Skip to content
AGJ, the AI governance job board
Menu

Executive job description template

Chief Privacy Officer (CPO)

The Chief Privacy Officer owns the enterprise privacy program, protecting personal data and keeping the organization compliant with data protection law across every jurisdiction it operates in. This template reflects how the role is scoped today, including growing responsibility for AI and automated processing. Replace the [highlighted fields] with your specifics, trim what does not apply, and post.

Download PDF Download reference sheet

TitleChief Privacy Officer (CPO)
DepartmentPrivacy / Legal / Data Governance
Reports to[General Counsel / Chief Executive Officer / Chief Compliance Officer]
Location[Remote / Hybrid / On-site]
Employment typeFull-time
Salary[Salary range. Postings with a range perform significantly better, and several states require one.]

Position overview

The Chief Privacy Officer (CPO) provides executive leadership for [Company]'s enterprise privacy and data protection program. This role owns the strategy, policies, controls, and governance that protect personal data and keep the organization compliant with global privacy law throughout the data lifecycle.

The CPO partners closely with legal, compliance, security, data governance, product, marketing, human resources, and business units to embed privacy by design, respond to individual rights requests, and manage privacy risk. The role often serves as, or oversees, the designated Data Protection Officer where required.

As organizations expand their use of AI and automated decision making, the Chief Privacy Officer plays a central role in governing how personal data is used to train and operate AI systems, ensuring transparency, fairness, and lawful processing alongside risk and AI governance leaders.

Key responsibilities

Privacy program leadership

Regulatory compliance

Ensure compliance with applicable privacy and data protection laws across jurisdictions, including:

Data governance and mapping

Privacy risk and assessments

Own the privacy impact assessment and Data Protection Impact Assessment (DPIA) process. Evaluate new products, vendors, technologies, and AI use cases for privacy risk, and drive mitigation before deployment.

Individual rights and incidents

Vendor and cross-border management

Assess third-party and processor privacy practices, manage data processing agreements, and govern international data transfers using approved mechanisms and safeguards.

Training, culture, and engagement

Deliver enterprise privacy training and awareness, advise business and product teams, and engage with regulators, supervisory authorities, and industry bodies on privacy matters.

Required qualifications

Preferred certifications

One or more of: CIPP (such as CIPP/US or CIPP/E), CIPM, CIPT, CDPSE, FIP, and a Juris Doctor (JD) where the role requires legal depth.

Technical knowledge

Enterprise privacy program design, global data protection law, privacy by design, data mapping and records of processing, DPIAs and privacy impact assessments, consent and lawful-basis management, data classification and retention, individual rights operations, breach response and notification, cross-border transfers, vendor privacy management, and privacy considerations for AI and automated processing.

Essential competencies

Executive leadership, legal and regulatory judgment, executive and Board communication, cross-functional influence, pragmatic risk balancing, program management, and the independence to advise on and escalate privacy risk.

Success measures: first 12 months

About [Company]

[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]

Post this role on GRC Careers

Reach professionals who specialize in enterprise privacy and data protection rather than hoping they find you in a general feed. Hand reviewed, live within one business day.

Post this role

See how others are hiring

Review live GRC leadership jobs postings to benchmark scope, level, and posted salary before you publish yours.

Browse GRC leadership jobs

Stay close to the market

Frequently asked questions

What does a Chief Privacy Officer (CPO) do?

The Chief Privacy Officer owns the enterprise privacy and data protection program. They set privacy strategy and policy, embed privacy by design, run DPIAs and individual rights processes, manage breaches, and keep the organization compliant with global data protection law.

What qualifications and certifications does a Chief Privacy Officer need?

Most CPOs bring 12 to 18 or more years in privacy, data protection, legal, or compliance, including at least 5 years leading programs, and many hold a Juris Doctor. Common certifications include CIPP such as CIPP/US or CIPP/E, CIPM, CIPT, CDPSE, and the FIP designation.

Who does a Chief Privacy Officer report to?

The CPO commonly reports to the General Counsel, the Chief Executive Officer, or the Chief Compliance Officer, and often serves as or oversees the designated Data Protection Officer where a DPO is legally required.

How does AI affect the Chief Privacy Officer role?

AI systems often rely on personal data for training and operation, which raises questions of lawful basis, transparency, and fairness. The CPO governs how personal data feeds AI, runs privacy assessments on AI use cases, and coordinates with risk and AI governance leaders under frameworks such as the GDPR and the EU AI Act.