Data protection officer
Keeps an organisation within data protection law, advises on it and reports directly to the top.
Or does one of these fit you better?

What does a data protection officer do?
A data protection officer, or DPO, makes sure an organisation handles personal data within the law. The role is set out in the GDPR itself: the DPO informs and advises the organisation and its staff, monitors compliance, advises on data protection impact assessments, and is the contact point for the supervisory authority and for the people whose data is processed.
The GDPR also protects the position. A DPO reports to the highest level of management, cannot be instructed on how to carry out the tasks, and cannot be dismissed or penalised for performing them. Public authorities must appoint one, and so must organisations whose core activities involve large-scale monitoring of people or large-scale processing of sensitive data.
How do you become a data protection officer?
- Start from your backgroundLaw, compliance, IT, security or risk: all of them lead here. What matters is that you can apply the rules, not where you learned them.
- Get certifiedThe CIPP/E shows you know the law, the CIPM that you can run the programme. Together they are what employers look for on a CV.
- Take on privacy work nowRecords of processing, impact assessments, access requests, breach logs: take them on in your current role and you build the experience a DPO needs.
- Land your first DPO roleDeputy DPO, DPO at a smaller organisation, or external DPO for several clients: each is a common first step.
Which certifications does a data protection officer need, and in which order?
- 1CIPP/EEuropean data protection law: the GDPR, the ePrivacy rules and how the authorities apply them.About a month at three hours a day
- 2CIPMRunning a privacy programme: governance, the operational life cycle, assessment and response.About three weeks at three hours a day, less with programme experience.
Already hold the CIPP/E? Start with the CIPM.
The GDPR does not require a certificate. It requires expert knowledge of data protection law and practice, and the CIPP/E with the CIPM is the most direct way to show both: the law, and running the programme.
What skills does a data protection officer need?
Not a summary of the GDPR but its articles, the guidelines and the decisions that apply them.
Deciding what matters most when everything is a risk, and saying so with reasons.
Turning a legal requirement into something a product team or a board can act on.
Giving advice the organisation does not want to hear, and standing by it.
The GDPR does not ask for a certificate. Employers do.
Start CIPP/E freeWhere does a data protection officer work?
A staff member in the organisation itself. Common in public authorities, healthcare, finance and technology companies.
A DPO under a service contract, often from a consultancy, serving several organisations at once. The GDPR allows it explicitly.
Allowed, as long as the other tasks do not create a conflict of interest. A DPO cannot decide on the purposes and means of the processing they monitor.
What does a data protection officer earn?
Pay depends on the country, the sector, your experience and whether the role is in-house or external. The ranges below come from published salary guides; verify them against the market you are in.
Sources: Morgan McKinley, salary guide 2026 (Ireland); Legiscope, GDPR DPO salary guide 2026 (Germany); French Compliance Institute, DPO salary 2026 (France).
Questions about the Data protection officer role
Does every organisation need a DPO?
No. Public authorities must appoint one, and so must organisations whose core activities involve large-scale, regular and systematic monitoring of people, or large-scale processing of special categories of data or data about criminal convictions. Many others appoint one voluntarily.
Do I need a law degree?
No. The GDPR asks for expert knowledge of data protection law and practice, not for a degree. DPOs come from law, compliance, security and IT.
Can a DPO be external?
Yes. The GDPR allows the DPO to be a member of staff or to work under a service contract, and a group of companies can share one DPO if each can reach them easily.
Is certification required?
Not by law. The certification is how you show the expert knowledge the GDPR asks for, and it is what employers see first on a CV.
Can a DPO have other tasks?
Yes, as long as they do not create a conflict of interest. A DPO cannot be the person who decides why and how personal data is processed, so combining the role with, say, head of IT or head of marketing rarely works.
Can a DPO be dismissed?
Not for doing the job. The GDPR forbids dismissing or penalising a DPO for performing their tasks. Dismissal for other reasons follows national employment law.
Your path starts with the CIPP/E
Your first lesson is free. No card.
