Skip to content
All articles
Blog

The position of the Data Protection Officer

· A.R. Vlieger

The Data Protection Officer must not receive instructions or be penalized for his work, is bound by a duty of confidentiality, and must not hold a second role that conflicts with his position.

My previous blog post about the Data Protection Officer (DPO) focused on the resources an organization must provide to the DPO: time, means, access, and visibility. However, the core of Article 38 GDPR concerns something else—what the organization must not take away from the DPO: their independence. And there are some misunderstandings regarding this.

No instructions in advance

Article 38(3) stipulates that the DPO shall not receive instructions regarding the performance of their tasks, shall not be dismissed or penalized for performing them, and shall report directly to the highest management level. Recital 97 adds that this applies equally to external DPOs.

"No instructions in advance" means that no one may dictate what the outcome of an advisory opinion should be, how a complaint is investigated, or when the Dutch Data Protection Authority (AP) is contacted. This prohibition applies only to their DPO duties; if the DPO has other responsibilities as well, they may of course be supervised in the performance of those tasks.

Can he be dismissed?

First of all: the rule against "subsequent sanctions" goes beyond merely "not dismissing" the person. A denied promotion, a stalled career, a withheld bonus: it all counts. Even the mere threat is not allowed, provided the intent is to penalize the DPO for their work.

However, and this is a nuance often overlooked, pay attention to the functional link. The DPO must not suffer any detriment as a result of their work as a DPO. Consequently, they can be dismissed for theft, harassment, or other serious misconduct, or in connection with their other duties. Moreover, a DPO who consistently fails to perform adequately can indeed be dismissed. The rationale is simple: protection against dismissal is intended to foster better GDPR compliance, not to create an untouchable DPO who neglects their duties.

A detail for the enthusiast: unlike almost everything else in the GDPR, this protection against dismissal is a matter of minimum, not maximum harmonization. Member States are therefore permitted to go further, provided they do not impede the free movement of data or data protection officers.

Finally, being independent means that the DPO is not held accountable for whether or not their advice is followed; the organization itself bears that responsibility. If advice is not followed, the "comply or explain" principle applies: jointly document what happened to the advice and why.

1784959668280 ontslag van de fg

A duty of confidentiality — enabling people to speak openly

Article 38(5) imposes a duty of confidentiality on the Data Protection Officer (DPO). The underlying rationale is the same as that for other forms of professional privilege: a suspect must be able to tell their lawyer everything, just as a patient must be able to tell their doctor everything. The importance of being able to speak freely outweighs the value of disclosure in any single instance. The same applies here: only those who trust that information will remain strictly between them and the DPO will share enough for the DPO to perform their job effectively.

Yet this confidentiality does not preclude contact with the Dutch Data Protection Authority (AP)—just as doctors and lawyers are permitted to share certain information with their respective supervisory bodies. In extreme cases—such as deliberate non-compliance—the DPO must be able to approach the AP; not via the standard tip-off form, but through dedicated DPO channels. Ultimately, the entire system hinges on trust in the DPO’s integrity: if people do not trust their DPO, they will share nothing, rendering the DPO unable to act.

In short

Independence is not a luxury but the very essence of the role: no prior instructions, no retrospective punishment for doing a good job, a duty of confidentiality that fosters trust, and no conflicts of interest. However, the Data Protection Officer (DPO) is not untouchable—anyone who neglects their duties or commits theft can simply be dismissed. All of this is becoming increasingly important in the healthcare sector: the EHDS is driving an increase in the secondary use of health data, and with it, a rise in the number of DPIAs and decisions with privacy implications. In such a context, you need a DPO who can offer advice freely—and who can also be held to account by the organization if they fail to be sufficiently rigorous.

You can read about how to properly position such a DPO—ensuring they have the necessary time, resources, and a direct line to senior management—in the first DPO blog by clicking here.