DPO and GDPR

When a DPO must be appointed, what the board should expect from that role and how to document accountability under the GDPR.

Legal status: August 2026

External DPO support

See also: NIS2 and KSC Incidents and Breaches Training and workshops AI Act

An external DPO for your organisationWhether the role is required, how it should be set up and what evidence it has to produce depend on how your processes actually run. Let us start with a conversation about yours — no obligation and no sales preamble. Explore the service

Scope of decisions, not job title — LabLogic article graphic by Michał Rutkowski
DPO and GDPR

Who cannot act as a data protection officer?

The GDPR contains no list of positions excluded from the role of data protection officer. The exclusion is decided by three separate provisions, and what settles a conflict of interests is the scope of decisions about purposes and means of processing, not the job title.

What should the board expect from a DPO? — LabLogic article graphic by Michał Rutkowski
DPO and GDPR

What information should the board expect from the DPO?

The board should expect from the data protection officer a picture of the state of data protection, not a report of activities. Six areas make up that picture. The GDPR does not set the format of the report, but it does settle that the flow of information has to exist.

Scroll to Top