The role of the DPO and why it matters

A widespread practice on the Polish market is to treat the data protection officer (DPO) as an additional administrative duty, most often landing on a manager's assistant or a member of the HR team. Yet under the General Data Protection Regulation (GDPR) and the guidance of the European Data Protection Board (EDPB), the DPO is a key, independent function that should have access to management, the resources and the standing necessary to perform its tasks effectively.

When a DPO is mandatory

Article 37 GDPR sets out when appointing a data protection officer is mandatory. First, for public authorities and public bodies — in practice every public sector institution must have a DPO. Second, for organisations whose core activities consist of processing data on a scale requiring regular and systematic monitoring, such as security agencies, data processing firms, cloud service providers and telecommunications operators. Third, for organisations whose core activities consist of processing special categories of data or data relating to criminal convictions and offences. Article 37 also allows organisations that do not meet those criteria to appoint a DPO voluntarily — which is advisable for any organisation processing significant volumes of personal data.

A DPO should be appointed as soon as possible.

The EDPB guidelines, published in 2017 and updated regularly, make clear that a DPO should be appointed as soon as possible where the organisation is required to have one. Research from 2023 by Poland's data protection authority (UODO) showed that a significant proportion of Polish organisations required to have a DPO still do not, exposing themselves to potential regulatory penalties. Failing to appoint a DPO where this is mandatory can attract a fine of up to EUR 10 million or 2 per cent of total worldwide annual turnover, whichever is higher.

The status and independence of the DPO

Article 38 GDPR defines the status and position of the DPO. The DPO may be an internal employee or a person employed by an external service provider — both options are permitted, though organisations must ensure the DPO is able to perform their tasks independently. The key requirement is the DPO's independence, expressed in Article 38(3), which requires that the DPO receive no instructions from anyone in the organisation regarding the exercise of their data protection tasks. This means the DPO cannot at the same time be the IT director, the HR director, or hold any other post that could place them in a conflict of interest with impartial data protection. The DPO must have direct access to the organisation's senior management — at least at director or board level.

The duties of the DPO

Article 39 GDPR sets out the DPO's tasks and duties. First, the DPO monitors compliance with GDPR, including verifying that the organisation collects, processes and stores personal data correctly, that it has appropriate contracts with data processors, and that it discharges the obligations contained in the regulation. Second, the DPO helps staff understand GDPR requirements through training, advice and the implementation of procedures. Third, the DPO acts as the point of contact with the President of UODO — it is the DPO who receives inspections, supports regulatory investigations and communicates with data protection authorities. Fourth, the DPO supports the conduct of data protection impact assessments (DPIAs) — complex risk assessment exercises for processing that may result in a high risk to the rights and freedoms of natural persons.

The DPO must have direct access to the organisation's senior management.

An exceptionally important DPO function, though one often neglected in Polish organisations, is supporting the organisation in meeting the obligations arising from Article 31 GDPR concerning consultation with UODO. Where processing may result in a high risk to the rights and freedoms of natural persons, the organisation must carry out a DPIA and, if the risk is not fully mitigated, consult UODO before the processing actually begins. The DPO is responsible for identifying situations requiring such consultation and for carrying it out.

Common failings in how the DPO function works

The most common mistake we see in Polish companies is assigning the DPO role as an additional duty to someone already employed full time in another position. A typical example is an HR employee given the DPO role while their original HR workload remains just as demanding. The consequence is that the DPO devotes only a few hours a week to data protection, if that, which makes performing the role effectively all but impossible. The EDPB states unequivocally that if the DPO does not have sufficient time to carry out their duties, the organisation is not meeting the requirement of DPO independence, and the DPO should report that shortcoming in their annual report.

Another serious mistake is placing the DPO in a reporting line that undermines their independence. If, for example, the DPO reports to the IT director, who is the principal decision-maker on data processing matters, the DPO has virtually no scope to assess risk impartially or raise objections. This is particularly problematic when the IT director introduces a new system whose compliance the DPO is then expected to oversee. Article 38 GDPR expressly prohibits arrangements of this kind.

The third common mistake is the DPO having no access to senior management. If the DPO has to report through several organisational layers, their messages can be filtered, diluted or ignored altogether. Article 38(4) GDPR states plainly that the organisation must ensure the DPO can perform their functions without obstruction — which means direct access to senior management. In practice, the DPO should meet the board regularly and be able to report risks and instances of non-compliance there.

