Certifications AIGP CIPP/E CIPP/US CIPM CIPT All certifications Career plan How it works Pricing Log in Start free
Career plan

Head of privacy

Owns privacy across the organisation: people, programme and budget.

The pathCIPP/E CIPM
How longAbout two monthsat three hours a day
What it paysUp to €180,000a year

Or does one of these fit you better?

Data protection officerCIPP/E CIPMUp to €150,000About two monthsAI governance managerCIPP/E AIGPUp to €120,000About two and a half monthsPrivacy counselCIPP/E CIPP/USUp to €140,000About two monthsPrivacy engineerCIPT CIPP/EUp to €110,000About two monthsPrivacy managerCIPM CIPP/EUp to €100,000About two months
AI-generated image - a head of privacy stands in front of her team
The job

What does a head of privacy do?

A head of privacy owns privacy for the whole organisation. The role sets the strategy, leads the privacy team, runs the programme and its budget, and answers to the board for how the organisation handles personal data.

It is a management role, which is what sets it apart from the data protection officer. The data protection officer advises and monitors; the head of privacy decides. In larger organisations the two sit side by side.

How to become one

How do you become a head of privacy?

  1. Build depth in privacyMost heads of privacy were privacy managers, privacy counsel or data protection officers first. The role rests on years of doing the work.
  2. Get certifiedThe CIPP/E shows you know the law, the CIPM that you can run the programme. At this level employers expect both.
  3. Lead somethingA programme, a team or a budget. Take ownership of one in your current role, and of the results it produces.
  4. Move upHead of privacy at a mid-sized organisation, or deputy in a large one: each is a common first step.
The path

Which certifications does a head of privacy need, and in which order?

  1. 1
    CIPP/EEuropean data protection law: the GDPR, the ePrivacy rules and how the authorities apply them.
    About a month at three hours a day
  2. 2
    CIPMRunning a privacy programme: governance, the operational life cycle, assessment and response.
    About three weeks at three hours a day, less with programme experience.

Already hold the CIPP/E? Start with the CIPM.

The CIPP/E gives you the law your programme has to meet, and the CIPM the way to run it. At this level employers expect both.

Skills

What skills does a head of privacy need?

Strategy

Deciding what the programme is for and what it will not do, and tying both to what the organisation is trying to achieve.

Leading people

Building a team, and getting the work done through colleagues in legal, security, product and HR who do not report to you.

The numbers

A budget, a business case and metrics that show the board what the programme delivers.

Standing before the board

Explaining risk in plain terms to the people who decide, and being clear about what you recommend.

The GDPR does not ask for a certificate. Employers do.

Start CIPP/E free
Where they work

Where does a head of privacy work?

Large organisations

Where privacy has its own team and its own budget, often reporting to the general counsel or the chief risk officer.

Regulated sectors

Finance, healthcare, telecommunications and technology, where personal data is at the centre of the business.

Groups and multinationals

Several countries and several laws, with local privacy leads who report in.

What it pays

What does a head of privacy earn?

Pay depends on the country, the sector, your experience and whether the role is in-house or external. The ranges below come from published salary guides; verify them against the market you are in.

Ireland€130,000 to €160,000 with 3 to 5 years; €160,000 to €180,000 with more than 5
Germany€131,000 on average; €163,000 at senior level
NetherlandsUp to €147,000

Sources: Morgan McKinley, salary guide 2026 (group chief privacy officer, Dublin); ERI SalaryExpert, 2026 (chief privacy officer, Germany); ERI SalaryExpert, 2026 (Netherlands).

Up to€180,000a year
Questions

Questions about the Head of privacy role

Is a head of privacy the same as a data protection officer?

No. The data protection officer is a role set out in the GDPR: independent, advising and monitoring. The head of privacy is a management role that decides how the organisation handles personal data and runs the programme that does it.

Can one person be both?

Usually not. A data protection officer must be free of conflicts of interest, and a head of privacy who decides how personal data is used would be checking their own decisions.

Is it the same as a chief privacy officer?

In practice, yes. Larger organisations tend to use chief privacy officer, others head of privacy or privacy director. The work is the same: owning privacy for the whole organisation.

Do I need to be a lawyer?

No. Many heads of privacy are lawyers, and many come from compliance, security or risk. What the role asks for is command of the law and the ability to run a programme.

Which certification first?

The CIPP/E if you need the legal foundation, the CIPM if you already have it. The two together are what the role asks for.

Your path starts with the CIPP/E

Your first lesson is free. No card.