Skip to content
compliancebase

Data protection officer (DPO)

An independent GDPR role required in specified circumstances to advise, monitor compliance, and serve as a contact point.

In practice

Assess whether appointment is mandatory, document the decision, publish contact details, and avoid conflicts of interest.

Common confusion

A DPO is not simply the executive accountable for deciding processing purposes.

Related controls

Framework versions referenced in this page:

Last verified: August 2026 · Primary sources linked above