| Title | Data Protection Officer |
|---|---|
| Reports to | Highest management level: [Board / CEO / equivalent] |
| Employment type | Full-time |
| Salary | [Salary range. Postings with a range perform significantly better, and several states require one.] |
Position overview
[Organization] is appointing a Data Protection Officer to perform the advisory, monitoring and liaison tasks established by applicable data-protection law. The DPO will report directly to the highest management level, receive timely access to matters involving personal data and perform DPO duties independently.
The organization remains accountable for compliance and for decisions about the purposes and means of processing. The DPO advises, monitors and escalates; the DPO does not assume management's legal responsibility.
Key responsibilities
Key responsibilities
- Inform and advise the organization and its employees about data-protection obligations.
- Monitor compliance with applicable law, policies, assigned responsibilities, training and audits.
- Advise on data protection impact assessments and monitor their performance.
- Cooperate with supervisory authorities and act as their contact point.
- Serve as an accessible contact point for individuals on data-protection matters.
- Report significant concerns to the highest management level.
- Monitor privacy risk, incidents, complaints, remediation and program effectiveness.
- Maintain awareness of processing operations, information systems and regulatory change.
Required qualifications
- Expert knowledge of data-protection law and practice appropriate to the organization's processing, sector and risk.
- Substantial experience advising on or monitoring privacy programs.
- Ability to exercise independent judgment and communicate concerns to senior leadership.
- Experience with DPIAs, audits, incidents, complaints and regulatory engagement.
- Working understanding of information systems, security, data governance and the organization's operations.
- Professional discretion, integrity and credibility.
Preferred certifications
CIPP/E and/or CIPM, while recognizing that the GDPR does not mandate a particular certification.; Prior DPO, Deputy DPO, senior privacy counsel, audit or privacy-leadership experience.; Experience in [industry] and across [relevant jurisdictions].; Relevant language skills.
Technical knowledge
GDPR, UK GDPR, CCPA / CPRA, ISO/IEC 27701, privacy impact assessments, data mapping, records of processing.
Essential competencies
Analysis, documentation, judgment, cross-functional collaboration, and clear communication of privacy risk.
Success in the first year
- Confirm the appointment's scope, resources, reporting and conflict safeguards.
- Establish direct access to the highest management level and a regular reporting cadence.
- Assess program effectiveness and prioritize material gaps.
- Review the DPIA, incident, complaint, training and monitoring arrangements.
- Build effective working relationships with management and supervisory authorities while preserving independence.
About [Company]
[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]
Post this role on GRC Careers
Reach professionals who specialize in statutory data protection oversight rather than hoping they find you in a general feed. Hand reviewed, live within one business day.
See how others are hiring
Review live Privacy jobs postings to benchmark scope, level, and posted salary before you publish yours.
Stay close to the market
Job alerts
Get new Privacy jobs roles sent to you as they post.
Newsletter
Hiring trends, salary signals, and new templates from GRC Careers.
Frequently asked questions
Want to edit it, not just read it?
Copying from the page works, and this template stays free. But if you want the real thing to make your own, the editable Word file is in the toolkit, along with all 44 job descriptions, 38 career guides, 21 reference sheets, and 16 executive briefs. Yours to adapt, rename, and reuse, commercially, forever.