The fourth mistake is underfunding the DPO function. The DPO needs tools to monitor compliance, access to specialist software, budget for training and keeping their knowledge current, and the ability to bring in additional staff if the organisation is large or highly complex. A DPO given an annual budget of zero cannot realistically function.

The fifth mistake is the absence of a clear policy defining the DPO's role and duties. The employee appointed as DPO often does not know exactly what they should be doing, and management has only a vague idea of the scope of the function. The organisation should publish an internal data protection policy that clearly defines the DPO's powers and responsibilities.

The sixth mistake is a conflict of interest with board members or directors. If the DPO says no to a proposed data processing project and a director pushes for it to go ahead "at the expense of compliance", the DPO's independence is compromised. In such a scenario the DPO should be able to escalate the conflict and receive support from a higher governing body.

The last mistake, and no less important, is staff being unaware that the DPO exists and what the role is for. If employees do not know who to approach with data protection questions, or do not know that they can report a suspected unlawful processing of data, then the DPO function is effectively invisible within the organisation.

The costliest of these mistakes is the conflict of interest. What it looks like in practice, and what it cost Poczta Polska, is set out in our piece on DPO independence.

The formalities that get forgotten

Appointing a DPO is not a decision taken in a conversation. The Polish Personal Data Protection Act and GDPR impose three formal obligations, and UODO genuinely imposes fines where they are not met.

A written act of appointment. In 2024 the President of UODO imposed a fine of PLN 25,000 on the District Building Supervision Inspectorate in Częstochowa because the public body had not effectively appointed a DPO — the role had been assigned orally, without any order, internal rules or contract. An effective appointment requires written form.

Notification of the President of UODO within 14 days. The period runs from the date of appointment. The notification must be submitted electronically only, with a qualified electronic signature or a trusted signature. The same fourteen-day deadline applies to changes to the DPO's details and to their dismissal.

Publication of contact details. The organisation must publish the DPO's name and contact details immediately after the appointment — on its website or, if it does not run one, in a generally accessible manner at its place of business.

That these are not dead letters is shown by the decision of 10 February 2026 concerning the Lumus Foundation: alongside a fine for failing to report a breach, UODO imposed a separate fine for three infringements of Article 37(7) GDPR — failure to publish the DPO's details and failure to notify the authority of the appointment of two successive officers.

Conflict of interest — what must not be combined with the DPO role

This is today the costliest area of DPO-related risk, and the one best documented by Polish decisions.

The starting point is Article 38(6) GDPR: the DPO may perform other tasks provided they do not give rise to a conflict of interest. Guidelines WP 243 rev.01, endorsed by the EDPB, establish a presumption of conflict for senior positions — chief executive, chief operating officer, chief financial officer, head of marketing, head of HR and head of IT. More junior positions are conflicted where they involve determining the purposes and means of processing.

The CJEU refined this in its judgment of 9 February 2023 in C-453/21 (X-FAB Dresden): a conflict of interest may exist where the DPO is entrusted with tasks that lead to determining the purposes and means of processing personal data, and the assessment is to be made case by case, each time, taking account of the organisational structure and the whole body of internal rules.

Polish supervisory practice points to three configurations to be avoided.

Supervising one's own activity. Decision of the President of UODO of 2 January 2026 concerning Poczta Polska — a fine of PLN 978,128. The DPO role was held by the director of an organisational unit who at the same time determined the purposes and means of processing and was then supposed to monitor them. UODO also identified a conflict of time (no analysis of how time-consuming the two roles were) and a conflict of representation — the DPO had been given power of attorney to represent the company before the President of UODO, which binds them to the principal's instructions. The infringement ran from 2018 until March 2025. The decision is not final; the company has announced an appeal.

A DPO reporting to the person managing the processing. Decision concerning Toyota Bank Polska of 18 December 2024 — PLN 261,918 for the infringement of Article 38(3) alone (part of a combined fine of PLN 576,220). The DPO worked in the security department and reported to its director, whose own deputy was in turn the DPO's superior. The bank's argument that the reporting line was "purely administrative" was not accepted. The Provincial Administrative Court in Warsaw dismissed the bank's appeal in its judgment of 18 September 2025.

A board member acting as DPO. Decision of 12 September 2025 concerning a medical company — PLN 11,365 for nearly six years in which the DPO role was held by the chief executive. The same pattern appears in the Lumus Foundation case (February 2026), where the DPO was successively a board member, chief executive and project coordinator, and the conflict of interest analysis was approved by the very person it concerned. UODO put it in a single sentence: the person heading an organisation cannot supervise their own lawfulness.

