2.6 Structuring the Privacy Team: DPO, CPO, Representatives & Resourcing

Key Takeaways

  • GDPR Article 37 makes a DPO mandatory in three cases: public authority processing, core activities requiring regular and systematic large-scale monitoring, and core activities involving large-scale special-category or criminal-conviction data.
  • Articles 38-39 protect DPO independence: no instructions on how to perform the role, no dismissal or penalty for performing it, direct reporting to the highest management level, and no conflicting duties.
  • A CPO is a business leadership role that owns the program and budget; a DPO is a statutory advisory and monitoring role. One person can hold both only if no conflict of interest exists.
  • Article 27 requires a written-mandated EU representative for non-EU controllers caught by Article 3(2), with a parallel UK representative requirement under the UK GDPR.
  • Privacy team capacity should scale with processing complexity — jurisdictions, systems, vendors, rights volume — not with total headcount, and a privacy champion network extends reach without extending headcount.
Last updated: August 2026

Roles the Exam Expects You to Tell Apart

Performance indicator I.A.4define the structure of the privacy team — is tested less as an org-chart question than as a role-confusion question. The CIPM repeatedly offers distractors that assign a statutory duty to a business role, or a business decision to a statutory one.

DPO versus CPO versus privacy manager

RoleNatureCore dutyWho can hold it
Data Protection Officer (DPO)Statutory role under GDPR Arts. 37-39Inform and advise, monitor compliance, advise on DPIAs, cooperate with and act as contact point for the supervisory authorityEmployee or external contractor; must be independent and conflict-free
Chief Privacy Officer (CPO)Business leadership roleOwns the privacy program, its strategy, budget, staffing and executive relationshipsAn executive; may sit over the DPO
Privacy managerOperational role — the CIPM's own subjectRuns the operational life cycle: assessments, vendor reviews, rights workflows, incidents, metricsReports into the CPO or DPO
Privacy champion / liaisonPart-time embedded roleExtends the program into a business unit; first-line triage and escalationA business-unit employee, not a privacy specialist

The most common exam trap is treating the DPO as "the person in charge of privacy." A DPO advises and monitors; the DPO does not own the decisions being monitored. That is precisely why the roles must be separable.

When a DPO is mandatory

GDPR Article 37(1) requires a DPO in exactly three circumstances:

  1. Processing is carried out by a public authority or body (except courts acting judicially).
  2. Core activities consist of processing operations that, by their nature, scope or purposes, require regular and systematic monitoring of data subjects on a large scale.
  3. Core activities consist of large-scale processing of special categories of data (Art. 9) or personal data relating to criminal convictions and offences (Art. 10).

Two words carry the weight. Core activities means the processing is part of what the organization does to achieve its purpose — a hospital's patient records are core; the hospital's own payroll is not. Large scale is not defined numerically in the regulation; regulators look at the number of data subjects, the volume and range of data, duration, and geographic extent. Note also that member-state law can impose additional DPO requirements, and Germany's threshold is famously broader than the GDPR baseline.

DPO independence — the protections that get tested

Article 38 is where scenario items live:

  • The DPO must be involved properly and in a timely manner in all issues relating to personal data protection.
  • The organization must provide the resources and access necessary, and support the DPO's ongoing expertise.
  • The DPO must receive no instructions regarding the exercise of their tasks.
  • The DPO cannot be dismissed or penalised for performing their tasks.
  • The DPO reports directly to the highest management level.
  • The DPO may hold other tasks and duties only where they create no conflict of interest.

That last clause is the classic item. A DPO who is also the Head of IT, Head of Marketing, CISO, or General Counsel is determining the purposes and means of processing they are supposed to monitor. Regulators have fined organizations over exactly this conflict. The safe structures are a standalone DPO, or an outsourced/fractional DPO for smaller organizations that cannot justify a full-time hire.

Representatives for organizations outside the EU

Article 27 requires a controller or processor not established in the Union but caught by Article 3(2) to designate, in writing, a representative established in a member state where the relevant data subjects are. The representative is the addressee for supervisory authorities and data subjects, must be identified in the privacy notice, and must maintain a copy of the record of processing activities. The narrow exemptions cover occasional processing that does not involve large-scale special-category data and is unlikely to result in risk, and public authorities. The UK GDPR imposes a parallel UK-representative requirement, so a US company selling into both the EU and the UK generally needs two representatives, not one. A representative is not a DPO — the roles, duties and appointment tests are entirely separate.

Sizing and extending the team

Privacy capacity tracks processing complexity, not headcount. The practical drivers are the number of jurisdictions, the number of in-scope systems, the vendor population, monthly rights-request volume, the release cadence that needs assessment, and the M&A pipeline.

Because headcount rarely keeps pace, the standard answer on the exam is a privacy champion network: named part-time liaisons embedded in each business unit, given targeted training, a defined escalation path, and time formally allocated by their manager. Champions triage early, flag new processing before launch, and localize training. The three failure modes are equally testable — appointing champions without allocating time, without training them, or without an escalation route to a real decision-maker.

Test Your Knowledge

A multinational retailer appoints its Head of IT Security as Data Protection Officer, reasoning that the role already understands the systems best. What is the most significant problem?

A
B
C
D
Test Your Knowledge

A US-based e-commerce company with no EU establishment ships to customers in France and Germany and tracks their browsing behaviour. It has appointed an EU representative under Article 27. What else does the exam expect the privacy manager to recognise?

A
B
C
D