The data protection officer (DPO) has to report to the highest management level and cannot simultaneously perform functions related to IT auditing or security in order to avoid conflicts of interest. Does your organisation comply with these rules? 

On 18 December 2024, the President of the Personal Data Protection Office (Polish DPA) issued an administrative decision in case DKN.5112.14.2022, in which he stated, among other things, that the controller had violated Article 38(3) of the GDPR of the GDPR, consisting in the controller not ensuring that the data protection officer reports directly to the highest management of the controller and does not receive instructions regarding the performance of his or her tasks. For this violation, the President of the Personal Data Protection Office imposed an administrative fine in the amount of PLN 261,918.00. 

This decision emphasises the importance of the key responsibilities of data controllers in ensuring the independence and appropriate working conditions for the DPO. According to Article 38(3) of the GDPR, the data controller is obliged to ensure that the DPO does not receive instructions regarding the performance of his or her tasks and reports directly to the highest management of the controller. In the case in question, it was found that this provision had been violated because the DPO did not report directly to the company’s management, which could have limited his independence and effectiveness. During his employment with the controller, the DPO also held the position of IT auditor or security specialist and reported directly to the director of the security department. 

This decision emphasises the necessity of an appropriate placement of the DPO in the organisational structure of the company. Direct subordination to the highest management ensures the DPO’s independence and the possibility of effective monitoring of the company’s compliance with data protection regulations. The controller is also responsible for ensuring that the DPO does not receive instructions regarding the performance of his or her duties. 

Summary: 

In connection with the decision of the President of the Personal Data Protection Office, each entity in which the DPO has been appointed should take the following actions: 

  • verify and, if necessary, correct the position of the DPO in the organisational structure; 
  • verify whether the DPO performs additional tasks that could cause a conflict of interest; 
  • adapt internal procedures to the principles of the DPO’s functioning and their compliance with the positions of the Polish DPA; 
  • take corrective action in case of detection of activities not compliant with Article 38(3) of the GDPR, in order to avoid financial penalties.