Cyber Risk Compendium

Data Protection Officer (DPO)

The Data Protection Officer (DPO) oversees the organisation's compliance with data protection law — see for how this relates to information security more broadly. The DPO advises on and monitors the handling of , supports data protection impact assessments, and acts as a contact point for data subjects and supervisory authorities.

Unlike a Risk owner, the DPO does not usually make the risk-acceptance decision themselves — the role is designed to be independent so it can challenge and advise management, which is why many regulations (e.g. GDPR, nDSG) restrict a DPO from also holding operational data-processing responsibilities that would create a conflict of interest.