The GDPR makes it clear that it is the controller, not the DPO, who is required to ‘implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation’ (Article 24(1)). Data protection compliance is a corporate responsibility of the data controller, not of the DPO.
However, the data controller benefits from the DPO’s expertise and insights as a counsel. The DPO therefore is accountable to the company’s top management, including the highest management circles. CEO, CFO, CISO, CLO and other chief officers shall keep in mind the advice of the DPO and make sure that the DPO possesses all necessary resources to provide them with the most relevant information and assessment results.
DPO is closely linked to the public image of the company, as the DPO is often a first contact of a dissatisfied user or worried tech journalist. Choose your DPO wisely.