DPO and GDPR

When a DPO must be appointed, what the board should expect from that role and how to document accountability under the GDPR.

Legal status: August 2026

External DPO support

See also: NIS2 and KSC Incidents and Breaches Training and workshops AI Act

An external DPO for your organisationWhether the role is required, how it should be set up and what evidence it has to produce depend on how your processes actually run. Let us start with a conversation about yours — no obligation and no sales preamble. Explore the service

Time, budget and access for the DPO — LabLogic article graphic by Michał Rutkowski
DPO and GDPR

What resources must a data protection officer receive?

Article 38(2) GDPR requires the DPO to be given resources for the tasks, access to personal data and processing operations and resources to maintain expert knowledge. The provision sets no hours or amounts, so the organisation assesses the scale for its own case and should be able to show that assessment.

Scope of decisions, not job title — LabLogic article graphic by Michał Rutkowski
DPO and GDPR

Who cannot act as a data protection officer?

The GDPR contains no list of positions excluded from the role of data protection officer. The exclusion is decided by three separate provisions, and what settles a conflict of interests is the scope of decisions about purposes and means of processing, not the job title.

What should the board expect from a DPO? — LabLogic article graphic by Michał Rutkowski
DPO and GDPR

What information should the board expect from the DPO?

The board should expect from the data protection officer a picture of the state of data protection, not a report of activities. Six areas make up that picture. The GDPR does not set the format of the report, but it does settle that the flow of information has to exist.

Scroll to Top