Devensa Advisory
Get started

Who Owns Privacy? Why a DPO Title Doesn't Guarantee Accountability

Twenty US states now have comprehensive privacy laws in effect. See why an independent DPO still isn't the same as owning privacy operationally.

Devensa Advisory 3 min read
A DPO oversight ring beside a separate product team box. Independent oversight is not operational authority.

Twenty US states now have comprehensive consumer privacy laws in effect, each with its own consent model and its own 30 to 45 day window for responding to a data subject request.1 GDPR requires a Data Protection Officer at certain companies and gives that person specific legal protections: independence, direct access to leadership, protection from being fired for doing the job. What it doesn't do is guarantee that person has any actual authority over the systems where privacy decisions get made.

That gap is where a lot of privacy programs quietly fail. A company hires a DPO, checks the compliance box, and hands them a title with no budget, no engineering resources, and no seat in the product review meetings where data collection decisions actually happen. The DPO can write policy. They can't stop a product team from adding a new tracking pixel if nobody's required to ask first.

Demonstrate, Not Just Claim

Article 5(2) of GDPR puts the accountability principle in plain terms: organizations must be able to demonstrate compliance, not just claim it. That's a meaningfully higher bar than having a privacy policy on the website. It means documented decisions, records of processing activities that are actually current, and a data protection impact assessment done before a new use case launches, not drafted afterward to justify a decision someone already made.

An Auditor of Decisions They Never Made

Here's the uncomfortable truth most privacy programs don't say out loud: a DPO with real independence but no operational authority is functionally an auditor of decisions they had no say in. That's a legitimate role. It's just not the same as owning privacy, and companies that conflate the two end up surprised when a regulator asks why the DPO's documented concerns from six months ago were never acted on.

Ownership Has to Sit in Two Places

Privacy ownership has to sit in two places at once for it to actually work. The DPO owns oversight, independence, and the relationship with regulators. Someone embedded in product and engineering has to own privacy-by-design decisions in real time, because privacy problems get created at the moment data collection is designed, not caught later in a review. Split those roles cleanly and give both of them the standing to slow down a launch, and the DPO title stops being decoration.

Frequently asked questions

Can the same person hold both the oversight and operational privacy role?

Legally, sometimes. Practically, it's a conflict of interest, since the person ends up reviewing decisions they made themselves.

Does every company need a formal DPO?

GDPR requires one under specific conditions, like large-scale monitoring or special category data. Many companies without a legal requirement still benefit from the independent-oversight role.

What's the single best early warning sign of a privacy ownership gap?

A DPIA that gets written after a product has already shipped, instead of before. That order reversal usually means the embedded role doesn't exist yet.

If a regulator asked for your last five DPIAs today, how many were finished before the feature shipped?

Sources

  1. U.S. State Privacy Law Tracker, 2026, Clym. https://www.clym.io/blog/us-privacy-law-comparison-map

Originally published on the Devensa blog.

Keep reading

All insights →
Privacy

Five Privacy Findings That Show Up Long After the Policy Was Signed

A privacy policy is a snapshot, not a subscription. See the five privacy findings that surface long after the policy was signed and board-approved.

AI Governance

Is Your AI Governance Tool Actually Governance?

Many AI governance tools are controls tools. Learn how governance and controls differ, why it matters, and what to ask before you buy.

Data Governance

Who Actually Owns the Data?

Poor data quality costs the average organization $12.9 million a year, according to Gartner. See why the owner-versus-custodian confusion is usually to blame.

Put a name next to every gap.

A Current State Assessment scores where you are across the six domains and sequences what comes next, with owners attached.

Get started Explore Privacy