Skip to main content

Who Owns Privacy? Why a DPO Title Doesn't Guarantee Accountability

Alyssa O'Brien3 min read

A DPO oversight ring beside a separate product team box. Independent oversight is not operational authority.

Twenty US states now have comprehensive consumer privacy laws in effect, each with its own consent model and its own 30 to 45 day window for responding to a data subject request.1 GDPR requires a Data Protection Officer at certain companies and gives that person specific legal protections: independence, direct access to leadership, protection from being fired for doing the job. What it doesn't do is guarantee that person has any actual authority over the systems where privacy decisions get made.

That gap is where a lot of privacy programs quietly fail. A company hires a DPO, checks the compliance box, and hands them a title with no budget, no engineering resources, and no seat in the product review meetings where data collection decisions actually happen. The DPO can write policy. They can't stop a product team from adding a new tracking pixel if nobody's required to ask first.

Demonstrate, Not Just Claim

Article 5(2) of GDPR puts the accountability principle in plain terms: organizations must be able to demonstrate compliance, not just claim it. That's a meaningfully higher bar than having a privacy policy on the website. It means documented decisions, records of processing activities that are actually current, and a data protection impact assessment done before a new use case launches, not drafted afterward to justify a decision someone already made.

An Auditor of Decisions They Never Made

Here's the uncomfortable truth most privacy programs don't say out loud: a DPO with real independence but no operational authority is functionally an auditor of decisions they had no say in. That's a legitimate role. It's just not the same as owning privacy, and companies that conflate the two end up surprised when a regulator asks why the DPO's documented concerns from six months ago were never acted on.

Ownership Has to Sit in Two Places

Privacy ownership has to sit in two places at once for it to actually work. The DPO owns oversight, independence, and the relationship with regulators. Someone embedded in product and engineering has to own privacy-by-design decisions in real time, because privacy problems get created at the moment data collection is designed, not caught later in a review. Split those roles cleanly and give both of them the standing to slow down a launch, and the DPO title stops being decoration.

Frequently asked questions

Can the same person hold both the oversight and operational privacy role?

Legally, sometimes. Practically, it's a conflict of interest, since the person ends up reviewing decisions they made themselves.

Does every company need a formal DPO?

GDPR requires one under specific conditions, like large-scale monitoring or special category data. Many companies without a legal requirement still benefit from the independent-oversight role.

What's the single best early warning sign of a privacy ownership gap?

A DPIA that gets written after a product has already shipped, instead of before. That order reversal usually means the embedded role doesn't exist yet.

Put Privacy Review Before Launch, Not After

Devensa AI's vCPO vOfficer pairs independent oversight with embedded privacy-by-design review, so DPIAs happen before launch instead of after a regulator asks for one.

If a regulator asked for your last five DPIAs today, how many were finished before the feature shipped?

Schedule a demo with our team at info@devensa.ai, or request early access to the Governance Readiness Assessment, coming to devensa.ai.

Request a demo Join early access

Sources

  1. U.S. State Privacy Law Tracker, 2026, Clym. https://www.clym.io/blog/us-privacy-law-comparison-map