or DPA notification acknowledgement)
Test: Request the applicability assessment and, where it concludes the duty applies, the appointment record. Verify: (1) the assessment names the criteria tested, the conclusion, the date and the author, (2) it has been repeated since the most recent material change to the processing, (3) where the duty applies, a named officer is appointed in writing, (4) the officer's contact details are published and the notification to the supervisory authority is evidenced, (5) a conflict of interest check against the officer's other duties is recorded.
DPO role description and independence charter confirming the DPO's mandate, access to senior management, and freedom from instruction.
Example: DPO Job Description or DPO Charter (HR system / Confluence), confirming: reporting line to board level, prohibition on instructions regarding tasks, defined resource allocation, and DPO access to all processing-related information
Test: Request the role description or charter for the data protection officer. Verify: (1) the reporting line is to the highest management level, (2) the document states that the officer takes no instruction on the exercise of their tasks, (3) the tasks are stated and cover advice on obligations, monitoring of compliance, advice on impact assessments and acting as the contact point for data subjects and the supervisory authority, (4) documented access to all processing activities is granted, (5) time, budget and tooling are allocated.
Questions (2)
Has your organisation recorded an assessment of whether it is required to designate a data protection officer?
The assessment is the artefact, whatever it concludes. An organisation that has concluded no duty applies meets this question if the conclusion, the criteria tested and the date are written down. Q2 covers the appointment where the duty does apply.
How is the DPO role structured within your organisation?
The DPO must not hold a role that creates a conflict of interest (e.g. CISO, legal counsel for processing decisions, or head of marketing). An external DPO is permitted under GDPR provided independence and access requirements are met.