CHAPTER IVCONTROLLER AND PROCESSOR

Article 38Position of the data protection officer

Official text

(1)The controller and the processor shall ensure that the data protection officer is involved, properly and in a timely manner, in all issues which relate to the protection of personal data.

(2)The controller and processor shall support the data protection officer in performing the tasks referred to in Article 39 by providing resources necessary to carry out those tasks and access to personal data and processing operations, and to maintain his or her expert knowledge.

(3)The controller and processor shall ensure that the data protection officer does not receive any instructions regarding the exercise of those tasks. He or she shall not be dismissed or penalised by the controller or the processor for performing his tasks. The data protection officer shall directly report to the highest management level of the controller or the processor.

(4)Data subjects may contact the data protection officer with regard to all issues related to processing of their personal data and to the exercise of their rights under this Regulation.

(5)The data protection officer shall be bound by secrecy or confidentiality concerning the performance of his or her tasks, in accordance with Union or Member State law.

(6)The data protection officer may fulfil other tasks and duties. The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests.

Commentary

Article 38 GDPR: Position of the Data Protection Officer

1. The basic purpose of Article 38

Article 37 answers the question “When must a DPO be appointed and who can be appointed?”

Article 39 answers “What does the DPO actually do?”

Article 38 sits between the two and answers a different, extremely important question:

“What organisational conditions must exist so that the DPO can actually perform those functions properly?”

This distinction is fundamental.

A company may appoint an exceptionally qualified privacy lawyer as its DPO. But if that person:

  • is never informed about new processing activities;

  • receives information only after business decisions have already been made;

  • has no access to relevant systems;

  • has no budget for training;

  • reports to the very manager whose decisions they are supposed to scrutinise;

  • is told what legal conclusion to reach;

  • is threatened with dismissal when giving inconvenient advice;

  • cannot communicate directly with senior management; or

  • simultaneously occupies a position in which they determine how personal data will be processed,

then the formal appointment of a DPO may exist, but the substantive position required by Article 38 does not.

The DPO is therefore not merely a job title. Article 38 establishes a governance architecture around the DPO.

The EDPB similarly emphasises that DPOs must be able to perform their functions independently, have access to processing operations, receive adequate resources and be involved from the earliest possible stage in relevant matters. (European Data Protection Board)

A useful way of understanding Article 38 is:

Article 38 protects the conditions under which Article 39 can be performed.

2. Article 38(1): Proper and timely involvement

The first obligation is deceptively simple. The DPO must be involved:

  1. in all issues relating to protection of personal data;

  2. properly; and

  3. in a timely manner.

Each of those elements matters.

2.1 “All issues which relate to the protection of personal data”

This does not mean that the DPO must personally participate in every single instance of processing.

That would be both impractical and contrary to the structure of the GDPR.

Example

suppose an organisation processes 20 million customer records every day.

The DPO does not need to be informed every time:

Customer A's address is retrieved from the CRM.

Nor does the DPO need to approve every routine database query.

The obligation operates primarily at the governance and decision-making level.

The DPO should be involved where an issue has data-protection implications.

Example

launching a new mobile application Suppose a bank is developing a new mobile application. The application will:

  • collect location data;
  • analyse transaction behaviour;
  • use device identifiers;
  • perform fraud detection;

  • create behavioural profiles; and

  • potentially use automated decision-making.

The DPO should not first learn about the project when the application is already finished.

The DPO should participate while the organisation is deciding:

  • what data will be collected;

  • why location information is necessary;

  • how long it will be retained;

  • whether profiling will occur;

  • whether Article 22 is implicated;

  • what legal basis applies;

  • what information will be provided to customers;

  • what security safeguards are necessary;

  • whether a DPIA is required; and

  • whether privacy-by-design measures should be incorporated.

This is what makes Article 38(1) a preventive governance provision, rather than merely an incident-response provision.

3. The DPO should not become a “privacy fire extinguisher”

One of the most common organisational failures is to treat the DPO as someone who is called only when something has already gone wrong.

For example:

“The marketing campaign goes live tomorrow. Can you quickly check whether the consent mechanism is GDPR-compliant?”

That is precisely the type of approach Article 38 seeks to prevent.

The DPO should ideally have been involved when the marketing team first proposed:

“We want to use customer purchase histories to create personalised advertising audiences.”

At that point the DPO can influence:

  • purpose specification;

  • lawful basis;

  • transparency;

  • objection rights;

  • profiling;

  • retention;

  • data minimisation;

  • processor arrangements;

  • international transfers; and

  • technical architecture.

Once the system has already been built, the DPO's ability to influence the outcome becomes much smaller.

This is why Article 38(1) must be read together with Article 25, which establishes data protection by design and by default.

Early involvement allows privacy considerations to be built into the processing architecture rather than added later as a compliance patch.

