Tasks of the DPO
The tasks of the Data Protection Officer (DPO) are the core duties that a designated privacy expert carries out within an organisation, such as advising staff on their data protection obligations, monitoring whether the organisation follows the rules, and acting as a point of contact for the supervisory authority. The DPO supports the organisation but does not personally take on the organisation's legal responsibility for compliance. Under the UK regime, an equivalent set of tasks applies, with some tasks defined separately for law enforcement processing.
Under Article 39 GDPR, the DPO is assigned at least the following tasks: to inform and advise the controller or processor and their employees of their obligations under the GDPR and other applicable data protection provisions; to monitor compliance with the GDPR, other data protection law, and the organisation's own data protection policies (including awareness-raising, staff training, and related audits); to provide advice on and monitor performance of Data Protection Impact Assessments where requested (see Article 35); to cooperate with the supervisory authority; and to act as the contact point for the supervisory authority on processing issues, including prior consultation. The DPO advises but does not assume the controller's or processor's accountability, which remains with those roles. In the UK, equivalent tasks apply under the UK GDPR (per ICO guidance), and for law enforcement processing the minimum tasks are set out in Part 3, Chapter 4 of the relevant Act rather than in the GDPR itself. Practitioners should verify the current article text and applicable national implementing provisions, as the precise scope may vary by regime and by member state derogation.
Why it matters
The tasks of the DPO sit at the heart of an organisation's accountability framework. A clearly scoped DPO role gives the controller or processor a designated expert who informs and advises on data protection obligations, monitors compliance, and serves as the recognised point of contact for the supervisory authority. Without a clear delineation of these tasks, organisations risk gaps in oversight or, conversely, confusion over where responsibility ultimately lies. It is important to understand that the DPO advises and monitors but does not personally assume the legal accountability for compliance, which remains with the controller or processor.
Because the DPO acts as the contact point for the supervisory authority, including in the context of prior consultation, the role is often the organisation's interface with the regulator on processing issues. The European Commission describes the DPO as assisting the controller or processor in all issues relating to the protection of personal data, and Article 39 GDPR sets out the minimum tasks. Under the UK GDPR, ICO guidance sets out an equivalent set of tasks, and for law enforcement processing the minimum tasks are defined separately in Part 3, Chapter 4 of the relevant Act rather than in the GDPR itself.
Misunderstanding the scope of DPO tasks can undermine a compliance programme in practice: for example, treating the DPO as the party liable for compliance failures, or failing to involve the DPO in Data Protection Impact Assessments, may weaken both governance and the organisation's ability to demonstrate accountability. Practitioners should verify the current article text and applicable national implementing provisions, as the precise scope may vary by regime and by member state derogation.
Who it's relevant to
Inside DPO
Common questions
Answers to the questions practitioners most commonly ask about DPO.