Skip to main content
Category: Controller & Processor Roles

Tasks of the DPO

Also known as: DPO, Data Protection Officer tasks, Responsibilities of the DPO, DPO duties
Simply put

The tasks of the Data Protection Officer (DPO) are the core duties that a designated privacy expert carries out within an organisation, such as advising staff on their data protection obligations, monitoring whether the organisation follows the rules, and acting as a point of contact for the supervisory authority. The DPO supports the organisation but does not personally take on the organisation's legal responsibility for compliance. Under the UK regime, an equivalent set of tasks applies, with some tasks defined separately for law enforcement processing.

Formal definition

Under Article 39 GDPR, the DPO is assigned at least the following tasks: to inform and advise the controller or processor and their employees of their obligations under the GDPR and other applicable data protection provisions; to monitor compliance with the GDPR, other data protection law, and the organisation's own data protection policies (including awareness-raising, staff training, and related audits); to provide advice on and monitor performance of Data Protection Impact Assessments where requested (see Article 35); to cooperate with the supervisory authority; and to act as the contact point for the supervisory authority on processing issues, including prior consultation. The DPO advises but does not assume the controller's or processor's accountability, which remains with those roles. In the UK, equivalent tasks apply under the UK GDPR (per ICO guidance), and for law enforcement processing the minimum tasks are set out in Part 3, Chapter 4 of the relevant Act rather than in the GDPR itself. Practitioners should verify the current article text and applicable national implementing provisions, as the precise scope may vary by regime and by member state derogation.

Why it matters

The tasks of the DPO sit at the heart of an organisation's accountability framework. A clearly scoped DPO role gives the controller or processor a designated expert who informs and advises on data protection obligations, monitors compliance, and serves as the recognised point of contact for the supervisory authority. Without a clear delineation of these tasks, organisations risk gaps in oversight or, conversely, confusion over where responsibility ultimately lies. It is important to understand that the DPO advises and monitors but does not personally assume the legal accountability for compliance, which remains with the controller or processor.

Because the DPO acts as the contact point for the supervisory authority, including in the context of prior consultation, the role is often the organisation's interface with the regulator on processing issues. The European Commission describes the DPO as assisting the controller or processor in all issues relating to the protection of personal data, and Article 39 GDPR sets out the minimum tasks. Under the UK GDPR, ICO guidance sets out an equivalent set of tasks, and for law enforcement processing the minimum tasks are defined separately in Part 3, Chapter 4 of the relevant Act rather than in the GDPR itself.

Misunderstanding the scope of DPO tasks can undermine a compliance programme in practice: for example, treating the DPO as the party liable for compliance failures, or failing to involve the DPO in Data Protection Impact Assessments, may weaken both governance and the organisation's ability to demonstrate accountability. Practitioners should verify the current article text and applicable national implementing provisions, as the precise scope may vary by regime and by member state derogation.

Who it's relevant to

Data Protection Officers
DPOs themselves need a precise understanding of their statutory tasks under Article 39 GDPR (or the equivalent tasks under the UK GDPR or, for law enforcement processing, Part 3, Chapter 4 of the relevant Act). This clarity helps them focus on informing and advising, monitoring compliance, advising on DPIAs where requested, and acting as the contact point for the supervisory authority, while recognising that legal accountability remains with the controller or processor.
Controllers and processors
Organisations acting as controllers or processors need to understand what tasks they can and should rely on the DPO to perform, and where their own accountability continues to lie. This includes involving the DPO in DPIAs and enabling the DPO to monitor compliance, while ensuring the organisation does not treat the DPO as the party bearing legal responsibility for compliance.
Compliance and governance leads
Those designing accountability frameworks should map DPO tasks against internal policies, training programmes, and audit activity, since monitoring compliance typically encompasses awareness-raising and related audits. They should also ensure the DPO's contact details are published and communicated to the supervisory authority as required.
Legal advisers and privacy counsel
Advisers should verify the current article text and the applicable national implementing provisions, as the precise scope of DPO tasks may vary by regime and by member state derogation. They also play a role in clarifying the distinction between the DPO's advisory and monitoring function and the enduring accountability of the controller or processor.

Inside DPO

Advising and informing
The DPO informs and advises the controller or processor and their employees who carry out processing about their obligations under the GDPR and other Union or member state data protection provisions. This is an advisory function rather than a decision-making one; accountability for compliance generally remains with the controller or processor.
Monitoring compliance
The DPO monitors compliance with the GDPR, with other applicable data protection law, and with the organisation's own policies, including the assignment of responsibilities, awareness-raising, staff training, and related audits. Monitoring means observing and assessing rather than being personally responsible for achieving compliance.
Advice on Data Protection Impact Assessments
Where requested, the DPO provides advice regarding a Data Protection Impact Assessment (DPIA) and monitors its performance. The obligation to carry out a DPIA and to identify when one is required typically rests with the controller; the DPO's role here is advisory and oversight-oriented.
Cooperation with the supervisory authority
The DPO cooperates with the competent supervisory authority on matters relating to processing.
Contact point function
The DPO acts as the contact point for the supervisory authority on issues relating to processing, including prior consultation where relevant, and may consult on any other matter. The DPO may also, in practice, serve as a point of contact for data subjects, though the precise scope can depend on how the role is structured.
Risk-based approach to duties
In performing tasks, the DPO has due regard to the risk associated with processing operations, taking into account the nature, scope, context, and purposes of processing. This allows the DPO to prioritise activities and focus attention on higher-risk processing.

