The data protection officer should review – not own all of the GDPR work

The data protection officer should review – not own all of the GDPR work

When the DPO becomes the entire GDPR function, both independence and business accountability disappear. How to separate the DPO, the operational data protection function and business ownership.

Summary: The data protection officer (DPO) should monitor, review and advise – not own all of the GDPR work. When the DPO becomes the organisation’s GDPR function, both independence and the business’s own accountability are eroded. The solution is a clear division of responsibilities: the business owns the processing, an operational data protection function drives the work, and the DPO reviews and reports to management.

Many organisations appoint a data protection officer and breathe a sigh of relief. Someone gets the role, often alongside their regular job. Then the questions start: Can you write our record of processing activities? Can you approve this supplier? Can you do the DPIA? Can you handle the incident?

Suddenly the DPO has become the GDPR function. That is a problem – both legally and in practice.

The difference between owning and monitoring

Under the GDPR, the DPO’s role is to inform, advise, monitor compliance and act as the point of contact for the supervisory authority and for data subjects. The DPO should not make the decisions about how personal data is processed. That responsibility rests with the controller – in other words, the organisation and its business operations.

  • The business owns the processing.
  • The organisation is accountable for compliance.
  • The DPO reviews, challenges and advises.

It is the business that should be able to answer:

  • Why do we process this data?
  • What is our legal basis?
  • How long do we keep it?
  • Who has access?
  • Which suppliers are involved?
  • What are the risks to the data subjects?

The DPO, in turn, should be able to ask: Is this necessary? Is it proportionate? Have you assessed the risks? Is this documented? How do you know it works?

If the same person both builds the solution and then reviews it, you have lost the independence. The DPO is then reviewing their own work.

This is where an operational data protection function is often needed

This is the step many organisations miss. GDPR work often needs two roles – not one: an operational function that drives the work and a DPO who monitors it. The operational function can be:

  • a GDPR or privacy manager
  • a data protection coordinator
  • the legal function with data protection responsibility
  • information security with clearly defined data protection tasks
  • designated privacy coordinators within the business
  • external operational support

The operational function maintains the record of processing activities, coordinates data protection impact assessments (DPIAs), runs supplier reviews, coordinates personal data breaches, trains staff and follows up. The DPO checks that this is done, advises and reports to top management.

In a smaller organisation the boundaries may need to be pragmatic. But the principle should be clear: the person who monitors should not also be the person who owns the decisions.

DPO support can also be external

It is entirely possible to have an external DPO, or external support for an internal DPO. The advantages are often specialist expertise, independence, experience from several organisations and a lower risk of conflicts of interest.

But even external DPO support needs a clear counterpart inside the organisation. Someone has to own the work internally. Otherwise the external DPO becomes a mailbox for questions that nobody on the inside takes responsibility for.

A practical division of responsibilities

  • Management – decides on priorities, resources and risk tolerance. Accountable for ensuring that data protection work exists and works.
  • Business and process owners – own the processing activities, purposes, legal basis, retention and access within their processes.
  • Operational data protection function – coordinates, documents, supports, trains and follows up.
  • Information security and IT – responsible for technical and organisational security measures.
  • Data protection officer – monitors, advises, reviews and reports independently to management.

When this division is clear, the DPO becomes a strength. When it is missing, the DPO becomes a bottleneck.

How Kristensson i Skåne works

We support organisations both with operational GDPR coordination and with DPO support – but we are clear that the roles should not be mixed. Depending on your needs, we can contribute with:

  • operational GDPR coordination
  • DPO support for an internal data protection officer
  • external specialist expertise in data protection
  • data protection impact assessments (DPIAs)
  • records of processing activities
  • risk assessments
  • personal data breach handling
  • supplier reviews
  • privacy governance and division of responsibilities
  • training
  • ongoing follow-up

What matters is not the title. What matters is that someone owns the work, that someone reviews it, and that management sees the difference.

A DPO who does everything alone has not solved the GDPR question. They have only moved the problem.

Want to review how data protection responsibilities are divided in your organisation? Read more about our data protection and privacy services or contact us for an informal conversation.

Sources: General Data Protection Regulation (GDPR), Articles 37–39 on the designation, position and tasks of the data protection officer; the Swedish Authority for Privacy Protection (IMY), guidance on data protection officers.

This text is general information and does not constitute legal advice in an individual matter.