Back to blog

Blog

The Data Protection Officer's Job Just Got Bigger — Has Anyone Updated the Job Description?

· 5 min read · Evan Ritter

compliancedata-protectiongdprai-governance
The Data Protection Officer's Job Just Got Bigger — Has Anyone Updated the Job Description?

When the GDPR created the Data Protection Officer role back in 2018, the brief was narrow and almost administrative: monitor compliance, advise on data protection impact assessments, act as the liaison with regulators. Eight years on, that description is close to fiction. The job hasn't grown — it's been rebuilt three times over, and most organisations are still paying for, and resourcing, the 2018 version.

That mismatch is the real story in data protection right now, and it's worth understanding whether you're the DPO, you manage one, or you're deciding whether your company needs one at all.

The role tripled while nobody was watching

Ask a working DPO what's actually on their desk this year and GDPR is only one line item among several. AI governance now sits squarely inside the job. The EU AI Act's next major compliance deadline lands on 2 August 2026, and it doesn't just bind the companies building AI models — it binds anyone deploying them. Organisations using off-the-shelf tools like ChatGPT to touch personal data are "deployers" under the Act, which means AI tool inventories (shadow AI included), data-flow mapping into AI systems, high-risk use-case classification, and formal impact assessments are now squarely a privacy team's problem. As one recent analysis put it bluntly: the Act doesn't let you outsource responsibility by outsourcing the technology.

Layer on top of that a US privacy landscape that's gone from a handful of state laws to what one industry report calls "a dense and evolving system" of over twenty state regimes, each with its own definitions and quirks — Connecticut's expanded sensitive-data categories, Maryland's notoriously demanding operational requirements, and more arriving every legislative session. Add NIS2's cybersecurity obligations, tightening rules around children's data (COPPA's updated rule now treats biometric identifiers as personal information), and a steady drip of new regimes across Asia-Pacific — Vietnam's comprehensive data law took effect this January, with South Korea and Malaysia both sharpening enforcement.

None of this replaced the original GDPR workload of records of processing, subject access requests, breach response, vendor due diligence, staff training, and regulator correspondence. It stacked on top of it.

The enforcement numbers make it a business risk, not a paperwork exercise

It's tempting to treat all this as compliance theatre until the fines land, and they keep landing at a scale that's hard to wave away. Regulators have issued more than 2,500 GDPR fines since 2018, totalling upwards of €7 billion, with roughly €1.2 billion of that in 2025 alone. The headline cases from the past year aren't small: TikTok was fined €530 million over unlawful EU-China data transfers, Google €325 million over consent and inbox-ad practices, and Shein €150 million over cookie consent. The AI Act raises the ceiling further, with penalties for high-risk violations reaching €15 million or 3% of global turnover — matching GDPR's own severity. The single most common violation across all of these cases, year after year, is the most basic one: processing personal data without a valid legal basis. Scale and sophistication haven't fixed the fundamentals; if anything, more systems touching more data has made the fundamentals harder to keep straight.

Why the role is underpaid for what it now covers

Here's the part that should concern anyone building a privacy function rather than just staffing one: compensation hasn't caught up to scope. The DPO is structurally a cost centre — its job is to prevent losses that, when the job is done well, never show up on anyone's balance sheet. That makes it hard to budget for ambitiously, and easy to underfund. It also means the strongest people don't stay in the DPO title; they migrate toward Chief Privacy Officer or AI Governance Lead roles that carry real budget authority and a seat closer to the table, leaving the DPO title itself filled disproportionately by less senior staff even as its actual responsibilities expand. The practitioners commanding a real premium right now are the ones straddling privacy and AI governance simultaneously — not the ones treating the job as GDPR Article 39 defines it on paper.

The angle worth taking

The interesting story here isn't "GDPR compliance is important" — everyone already accepts that. The sharper, more useful story is that the job has quietly become one of the most cross-functional, technically demanding roles in the modern company, sitting at the intersection of law, engineering, AI governance, and cybersecurity — while the org chart, the budget, and the job title still describe something much smaller. Companies that recognise this and resource the role accordingly — with real authority, a seat in AI procurement decisions, and pay that reflects the actual scope — are going to navigate the AI-and-privacy convergence of the next two years in noticeably better shape than the ones still treating their DPO as a box-ticking function bolted onto legal.

For anyone currently holding the title: the data suggests the smart move is to stop waiting for the job description to catch up and start building the cross-domain expertise — AI governance especially — that the market is already quietly paying for.


Sources

Share