The appointment of a Data Protection Officer (DPO) is one of the most visible structural requirements introduced by the General Data Protection Regulation (GDPR). Yet, despite its prominence, the DPO role is often misunderstood. Many organisations focus on whether a DPO is required under Article 37, but far less attention is paid to what the DPO must actually do and how the organisation must enable the role once appointed.
Articles 38 and 39 of the GDPR sit at the core of this analysis. Together, they establish not only the tasks of the DPO but also the institutional guarantees that ensure the DPO can perform those tasks independently, effectively, and without undue influence. Regulators across Europe consistently assess Articles 38 and 39 when investigating GDPR compliance, and deficiencies in DPO positioning or resourcing are frequently cited as indicators of broader governance failures.
This page explains, in detail, what the GDPR requires of a DPO, how Articles 38 and 39 operate together, and what businesses must do to ensure the role is legally compliant in practice.
Articles 38 and 39: Two Halves of a Single Framework
Article 39 defines what the DPO does. It sets out a minimum list of tasks that must be assigned to the DPO in all organisations that appoint one.
Article 38 defines how the DPO must be positioned within the organisation in order to carry out those tasks. This includes independence, access to information, protection from retaliation, and direct access to senior management.
Regulators do not assess these provisions in isolation. A DPO who is nominally appointed but lacks independence or resources is considered non-compliant just as much as an organisation that fails to assign the required tasks.
Article 38 GDPR: Position of the Data Protection Officer
Article 38 is concerned entirely with organisational design and governance. Its purpose is to ensure that the DPO is not a symbolic role, but a function capable of exercising independent judgment—even where that judgment conflicts with commercial or operational preferences.
Proper and Timely Involvement in All Data Protection Matters
The GDPR requires that the controller and processor ensure that the DPO is involved properly and in a timely manner in all issues relating to the protection of personal data.
This is one of the most frequently misunderstood requirements. “Proper and timely involvement” means the DPO must be consulted before decisions are finalised, not after systems are built, vendors contracted, or processing rolled out. In practice, this includes involvement in the design of new products or services involving personal data, decisions on data retention, profiling, or large-scale analytics, vendor selection and processor onboarding, and the handling of data subject rights requests and personal data breaches.
Late involvement undermines the GDPR’s principle of data protection by design and is a recurring theme in regulatory enforcement.
Resources, Access, and Organisational Support
Article 38 requires organisations to support the DPO by providing the resources necessary to carry out their tasks, access to personal data and processing operations, and support for maintaining expert knowledge.
This obligation goes well beyond appointment. Regulators expect sufficient time to perform DPO duties (not a “side role”), access to systems, documentation, and personnel, budget for training, tools, and where necessary, external advice, and administrative support proportionate to organisational complexity.
A DPO who lacks access or resources is effectively prevented from fulfilling Article 39 duties, creating structural non-compliance.
Independence and Freedom from Instruction
A cornerstone of Article 38 is that the DPO must not receive instructions regarding the exercise of their tasks. This does not mean the DPO operates outside the organisation’s governance structure. It means management cannot tell the DPO what conclusions to reach, the DPO cannot be pressured to approve risky processing, and disagreement with management must not be penalised.
Regulators view independence as essential to accountability. Where DPOs are managed by operational teams whose success depends on data exploitation, independence is often compromised.
Protection from Dismissal or Penalty
Article 38 expressly prohibits dismissal or penalisation of the DPO for performing their tasks. This protection is not limited to termination. It extends to demotion, performance-based penalties, exclusion from decision-making, and indirect retaliation for raising concerns. Supervisory authorities increasingly treat adverse treatment of DPOs as a serious governance failure.
Direct Reporting to the Highest Management Level
The DPO must report directly to the highest management level of the controller or processor. In practice, this usually means the board, the chief executive officer, or an equivalent executive body. The requirement is intended to ensure that data protection risks are escalated to those with authority to act. Burying the DPO several layers down the hierarchy is inconsistent with Article 38, even if informal access exists.
