Getting the Data Protection Officer Role Right: Lessons From The GDPR And A Recent Fine

Under the GDPR, the role of the Data Protection Officer (DPO) plays a central part in how organisations are expected to govern data. Ignoring the rules on designation, independence, and support doesn’t just create theoretical risks. It can lead to penalties worth millions.

What the GDPR Requires: Designation, Position, and Responsibilities of the DPO

Not every organisation needs to appoint a Data Protection Officer, but when a business’s core activities involve regular and systematic monitoring of people or the large-scale processing of sensitive data, a DPO is mandatory. The same applies to public authorities and bodies. Even when the appointment is voluntary, the same obligations around structure and independence apply.

As a result, organisations must select the DPO based on professional experience and expert knowledge of data protection law to ensure they can fulfill the role effectively. But it’s not enough to just hire someone with the right CV. The GDPR and the former Article 29 Working Party guidelines make it clear that the DPO’s position within the organisation must allow them to do the job effectively.

That means:

  • They must be involved early in decisions affecting personal data, not looped in after the fact.
  • They need real independence. The DPO must carry out their duties without interference, remain protected from dismissal for performing those duties, and report directly to the highest management level, which is typically the board of directors or the CEO, depending on the organisation’s structure.
  • They must be adequately resourced. That includes time, staff, budget, and access to relevant information. The resources must be adequate and proportional. The more complex or sensitive the processing is, might require more resources to adequately comply with its function and obligations.
  • They must be visible. Their contact details should be easy to find, not just internally, but publicly available so data subjects and regulators can reach them. A good practice is to include the contact details of the DPO in the privacy notice and internal policies and procedures so that the DPO is accessible to the company and the Data Subjects.
  • They must be free from conflicts of interest. This becomes especially important when the DPO holds additional roles within the organisation. After all, a person cannot both determine how data is processed and be responsible for overseeing that same processing.

The guidelines also stress that having a DPO is not a box-ticking exercise. Organisations need to define the DPO’s role clearly and ensure they integrate it into the actual processes used to manage personal data. In particular, this means keeping a record of the assessment performed in order to determine the necessity of a DPO.

The Telenor Case – A Master Class In What Not To Do

In March 2025, the Norwegian Data Protection Authority (Datatilsynet) fined telecom provider Telenor ASA NOK 4 million (€351,000 approximately) for failing to properly structure and support its Data Protection Officer function (official press release here).

The case followed a strategic audit launched back in 2021, as part of the DPA’s broader effort to assess how large organisations implement core GDPR obligations. During the investigation, the DPA found multiple weaknesses in how Telenor had appointed, positioned, and resourced its DPO. Despite having formal documents in place, these deficiencies were neither isolated nor accidental. They reflected a broader lack of internal control and accountability, particularly in how the organisation ensured the independence and visibility of the DPO role.

The authority found that Telenor had violated several key provisions of the GDPR:
Articles 37(7), 38(2), 38(3), 24(1), and 24(2). Which is related to noncompliance with regard to the position, appointment, tasks of the DPO, and the responsibilities of the controller.

Lessons From The Case

  • No clear reporting line. The DPO didn’t report directly to the board or CEO. Instead, they answered to mid-level roles such as the Chief People & Sustainability Officer, which the DPA found did not meet the threshold for “highest management level.” This undermined the DPO’s ability to influence decision-making at the top.
  • Insufficient resources. The role was set up as a 50% part-time position. But the DPO reported working significantly more than that. Often on reactive issues, with little time for strategic input. Requests for more support were made, but not acted on. The DPA said that it showed a clear failure to meet the obligations under Article 38(2).
  • Potential conflict of interest. The DPO was also a member of the legal team and used the same signature and email for both roles. This made it unclear to staff whether advice was coming from the legal department or the DPO. The concern went beyond confusion. The issue focused on the DPO’s independence, as their other duties may have involved advising on the same processing activities they were responsible for overseeing.
  • Limited visibility. Telenor had only published the DPO’s contact details on their internal network, arguing that most processing affected employees. But the GDPR requires this information to be public. The DPA noted that all data subjects, internal or external, must be able to easily reach the DPO.
  • Lack of documentation and clarity. The DPA described Telenor’s internal approach as informal and poorly documented. Having slides or job descriptions stating that the DPO “could escalate issues” was not enough. What matters is whether this actually happens and whether it’s clear to the organisation how, when, and to whom.

The violations of Article 24 were perhaps the most structural: Telenor failed to show it had implemented appropriate organisational measures to ensure and demonstrate compliance. That’s the bigger message here. Appointing a DPO is only one piece of the puzzle. The role must be functional, protected, and documented in a way that proves real accountability.

Symmetry Compliance

This case clearly reminds us that simply appointing a DPO isn’t enough. What truly matters is how your organisation embeds, supports, and protects the role. If you’re reviewing your DPO setup or need guidance to ensure you’re aligned with both the GDPR and regulator expectations, contact us.  At Symmetry, we help organisations turn formal compliance into real accountability.

2025-03-26T13:30:23+01:00March 26th, 2025|Data Protection, DPO, GDPR, Uncategorized|