Twenty US states now have comprehensive consumer privacy laws in effect, each with its own consent model and its own 30 to 45 day window for responding to a data subject request.1 GDPR requires a Data Protection Officer at certain companies and gives that person specific legal protections: independence, direct access to leadership, protection from being fired for doing the job. What it doesn't do is guarantee that person has any actual authority over the systems where privacy decisions get made.
That gap is where a lot of privacy programs quietly fail. A company hires a DPO, checks the compliance box, and hands them a title with no budget, no engineering resources, and no seat in the product review meetings where data collection decisions actually happen. The DPO can write policy. They can't stop a product team from adding a new tracking pixel if nobody's required to ask first.
Article 5(2) of GDPR puts the accountability principle in plain terms: organizations must be able to demonstrate compliance, not just claim it. That's a meaningfully higher bar than having a privacy policy on the website. It means documented decisions, records of processing activities that are actually current, and a data protection impact assessment done before a new use case launches, not drafted afterward to justify a decision someone already made.
Here's the uncomfortable truth most privacy programs don't say out loud: a DPO with real independence but no operational authority is functionally an auditor of decisions they had no say in. That's a legitimate role. It's just not the same as owning privacy, and companies that conflate the two end up surprised when a regulator asks why the DPO's documented concerns from six months ago were never acted on.
Privacy ownership has to sit in two places at once for it to actually work. The DPO owns oversight, independence, and the relationship with regulators. Someone embedded in product and engineering has to own privacy-by-design decisions in real time, because privacy problems get created at the moment data collection is designed, not caught later in a review. Split those roles cleanly and give both of them the standing to slow down a launch, and the DPO title stops being decoration.
Legally, sometimes. Practically, it's a conflict of interest, since the person ends up reviewing decisions they made themselves.
GDPR requires one under specific conditions, like large-scale monitoring or special category data. Many companies without a legal requirement still benefit from the independent-oversight role.
A DPIA that gets written after a product has already shipped, instead of before. That order reversal usually means the embedded role doesn't exist yet.
Devensa AI's vCPO vOfficer pairs independent oversight with embedded privacy-by-design review, so DPIAs happen before launch instead of after a regulator asks for one.
If a regulator asked for your last five DPIAs today, how many were finished before the feature shipped?
Schedule a demo with our team at info@devensa.ai, or request early access to the Governance Readiness Assessment, coming to devensa.ai.