Who cannot act as a data protection officer?

Michał Rutkowski • for boards and HR • published September 13, 2026 • 7 min read

Let’s talk

Wondering how this plays out in your organisation? Get in touch — I answer personally.

Short answer

The GDPR contains no list of positions excluded from the role of data protection officer. In my assessment the exclusion comes down to three separate provisions, and the most frequently disputed of them is the DPO conflict of interest under Article 38(6). What decides is not the job title but the scope of decisions about the purposes and means of processing. Establishing that circumstance falls to the controller or the processor, because it is they who are required to ensure that no such conflict arises.

Why this question arises at all

An organisation looks for a candidate inside its own structure and asks whom it may appoint. The answers circulating on the market take the form of a list of forbidden positions. No such list exists in the Regulation, and a list without a criterion leads to two opposite mistakes. The first is rejecting a person who determines neither the purposes nor the means of processing. The second is appointing a person outside the list who does in fact decide about those purposes.

The second source of confusion concerns the basis of this requirement. It is often attributed to the guidelines of the EU Article 29 Data Protection Working Party, known as WP 243. It is laid down in the Regulation itself, which is directly applicable. The guidelines add a criterion and examples of positions to it, not the norm.

The third source is practical. A DPO conflict of interest is sometimes treated as a feature of the candidate that it is enough to assess once, in an interview. The provision addresses that duty to the organisation. Article 24(1) GDPR additionally requires the controller to implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with the Regulation. A trace of the assessment should therefore remain in the documents.

The question of exclusion only makes sense once the obligation to designate has already been settled. The order of those decisions is described in How to determine if an organization must appoint a DPO?.

What has to be established before a decision

When a DPO conflict of interest arises

Article 38(6) GDPR permits the combining of functions. The data protection officer may fulfil other tasks and duties. The limit is set by the second sentence of that paragraph, which requires the controller or the processor to ensure that any such tasks and duties do not result in a conflict of interests.

The Regulation does not define the conflict itself. The criterion comes from the WP 243 guidelines. The DPO cannot hold a position within the organisation that leads him or her to determine the purposes and the means of the processing of personal data. As a rule of thumb, the guidelines say that conflicting positions may include senior management positions. They name chief executive, chief operating, chief financial and chief medical officer. They also name the head of the marketing department, the head of Human Resources and the head of IT departments.

The criterion is functional rather than nominal. The guidelines extend it to other roles lower down in the organisational structure if those roles lead to the determination of purposes and means of processing. They state that, due to the specific organisational structure in each organisation, this has to be considered case by case. In my assessment senior management positions therefore call for a documented justification, because the guidelines name them first among the conflicting ones.

The guidelines add a further example, a conflict arising on the service provider’s side. As an example they give an external DPO asked to represent the controller or processor before the Courts in cases involving data protection issues.

Who decides whether a DPO conflict of interest exists

The addressee of the norm is the controller or the processor. The provision imposes no obligation on the candidate and does not require any declaration from him or her. A DPO conflict of interest is therefore established by the organisation, and what is assessed are the tasks and duties of a specific person.

In practice this comes down to three steps. The organisation describes the scope of decisions attached to the candidate’s position. It sets that scope against the tasks of the officer under Article 39(1). It records the conclusion together with the reasoning.

Depending on the activities, size and structure of the organisation, the guidelines say it can be good practice for controllers or processors to do five things. To identify the positions which would be incompatible with the function of DPO. To draw up internal rules to that effect in order to avoid conflicts of interests. To include a more general explanation about conflicts of interests. To declare that their DPO has no conflict of interests with regard to his or her function as a DPO, as a way of raising awareness of this requirement. To include safeguards in the internal rules and to ensure that the vacancy notice for the position of DPO or the service contract is sufficiently precise and detailed, in order to avoid a conflict of interests. The declaration therefore does not replace the organisation’s assessment, it supplements it. I recommend recording negative decisions as well, because it is useful to be able to return to a rejected candidacy at the next change of structure.

What Article 37(5) requires, the second ground for exclusion

The officer is designated on the basis of professional qualities. The provision points in particular to expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39.