The EDPB expressly recommends that DPOs be involved at an early stage whenever decisions with data-protection implications are being taken. (European Data Protection Board)

4. What does “properly” involved mean?

“Proper involvement” is more than simply inviting the DPO to a meeting.

Imagine this:

The product team has already decided to launch facial recognition. The board has already approved the budget. The engineering architecture is already fixed. The vendor has already been selected. The launch date has already been announced.

The DPO is then invited to a 30-minute meeting and asked:

“Any GDPR concerns?”

Technically, the DPO was “involved”.

Substantively, however, the organisation has created little meaningful opportunity for the DPO to influence the decision.

Proper involvement requires that the DPO have:

  • sufficient information;

  • sufficient time;

  • access to relevant personnel;

  • access to relevant documentation;

  • access to relevant processing operations;

  • an opportunity to give advice;

  • an opportunity for that advice to be considered; and

  • an appropriate channel to escalate disagreement.

The DPO must therefore be a participant in the decision-making process as an independent adviser, not merely a ceremonial reviewer.

5. Does the DPO have a right to demand involvement?

Yes, this is an important practical consequence.

The obligation placed on the controller or processor necessarily implies that the DPO must be able to insist on being involved in matters falling within Article 38(1).

Otherwise the provision would be almost meaningless.

Imagine a company telling its DPO:

“We decide which matters you need to see. If we don't send something to you, you don't need to worry about it.”

That would effectively allow the organisation to control the DPO's visibility and thereby undermine the monitoring function required by Article 39.

The DPO therefore needs sufficient organisational access to identify relevant processing activities independently.

6. “Timely manner”: timing is legally significant

The phrase “timely manner” is one of the most important parts of Article 38(1).

It means that the DPO must be involved sufficiently early for their advice to have practical significance.

Consider three stages of a project:

Stage 1: Concept

“We want to introduce AI-powered employee monitoring.”

Stage 2: Design

“We have decided to monitor keystrokes, screenshots and application usage.”

Stage 3: Deployment

“The system is already installed. Please tell us whether this is GDPR-compliant.”

The best point for DPO involvement is Stage 1 and certainly Stage 2.

At Stage 3, the DPO may still identify serious problems, but the organisation has already invested substantial resources and may resist changing the system.

This is why early DPO involvement supports privacy by design.

7. DPIAs provide a particularly important example

The relationship between Article 38(1) and Article 35 is especially important.

Where a DPIA is required, the DPO should be consulted.

Suppose a hospital wants to deploy an AI system that predicts patient readmission risk.

The system processes:

  • health information;

  • medical history;

  • demographic information;

  • treatment records; and

  • potentially other sensitive information.

If the organisation first builds the AI system and then asks the DPO:

“Please sign off on the DPIA.”

the DPO's role has been reduced to post-hoc validation.

That is inconsistent with the preventative purpose of the DPO function.

The DPO should instead be involved while the organisation is determining:

  • the purpose;

  • the scope;

  • the data sources;

  • necessity;

  • proportionality;

  • risks;

  • safeguards;

  • retention;

  • access controls; and

  • potential rights impacts.

8. The DPO's opinion is important, but the DPO is not the decision-maker

This is perhaps the most important conceptual distinction in Article 38.

The DPO is independent, but the DPO does not become the controller.

Suppose the DPO tells the company:

“I consider this processing disproportionate and recommend that the company not launch it.”

Management disagrees.

Management may ultimately decide:

“We will proceed.”

That does not automatically mean the DPO has failed.

The DPO's function is primarily to:

  • advise;

  • monitor;

  • inform;

  • facilitate compliance;

  • raise risks;

  • assist with DPIAs;

  • cooperate with the supervisory authority; and

  • act as a point of contact.

The controller remains responsible for the processing decision and for demonstrating compliance.

This distinction prevents a common misunderstanding:

DPO independence does not mean DPO decision-making authority.

The EDPB expressly explains that DPO autonomy does not give the DPO decision-making powers beyond the tasks assigned under Article 39; responsibility for compliance remains with the controller or processor. (European Data Protection Board)

9. What should management do if it disagrees with the DPO?

Disagreement is not itself a GDPR violation.

In fact, disagreement can be perfectly legitimate.

The important question is how the disagreement is handled.

Suppose:

DPO: “A DPIA should be conducted.”

CEO: “I disagree. I don't think Article 35 applies.”

The organisation may ultimately take a different view.

But good governance requires the disagreement to be documented, particularly where the DPO has identified a material compliance risk.

This is closely connected to the GDPR's broader accountability principle under Article 5(2).

A good governance record might contain:

“DPO advised that the proposed behavioural monitoring constituted high-risk processing and recommended a DPIA. Management considered the matter and concluded that the processing did not meet the applicable threshold because...”