Accessibility to Data Subjects
Data subjects must be able to contact the DPO on all matters relating to the processing of their personal data and the exercise of their rights. This makes the DPO a visible, external-facing accountability function, not merely an internal compliance advisor. Organisations must ensure that contact details are published and that the DPO can respond meaningfully to enquiries.
Confidentiality Obligations
The DPO is bound by secrecy or confidentiality in accordance with Union or Member State law. This does not mean the DPO is exempt from internal reporting duties. Rather, it protects communications with data subjects and sensitive assessments from inappropriate disclosure.
Avoiding Conflicts of Interest
Although the DPO may perform other tasks, the organisation must ensure those tasks do not result in conflicts of interest. Regulators have consistently found conflicts where DPOs also hold roles such as head of IT, chief information security officer, head of HR, or marketing leadership positions. These roles often determine the purposes and means of processing, which is incompatible with DPO independence.
Article 39 GDPR: Tasks of the Data Protection Officer
Article 39 defines the substantive obligations of the DPO. These tasks are mandatory and apply regardless of organisational size or sector.
Advising on GDPR and Data Protection Obligations
The DPO must inform and advise the controller, processor, and employees who carry out processing of their obligations under the GDPR and other applicable data protection laws. This advisory function is continuous, not reactive. It includes explaining legal requirements in operational terms, advising on lawful bases for processing, guidance on consent, transparency, and data subject rights, and supporting compliance with national implementing laws. Importantly, advising does not mean deciding. The DPO is accountable for advice, not for business outcomes.
Monitoring Compliance with the GDPR
Monitoring compliance is one of the most demanding Article 39 duties. It includes oversight of internal policies and procedures, assignment of responsibilities, staff awareness and training, and internal audits relating to personal data processing. Regulators expect DPOs to adopt a risk-based monitoring approach, focusing attention on higher-risk processing activities rather than attempting exhaustive oversight of every operation.
Data Protection Impact Assessments (DPIAs)
Under Article 39, the DPO must provide advice where requested regarding DPIAs and monitor their performance pursuant to Article 35. This does not make the DPO the “owner” of the DPIA. Instead, the DPO must advise on whether a DPIA is required, review methodology and conclusions, assess whether risks are properly addressed, and document dissent where recommendations are not followed. Supervisory authorities consistently review the DPO’s involvement in DPIAs during investigations.
Cooperation with Supervisory Authorities
The DPO must cooperate with supervisory authorities. This task reflects the DPO’s role as a bridge between organisation and regulator. It includes supporting responses to regulatory inquiries, facilitating inspections and audits, and advising management on regulator expectations. The DPO’s independence is particularly important here, as they may need to communicate concerns that are uncomfortable for management.
Acting as Contact Point for Supervisory Authorities
Finally, the DPO must act as the contact point for supervisory authorities on processing issues, including prior consultation under Article 36. This responsibility reinforces the DPO’s external accountability function and requires credibility, legal competence, and organisational authority.
Risk-Based Performance of Tasks
Article 39 requires the DPO to have due regard to the risk associated with processing operations, taking into account their nature, scope, context, and purposes. This explicitly rejects a “checklist compliance” approach. High-risk processing—such as large-scale monitoring, sensitive data processing, or automated decision-making—requires deeper and more frequent DPO involvement.
What Articles 38 and 39 Mean for Businesses in Practice
Together, Articles 38 and 39 transform the DPO into a governance function, not a technical specialist or administrative role. Businesses must design reporting structures around DPO independence, allocate resources and authority, embed early consultation into decision-making, and accept that the DPO may challenge strategic initiatives. Failure to do so is increasingly treated by regulators as a systemic GDPR violation.
Conclusion
Articles 38 and 39 GDPR define the modern Data Protection Officer as an independent, well-resourced, and deeply embedded governance function. The DPO is not responsible for compliance outcomes, but they are responsible for oversight, advice, and accountability.
Organisations that view the DPO as a procedural requirement—rather than a strategic control—face significantly higher enforcement risk. In contrast, businesses that implement Articles 38 and 39 faithfully benefit from clearer governance, reduced compliance risk, and stronger regulatory credibility.
