Entry 03

DPO conflict of interest: where the line actually falls

Updated 11 min read dpoasaservice.eu

Article 38(6) is nineteen words long and decides more outsourced appointments than any other provision in the Regulation. It permits the officer to hold other roles, and it makes the controller responsible for ensuring that those roles do not compromise the one that matters.

The rule in one sentence

The provision reads: "The data protection officer may fulfil other tasks and duties. The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests." Two things follow immediately. Holding another role is expressly permitted, so an arrangement is not unlawful merely because the officer does something else. And the duty to police the boundary sits with you, not with the officer and not with the provider you bought them from.

The absence of a conflict is, as the Article 29 Working Party puts it, closely linked to the requirement to act in an independent manner. That is the function the rule protects. It is not a general integrity rule, and it is not about appearances: it is about whether the other tasks would stop the officer performing the Article 39 tasks properly.

The test the Court of Justice actually gave

In Case C-453/21, X-FAB Dresden GmbH & Co. KG v FC, decided on 9 February 2023, the Court was asked whether the chair of a works council could simultaneously be the undertaking's Data Protection Officer. It answered by setting out a test rather than a list, and the reasoning is worth following because it explains why the outsourced version of the problem exists at all.

The Court began with the text. It follows from the wording of Article 38(6), it held, that the Regulation does not establish a fundamental incompatibility between the performance of the officer's duties and the performance of other duties within the controller or processor, since the provision specifically provides that the officer may be entrusted with other tasks and duties. The fact remains that the controller must ensure those other tasks do not give rise to a conflict, and in accordance with the objective pursued, the officer cannot be entrusted with performing tasks or duties which could impair the execution of the functions performed by the officer.

It then identified that objective: the provision is intended to preserve the functional independence of the officer and, consequently, to ensure the effectiveness of the provisions of the Regulation. And then it reached for the context, which is the sentence this whole guide turns on. Under Article 39(1)(b) the officer's task is to monitor compliance with the Regulation, other data protection provisions and the policies of the controller or processor, "including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits".

From that, the Court drew the operative conclusion: it follows, in particular, that an officer cannot be entrusted with tasks or duties which would result in him or her determining the objectives and methods of processing personal data on the part of the controller or its processor, because under data protection law the review of those objectives and methods must be carried out independently by the officer.

A "conflict of interests" … may exist where a data protection officer is entrusted with other tasks or duties, which would result in him or her determining the objectives and methods of processing personal data on the part of the controller or its processor, which is a matter for the national court to determine, case by case, on the basis of an assessment of all the relevant circumstances, in particular the organisational structure of the controller or its processor and in the light of all the applicable rules, including any policies of the controller or its processor.Case C-453/21 X-FAB Dresden, judgment of 9 February 2023, operative part, point 2

Note what the operative part does not do. It gives no list, it settles no category of role, and it expressly makes the determination a case-by-case assessment of all the relevant circumstances. Anyone telling you that a particular arrangement is definitively clean, or definitively prohibited, is telling you something the Court declined to say.

The positions the guidance names

The Working Party supplies what the Court would not: a rule of thumb. The officer cannot hold a position within the organisation that leads him or her to determine the purposes and the means of the processing of personal data, and because organisational structures differ, this has to be considered case by case. As a rule of thumb, conflicting positions may include senior management positions, but also other roles lower down the structure if those roles lead to determining purposes and means.

Positions guidance and supervisory authorities identify as conflicting, and why
PositionWhy it conflictsNamed by
Chief executive officerSets the organisation's purposes for processing at the highest levelWP 243 rev.01, §3.5
Chief operating officerDetermines how operations, and therefore processing, are carried outWP 243 rev.01, §3.5
Chief financial officerDetermines purposes and means for financial and payroll processingWP 243 rev.01, §3.5
Chief medical officerDetermines purposes and means for health data, the most sensitive categoryWP 243 rev.01, §3.5
Head of marketingDetermines purposes for profiling, targeting and customer analyticsWP 243 rev.01, §3.5
Head of human resourcesDetermines purposes and means for employee dataWP 243 rev.01, §3.5
Head of ITDetermines the means of processing across every system in the organisationWP 243 rev.01, §3.5
Information security officerDetermines the technical and organisational means, and would then review themData Protection Ombudsman, Finland
External officer representing you in court on a data protection caseAdvocacy for a position the officer is supposed to assess independentlyWP 243 rev.01, §3.5
The Working Party's list is a rule of thumb, not a closed set, and it extends to roles lower in the structure wherever they lead to determining purposes and means. The Court of Justice requires the assessment to be made case by case in any event.

