Every week, I get questions about whether a data protection officer (DPO) can juggle multiple roles, especially in IT security. These questions often arise after a new DPO appointment or organizational restructuring. They come from legal teams, HR directors, and sometimes the DPOs themselves, who realize their job descriptions might create conflicts.
The confusion is understandable. Article 39 of the GDPR outlines a DPO's duties but doesn't specify roles they can't hold simultaneously. This ambiguity leaves you figuring out the line between "efficient use of talent" and "conflict of interest that could cause issues during an audit."
Here's what you need to know, based on actual requirements rather than vague advice.
Can our CISO also serve as DPO?
No, if they're involved in decision-making about data processing purposes or means.
The conflict arises from decision-making authority. If your CISO decides how long to keep logs, proposes security measures affecting personal data, or approves data access requests, they're determining processing means. A DPO can't audit decisions they made in another role.
Article 38(6) states the DPO "shall not receive any instructions regarding the exercise of those tasks." If the same person sets retention periods and reviews GDPR compliance, independence is compromised.
The French supervisory authority warns against this: if the DPO has decision-making power over processing purposes and means, there's a conflict. The person's capability or team size doesn't change this.
What about part-time DPOs with other responsibilities?
It's allowed, but only if those tasks don't interfere with DPO duties or create conflicts.
The GDPR allows part-time DPOs. The test is twofold: does the additional work prevent them from fulfilling Article 39 obligations, and does it put them in a position of conflict in data protection decisions?
Senior management roles often fail this test. A head of HR who also serves as DPO faces a conflict: HR determines purposes and means of employee data processing, which the DPO must review independently.
Lower-level roles can also create conflicts if they involve determining processing purposes or means. An analyst deciding which customer data goes into a fraud detection model can't independently assess compliance with Articles 5 and 6.
Our DPO sits on our ethics committee. Problem?
Yes, potentially.
If the ethics committee votes on projects involving personal data processing or takes positions on data protection, your DPO faces a conflict. They're expected to provide impartial guidance under Article 39(1)(a), but committee membership may require advocacy or compromise.
The same applies to employee representatives or union roles. When a works council votes on new monitoring measures, a DPO who's also a council member must choose between their advisory role and representative obligations, creating a conflict of interest.
We want to hire an external DPO whose law firm previously represented us in a data protection dispute. Can we?
No, that's a direct conflict.
If the DPO or their firm represented you in data protection litigation, they've already taken a position on your processing activities. Article 38(6) prohibits instructions that create bias.
The same concern applies if your external DPO works for an entity with conflicting interests: your processor, a joint controller, or a data source. They can't provide independent oversight when other clients' interests conflict with yours.
Can we appoint a "substitute DPO" to handle the conflicts?
Yes, but it must be substantive, not just paperwork.
If you've identified a conflict, one solution is to assign a substitute DPO for the affected activities. They must receive the same protections as your primary DPO: adequate resources, involvement in decisions, access to data, and protection from dismissal or penalty for performing DPO tasks.
The substitute can't report to the primary DPO on matters within the conflict scope. If your DPO runs fraud prevention and you appoint a fraud analyst as their substitute, you haven't solved anything. The analyst can't independently review their supervisor's decisions.
Document the conflict, specify which activities fall under the substitute's remit, and ensure both DPOs cover your full processing landscape without gaps. The substitute doesn't need separate registration with your supervisory authority but must have real authority.
What if our external DPO serves both us and our processor?
Ensure different individuals handle each relationship.
When a DPO entity serves both a controller and processor, the firm must assign separate staff to each client, with confidentiality obligations. Those individuals can't have reporting relationships that undermine independence.
Document who handles each client, how you've verified independence, and confirm that each person receives Article 37 and 39 protections. Your processor should do the same verification.
Where do I find the specific rules on this?
Start with Articles 37-39 of the GDPR, which cover DPO designation, position, and tasks. Article 38(6) specifically addresses the "no instructions" rule central to conflict analysis.
The CNIL's guidance on DPOs provides questions for identifying conflicts and remediation frameworks. While it's French guidance, the analysis applies across the EU as it interprets the GDPR's text.
When working through a scenario, document your analysis: what roles does the person hold, what decision-making authority comes with each, and where do those authorities overlap with DPO responsibilities? This documentation is your evidence of the case-by-case assessment the GDPR requires.



