Insights / Regulatory & Compliance

I Have a DPO. Am I Automatically Data-Compliant?

By Clay & Associates Advocates · 2 min read ·

Colleagues reviewing information together on laptops in an office

Appointing a data protection officer is one of the more visible steps a company takes toward complying with the Data Protection Act, 2019, and it is tempting to treat it as the finish line. It is not. A DPO’s role under the Act is to advise, monitor, and report, not to personally carry the company’s compliance obligations, and the distinction matters more than most businesses realise once something actually goes wrong.

The obligation sits with the company, not the DPO

Under the Data Protection Act, the data controller or data processor, meaning the company itself, remains legally responsible for complying with the Act. The DPO’s job is to advise the company on its obligations, monitor compliance, and act as a point of contact with the Office of the Data Protection Commissioner and with data subjects. If the company ignores that advice, or never implements it, the DPO having flagged the issue does not transfer liability away from the company. A DPO who is appointed but not actually listened to protects the company only on paper.

What still has to actually exist

Having a named DPO does not, by itself, mean any of the following are in place, and each is a separate compliance requirement in its own right: a registered notification with the ODPC as a data controller or processor where the thresholds apply, documented data processing impact assessments for higher-risk processing, a lawful basis identified for each category of personal data you process, data subject rights procedures that actually work when someone exercises them, and a breach response plan that meets the notification timelines the Act sets. A DPO can recommend all of this. Only the company can actually put it in place.

Where this catches companies out

The most common gap is not having no DPO, it is having a DPO whose recommendations sit in an email nobody acted on. If your DPO reported to a department that then deprioritised implementing their recommendations, or if the DPO role was created mainly to answer a client’s due diligence questionnaire rather than to actually change how data is handled, the company’s real exposure has not moved much regardless of the appointment. Regulators and enforcement actions look at what a company actually does with personal data, not primarily at whether a job title exists on an organisational chart.

What actually closes the gap

Give the DPO direct access to whoever actually makes decisions, rather than routing their findings through several layers of management first. Treat their recommendations as something to act on or formally decide against, not something to quietly file away. And periodically check the substance, are impact assessments actually being done, are breach procedures actually tested, rather than checking only that the appointment itself is current. A DPO is meant to be the mechanism that gets a company compliant, not a substitute for actually becoming compliant.

&

Clay & Associates Advocates
This article is general information, not legal advice. For advice on your matter, speak to counsel.

Related Insights

Discover more