Finland's Data Protection Ombudsman states the security variant in its own words: the officer cannot hold a position or duty that requires them to define the purposes and methods of the processing of personal data, and conflicts of interest may arise if, for example, an information security officer or senior manager is designated as the Data Protection Officer. That is the one line every organisation buying security services and data protection services from the same place should read twice.

The conflicts that only appear when the officer is external

Everything above concerns roles inside the controller. An outsourced appointment adds a second surface, and the European Data Protection Board devoted part of its 2024 report on the coordinated enforcement action to it. Up to fifteen of the participating supervisory authorities reported in their qualitative analysis that certain officers are likely to be in a situation of conflict of interests, or identified risks to independence.

Monitoring your own work

The Board records the mechanism directly. The issues, it writes, are also relevant for external officers, who may be entrusted with both the regular tasks of the officer and additional tasks, which may lead to situations where the outsourced officers monitor their own activities. Its worked example concerns law firms designated as external officers and then asked to represent their clients in court in data protection cases, which the Working Party had already identified as a conflict.

The same mechanism operates on any provider that sells something the officer would then have to review under Article 39(1)(b). If the firm holding your appointment also designed your access controls, wrote your retention policy, built your consent flow or tested your production platform, then the "related audits" that Article 39(1)(b) puts inside the officer's monitoring duty are audits of its own delivery. The Court's reasoning bites precisely here: the review of purposes and methods must be carried out independently by the officer.

Acting for the controller and the processor at once

A second example from the same report: one authority found that an external officer acted as the officer for both the controller and its processor. Even though the controller is itself obliged to monitor the processor under Articles 28(1) and 28(3)(h), the Board concluded that the simultaneous performance of monitoring tasks towards the controller and towards the processor leads to a conflict of interests, because of their different responsibilities and interests, and weakens the fulfilment of the role.

The wrong contract

The third is contractual rather than functional. Interferences with independence, the Board writes, may also derive from the contractual and budgetary set-up, and controllers using an external officer need to be very mindful that the relationship does not entail, directly or indirectly, instructions as to how the tasks are carried out. One authority encountered a data processing agreement between an organisation and its external officer and pointed out that considering the officer as a processor could breach Article 38(3). It is worth restating why that is not a technicality: a processor is defined by acting on documented instructions, and an officer is defined partly by receiving none.

Five questions that will settle most arrangements

  1. Does the candidate, or the candidate's employer, decide anything about why or how our personal data is processed? If yes, the Court's test is engaged and the answer is probably no.
  2. Would the candidate, performing Article 39(1)(b) monitoring honestly, end up assessing work that they or their employer delivered to us? If yes, that is the self-review pattern the Board named.
  3. Does the same provider hold the appointment for both us and one of our processors, or for both us and one of our controllers? If yes, that is the arrangement one authority treated as a conflict.
  4. Is the engagement papered as anything that gives instructions on the tasks, a processing agreement most of all? If yes, fix the instrument.
  5. Would the candidate represent us against a supervisory authority or in court on a data protection matter? If yes, the Working Party names that specifically.

A "no" to all five does not make the arrangement lawful, because the assessment is case by case on all the relevant circumstances. A "yes" to any of them means you have work to do before signing, and a documented reason if you sign anyway.

Recording the absence of a conflict

The Working Party sets out good practice for controllers and processors, and it reads like a short internal procedure: identify the positions that would be incompatible with the function; draw up internal rules to that effect in order to avoid conflicts; include a more general explanation about conflicts of interests; declare that the officer has no conflict of interests with regard to the function, as a way of raising awareness of the requirement; and include safeguards in the internal rules, ensuring that the vacancy notice for the position, or the service contract, is sufficiently precise and detailed to avoid a conflict. It closes by noting that conflicts may take various forms depending on whether the officer is recruited internally or externally.

One supervisory authority in the coordinated action noted the absence of any such procedure at the organisations it looked at: there were no arrangements to ensure conflicts are avoided from the designation stage onward. A one-page conflicts declaration signed at appointment, refreshed annually, and a named list of incompatible positions will cover most of what the guidance asks for.

