Data protection officers · the role

What does a data protection officer do?

The short answer · updated

A data protection officer (DPO) is the person an organisation appoints under the UK GDPR to inform and advise it on data protection law, monitor its compliance, advise on data protection impact assessments, and act as the contact point for the ICO and for people whose data it holds. The DPO reports to the highest management level and works independently.

What is a data protection officer?

A data protection officer is a role defined in law, not just a job title. Articles 37 to 39 of the UK GDPR say when a controller or processor must designate one, what position the DPO holds and what the DPO does. The ICO’s guidance on data protection officers sums it up: the DPO must be independent, an expert in data protection, adequately resourced, and report to the highest management level.

The DPO is an adviser and a monitor. The organisation, as controller or processor, stays responsible for complying with the law; the ICO is clear that the DPO is not personally liable for data protection compliance. A good DPO makes it easier for the board to show that it has done what the law asks.

The title is protected in practice. An organisation designates one individual as its DPO, who may lead a team of data protection specialists. The ICO advises that other specialists should not be called the DPO, because the DPO is a specific role with particular requirements.

When the law requires a DPO

Under Article 37 of the UK GDPR, you must designate a DPO if you are a public authority or body, or if your core activities consist of large-scale, regular and systematic monitoring of individuals, or large-scale processing of special category data or criminal offence data. The duty applies to controllers and processors alike. Courts acting in their judicial capacity are exempt; since 20 August 2025 the Data (Use and Access) Act 2025 has extended that exception to tribunals.

Core activities are the processing you need to achieve your main purpose, not routine back-office processing such as payroll. The ICO gives the example of an HR service provider: processing personal data is core to its service for clients, but its own staff records are ancillary. To judge “large scale”, the ICO lists the number of people concerned, the volume and range of data, the geographical extent and how long the processing runs.

You may appoint a DPO voluntarily. If you do, the same rules on position and tasks apply as if the appointment were mandatory. If you decide you do not need one, the ICO suggests recording that decision and your reasons, to help show accountability.

What a DPO does: the Article 39 tasks

Article 39 sets the minimum. The ICO’s guidance lists the tasks as:

  • Inform and advise the organisation and its staff about their obligations under the UK GDPR and other data protection law.
  • Monitor compliance with that law and with the organisation’s own data protection policies, including assigning responsibilities, raising awareness, training staff and running internal audits.
  • Advise on data protection impact assessments (DPIAs) and monitor how they are carried out.
  • Cooperate with the ICO and act as its first point of contact, including on prior consultation about high-risk processing.
  • Be a contact point for individuals whose data is processed, such as employees and customers.

What the work looks like week to week

Most of the work is advice at the point of decision. The ICO’s DPIA guidance says that if you have a DPO you must seek their advice on a DPIA (whether one is needed, how to do it, what measures reduce the risk, and whether the processing can go ahead) and record it; if you do not follow that advice, record why. New systems, suppliers, marketing campaigns and uses of AI all pass across the DPO’s desk for that reason.

The rest is the compliance cycle: keeping the records of processing up to date, reviewing privacy notices and contracts with processors, training staff, auditing, and handling rights requests and complaints. When a personal data breach happens, the DPO usually leads the assessment; where a risk to people is likely, the ICO expects a report as soon as possible and, where feasible, within 72 hours.

The ICO’s guidance does not set fixed credentials, but Article 37 requires expert knowledge of data protection law and practice, in proportion to the processing. Common qualifications include the BCS Practitioner Certificate in Data Protection, which covers the UK GDPR, the Data Protection Act 2018 and the designation, position and tasks of a DPO, and the IAPP’s CIPP/E. Knowledge of your sector matters as much as the certificate.

Independence and conflicts of interest

Article 38 sets the DPO’s position. The organisation must involve the DPO properly and in good time in every issue relating to personal data, give them the resources and access they need, and must not instruct them on how to carry out their tasks. The DPO cannot be dismissed or penalised for doing the job, and reports directly to the highest management level. The ICO adds that this does not mean the board must line-manage the DPO, only that the DPO has direct access to the senior people making decisions about personal data.

A DPO may hold other duties, but not ones that create a conflict of interests. In practice that rules out anyone who decides why and how personal data is processed. The ICO’s example: a head of marketing who plans which customers to target and with what data cannot also be the DPO. By contrast, a public authority could appoint its freedom of information officer or records manager, because those roles are about information rights compliance rather than deciding on processing.

That is why heads of IT, HR directors and data strategy leads are usually poor choices for the seat, however much they know about the data.