This is a positive condition, so it works differently from a prohibition. A person without such qualities is not excluded by name. What that person does not meet is the condition on the basis of which the designation happens at all.

The provisions indicate neither a required education, nor a certificate, nor a length of service. Recital 97 of the Regulation does indicate how to establish the necessary level of expert knowledge. It should be determined in particular according to the data processing operations carried out and the protection required for the personal data processed. The level of knowledge is therefore assessed against a specific organisation rather than against a general benchmark.

The third ground, the candidate’s place in the structure

Article 38(3) GDPR contains three separate norms. The controller and processor ensure that the officer does not receive any instructions regarding the exercise of those tasks. He or she is not dismissed or penalised by the controller or the processor for performing his tasks. The officer reports directly to the highest management level of the controller or the processor.

The last of those norms tends to be overlooked when selecting a candidate. The placement in the structure must allow direct reporting to the highest management level. A candidate for whom this cannot be ensured is out for that very reason. The WP 243 guidelines tie the place in the structure to the assessment of qualities as well, because they read the ability to fulfil the tasks incumbent on the DPO as referring both to personal qualities and knowledge and to the position within the organisation.

Can a company or a team act as the officer

Article 37(6) permits two forms. The officer may be a staff member or fulfil the tasks on the basis of a service contract. The WP 243 guidelines add that such a contract may be concluded with an individual or an organisation outside the controller’s or processor’s organisation.

Polish law lays down no such prohibition, but its notification procedure is not without significance. Article 10(1) of the Polish Act on Personal Data Protection requires the President of the Personal Data Protection Office (UODO) to be notified within 14 days of the designation. The notification states the officer’s first name, surname and e-mail address or telephone number. In my assessment the designated person is therefore a natural person, even where the contract was concluded with a company.

The WP 243 guidelines allow a team to work on the service provider’s side. They set the condition that each member of the organisation exercising the functions of a DPO fulfils all applicable requirements of Section 4 of the GDPR. As an example they give that no one has a conflict of interests. They treat it as equally important that each such member be protected by the provisions of the GDPR. They also recommend a clear allocation of tasks within the DPO team and assigning a single individual as a lead contact and person in charge for each client. They add that it would generally also be useful to specify these points in the service contract.

What is required of the deputy

Article 11a(1) of the Polish Act allows a person to be designated to stand in for the officer during his or her absence. The provision requires the criteria of Article 37(5) and (6) of the Regulation to be taken into account. Article 11a(2) further requires the provisions concerning the officer to be applied to the deputy accordingly. It does so, however, in connection with performing the officer’s duties during his or her absence.

The effect is practical. In my assessment the three grounds therefore cover the deputy as well, although the provision expressly refers only to Article 37(5) and (6). Article 11a(3) adds notification under Article 10 and the publication of data under Article 11.

What does not exclude a candidate

Three circumstances are sometimes treated as an obstacle, although the provisions do not make any of them one.

The first is one person serving several entities. Article 37(2) permits a single officer for a group of undertakings, provided that the officer is easily accessible from each establishment. Article 37(3) permits a single officer for several public authorities or bodies, taking account of their organisational structure and size. A third arrangement is described by the second sentence of Article 37(4), which permits the officer to act for associations and other bodies representing controllers or processors. Beyond those three arrangements, admissibility rests on Article 37(6) and on section 2.5 of the guidelines rather than on a separate provision.

The second is not being employed by the organisation. Article 37(6) permits both forms.

The third is performing other tasks. The first sentence of Article 38(6) permits them expressly. The limit is set by the DPO conflict of interest and, in my assessment, also by the requirements of Article 38(1) and (2).

Three grounds that decide most cases

The table orders the grounds which in my assessment decide most cases. It is not a statutory list.

