The resources required by the Data Protection Officer
The GDPR requires organizations not only to appoint a Data Protection Officer (DPO) but also to create the conditions necessary for them to effectively perform their duties. Part 1 on the DPO’s position: involvement, resources, and visibility.
A Data Protection Officer (DPO) just on paper is useless, and a risk
It is impossible for a Data Protection Authority (DPA) to monitor every instance of data processing in its country. The GDPR therefore introduced a solution: a Data Protection Officer (DPO) must be appointed in situations where strict compliance is particularly important. This person acts as both an internal supervisor and an advisor. While not an extension of the DPA, the DPO (usually) serves as the intermediary.
Article 39 outlines the DPO’s specific duties. However, duties are meaningless without the resources to carry them out, so Article 38 specifies the DPO's necessary resources. This blog post (part one of a two-part series) addresses this topic. In short: a DPO who is relegated to an attic office, excluded from meetings, and left to muddle through without time or a budget offers no protection. Instead, this poses a risk.
Involve the DPO properly and in a timely manner
Article 38(1) states that the DPO must be "properly and in a timely manner involved in all issues" relating to data protection. Note that verb: be involved. The initiative therefore also lies with the organization. Yes, the DPO is independent and should raise issues himself, but that does not absolve management of the duty to invite him to the table proactively.
"In all issues" means they are a partner who joins the working groups and discussions where personal data is being processed. And "in a timely manner" means: as early as possible. Advice received after key decisions have already been made is generally disregarded. Calling the DPO right at the start of a DPIA (Article 35) enables privacy by design; calling them later amounts to asking for a rubber stamp, which is not the intention. In the event of a potential data breach, the rule is: call immediately.

Provide the DPO with resources and a direct line to senior management
Article 38(2) requires the organization to support the Data Protection Officer (DPO) by granting access to all processing operations and providing the necessary resources. Access to "everything" means access not only to management but also to HR, Legal, IT, and Security. Only in this manner can the DPO truly get to know the organization and provide sound advice on all matters related to personal data.
These resources entail a number of concrete elements: sufficient time (it is best to specify a percentage) and an adequate budget. One requirement stands out: a direct line to senior management. Indirect access is insufficient: a ruling made by the French supervisory authority as early as 2021, and for good reason: if the DPO can only reach senior management through the director to whom they report, they cannot effectively oversee that specific director. Poland and Norway have also issued fines for this shortcoming.
And do not assume that an external DPO can make do with less; they, too, must be allocated sufficient resources, as France has reiterated. They should be able to continue their professional training and are not expected to know everything—they are permitted to seek advice on specialized issues. If problems arise regarding resources or their position, they should discuss the matter with the board and, as a last resort, seek backing from the Data Protection Authority.
Make the DPO easy to find
A Data Protection Officer whom no one can find is useless. Therefore, active support for the appointment and an official announcement are required. Within a corporate group, the DPO must be easily accessible from every branch. A general email address (dpo@organization.nl) suffices according to the Dutch Data Protection Authority (AP): the individual's name does not need to be made public.
However, note that acting as a point of contact is different from acting as a spokesperson. The DPO does not speak on behalf of the organization and does not act as legal counsel for the case (although a lawyer can certainly serve as a DPO). The Dutch DPA specifically does not want the DPO to act as the public face of the organization when serious issues arise—such as investigations, sanctions, or objection proceedings—so that the DPO is not held accountable for the supervisory authority's actions.
In short
Involve the DPO early on; provide access, time, funding, and a direct line to senior management; and ensure everyone knows how to reach him. Fail to do so, and you are left with a DPO in name only and the associated risk of fines. Moreover, 'privacy by design' is more cost-effective than having to overhaul the entire design later on.
The second part addresses the other half of Article 38: the independence of the DPO. Can they be dismissed? Are they bound by a duty of confidentiality? And can the DPO simultaneously serve as the head of the IT department? See 'DPO Resources: Part 2'.