This creates evidence that:

  1. the DPO was involved;

  2. the advice was considered;

  3. management made the ultimate decision; and

  4. the organisation can explain its reasoning.

10. Article 38(2): The organisation must actually support the DPO

Article 38(2) moves from involvement tocapacity.

It is not enough to say:

“We have a DPO.”

The organisation must provide the DPO with the resources necessary to perform the job.

This includes:

  • adequate time;

  • financial resources;

  • staff support where appropriate;

  • infrastructure;

  • access to information;

  • access to processing operations;

  • access to relevant departments;

  • training; and

  • continuing professional development.

The principle is proportionality:

The greater the complexity, scale and sensitivity of processing, the greater the resources the DPO may require.

11. A part-time DPO is not automatically unlawful

Another important nuance is that the GDPR does not require every DPO to work full-time.

A DPO may perform the role part-time.

Example

a relatively small organisation might appoint an individual who spends:

40% of their time on DPO responsibilities 60% on other permissible functions.

That can work.

The problem arises when the organisation says:

“You are our DPO, but you only have two hours per month to do it.”

while simultaneously processing enormous volumes of sensitive information.

The question is not:

“Is the DPO full-time?”

The question is:

“Does the DPO have sufficient resources to perform the required functions effectively?”

12. Resources include access to people

DPO work is not merely a desk exercise.

Suppose the DPO is investigating an employee-monitoring system.

They may need to speak with:

  • HR;

  • IT;

  • cybersecurity;

  • procurement;

  • legal;

  • engineering;

  • product;

  • security;

  • vendors; and

  • senior management.

If the DPO has no authority or practical ability to obtain information from those departments, their monitoring function becomes ineffective.

The organisation therefore needs a governance structure in which employees understand:

“The DPO is entitled to receive information necessary to perform the DPO's role.”

13. Access to personal data and processing operations

This is particularly significant.

A DPO cannot meaningfully monitor compliance with processing activities that they cannot inspect.

Imagine a company tells its DPO:

“You can review our privacy policies, but you cannot access our CRM.”

That may be inadequate.

Or:

“You can read the Article 30 ROPA, but you cannot speak to the engineering team.”

Again, potentially inadequate.

Article 38(2) requires access to personal data and processing operations necessary for the DPO's tasks.

The DPO may therefore need to understand:

  • what data is collected;

  • where it comes from;

  • where it is stored;

  • who accesses it;

  • what systems process it;

  • what vendors receive it;

  • how long it is retained;

  • what security controls apply;

  • whether profiling occurs; and

  • whether international transfers occur.

The EDPB specifically notes that DPOs should have access to processing operations and the personal data involved in those operations. (European Data Protection Board)

14. Access does not mean unlimited curiosity

There is another nuance.

Article 38(2) does not transform the DPO into an unrestricted employee entitled to access every piece of information for any purpose.

Access must relate to the DPO's legitimate functions.

Example

if the DPO is reviewing a payroll-processing activity, they may need to inspect:

  • categories of employee data;

  • access controls;

  • retention;

  • processing purposes;

  • payroll vendors;

  • security measures.

But that does not necessarily mean the DPO should indiscriminately download every employee's entire personnel file.

The principle remains one of necessary access for effective performance of DPO functions.

15. The DPO must be able to inspect the practical reality, not just paperwork

A particularly important compliance lesson is that the DPO should not be restricted to documentation.

Suppose the ROPA says:

“Customer data retained for five years.”

The DPO discovers through an audit that backups are retained indefinitely.

The DPO needs access to the actual processing environment to identify the discrepancy.

Similarly:

Policy: “Only HR can access employee health information.”

Actual system configuration:

43 managers have access.

A DPO who can only read policies but cannot inspect relevant systems cannot effectively monitor compliance.

16. External DPOs

Article 37(6) permits external DPO arrangements.

An external DPO can therefore provide services under contract.

But outsourcing the DPO function does not outsource the organisation's GDPR responsibility.

Suppose Company X hires an external privacy consultancy as its DPO.

Company X cannot later argue:

“The consultant was our DPO, so GDPR compliance was their responsibility.”

No.

The controller remains responsible for compliance.

The external DPO must receive:

  • access;

  • information;

  • time;

  • cooperation; and

  • appropriate resources.

The EDPB expressly recognises external DPO arrangements while emphasising that the DPO must still have the necessary independence and access. (European Data Protection Board)

17. Maintaining expert knowledge

Article 38(2) also requires the organisation to enable the DPO to maintain expert knowledge.

This is logical because privacy law is constantly changing.

A DPO cannot reasonably be expected to remain competent indefinitely based solely on knowledge acquired on the day of appointment.

