Skip to content
Legiscope
Menu
Personal Data

DPO or compliance officer ?

Only the DPO is regulated by the GDPR. See how the Data Protection Officer differs from a compliance officer, when it is mandatory, and who appoints one.

Also available in:Français

It’s very important to understand the difference between a Data Protection Officer and all other titles such as Data Privacy Officer, compliance officer, GDPR compliance officer, and for one reason : only the Data Protection Officer (DPO) is regulated by the GDPR. In practical terms this means, the DPO has specific tasks he needs to conduct, specific position and specific protection in regard to his liability.

And that’s not the case with all the other titles.

In an organization, someone might be responsible for GDPR compliance without being a DPO, and provided the organization doesn’t have to designate a DPO, that’s perfectly fine. The Data Protection Officer, however, is appointed through a procedure outlined in the GDPR, which involves distinct responsibilities such as monitoring adherence to the regulation, providing advice on data protection impact assessments, and overseeing their execution.

So in order to determine if your organization needs to appoint a DPO, or if it would be beneficial, let’s look at the cases where a DPO is mandatory.

2026 Update — Recent Developments

The DPO vs Compliance Officer debate has clarified in 2024-2026: DPOs focus on GDPR-specific obligations (Articles 37-39), while Compliance Officers cover broader regulatory landscapes (DORA, NIS2, anti-bribery, ESG). The two roles are complementary, not interchangeable.

Recent companion resources:

Is a GDPR DPO Mandatory?

Organizations are required to ensure compliance with the GDPR, and for sure, this necessitates having at least one person responsible for this task (a “lead” or “mission officer” for the GDPR).

Yet, the appointment of a GDPR DPO is mandatory only in three scenarios (Art. 37 GDPR), as detailed in our article on GDPR DPO designation:

  • If the organization is a public authority or body (see the role of the supervisory authority);
  • If the organization conducts large-scale, systematic monitoring of individuals;
  • If the organization’s core activities involve large-scale processing of sensitive GDPR data (Art. 9 and 10), such as health data — see our guide on what is personal data.

Outside of these cases, appointing a DPO remains optional.

Is It Advisable to Appoint a DPO?

It is absolutely essential to have someone within the organization who is trained, and whose mission is to ensures the obligations imposed by the GDPR are being met.

The DPO can partially play this role, or it can also be a person who has undergone GDPR training to ensure that the organization complies with data protection regulations.

In cases where the desgination of a DPO is mandatory the situation is simple : the organization will have to appoint a DPO. However do not expect the DPO to handle the GDPR compliance of the organization, that’s not his role at all! Yes, this adds to the confusion of the reality of the role of the DPO, but there’s a fundamental segmentation of responsibilities : the DPO is not the controller, and he is independant from him. Therefore it’s not his role to ensure the compliance of the organization, that’s the controller role! Do not confuse that. Let’s look at article 38.7:

Art. 38.3 The controller and processor shall ensure that the data protection officer does not receive any instructions regarding the exercise of those tasks. He or she shall not be dismissed or penalized by the controller or the processor for performing his tasks.

The role of the controller is defined in article 4 :

‘controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data

Therefore, the controller has to handle its own GDPR compliance, independently from the DPO, as he will be the one liable for it.

An easy way to understand the position of the DPO is to see him as an employee of the national control authority, but paid by the controller. The DPO is independent from the controller, gives feedback about the level of compliance, does not organizes the overall GDPR compliance of the organization, but helps reviewing the work and provides independant opinion in that regard.

Beyond the 3 cases where the organization has to appoint a DPO, it’s designation through the procedure outlined in the GDPR is to the choice of the controller. Can it be beneficial ? Sure. In particular in very large organizations (fortune 500, CAC40…) where a legal team is in charge of compliance, and the DPO will offer indenpendant assessement of the work and quality control. The distinction between DPO and compliance officer is becoming even more relevant with the EU AI Act, whose high-risk obligations apply from August 2, 2026: organizations deploying high-risk AI systems will need to appoint AI compliance officers under Article 26, creating potential overlap with the DPO role that must be carefully managed to avoid conflicts of interest.