Common questions

Answers to the questions practitioners most commonly ask about DPO.

Does the DPO decide the organisation's data protection strategy and bear personal responsibility for compliance?
No. Under Article 39, the DPO's tasks are advisory and monitoring in nature: informing and advising the controller or processor and their staff of their obligations, monitoring compliance, providing advice on data protection impact assessments, cooperating with the supervisory authority, and acting as a contact point. Responsibility for compliance generally remains with the controller or processor. The DPO does not determine the purposes and means of processing and is not personally liable for the organisation's non-compliance in the way the accountable entity is. Guidance from the European Data Protection Board (formerly the Article 29 Working Party) reinforces this distinction, though readers should verify the current text.
Is the DPO required to approve every processing activity before it goes ahead?
Generally no. The DPO's role in relation to activities such as a data protection impact assessment is to provide advice where requested and to monitor its performance, not to sign off or authorise processing. Decision-making authority typically rests with the controller. Treating the DPO as an approval gate can compromise the independence Article 38 is intended to protect, since the DPO should not be placed in a position of deciding matters they are also expected to monitor. The precise allocation of roles can depend on internal governance arrangements, which should be documented.
How should we involve the DPO in a new project involving personal data?
Article 38 provides that the DPO should be involved properly and in a timely manner in all issues relating to the protection of personal data. In practice this typically means engaging the DPO early in project or product design rather than after decisions are made, giving them access to processing operations and relevant information, and ensuring they can advise before processing begins. The specific mechanisms, for example intake procedures or design review points, are a matter for internal governance and should be recorded to demonstrate accountability.
How does the DPO monitor compliance in practice?
Monitoring under Article 39 can generally include collecting information to identify processing activities, analysing and checking their compliance, and informing and advising the organisation. In practice this may involve reviewing records of processing activities, conducting or overseeing audits and assessments, and tracking whether advice is acted upon. The DPO monitors compliance but does not itself become responsible for achieving it; the accountable entity retains that responsibility. The scale and method of monitoring should be proportionate to the nature, scope and risk of the processing.
What resources and safeguards does the DPO need to carry out their tasks?
Article 38 indicates that the DPO should be supported with the resources necessary to perform their tasks, access to personal data and processing operations, and the means to maintain their expert knowledge. The DPO should not receive instructions regarding the exercise of their tasks and should not be dismissed or penalised for performing them. Where the DPO holds other roles, those should not give rise to a conflict of interests. The adequacy of resources is assessed in context and can vary with the size and complexity of the organisation's processing.
How should the DPO handle the risk-based prioritisation of their tasks?
Article 39 provides that the DPO should have due regard to the risk associated with processing operations, taking into account the nature, scope, context and purposes of processing. In practice this generally supports prioritising attention toward higher-risk activities. This is a matter of applying the DPO's judgement rather than following a fixed rule, and how risk is weighted may reflect the organisation's specific processing and any relevant supervisory authority guidance, which should be checked against current sources.

Common misconceptions

The DPO is personally liable for the organisation's data protection compliance.
The DPO's statutory tasks are generally advisory and monitoring in nature. Responsibility and accountability for compliance typically remain with the controller or processor, who must demonstrate compliance. The DPO should not be penalised or dismissed for performing their tasks; guidance from regulators has addressed the DPO's protected and independent position, and readers should verify the current position against official sources.
The DPO decides whether a DPIA is needed and carries it out.
The GDPR generally places the obligation to determine whether a DPIA is required, and to conduct it, on the controller. The DPO's role is to provide advice where requested and to monitor the DPIA's performance, not to own the assessment.
The DPO must give equal attention to every processing activity.
The DPO is expected to have due regard to risk, taking into account the nature, scope, context, and purposes of processing. In most cases this supports a risk-based prioritisation of effort rather than uniform coverage of all operations.

Best practices

Document the DPO's tasks and reporting lines so that the advisory and monitoring nature of the role is clear and distinct from operational decision-making, which generally remains with the controller or processor.
Establish the DPO as a clearly published contact point for the supervisory authority and, where appropriate, for data subjects, and ensure the DPO is involved early in relevant processing matters.
Adopt a risk-based methodology so the DPO prioritises monitoring and advice according to the nature, scope, context, and purposes of processing.
Involve the DPO in DPIAs by seeking advice where required and enabling the DPO to monitor performance, while keeping the assessment obligation with the controller.
Support the DPO's monitoring function through access to processing operations, records, awareness-raising, and staff training, and safeguard the DPO's independence in performing these tasks.
Maintain a documented cooperation channel with the competent supervisory authority, and verify the specific applicable obligations against the current official GDPR text and relevant national implementing law, as member state positions can vary.