Relevant developments may include:

  • new CJEU judgments;

  • EDPB guidance;

  • supervisory authority decisions;

  • new national legislation;

  • technological developments;

  • AI regulation;

  • cybersecurity developments;

  • international transfer jurisprudence;

  • emerging enforcement approaches.

Therefore, training is not a luxury.

It is part of the infrastructure necessary for the DPO's function.

18. Article 38(3): Independence

Article 38(3) contains the heart of the DPO's institutional protection.

It has three major components:

  1. no instructions concerning DPO tasks;

  2. no dismissal or penalties for performing DPO tasks;

  3. direct reporting to the highest management level.

These three elements work together.

19. “No instructions” does not mean the DPO is an independent sovereign

This distinction is extremely important.

The organisation can give the DPO ordinary employment or contractual instructions concerning matters unrelated to their DPO functions.

What it cannot do is dictate the substance or outcome of the DPO's GDPR work.

Unlawful-type instruction

“Write your assessment so that it concludes the processing is compliant.”

Unlawful-type instruction

“Do not investigate the customer's complaint.”

Unlawful-type instruction

“Do not contact the supervisory authority.”

Unlawful-type instruction

“Interpret Article 6(1)(f) in the company's favour.”

These undermine independence.

By contrast, an instruction such as:

“Please attend the quarterly governance meeting on Tuesday”

does not necessarily interfere with DPO independence.

The EDPB explains that DPOs should not be instructed regarding how to handle matters, what result to reach, how to investigate complaints, whether to consult the supervisory authority, or what interpretation of data-protection law to adopt. (European Data Protection Board)

20. A powerful illustration: the DPO versus the CEO

Imagine:

CEO: “We want to launch facial recognition.”

DPO: “I consider that the proposed processing creates significant risks and recommend a DPIA and further safeguards.”

CEO: “I disagree.”

That disagreement itself is permissible.

But imagine the CEO says:

“Change your written advice to say there is no risk.”

That is entirely different.

The first is management exercising its decision-making authority.

The second is management attempting to control the DPO's independent professional assessment.

Article 38(3) is designed to prevent the second situation.

21. Independence does not mean immunity from accountability

A DPO cannot say:

“Because I am independent, nobody can question me.”

That is incorrect.

The DPO can be expected to:

  • perform their contractual duties;

  • meet reasonable professional standards;

  • maintain expertise;

  • provide competent advice;

  • follow legitimate organisational procedures;

  • respect confidentiality; and

  • comply with applicable law.

Independence protects the substance of the DPO's professional function, not every aspect of the DPO's employment relationship.

22. No dismissal or penalties

The second major protection is that the DPO cannot be dismissed or penalised for performing DPO tasks.

This is necessary because the DPO will sometimes have to deliver unwelcome news.

Imagine the DPO tells the board:

“Your current employee monitoring system is likely disproportionate.”

Management is unhappy.

The next day:

“Your employment is terminated.”

That would fundamentally undermine the purpose of the DPO.

A DPO who fears losing their job whenever they disagree with management cannot function independently.

23. What counts as a “penalty”?

The concept should not be understood narrowly.

A penalty need not be:

“You are fired.”

It may potentially include adverse treatment connected to the DPO's performance.

For example:

  • deliberately denying promotion;

  • reducing benefits;

  • threatening dismissal;

  • removing responsibilities;

  • deliberately damaging career progression;

  • imposing disadvantageous conditions;

  • retaliating against the DPO for raising compliance concerns.

The critical causal question is:

Was the adverse treatment imposed because the person performed their DPO functions?

24. Example: the DPIA disagreement

Consider:

DPO: “The proposed AI system is likely to create a high risk to individuals. I recommend conducting a DPIA.”

Management: “We disagree.”

Management decides not to conduct the DPIA.

The DPO cannot be dismissed merely because they gave that advice.

The fact that management disagrees with the DPO does not convert the DPO's professional advice into misconduct.

The EDPB uses essentially this type of situation to illustrate the protection against penalties. (European Data Protection Board)

25. But the DPO cannot never be dismissed

This is an important examination and practical nuance.

Article 38(3) does not create absolute employment tenure.

Suppose the DPO commits:

  • theft;

  • serious misconduct;

  • harassment;

  • fraud; or

  • another legitimate ground for termination unrelated to DPO activities.

Article 38 does not make the person untouchable.

The legal question is whether the dismissal is genuinely unrelated to the performance of DPO duties.

26. The X-FAB case: an essential authority

The CJEU's decision in X-FAB Dresden, C-453/21 is particularly important for understanding Article 38(3) and 38(6).

The case involved an employee who served as both:

  • chairman of the works council; and

  • DPO.

The German employer dismissed him from his DPO position, raising questions concerning dismissal protection and conflict of interests.

The CJEU examined the relationship between the GDPR's protection of DPO independence and national rules concerning dismissal. (InfoCuria)

The Court held, importantly, that Article 38(3) does not prevent Member States from adopting stronger protection against dismissal, provided that such protection does not undermine the objectives of the GDPR.

