Assigning the Data Protection Officer (DPO) role to a C-suite executive or senior leader can seem like a practical solution. They understand the organisation, have direct access to decision-makers, and are often already responsible for overseeing compliance or governance.
However, this is a risky strategy that could violate data protection laws like the General Data Protection RegulationRegulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation). (GDPR).
This blog explains what the law says, why conflicts of interest commonly arise for C-suite executives, and how organisations can structure the DPO role to support effective and independent oversight.





