Policy Register

Data protection officer and privacy roles

Who the data protection officer is, how they are placed and resourced, what they do, and who else holds privacy responsibilities.

How the register reads it

Also calledDPO appointment, privacy governance
FamilyPrivacy
Document typeRecord. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Folds intoThe regimes accept it folded into the information security roles and responsibilities; when neither is listed, the gap is counted once, under the parent.
Expected ownerThe data protection officer or privacy lead.
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whennever on its own: the register recognises it and names the clauses, but no ticked regime lists it as a separate document (its parent, information security roles and responsibilities, is).
TemplateNo template yet. The clauses below say what the document is expected to contain.

Which standards require it, and what each expects it to contain

3 requiring clauses, 2 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 27701:2025

ISO 27701 5.3 Roles, responsibilities and authorities

Top management shall ensure that the responsibilities and authorities for roles relevant to the privacy information management system are assigned and communicated within the organization. Top management shall assign the responsibility and authority for ensuring that the PIMS conforms to the requirements of this document, and for reporting on the performance of the PIMS to top management. Roles that jurisdictions can require, such as a data protection officer, and the point of contact for PII principals and for customers are addressed by the controls in Annex A (A.3.4).

Evidence an auditor accepts: Role descriptions assigning PIMS responsibilities and authorities; appointment of the person or function responsible for conformity and for performance reporting; communication of responsibilities to those who hold them
Common gap: Responsibilities assigned but never communicated
Source: ISO/IEC 27701:2025

GDPR (Regulation (EU) 2016/679)

GDPR Art. 37 Designation of the data protection officer

Designate a data protection officer where the processing is carried out by a public authority or body, except for courts acting in their judicial capacity, where the core activities consist of processing operations which by their nature, scope or purposes require regular and systematic monitoring of data subjects on a large scale, or where the core activities consist of processing on a large scale of special category data or of personal data relating to criminal convictions and offences. A group of undertakings may appoint a single data protection officer provided that officer is easily accessible from each establishment. Designate on the basis of professional qualities, in particular expert knowledge of data protection law and practice and the ability to fulfil the Article 39 tasks. The officer may be a staff member or fulfil the tasks under a service contract. Publish the officer's contact details and communicate them to the supervisory authority.

Evidence an auditor accepts: The Article 37(1) assessment, made whether or not an officer was appointed, showing how core activities, large scale and regular and systematic monitoring were judged; the designation record, with evidence the contact details were both published and communicated to the supervisory authority; the officer's qualifications and experience measured against the data protection risk the organisation's processing presents
Common gap: No appointment made and no assessment on file, so the absence of an officer cannot be justified when it is challenged
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 39 Tasks of the data protection officer

The data protection officer must at least inform and advise the controller or processor and the employees who carry out processing of their obligations under the Regulation and other Union or Member State data protection provisions; monitor compliance with those provisions and with the controller's or processor's own data protection policies, including the assignment of responsibilities, awareness raising, the training of staff involved in processing operations, and the related audits; provide advice where requested on the data protection impact assessment and monitor its performance under Article 35; cooperate with the supervisory authority; and act as the contact point for the supervisory authority on processing issues including the Article 36 prior consultation, consulting on any other matter where appropriate. In performing these tasks the officer must have due regard to the risk associated with the processing operations, taking account of their nature, scope, context and purposes.

Evidence an auditor accepts: The officer's monitoring plan and its output, such as a review or audit programme with findings and their closure; advice given, recorded with its date and outcome including where it was not followed and by whose decision; training and awareness activity delivered or overseen, with coverage figures for the staff involved in processing operations
Common gap: The officer acting as the compliance delivery function, writing and running the very controls they are meant to independently monitor
Source: GDPR (Regulation (EU) 2016/679)

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Data protection impact assessment procedure · Data protection policy