The practical conclusion: a documented conflict of interest analysis should be produced before the DPO is appointed, approved by someone other than the candidate, and cover three dimensions — substantive (does the DPO end up assessing their own decisions), temporal (do they genuinely have time for the Article 39 tasks) and representational (do they act on the controller's behalf in data protection matters).

DPO independence in practice

Article 38(3) GDPR gives the DPO three guarantees: no instructions as to the exercise of their tasks, direct reporting to the highest management level, and protection against dismissal or penalty for performing their duties.

CJEU case law has marked out the limits of that protection. In C-534/20 (Leistritz) of 22 June 2022 the Court confirmed that the protection covers decisions terminating the role or placing the DPO at a disadvantage, but that it cannot undermine the objectives of GDPR — so it does not protect someone who lacks the necessary qualifications or does not perform their tasks properly. In C-453/21 and C-560/21 (KISA), both of 9 February 2023, the Court held that national law may permit the dismissal of an employed DPO only for serious cause.

The direction of travel is towards greater protection. In January 2026 the European Data Protection Supervisor adopted a decision requiring EU institutions to obtain the EDPS's prior consent to dismiss a DPO before the end of their term. That is the regime of Regulation 2018/1725 rather than GDPR, but it shows where the interpretation of independence is heading.

The scale of the problem is systemic rather than isolated. The EDPB's coordinated enforcement action on the designation and position of DPOs, the results of which were published in January 2024, covered 25 supervisory authorities and more than 17,000 responses. The recurring problems: assigning controller tasks to the DPO (maintaining the record of processing activities, for instance), a lack of formal appointment, and placing the DPO outside the structure reporting to senior management.

The external DPO — when it pays off and how to structure the contract

Article 37(6) GDPR expressly allows the DPO to perform their tasks on the basis of a service contract. In material updated on 8 July 2026, UODO takes the opportunity to correct the most common misunderstanding: a contract with an external DPO is not a data processing agreement within the meaning of Article 28 GDPR. They are two different constructions, and confusing them produces documentation that will not stand up to inspection.

What to look for in the contract:

  • the subject matter is the tasks under Article 39(1) GDPR, not the controller's tasks — an external DPO does not maintain the record of processing activities on the organisation's behalf and does not "implement GDPR" for it;
  • no instructions as to how the tasks are performed — the controller may specify availability and the form of reporting, but not the content of the officer's opinion;
  • genuine availability — if a single officer serves several dozen organisations, it is worth checking the declared response time and how it is measured;
  • naming a contact person where the role is held by a team — the WP 243 guidelines allow a team model provided tasks are clearly divided and a single point of contact is identified;
  • excluding representation in disputes concerning data protection — a source of conflict of interest, as confirmed by the Poczta Polska decision;
  • access to data and resources, plus the duty of secrecy (Article 38(5)).

Outsourcing solves the most common problem faced by smaller organisations — the absence of anyone who is not already involved in processing data. What it does not solve is the problem of engagement: an officer whom nobody tells about new projects is just as ineffective from outside as from within.

What the Digital Omnibus will change — the position as at July 2026

Briefly, because a good deal of confusion has grown up around this package: the provisions on the data protection officer are not changing. The Commission's proposal of 19 November 2025 concerns, among other things, the definition of personal data, the legal bases for processing for AI purposes, the breach notification deadline and the rules on cookies. Articles 37–39 GDPR are not covered by it.

The GDPR element of the package itself has not been adopted. In late June 2026 the Cypriot Presidency withdrew the compromise text for want of a qualified majority in the Council, and from 1 July 2026 the dossier has been handled by the Irish Presidency. The separate act concerning the AI Act has been finalised — but that is a different procedure and does not concern GDPR.

What is changing is the environment the officer works in: if the breach notification deadline is extended to 96 hours and the lists of operations requiring an impact assessment are harmonised at EU level, internal procedures will need updating. Worth following, but not worth rewriting your documentation before the legislative process concludes.

In summary

A well-functioning DPO is the guarantee that the organisation will comply with GDPR, which makes it possible to avoid potential fines and maintain client trust. The DPO should be seen not as a bureaucratic obligation but as a strategic partner to the board in managing data protection risk. Organisations that see the DPO in these terms will be in a far better position to meet GDPR requirements and to protect the data of their clients and employees. Where appointing an officer, or fixing where the function sits, is beyond the organisation's internal capacity, one option is legal support in entrusting the DPO role to an external provider.