What happens when it goes wrong

Infringements of Articles 37 to 39 fall in the lower of the two fining tiers. Under Article 83(4), they attract administrative fines of up to 10 000 000 EUR or, in the case of an undertaking, up to 2 % of total worldwide annual turnover of the preceding financial year, whichever is higher.

This is not theoretical. The Board's report records that ten of the participating authorities had already taken enforcement action on officer requirements before the coordinated action began. Belgium's authority adopted eight decisions between April 2020 and August 2023 touching independence, conflicts of interest with assigned tasks, the level of organisational support, failure to report to the highest management level, failure to appoint an officer, and lack of involvement. Italy's authority adopted eleven decisions between 2021 and 2022 on failures to appoint, to publish or communicate contact details, and on conflicts with other assigned tasks. France's authority ordered twenty-two municipalities to appoint an officer in May 2022, Portugal opened infringement procedures and issued fines against local government bodies for failing to designate, and Ireland identified seventy-seven entities as potentially non-compliant after assessing public bodies in 2020.

Poland's authority went a step further and imposed a fine in connection with the performance of the officer's tasks without due regard to the risks associated with the processing operations, and for not involving the officer in the processing operations carried out. That is an enforcement action about the quality of the arrangement rather than its existence, which is the direction of travel worth planning for.

If you are still deciding whether the obligation applies at all, start at the Article 37(1) analysis. If you have decided and are choosing a model, the service-contract entry covers what the agreement has to carry.

Sources

  1. Case C-453/21, X-FAB Dresden GmbH & Co. KG v FC Court of Justice of the European Union · 2023 Judgment of 9 February 2023, ECLI:EU:C:2023:79. Paragraphs 40 to 45 and operative point 2 on the Article 38(6) conflict-of-interest test.
  2. Regulation (EU) 2016/679 (General Data Protection Regulation) EUR-Lex · 2016 Article 38(6) on other tasks and conflicts, Article 39(1)(b) on monitoring compliance and the related audits, Article 28(1) and (3)(h) on processor monitoring, and Article 83(4) on the fining tier.
  3. Guidelines on Data Protection Officers (DPOs), WP 243 rev.01 Article 29 Data Protection Working Party · 2017 Section 3.5 on conflicts of interest, including the rule of thumb, the list of conflicting positions, the external-representation example and the good-practice list.
  4. 2023 Coordinated Enforcement Action: Designation and Position of Data Protection Officers European Data Protection Board · 2024 Section 4.5 on conflicts and independence, including outsourced officers monitoring their own activities, the controller-and-processor case and the processing-agreement finding; section 5.1 on prior national enforcement.
  5. Designating a data protection officer Office of the Data Protection Ombudsman, Finland National statement that a conflict may arise where an information security officer or senior manager is designated as the officer.

Queries

Queries

Related questions

Can our Head of IT be the Data Protection Officer?

The Working Party names head of IT in its rule-of-thumb list of conflicting positions, because such a role determines the means of processing. The Court of Justice requires a case-by-case assessment, so it is not an automatic prohibition, but you would be arguing against both the guidance and the obvious reading of the role.

Can our external law firm be our DPO?

It can hold the appointment, and many do. The specific conflict the Working Party names is being asked to represent the controller or processor before the courts in cases involving data protection issues, and the European Data Protection Board reports that authorities found exactly that combination in practice. Separate the two engagements, or separate the firms.

Can one provider be the DPO for us and for our processor?

One supervisory authority in the 2023 coordinated action treated that as a conflict. The Board agreed: even though the controller is obliged to monitor the processor under Articles 28(1) and 28(3)(h), performing monitoring tasks towards both parties at once conflicts, because their responsibilities and interests differ.

Is a conflict of interest by itself a fineable infringement?

Article 38(6) is inside the Article 83(4) band, so infringements attract fines of up to 10 000 000 EUR or 2 % of total worldwide annual turnover, whichever is higher. Belgium's authority has adopted decisions specifically on conflicts with the officer's assigned tasks, and Italy's has done so as part of eleven officer-related decisions.

How do we prove there is no conflict?

The Working Party's good practice is to identify the incompatible positions, write internal rules to that effect, explain the concept generally, obtain a declaration from the officer that no conflict exists, and make the vacancy notice or the service contract precise enough to prevent one. Keep the declaration dated and refresh it.