Skip to content
Legiscope
Menu
Data Privacy

GDPR Article 39: DPO Tasks Explained (Full List)

GDPR Article 39 DPO tasks: 6 mandatory duties, EDPB WP243 guidance, independence rules, reporting line, sanctions, internal vs external DPO.

In one sentence. GDPR Article 39 lists the six mandatory tasks of the Data Protection Officer: (a) inform and advise on GDPR obligations, (b) monitor compliance and assign responsibilities, © advise on and monitor DPIAs, (d) cooperate with the supervisory authority, (e) act as contact point for the supervisory authority, (f) consult the supervisory authority on prior consultation matters. The DPO performs these tasks with due regard to risk associated with processing operations. Official text: EUR-Lex Regulation (EU) 2016/679, Article 39.

The DPO is not the controller — they advise. Article 38 protects DPO independence; Article 37 sets designation criteria; Article 39 defines what the DPO actually does. The EDPB DPO guidelines (WP243 rev.01) remain the authoritative interpretation, and the ICO’s data protection officer guidance gives the equivalent UK GDPR reading, which tracks Article 39 almost verbatim.

Key takeaways

  • 6 mandatory tasks under Article 39(1)(a)-(f).
  • DPO tasks performed with due regard to risk (Article 39(2)).
  • DPO is not personally liable for GDPR compliance — the controller is.
  • Independence and no-conflict-of-interest rules under Article 38.
  • DPO contact must be in privacy notice and ROPA (Articles 13, 14, 30).
  • Sanctions for failure to designate (Article 37) or interfere (Article 38): Article 83(4) — up to €10M / 2%.

1. Article 39 official text

Article 39 — Tasks of the data protection officer

  1. The data protection officer shall have at least the following tasks: (a) to inform and advise the controller or the processor and the employees who carry out processing of their obligations pursuant to this Regulation and to other Union or Member State data protection provisions; (b) to monitor compliance with this Regulation, with other Union or Member State data protection provisions and with the policies of the controller or processor in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits; © to provide advice where requested as regards the data protection impact assessment and monitor its performance pursuant to Article 35; (d) to cooperate with the supervisory authority; (e) to act as the contact point for the supervisory authority on issues relating to processing, including the prior consultation referred to in Article 36, and to consult, where appropriate, with regard to any other matter; (f) in performing his or her tasks, the data protection officer shall have due regard to the risk associated with processing operations, taking into account the nature, scope, context and purposes of processing.

2. Task (a) — Inform and advise

The DPO advises:

  • Senior management (board level — required by EDPB)
  • Operational teams handling personal data
  • IT, HR, marketing, sales — wherever processing occurs

Output: written advisory notes, training sessions, RFC reviews of new processing.

3. Task (b) — Monitor compliance

The DPO is the second line of defence — they monitor, they don’t operate.

4. Task © — Advise on and monitor DPIAs

5. Task (d) — Cooperate with the supervisory authority

Operational obligations:

  • Respond to DPA inquiries and information requests
  • Provide records (ROPA, DPIA, breach log) on request
  • Facilitate inspections
  • Collaborate on investigations following complaints

6. Task (e) — Contact point for the supervisory authority

Article 39(1)(e) makes the DPO the single point of contact for:

  • Prior consultation under Article 36
  • Routine queries
  • Inspection scheduling

DPO contact must be published in the privacy notice (Articles 13/14) and communicated to the DPA (Article 37(7)).

7. Task (f) implicit — Data subject contact point

8. Independence and protection (Article 38)

  • No instructions on how to perform tasks (Article 38(3))
  • Cannot be dismissed or penalised for performing tasks
  • Reports directly to highest management
  • No conflict of interest with other functions
  • Resources and access provided (Article 38(2))

Forbidden combinations: DPO + CISO, DPO + IT director, DPO + HR director, DPO + CEO (per EDPB WP243rev.01 and DPA decisions).

9. Internal vs external DPO

Aspect Internal External
Cost €60-€120k/year salary €1,500-€8,000/month retainer
Knowledge Deep org context Cross-sector benchmarks
Independence Risk of conflict Naturally independent
Availability Full-time Shared time
Compliance Same Article 39 obligations Same Article 39 obligations

For SMEs, external DPO is typical. For large groups, internal DPO with team.

10. Sanctions and enforcement

Article 83(4)(a) — up to €10M or 2% of global turnover — covers Article 37 (designation), 38 (position) and 39 (tasks) violations.