What the Data (Use and Access) Act 2025 changed

The Data (Use and Access) Act 2025 amends the UK GDPR, the Data Protection Act 2018 and the electronic communications rules; it does not replace them. The ICO’s summary for organisations, updated on 19 June 2026, says all its data protection provisions are now in force. Articles 37 to 39 still stand, so the rules on when to appoint a DPO and what the DPO does are unchanged apart from the tribunal exception above.

The DPO’s workload has changed. Organisations must now help people make data protection complaints, acknowledge a complaint within 30 days and respond without undue delay; there are new rules on recognised legitimate interests, automated decision-making, research and some cookies; and the ICO has new investigation powers. Each of those lands with the DPO as advice, a policy change or a process to run. The ICO notes that its DPO guidance is itself under review because of the Act.

DPO vs general counsel, CISO, CDO and compliance officer

A general counsel owns the organisation’s legal risk across contracts, disputes and employment, and gives the business legal advice. A DPO may be a lawyer, but the DPO’s remit is data protection and the role carries statutory independence. See what a general counsel does.

A CISO runs information security: the controls, the security team and the incident response. Security is one part of data protection; the DPO advises on whether the processing is lawful, fair and proportionate as well as secure. See what a CISO does.

A chief data officer decides how the organisation uses its data. That is the kind of decision-making that conflicts with the DPO seat, so the two should be different people. See what a chief data officer does.

A compliance officer covers wider regulatory rules, often under a sector regulator. In smaller firms one person may hold both seats if there is no conflict; see part-time compliance officer roles.

Employed, outsourced or fractional DPO

Article 37 allows the DPO to be a member of staff or to work under a service contract, and the ICO confirms that an externally appointed DPO has the same position, tasks and duties as an internal one. A group of companies can share one DPO if the DPO is easily accessible from each establishment. That leaves three common routes: an employed DPO; an outsourced DPO service; or a fractional DPO, a named senior individual for an agreed number of days.

Where an outsourced or fractional DPO works through their own limited company, the off-payroll working rules (IR35) may apply. Status depends on how the engagement runs in practice, and a medium or large client makes the determination. Our IR35 guide sets out the tests.

We recruit permanent, interim, fractional, part-time and temporary executives, and non-executive directors. To hire a data protection officer, see data protection officer recruitment; to hire a fractional DPO, see the fractional page. Every brief gets a shortlist of 3–5, each with pay or day rate, availability and IR35 position set out, after our five-stage vetting. Open roles are on the data protection officer jobs page.

Questions people ask

Does every organisation need a data protection officer?

No. Under Article 37 you must appoint one if you are a public authority or body, or if your core activities involve large-scale regular and systematic monitoring of people, or large-scale processing of special category or criminal offence data. Others may appoint one voluntarily, on the same terms.

Who should the DPO report to?

Directly to the highest management level, usually the board. The ICO says the DPO need not be line-managed at that level, but must have direct access to the senior people who make decisions about personal data.

Can the DPO be an existing employee?

Yes, if their other duties do not create a conflict of interests. Someone who decides why and how personal data is processed, such as a head of marketing or of IT, is usually unsuitable. The ICO’s guidance gives examples.

Can a data protection officer be outsourced?

Yes. Article 37 allows the DPO to work under a service contract with an individual or an organisation, and the external DPO has the same position, tasks and duties as an internal one. A fractional DPO is one form of this.

Is the DPO personally liable if the organisation breaks data protection law?

No. The ICO says the DPO is not personally liable for compliance; the organisation, as controller or processor, remains responsible. The DPO must not be dismissed or penalised for performing their tasks.

What qualifications does a data protection officer need?

The law asks for expert knowledge of data protection law and practice, in proportion to the processing, rather than a named qualification. Common choices are the BCS Practitioner Certificate in Data Protection and the IAPP’s CIPP/E.

How much does a data protection officer earn?

It depends on the sector, the size and risk of the processing, whether the role leads a team, and the location. We do not quote a figure we cannot verify; on every shortlist we set out each candidate’s pay or day rate.

How do I hire a data protection officer?

Decide first whether the law requires one, then whether the seat should be employed, outsourced or fractional, and test candidates on a real DPIA or breach scenario. See data protection officer recruitment; we send a shortlist of 3–5, each with pay or day rate, availability and IR35 position set out.

For hiring managers

Bring the brief. We bring the shortlist.

Sign up now →Book a call

  1. A shortlist of 3–5, each with day rate, availability and IR35 position
  2. Fractional, interim, part-time, temporary or permanent — and non-executive directors
  3. Every candidate through our five-stage vetting
  4. Your briefs and their candidates, in one room
Fractional Quest logo — how to hire a data protection officer, what is a data protection officer