Combining the DPO and Compliance Officer roles is common. But recent guidance from the CNIL is a useful reminder that job titles matter less than the actual decision-making power exercised over personal data processing.
In many organisations, Privacy and Compliance sit within the same team, and are sometimes entrusted to the same person.
The GDPR does not prohibit this combination.
But a DPO must not perform other duties that compromise their independence or place them in a position where they effectively become judge and party.
The issue is not the title, but the role actually performed
The key question is whether, in their other role, the DPO participates in determining the purposes or means of personal data processing.
This is where the DPO / Compliance Officer combination deserves particular attention.
The Compliance function is not always limited to advisory or oversight activities. It may also involve:
- selecting or implementing a whistleblowing tool;
- designing TPRM or third-party due diligence processes;
- implementing risk mapping or internal control tools;
- defining the data collected, scoring criteria, access rights or workflows;
- organising conflicts of interest, gifts and hospitality, or sanctions screening processes;
- determining certain retention, handling or monitoring arrangements.
In these situations, the Compliance Officer may directly participate in designing or operating processing activities that they would later be expected to review in their capacity as DPO.
The more operational the Compliance function becomes in the design and configuration of these systems, the more important it is to assess whether the DPO retains genuine independent oversight.
Does this mean the two roles are automatically incompatible? No.
The combination can remain workable where the Compliance function retains an advisory, supervisory or control role and operational decisions are taken by other functions.
But the greater the Compliance Officer’s decision-making authority over the design and operation of processing activities, the greater the risk of a conflict of interest.
The right question is therefore not: “Can one person be both DPO and Compliance Officer?”
But rather: “On which processing activities does the Compliance Officer actually make decisions, and can the DPO then review those decisions independently?”
What should organisations check?
For organisations combining both roles, three checks are particularly useful:
- identify the processing activities over which the Compliance Officer has genuine decision-making authority;
- distinguish clearly between design, decision-making, advisory and oversight responsibilities;
- where necessary, put in place a recusal mechanism or another appropriate remediation measure for conflicting areas.
The analysis should therefore go beyond job descriptions or organisational charts.
To go further
CNIL – DPOs and conflicts of interest. The CNIL reiterates that a DPO may perform other duties, provided that these do not compromise their independence or place them in a situation of conflict of interest.
Read the CNIL article
The practical approach
Assess the DPO / Compliance combination by looking at the decisions actually taken for each processing activity.