This creates an important distinction:

GDPR floor

The GDPR prohibits dismissal or penalties because the DPO performed their tasks.

National law

A Member State may potentially provide additional employment protection.

But that additional protection cannot make it impossible to remove a person who genuinely cannot perform the DPO role independently, including because of a conflict of interests.

27. Direct reporting to the highest management level

The third component of Article 38(3) is direct reporting.

This provision is frequently misunderstood.

It does not necessarily mean:

“The DPO must be a member of the board.”

It means that the DPO must have a direct reporting line to the highest management level.

The reason is obvious.

Suppose the DPO reports:

DPO → Privacy Manager → General Counsel → CEO

and the Privacy Manager can prevent the DPO from communicating with the CEO.

The DPO's independence is weakened.

A better structure might be:

DPO → Board / CEO / highest management level

while the DPO can still collaborate operationally with:

  • Legal;

  • IT;

  • Security;

  • HR;

  • Procurement;

  • Compliance.

The key is that the DPO must retain the ability to communicate directly with the highest management level.

The EDPB confirms that DPOs should directly report to the highest management level. (European Data Protection Board)

28. Why direct reporting matters

Suppose the DPO concludes:

“The organisation is systematically failing to honour data-subject rights.”

The legal department disagrees.

If the legal department controls whether the DPO can reach the CEO, the DPO's escalation capability is compromised.

Article 38(3) prevents this structural bottleneck.

The DPO must be able to say directly to senior management:

“This is my assessment. This is the risk. This is my recommendation. Management should be aware that I disagree.”

This is a fundamental accountability mechanism.

29. Article 38(4): Data subjects can contact the DPO

Article 38(4) changes the DPO from being merely an internal compliance function into an external contact point for individuals.

A data subject may contact the DPO concerning:

  • processing of their personal data;

  • concerns about unlawful processing;

  • exercise of access rights;

  • rectification;

  • erasure;

  • restriction;

  • objection;

  • automated decision-making;

  • other GDPR rights.

This is important because the DPO provides an internal route through which an individual can raise concerns.

30. Example: employee surveillance

Suppose an employee believes:

“My employer is monitoring my private communications.”

Instead of merely contacting HR, the employee can contact the DPO.

The DPO can examine:

  • what monitoring occurs;

  • the purpose;

  • legal basis;

  • proportionality;

  • transparency;

  • access;

  • retention;

  • safeguards.

The DPO may then advise management and, where appropriate, escalate the issue.

31. The DPO is not necessarily the person who executes every data-subject right

This is another crucial distinction.

Suppose a person submits an Article 15 access request.

The DPO does not automatically become the operational processor of every access request.

The organisation may have:

Privacy Operations Team → handles DSARs

while:

DPO → advises and monitors compliance.

The ultimate legal responsibility remains with the controller.

The DPO's role is not to replace the controller's operational teams.

This distinction becomes particularly important in large organisations where thousands of rights requests may be processed.

32. The DPO should be genuinely reachable

There is little value in Article 38(4) if the DPO's contact details are effectively inaccessible.

For example:

“For privacy concerns, contact privacy@example.com.”

But the mailbox is controlled entirely by a department that decides whether the DPO will see the message.

That structure could undermine the purpose of direct contact.

The DPO's contact details should therefore allow individuals to communicate with the DPO or the DPO's team in a meaningful way.

This connects Article 38(4) with:

  • Article 37(7);

  • Article 13;

  • Article 14.

33. Article 38(5): Confidentiality

The DPO is subject to secrecy or confidentiality concerning performance of their tasks, in accordance with Union or Member State law.

This is particularly important because the DPO may receive extremely sensitive information.

Consider a complaint:

“My employer is unlawfully processing my medical information.”

The DPO may learn:

  • the complainant's identity;

  • medical information;

  • employment information;

  • internal communications;

  • security incidents;

  • allegations of misconduct.

The DPO cannot casually circulate this information throughout the organisation.

Confidentiality encourages people to approach the DPO.

34. Confidentiality protects both sides

The obligation protects data subjects, but it can also protect the organisation.

Suppose the DPO is investigating a suspected data breach.

During the investigation the DPO obtains:

  • security architecture;

  • vulnerabilities;

  • trade secrets;

  • confidential contracts;

  • employee information.

The DPO's confidentiality obligations help ensure that access to this information does not become uncontrolled disclosure.

Thus Article 38(5) facilitates another important feature of Article 38(2):

The DPO needs broad access, but that access must coexist with confidentiality.

35. Confidentiality does not prevent communication with the supervisory authority

This is an important nuance.

Confidentiality cannot be interpreted so broadly that it prevents the DPO from performing their other GDPR functions.

