top of page
Search

The New CNIL DPO Guidelines

  • Writer: Katarzyna  Celińska
    Katarzyna Celińska
  • 9 hours ago
  • 2 min read

One of the most valuable aspects of the newly updated CNIL Practical Guide for DPO is that it addresses an issue I repeatedly encounter during GDPR audits, an issue that is still surprisingly misunderstood by many organizations.

 

The concept of DPO independence.

 

On paper, most organizations know that the GDPR requires the DPO to operate independently. In practice, however, the distinction between having a DPO and allowing the DPO to perform the role independently is often blurred. The CNIL guidance provides much-needed clarification by explaining not only what the DPO should do, but also what the DPO must not be expected to do.

 

Photo archistell na Magnific


One recurring challenge is the accumulation of responsibilities.

Many organizations appoint a DPO who simultaneously serves as Head of IT, CIO, HR Director, Operations Manager, Compliance Lead, or even Marketing Manager. While this may appear efficient from a resource perspective, it frequently creates situations where the DPO is effectively reviewing decisions they have already made themselves.

 

That is precisely what the GDPR seeks to prevent.

 

A DPO cannot objectively assess compliance if they determine the purposes or means of processing personal data. The CNIL explicitly highlights that positions such as senior management, HR, IT leadership, operations, or marketing are all roles that may create conflict sof interest because they influence how personal data is processed. Importantly, the guidance also notes that conflicts are not limited to executive positions. Any role that materially influences processing decisions may compromise DPO independence.

 

But there is another dimension that deserves equal attention. Not every conflict of interest stems from combining different job titles. Sometimes, the privacy-related tasks themselves assigned to the DPO can undermine the independence of the function. For example, organizations occasionally expect the DPO to make final operational decisions regarding processing activities, approve business initiatives, determine technical controls, or formally accept risks on behalf of management. The DPO is an advisor, monitor and independent expert, not the decision-maker.

 

The CNIL clearly explains that while a DPO may coordinate GDPR activities, maintain the record of processing activities, participate in DPIAs, monitor data breach management and support compliance initiatives, responsibility for compliance always remains with the controller or processor. The DPO informs, advises and monitors, but does not replace management.



 
 
 

Comments


Stay in touch

META FOR MENA Information Technology Consultants Est.

City Avenue, 7th floor, office 706-0114

2 27 Street, Port Saeed, Deira, Dubai, United Arab Emirates
P.O. BOX: 40138
Licence N.O.: 1049080

Privacy policy

  • Facebook
  • Twitter
  • LinkedIn
  • Instagram
bottom of page