Two important requirements for the DPO

If the organization decides to appoint a DPO, two important requirements will need to be met (Art. 37.5), specifically:

  • Knowledge of data protection law and practices
  • Ability to fulfill their responsibilities

How is the GDPR DPO Appointed?

If an organization wishes to appoint a DPO in accordance with GDPR requirements, it must designate this individual directly to the national supervisory authority - in France, for example, the CNIL, who has an online procedure.

Alternatively, if an organization simply wants someone to handle these matters without formal DPO designation, no procedure is required beyond ensuring that their responsibilities are included in the job description of the employee or in the service contract with the chosen provider.

Can the DPO be an External Party, or Must They Be Internal?

The DPO can be either an internal employee or an external service provider. Article 37.6 of the GDPR specifically allows for this:

  1. The data protection officer may be a staff member of the data controller or processor, or fulfill their tasks on the basis of a service contract.

FAQ

What is the difference between a DPO and a Compliance Officer?

A DPO (GDPR Articles 37-39) has a specific legal status: independent, cannot be dismissed for DPO tasks, and reports to senior management. A Compliance Officer is a general business role with no statutory definition or protections under GDPR.

Can the same person be both DPO and Compliance Officer?

Yes, if there is no conflict of interest. A Compliance Officer who also sets compliance policy should not be DPO if that policy includes data protection decisions — this would conflict with the DPO’s independence requirement under Article 38(6).

Is a DPO mandatory for all companies in the EU?

No. Article 37(1) mandates a DPO only for public authorities, organisations doing large-scale systematic monitoring, and those processing large-scale special category data. All other organisations may appoint one voluntarily and are encouraged to.

Can a DPO be shared between multiple organisations?

Yes. Article 37(2) allows a group of undertakings to designate a single DPO. Public authorities may also share a DPO. The DPO must be accessible to all entities and to supervisory authorities and data subjects at all times.

L
Written by
Legiscope
Legiscope

Put this guidance into operation

See how Legiscope connects privacy records, source material and review-controlled work.

Book a tailored demo
Continue reading

Related articles

01Personal Data

Article 28 of the GDPR: Obligations Imposed on Processors

Article 28 of the GDPR is arguably one of the most important provisions in practical terms, as it imposes a series of practical obligations on data controllers (DC) in managing the processors (PR)…

02Personal Data

EU Representative GDPR Compliance Guide 2024

Navigating the complexities of the European Union's General Data Protection Regulation (GDPR) is essential for businesses operating within or targeting the EU market. GDPR, which came into effect on…

03Personal Data

GDPR and AML: 5 Compliance Conflicts + Resolution Guide 2026

In one sentence. GDPR and AML (Anti-Money Laundering) regulations pull in opposite directions: AML mandates 5-10 year retention of identity and transaction data, sanctions screening of every…

November 29, 2022
04Personal Data

GDPR and Outbound sales : €500,000 fines for non-compliance

Commercial prospecting is undoubtedly one of the risk areas of the GDPR, where it is important to be rigorous to ensure compliance with the law. Enforcement in this area continues to intensify: by Q1…

05Personal Data

GDPR Audit Guide: Step-by-Step Compliance Checklist

- A GDPR audit is essential for identifying compliance gaps and mitigating data protection risks. - Comprehensive data mapping and inventory are foundational steps in the GDPR audit process. -…

06Personal Data

GDPR Compliance Guide 2026: 10 Obligations, Step by Step

GDPR compliance rests on 10 obligations, in this order: (1) establish a lawful basis for every processing activity (Art. 6), (2) record those activities in a ROPA (Art. 30), (3) tell people what you…

07Personal Data

GDPR DPO Designation: Article 37 Requirements Explained

Under GDPR Article 37, a Data Protection Officer must be designated whenever an organization is a public authority, carries out large-scale systematic monitoring, or processes sensitive data at…

February 19, 2024
08Personal Data

GDPR Information notices, a few things you need to know

GDPR information notices are among the mandatory mentions that are important to comply with. Indeed, they will demonstrate whether an organization is in compliance or not with the European…