Example

the DPO may consult the supervisory authority where appropriate.

Therefore:

“I am bound by confidentiality, so I can never speak to the regulator”

would be an incorrect interpretation.

The WP29 guidance specifically recognised that the confidentiality obligation does not prevent the DPO from contacting or seeking advice from the supervisory authority. (European Data Protection Board)

36. Article 38(6): Other tasks are permitted

The GDPR does something interesting in Article 38(6).

It does not say:

“The DPO may perform no other work.”

Instead, it expressly allows the DPO to perform other tasks and duties.

But there is a condition:

Those other tasks must not create a conflict of interests.

This is where many organisational structures become difficult.

37. The core conflict-of-interest test

The fundamental question is:

Does the additional role cause the DPO to determine the purposes and means of processing personal data?

If yes, there is a serious conflict problem.

Why?

Because the DPO's Article 39 function includes monitoring compliance.

Imagine the same person:

  1. decides what personal data the company will collect;

  2. decides why it will collect it;

  3. decides how it will process it; and

  4. then audits their own decisions as DPO.

The person effectively becomes:

the person who makes the rules + the person who audits compliance with those rules.

That creates a structural conflict.

38. Classic conflict: Head of IT as DPO

Suppose:

Head of IT = DPO.

The Head of IT decides:

  • which employee monitoring software to purchase;

  • what logs to collect;

  • how long logs are retained;

  • who can access them.

The same person then acts as DPO and evaluates:

“Is this processing compliant?”

That is problematic because the person has participated in determining the means of processing.

39. Classic conflict: Head of HR as DPO

Suppose:

HR Director = DPO.

HR determines:

  • employee monitoring;

  • recruitment databases;

  • employee performance systems;

  • health-information processing;

  • disciplinary records.

The same person then audits the legality of those practices.

Again, independence becomes questionable.

40. Classic conflict: Chief Marketing Officer as DPO

Suppose the CMO decides:

“We will use customer behavioural data for targeted advertising.”

The same CMO then becomes DPO and evaluates whether the targeting is GDPR-compliant.

The person would effectively be reviewing their own strategic decision.

That is precisely the type of conflict Article 38(6) seeks to prevent.

The EDPB identifies senior management and functions such as CEO, COO, CFO, HR and IT leadership as positions that can create conflicts where they determine the purposes and means of processing. (European Data Protection Board)

41. But not every additional role creates a conflict

This is equally important.

Article 38(6) does not create an absolute incompatibility between the DPO function and every other organisational role.

Example

a DPO might also perform:

  • certain compliance functions;

  • training;

  • policy work;

  • legal research;

  • governance activities,

provided those functions do not compromise the DPO's independence.

The test is functional rather than purely based on job title.

42. The CJEU's conflict-of-interest test in X-FAB

The CJEU's decision in X-FAB Dresden is particularly important here.

The Court explained that a conflict of interests can arise where other functions would lead the DPO to determine the purposes and means of processing. It also stressed that the assessment is case-specific, taking account of the organisational structure and applicable rules.

This is important because it prevents an overly mechanical rule such as:

“Every employee with a second job is automatically conflicted.”

That is not the GDPR test.

Instead:

What authority does the person actually exercise?

That is the more meaningful question.

43. Why “purposes and means” is the decisive concept

The controller determines the purposes and means of processing.

The DPO monitors whether that processing complies with data protection law.

Therefore, the DPO should not simultaneously occupy a role where they make those fundamental processing decisions.

Think of it as:

Controller function

“We will collect location data because we want to provide location-based recommendations.”

DPO function

“Is this collection lawful, necessary, proportionate and transparent?”

The second function can advise on the first.

But if the same person independently makes the first decision and then audits themselves under the second function, the independence problem emerges.

44. Economic conflicts

Conflict of interest is not limited to formal job titles.

Imagine the DPO owns a substantial part of the company.

The DPO may have an economic incentive to prioritise business success over independent privacy advice.

Similarly, an external DPO consultancy might be financially dependent on a particular client to an extent that creates pressure to provide favourable advice.

This does not mean every financial relationship automatically creates a conflict.

The question is whether the interest could realistically impair independent performance.

Another subtle example concerns external lawyers.

Suppose a law firm acts as:

DPO + litigation counsel

for a company.

Now imagine the company is sued concerning a GDPR violation.

The same firm is asked to:

  1. independently monitor the company's compliance as DPO; and

  2. defend the company in litigation concerning that compliance.

That creates a potential conflict because the DPO's role is one of independent monitoring, whereas litigation counsel's role is to defend the client's interests.

The WP29 guidance identifies representation before courts in data-protection matters as an example where an external DPO may face a conflict. (European Data Protection Board)

46. Article 38 and accountability

Article 38 cannot be understood independently of the GDPR's broader accountability framework.

