Skip to content
AGJ, the AI governance job board
Menu

Executive job description template

Data Protection Officer (DPO)

The Data Protection Officer is the organization's independent authority on data protection, monitoring compliance with the GDPR and advising on how personal data is handled. This template reflects the role as defined under GDPR Articles 37 to 39 and scoped at organizations with significant data processing today. Replace the [highlighted fields] with your specifics, trim what does not apply, and post.

Download PDF Download reference sheet

TitleData Protection Officer (DPO)
DepartmentPrivacy / Legal / Compliance
Reports to[Board / General Counsel / Chief Privacy Officer]
Location[Remote / Hybrid / On-site]
Employment typeFull-time
Salary[Salary range. Postings with a range perform significantly better, and several states require one.]

Position overview

The Data Protection Officer (DPO) provides independent oversight of [Company]'s data protection compliance. As defined under GDPR Articles 37 to 39, the DPO monitors compliance, advises the organization, and serves as the contact point for supervisory authorities and data subjects.

The DPO partners with legal, privacy, security, IT, and business units to embed data protection by design, advise on data protection impact assessments, and support the exercise of data subject rights, while maintaining the independence the role requires.

As privacy regulation expands globally, the DPO serves as the organization's trusted authority on data protection compliance and the responsible handling of personal data.

Key responsibilities

Compliance monitoring

Advisory and DPIAs

Provide advice on data protection impact assessments and high-risk processing, including:

Data subject rights

Data protection by design

Advise on embedding data protection by design and by default into systems, products, and processes, including data minimization, purpose limitation, retention, and security safeguards.

Supervisory authority liaison

Serve as the contact point for supervisory authorities, cooperate on investigations and consultations, and act as the contact for data subjects on matters related to processing of their personal data.

Records and accountability

Awareness and training

Raise awareness of data protection across the organization through training, guidance, and staff education, and monitor the effectiveness of data protection controls.

Required qualifications

Preferred certifications

One or more of: CIPP/E, CIPM, CIPT, or ISO 27701 Lead Implementer or Lead Auditor.

Technical knowledge

GDPR and data protection law, data protection impact assessments, data subject rights, lawful bases and consent, records of processing activities, international data transfers, data processing agreements, privacy by design, ISO 27701, and vendor and processor assessment.

Essential competencies

Independence and objectivity, sound judgment, regulatory interpretation, stakeholder advisory, discretion and confidentiality, clear communication, and the ability to influence without authority.

Success measures: first 12 months

About [Company]

[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]

Post this role on GRC Careers

Reach professionals who specialize in data protection and privacy compliance rather than hoping they find you in a general feed. Hand reviewed, live within one business day.

Post this role

See how others are hiring

Review live GRC leadership jobs postings to benchmark scope, level, and posted salary before you publish yours.

Browse GRC leadership jobs

Stay close to the market

Frequently asked questions

What does a Data Protection Officer (DPO) do?

The Data Protection Officer monitors an organization's compliance with the GDPR and applicable data protection laws. As defined in GDPR Articles 37 to 39, they advise on obligations, support DPIAs and data subject rights, and act as the contact point for supervisory authorities and data subjects.

What qualifications and certifications does a DPO need?

Most DPOs bring 8 to 12 or more years in data protection, privacy, legal, or compliance, with expert knowledge of the GDPR. Common certifications include CIPP/E, CIPM, CIPT, and ISO 27701 Lead Implementer or Lead Auditor.

Who does a Data Protection Officer report to?

To preserve independence, the DPO reports to the highest level of management, often the Board, General Counsel, or Chief Privacy Officer, and cannot be instructed on how to perform the DPO tasks.

What frameworks does a DPO use?

The DPO works primarily from the GDPR, including Articles 37 to 39, supported by ISO/IEC 27701 and ISO/IEC 27001, the NIST Privacy Framework, and guidance from the European Data Protection Board.