Notable cases:

  • DLT Centrum Wschód (Polish UODO 2020): conflict of interest sanctioned
  • Multiple French cases: failure to designate
  • Italian construction firm (Garante 2021): DPO contact not published

10a. What “due regard to risk” changes in practice

Article 39(2) is not decorative. It tells the DPO to allocate scrutiny where the processing risk is highest — a risk-based work plan, not a uniform sweep. A DPO overseeing a hospital devotes most of the monitoring budget to special-category health data and access-control audits; a DPO in a SaaS firm prioritises the ROPA of tracking and profiling activities and the Article 28 chain of sub-processors. The practical test a supervisory authority applies during an inspection is simple: can the DPO show that the riskiest processing received the most attention, with dated evidence — audit reports, advisory notes, DPIA reviews — rather than a generic annual checklist? Document the risk ranking that drives the plan; it is the DPO’s own accountability record under Article 5(2).

11. Implementation checklist

  1. Confirm whether DPO is mandatory (Article 37(1))
  2. Designate DPO and notify DPA (within 30 days of appointment)
  3. Publish DPO contact in privacy notice (Articles 13/14)
  4. Resource the DPO: time, budget, access
  5. Reporting line to top management documented
  6. Tasks (a)-(f) operationalised with workflows
  7. Annual DPO activity report to board

12. Tooling

FAQ

What are the 6 tasks of a DPO under GDPR Article 39?

(a) Inform and advise on GDPR obligations, (b) Monitor compliance, © Advise on and monitor DPIAs, (d) Cooperate with the supervisory authority, (e) Act as contact point for the supervisory authority, (f) Perform tasks with due regard to risk.

Is the DPO personally liable for GDPR compliance?

No. The controller is accountable (Article 24). The DPO advises and monitors; they are not personally liable for the controller’s breaches. They can however be held accountable for breach of their own employment or contractual duties.

Can the CISO be the DPO?

EDPB WP243rev.01 and several DPA decisions consider CISO/IT director/HR director combinations as conflicts of interest — those functions decide how processing occurs, and the DPO must independently monitor those decisions.

Does the DPO handle DSARs?

Article 38(4) makes the DPO the contact point for data subjects on all processing issues. In practice the DPO oversees or operates the DSAR process per Articles 15-22.

What’s the sanction for failing to appoint a DPO?

Up to €10M or 2% of global turnover (Article 83(4)(a)). Multiple national cases have reached six-figure sanctions for missing or improperly positioned DPOs.

L
Written by
Legiscope
Legiscope

Put this guidance into operation

See how Legiscope connects privacy records, source material and review-controlled work.

Book a tailored demo
Continue reading

Related articles

01Data Privacy

DPO Position GDPR (Art. 38): Independence Rules + 2026 Cases

Art. 38 GDPR defines the position of the Data Protection Officer within an organisation. It is not about what a DPO does (that is Art. 39) or when a DPO must be designated (Art. 37). Art. 38 is about…

February 20, 2024
02GDPR Compliance

DPO Salary and Career Guide 2026

The Data Protection Officer role has gone from a niche legal function to one of the most in-demand compliance positions in Europe. Since GDPR made DPO designation mandatory for certain organisations…

April 12, 2026
03GDPR Compliance

GDPR DPO Job Description Template (2026 Edition)

Hiring a Data Protection Officer (DPO) is one of the most consequential compliance decisions a company makes. Get the role definition wrong — vague responsibilities, missing GDPR Article 39 tasks,…

April 30, 2026
04Data Privacy

Australia–EU Data Transfers: Adequacy Status and SCCs

Australia does not hold an EU adequacy decision. Verified against the European Commission's published list of adequacy decisions on 30 July 2026. Australia has never held one, is not the subject of…

July 30, 2026
05Data Privacy

BCR vs SCC vs DPF: Choosing the Right GDPR Transfer Mechanism

GDPR Article 46 lists multiple safeguards for international data transfers. Three dominate practice: Binding Corporate Rules (BCRs), Standard Contractual Clauses (SCCs), and the EU-U.S. Data Privacy…

April 30, 2026
06Data Privacy

Best DPO Software 2026: Internal & Outsourced DPOs

The DPO role is defined by Art. 37-39 GDPR, and the EDPB made it a 2023 coordinated-enforcement priority — so the software a DPO uses is now itself an accountability signal.

July 7, 2026
07Data Privacy

Best GDPR Compliance Software: 6 Tools Compared + Pricing 2026

Choosing the right GDPR compliance software is no longer optional for small and medium-sized enterprises operating in the EU. Data protection authorities across Europe have shifted enforcement focus…

March 28, 2026
08Data Privacy

Canada-EU Data Transfers: Adequacy Scope and SCCs

Canada is one of the few countries the European Commission has recognised as offering adequate protection, and it is the country where that recognition is most often over-read. The decision is…

July 30, 2026