Who Owns Privacy? Why a DPO Title Doesn't Guarantee Accountability
Twenty US states now have comprehensive privacy laws in effect. See why an independent DPO still isn't the same as owning privacy operationally.
Twenty US states now have comprehensive consumer privacy laws in effect, each with its own consent model and its own 30 to 45 day window for responding to a data subject request.1 GDPR requires a Data Protection Officer at certain companies and gives that person specific legal protections: independence, direct access to leadership, protection from being fired for doing the job. What it doesn't do is guarantee that person has any actual authority over the systems where privacy decisions get made.
That gap is where a lot of privacy programs quietly fail. A company hires a DPO, checks the compliance box, and hands them a title with no budget, no engineering resources, and no seat in the product review meetings where data collection decisions actually happen. The DPO can write policy. They can't stop a product team from adding a new tracking pixel if nobody's required to ask first.
Demonstrate, Not Just Claim
Article 5(2) of GDPR puts the accountability principle in plain terms: organizations must be able to demonstrate compliance, not just claim it. That's a meaningfully higher bar than having a privacy policy on the website. It means documented decisions, records of processing activities that are actually current, and a data protection impact assessment done before a new use case launches, not drafted afterward to justify a decision someone already made.
An Auditor of Decisions They Never Made
Here's the uncomfortable truth most privacy programs don't say out loud: a DPO with real independence but no operational authority is functionally an auditor of decisions they had no say in. That's a legitimate role. It's just not the same as owning privacy, and companies that conflate the two end up surprised when a regulator asks why the DPO's documented concerns from six months ago were never acted on.
Ownership Has to Sit in Two Places
Privacy ownership has to sit in two places at once for it to actually work. The DPO owns oversight, independence, and the relationship with regulators. Someone embedded in product and engineering has to own privacy-by-design decisions in real time, because privacy problems get created at the moment data collection is designed, not caught later in a review. Split those roles cleanly and give both of them the standing to slow down a launch, and the DPO title stops being decoration.
Frequently asked questions
Can the same person hold both the oversight and operational privacy role?
Legally, sometimes. Practically, it's a conflict of interest, since the person ends up reviewing decisions they made themselves.
Does every company need a formal DPO?
GDPR requires one under specific conditions, like large-scale monitoring or special category data. Many companies without a legal requirement still benefit from the independent-oversight role.
What's the single best early warning sign of a privacy ownership gap?
A DPIA that gets written after a product has already shipped, instead of before. That order reversal usually means the embedded role doesn't exist yet.
If a regulator asked for your last five DPIAs today, how many were finished before the feature shipped?
Sources
- U.S. State Privacy Law Tracker, 2026, Clym. https://www.clym.io/blog/us-privacy-law-comparison-map
Originally published on the Devensa blog.