2.6 Structuring the Privacy Team: DPO, CPO, Representatives & Resourcing
Key Takeaways
- GDPR Article 37 makes a DPO mandatory in three cases: public authority processing, core activities requiring regular and systematic large-scale monitoring, and core activities involving large-scale special-category or criminal-conviction data.
- Articles 38-39 protect DPO independence: no instructions on how to perform the role, no dismissal or penalty for performing it, direct reporting to the highest management level, and no conflicting duties.
- A CPO is a business leadership role that owns the program and budget; a DPO is a statutory advisory and monitoring role. One person can hold both only if no conflict of interest exists.
- Article 27 requires a written-mandated EU representative for non-EU controllers caught by Article 3(2), with a parallel UK representative requirement under the UK GDPR.
- Privacy team capacity should scale with processing complexity — jurisdictions, systems, vendors, rights volume — not with total headcount, and a privacy champion network extends reach without extending headcount.
Roles the Exam Expects You to Tell Apart
Performance indicator I.A.4 — define the structure of the privacy team — is tested less as an org-chart question than as a role-confusion question. The CIPM repeatedly offers distractors that assign a statutory duty to a business role, or a business decision to a statutory one.
DPO versus CPO versus privacy manager
| Role | Nature | Core duty | Who can hold it |
|---|---|---|---|
| Data Protection Officer (DPO) | Statutory role under GDPR Arts. 37-39 | Inform and advise, monitor compliance, advise on DPIAs, cooperate with and act as contact point for the supervisory authority | Employee or external contractor; must be independent and conflict-free |
| Chief Privacy Officer (CPO) | Business leadership role | Owns the privacy program, its strategy, budget, staffing and executive relationships | An executive; may sit over the DPO |
| Privacy manager | Operational role — the CIPM's own subject | Runs the operational life cycle: assessments, vendor reviews, rights workflows, incidents, metrics | Reports into the CPO or DPO |
| Privacy champion / liaison | Part-time embedded role | Extends the program into a business unit; first-line triage and escalation | A business-unit employee, not a privacy specialist |
The most common exam trap is treating the DPO as "the person in charge of privacy." A DPO advises and monitors; the DPO does not own the decisions being monitored. That is precisely why the roles must be separable.
When a DPO is mandatory
GDPR Article 37(1) requires a DPO in exactly three circumstances:
- Processing is carried out by a public authority or body (except courts acting judicially).
- Core activities consist of processing operations that, by their nature, scope or purposes, require regular and systematic monitoring of data subjects on a large scale.
- Core activities consist of large-scale processing of special categories of data (Art. 9) or personal data relating to criminal convictions and offences (Art. 10).
Two words carry the weight. Core activities means the processing is part of what the organization does to achieve its purpose — a hospital's patient records are core; the hospital's own payroll is not. Large scale is not defined numerically in the regulation; regulators look at the number of data subjects, the volume and range of data, duration, and geographic extent. Note also that member-state law can impose additional DPO requirements, and Germany's threshold is famously broader than the GDPR baseline.
DPO independence — the protections that get tested
Article 38 is where scenario items live:
- The DPO must be involved properly and in a timely manner in all issues relating to personal data protection.
- The organization must provide the resources and access necessary, and support the DPO's ongoing expertise.
- The DPO must receive no instructions regarding the exercise of their tasks.
- The DPO cannot be dismissed or penalised for performing their tasks.
- The DPO reports directly to the highest management level.
- The DPO may hold other tasks and duties only where they create no conflict of interest.
That last clause is the classic item. A DPO who is also the Head of IT, Head of Marketing, CISO, or General Counsel is determining the purposes and means of processing they are supposed to monitor. Regulators have fined organizations over exactly this conflict. The safe structures are a standalone DPO, or an outsourced/fractional DPO for smaller organizations that cannot justify a full-time hire.
Representatives for organizations outside the EU
Article 27 requires a controller or processor not established in the Union but caught by Article 3(2) to designate, in writing, a representative established in a member state where the relevant data subjects are. The representative is the addressee for supervisory authorities and data subjects, must be identified in the privacy notice, and must maintain a copy of the record of processing activities. The narrow exemptions cover occasional processing that does not involve large-scale special-category data and is unlikely to result in risk, and public authorities. The UK GDPR imposes a parallel UK-representative requirement, so a US company selling into both the EU and the UK generally needs two representatives, not one. A representative is not a DPO — the roles, duties and appointment tests are entirely separate.
Sizing and extending the team
Privacy capacity tracks processing complexity, not headcount. The practical drivers are the number of jurisdictions, the number of in-scope systems, the vendor population, monthly rights-request volume, the release cadence that needs assessment, and the M&A pipeline.
Because headcount rarely keeps pace, the standard answer on the exam is a privacy champion network: named part-time liaisons embedded in each business unit, given targeted training, a defined escalation path, and time formally allocated by their manager. Champions triage early, flag new processing before launch, and localize training. The three failure modes are equally testable — appointing champions without allocating time, without training them, or without an escalation route to a real decision-maker.
A multinational retailer appoints its Head of IT Security as Data Protection Officer, reasoning that the role already understands the systems best. What is the most significant problem?
A US-based e-commerce company with no EU establishment ships to customers in France and Germany and tracks their browsing behaviour. It has appointed an EU representative under Article 27. What else does the exam expect the privacy manager to recognise?