The controller remains responsible.

The DPO helps the controller:

  • identify risks;

  • monitor compliance;

  • advise management;

  • facilitate DPIAs;

  • train employees;

  • cooperate with regulators;

  • respond to data-subject concerns.

But the existence of a DPO does not allow management to say:

“Our DPO was responsible for GDPR compliance.”

That reverses the GDPR structure.

The controller cannot delegate away its accountability merely by appointing a DPO.

47. A complete practical example

Consider a fictional company:

HealthAI Ltd.

It develops an AI platform for hospitals.

The company appoints a DPO.

Step 1: Product proposal

Engineering proposes:

“We want to collect patient records to improve the AI model.”

The DPO is informed immediately.

This satisfies the principle of timely involvement.

Step 2: DPO investigation

The DPO asks:

  • What is the purpose?

  • What categories of data are used?

  • Is health data involved?

  • What legal basis applies?

  • Is the data necessary?

  • Who will access it?

  • Will it be used for model training?

  • How long will it be retained?

  • Will it leave the EEA?

  • Is a DPIA necessary?

Step 3: Resources

The company gives the DPO:

  • access to engineers;

  • access to security teams;

  • access to architecture documentation;

  • sufficient time;

  • budget for specialist advice;

  • training resources.

This addresses Article 38(2).

Step 4: Independent advice

The DPO concludes:

“A DPIA should be completed before deployment.”

The CEO says:

“We need to launch next week.”

The CEO may disagree.

But the CEO cannot instruct the DPO:

“Change your assessment.”

That engages Article 38(3).

Step 5: Escalation

The DPO reports directly to the board.

The board is therefore aware of the disagreement.

Step 6: Data-subject complaint

A patient complains:

“My medical information was used for AI training without proper information.”

The patient contacts the DPO.

The DPO investigates and advises the organisation.

That illustrates Article 38(4).

Step 7: Confidentiality

During the investigation the DPO learns sensitive information.

The DPO must handle that information confidentially.

That illustrates Article 38(5).

Step 8: Additional role

The company proposes making the DPO:

“Chief AI Product Officer.”

That role would involve determining what patient data is collected and how it is used.

Now Article 38(6) becomes a major problem because the DPO would be determining processing purposes and means while simultaneously monitoring compliance.

48. The deeper conceptual structure of Article 38

Article 38 can therefore be understood as creating six layers of protection around the DPO.

Layer 1: Visibility

The DPO must be involved.

Layer 2: Timing

The DPO must be involved early enough to influence decisions.

Layer 3: Capacity

The DPO must have resources, access and expertise.

Layer 4: Independence

The DPO cannot be instructed on how to perform their DPO functions.

Layer 5: Protection

The DPO cannot be punished for performing those functions.

Layer 6: Structural integrity

The DPO's other duties cannot compromise independence.

These layers work together.

If one is missing, the effectiveness of the DPO may be undermined.

49. The most important distinction: DPO independence vs organisational responsibility

This is probably the single most important conceptual point for an examination or professional analysis.

There are two different questions:

Question 1

Who decides the purposes and means of processing?

Controller/processor.

Question 2

Who independently advises and monitors whether those decisions comply with data-protection law?

DPO.

The DPO should not become the controller.

The controller should not become the DPO.

The whole point of Article 38 is to maintain that separation.

50. Practical compliance model

A mature organisation should therefore create procedures such as:

New processing activity

  1. Business/Product identifies project
  2. DPO automatically notified
  3. DPO assesses whether privacy implications exist
  4. Legal/security/IT/HR provide relevant information
  5. DPO advises
  6. DPIA conducted where necessary
  7. Management makes ultimate decision
  8. DPO records advice and, where appropriate, dissent
  9. Processing begins
  10. DPO monitors compliance
  11. Data subjects can contact DPO
  12. DPO reports material issues to senior management

This is much closer to what Article 38 envisages than merely putting:

“DPO: John Smith”

on the company's privacy policy.

51. Common Article 38 mistakes

Mistake 1: Appointing a DPO but excluding them from projects

Problem: violates the practical requirement of proper and timely involvement.

Mistake 2: Calling the DPO only at the end

Problem: defeats early intervention and privacy by design.

Mistake 3: Giving the DPO no budget

Problem: may undermine the resource requirement.

Mistake 4: Giving the DPO no system access

Problem: prevents effective monitoring.

Mistake 5: Making the DPO report only to the General Counsel

Not automatically unlawful in every organisational configuration, but potentially problematic if the structure prevents direct reporting to the highest management level.

Mistake 6: Telling the DPO what conclusion to reach

Problem: directly undermines independence.

Mistake 7: Punishing the DPO for raising compliance concerns

Problem: potentially violates Article 38(3).

Mistake 8: Making the Head of IT the DPO

Potential conflict if that person determines processing purposes or means.