GroundWhom it excludesExceptions and limitsApplicable from
Article 38(6) GDPRa person whose other tasks result in a conflict of interestsother tasks and duties are permitted; the limit is the conflict itself25 May 2018
Article 37(5) GDPRdoes not exclude by name — it sets a positive condition which a person without professional qualities does not meetexpert knowledge and the ability to fulfil the tasks of Article 39 are “in particular”, not the whole catalogue; the provision indicates no education, certificate or length of service25 May 2018
Article 38(3) GDPRa person whose placement rules out direct reportingthe norm concerns the place in the structure, not the content of other tasks25 May 2018

Common mistakes

  • Treating the list of positions as a closed catalogue. The guidelines extend the criterion to roles lower down in the organisational structure if those roles lead to the determination of purposes and means of processing.
  • Attributing the requirement to the guidelines. The duty to ensure the absence of a conflict stands in Article 38(6) of the Regulation and is directly applicable.
  • Expecting a declaration from the candidate instead of an assessment by the organisation. The provision addresses that duty to the controller or the processor. A declaration of no conflict is listed by the guidelines as good practice supplementing that assessment.
  • Rejecting people from outside the organisation. Article 37(6) permits both a staff member and a person acting on the basis of a service contract.
  • Overlooking the deputy. Article 11a(2) of the Polish Act requires the provisions concerning the officer to be applied to the deputy accordingly.
  • Overlooking the requirement of direct reporting. A candidate without a conflict is sometimes excluded because of the place in the structure alone.
  • Treating a company as the designated officer. In my assessment the notification under Article 10(1) of the Polish Act settles that a natural person is designated.

Conclusions and next steps

A DPO conflict of interest is in my assessment only one of three grounds that decide most cases. The other two grounds work independently of it, so a candidate without a conflict may still be unsuitable.

Remember

A list of positions shortens the way to the answer but does not replace it.

Four steps that put candidate selection in order.

  1. Describe the scope of decisions attached to the candidate’s position, indicating the purposes and means of processing he or she takes part in determining.
  2. Set that scope against the tasks of Article 39(1) and record the conclusion together with the reasoning.
  3. Check the qualities against the processing operations carried out in the organisation, in line with recital 97.
  4. Establish whether the candidate’s placement allows direct reporting to the highest management level.

Return to this set at every change of structure. A promotion or taking over a new department can create a conflict that did not exist on the day of designation.

Related materials

Sources

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), consolidated version — Article 24(1), Article 37(2), (3), (4), (5) and (6), Article 38(1), (2), (3) and (6), Article 39 and Article 99(2) — eur-lex.europa.eu (dostęp: 13.09.2026).
  • Regulation (EU) 2016/679 (GDPR), version as published in OJ EU L 119 of 4 May 2016 — recital 97 — eur-lex.europa.eu (dostęp: 13.09.2026).
  • Act of 10 May 2018 on the Protection of Personal Data, consolidated text as at 6 May 2026 — Articles 8 to 11a (in Polish) — isap.sejm.gov.pl (dostęp: 13.09.2026).
  • Personal Data Protection Office (UODO), Guarantees of the independence of the data protection officer (in Polish) — uodo.gov.pl (dostęp: 13.09.2026).
  • Personal Data Protection Office (UODO), Does a processing agreement have to be concluded with an external DPO? (in Polish) — uodo.gov.pl (dostęp: 13.09.2026).
  • Article 29 Data Protection Working Party, Guidelines on Data Protection Officers (‘DPOs’), wp243rev.01, adopted 13 December 2016, last revised 5 April 2017 — sections 2.5 and 3.5 — ec.europa.eu (dostęp: 13.09.2026).

Check whether your candidate would pass this assessment

Selecting an officer is decided where the organisational structure meets the tasks of Article 39. External DPO support covers the assessment of a candidacy and the preparation of a record justifying the choice.

Author

Michał Rutkowski — LabLogic. He combines the legal, organisational and technological perspective in his work with the boards of medium-sized and large organisations: support for and performance of the DPO role, preparation for NIS2 and the Polish KSC Act, incident response, audits and training. Contact: M.Rutkowski@LabLogic.pl · LinkedIn

This material is general and educational in nature. It is not an individual legal opinion or a recommendation for any specific organisation. The scope of the obligations should be assessed against the situation of the organisation concerned.

Legal status: September 2026.

Scroll to Top