What a DPO does: duties, independence and limits

What a Data Protection Officer (DPO) does: the main duties, why the role must be independent and what is not the DPO's responsibility.

The Data Protection Officer, or DPO, is the person who helps an organization follow the rules on personal data. The role is described in the GDPR, with which Albanian Law 124/2024 is aligned, and it is often misunderstood: the DPO is neither the company lawyer nor the head of IT.

The main duties

  • Informs and advises management and staff about their obligations.
  • Monitors whether the organization follows the rules and its own policies.
  • Gives an opinion on impact assessments (DPIAs) and follows up on them.
  • Acts as the contact point for the supervisory authority.
  • Acts as the contact point for people who want to exercise their rights.

Why the role must be independent

The DPO has to be able to say what management does not want to hear. That is why the DPO takes no instructions on how to carry out the duties, reports to the highest level of management, and is not penalized for performing them.

Independence also means no conflict of interest. Someone who decides how data is processed, such as the head of IT, marketing or HR, cannot at the same time oversee that processing as DPO.

What is not the DPO's job

  • The DPO does not make the processing decisions: the organization does.
  • The DPO does not carry legal responsibility for compliance: that stays with the controller.
  • The DPO does not write every document alone: the role advises and checks, while departments do their own work.

A DPO works well when involved early, before a system is bought or a project starts, and when given enough time and resources for the role.

Related serviceData Protection Officer (DPO)Outsourced DPO: advice, monitoring and a contact point for the Commissioner.Learn more

Let's talk about your next engagement.

Tell us about your engagement — we typically respond within one business day.

WhatsApp +355 69 522 4573