Mistake 9: Making the DPO responsible for all GDPR compliance

Problem: confuses the DPO's advisory/monitoring role with the controller's accountability.

Mistake 10: Treating confidentiality as preventing regulatory contact

Incorrect. Confidentiality does not eliminate the DPO's ability to perform their GDPR functions.

52. Article 38 and the DPO's relationship with senior management

A well-designed DPO should be neither:

management's servant

nor:

management's adversary.

The DPO is better understood as an independent internal governance function.

The DPO should be able to tell management:

“This is legally acceptable.”

But equally:

“This creates a significant compliance risk.”

And, where necessary:

“I disagree with the proposed approach.”

The organisation is not required to accept every DPO recommendation.

But it must create a structure in which the DPO can make those recommendations freely, competently and without retaliation.

53. Article 38 as a governance mechanism

The deeper significance of Article 38 becomes apparent when it is read together with Recital 97.

Recital 97 describes the DPO as an expert who assists the organisation in monitoring internal compliance and emphasises the need for the DPO to be able to perform their duties independently.

Thus the DPO is not simply:

“the person who answers privacy emails.”

The DPO is part of the organisation's internal privacy governance architecture.

The EDPB's guidance similarly treats the DPO as a discussion partner who should be integrated into relevant organisational decision-making rather than isolated as a purely administrative contact point. (European Data Protection Board)

54. Article 38 and the 2024 EDPB coordinated enforcement action

The importance of Article 38 is also evident from the EDPB's coordinated enforcement work examining the designation and position of DPOs across Europe.

The EDPB identified the position of DPOs as an area requiring improvement and focused specifically on issues surrounding their recognition and ability to perform their functions effectively. (European Data Protection Board)

This is significant because it demonstrates that Article 38 is not merely theoretical.

Supervisory authorities are interested in questions such as:

  • Is the DPO sufficiently resourced?

  • Is the DPO genuinely independent?

  • Is the DPO involved early enough?

  • Can the DPO communicate with senior management?

  • Does the DPO have adequate access?

  • Does the organisation recognise the DPO's role?

  • Are there conflicts of interest?

55. Examination-ready synthesis

If asked:

“Explain the position of the DPO under Article 38 GDPR.”

the strongest answer is not merely:

“The DPO must be independent and properly resourced.”

A better analysis is:

Article 38 creates the institutional safeguards necessary for the effective performance of the DPO's Article 39 functions. It requires the controller or processor to involve the DPO properly and in a timely manner in data-protection matters, thereby ensuring that privacy considerations can influence decisions before processing is implemented. It further requires the organisation to provide adequate resources, access to personal data and processing operations, and opportunities to maintain professional expertise. The DPO must be functionally independent and cannot receive instructions concerning the performance of DPO duties or suffer dismissal or penalties because of those duties. Direct reporting to the highest management level ensures that the DPO can communicate independently with the organisation's ultimate decision-makers. Data subjects must be able to contact the DPO regarding processing and their GDPR rights. At the same time, the DPO is bound by confidentiality. Finally, the DPO may perform other functions, but only provided that these do not create conflicts of interest, particularly by placing the DPO in a position to determine the purposes and means of processing.

The CJEU's X-FAB Dresden judgment reinforces the functional nature of these requirements. It confirms that additional national protection against dismissal may coexist with Article 38, but that the DPO's independence remains central; it also confirms that a conflict of interest may arise where other duties cause the DPO to determine the purposes and means of processing. (InfoCuria)

56. The “golden rule” for Article 38

A useful way to remember the entire provision is:

The DPO must be close enough to the organisation to know what it is doing, powerful enough to question what it is doing, independent enough to say when it is wrong, protected enough to say so without fear, and sufficiently resourced to perform that function effectively.

But there is an equally important second half:

The DPO advises and monitors; the controller remains responsible for deciding the purposes and means of processing and for demonstrating GDPR compliance.

That balance is the essence of Article 38.

Key authorities to remember

  • Article 37 → designation of the DPO.

  • Article 38 → position, independence, resources and safeguards.

  • Article 39 → tasks of the DPO.

  • Recital 97 → expert knowledge, internal compliance and independence.

  • Article 25 → privacy by design, explaining the importance of early DPO involvement.

  • Article 35 → DPIA, where DPO consultation becomes particularly important.

  • Article 5(2) → accountability, supporting documentation of management decisions and disagreements.

  • CJEU, X-FAB Dresden, C-453/21 → functional independence, dismissal protection and conflict of interest.

  • EDPB/WP29 DPO guidance → practical interpretation of involvement, resources, independence, reporting lines and conflicts of interest. (European Data Protection Board)

EDPB: Data Protection Officer guidance and resources

CJEU: X-FAB Dresden, Case C-453/21