The DPO Role: What the Regulator Expects
- Rock Consultancy

- 3 days ago
- 4 min read
Updated: 2 days ago

July 2026
Appointing a DPO is the easy part. The DPC's Annual Report 2025 makes clear that under-resourcing one is an infringement of the GDPR — and that the DPC is checking.
Introduction
The Data Protection Commission (DPC) Annual Report 2025 (Annual Report) turns the spotlight on the Data Protection Officer (DPO) — and on the organisations that appoint them. The message is blunt: designation is a starting point, not a defence. Where a DPO is not properly resourced, supported and able to act independently, the organisation is in breach of the GDPR, not merely falling short of best practice.
By the end of 2025, 4,218 DPOs had been formally designated and notified to the DPC. This represents a year-on-year increase of over 7%, which highlights that privacy governance is still expanding across Ireland. The harder question — and the one the DPC is now asking — is whether those DPOs come with the budget, time and authority needed to function.
What the DPC is actually testing
The DPC describes the DPO as "an essential pillar for ensuring both compliance and accountability on the part of data controllers." Under the GDPR, a DPO's role includes advising the organisation on its data protection obligations, monitoring compliance, overseeing data protection policies, and delivering training and awareness for staff.
Who has to appoint a DPO — and what it costs not to
The obligation to appoint a DPO falls to both controllers and processors. Where that obligation applies, failing to appoint is itself an infringement — and a costly one, with a fine of up to €10 million or 2% of total worldwide annual turnover for the preceding financial year, whichever is higher. For an Irish public body or public authority the fine is capped at €1 million — lower, but payable from public funds.
A key message from the Annual Report is that appointing a DPO alone is not sufficient. The DPC states:
"Where a DPO has been designated by an organisation it is required that they are adequately supported by management and resourced to allow them to carry out their tasks, and failure to do so is an infringement of the GDPR."
Resourcing: where it quietly fails
Adequate resourcing means access to:
resources and infrastructure;
support staff;
regular and adequate training;
external support; and
sufficient time to perform DPO responsibilities.
Organisations must also safeguard the DPO's independence and ensure that additional duties do not create conflicts of interest.
Your DPO is the DPC's first port of call
The report confirms that the DPO is the organisation's primary point of contact with the DPC:
"DPOs also play an important role as the primary contact point for the DPC in their organisation."
That contact point is not theoretical. The Annual Report confirms that where an organisation has designated a DPO and a data subject raises a concern with the DPC, the DPC will engage directly with that DPO. The practical consequence is that the DPO becomes the organisation's face in a regulatory query — so response times, record-keeping and the DPO's own access to the relevant business information all become visible to the regulator at precisely the moment the organisation can least afford gaps.
The Annual Report also notes that the DPC undertook supervisory examinations into the resourcing of DPOs during 2025 and will continue this work in 2026 — a clear signal that designation records are no longer the end of the enquiry.
Breach notification: judgment, not box-ticking
Breach notifications are usually submitted by the DPO, who has to tell a minor incident from a major one on a risk-based assessment. That judgment is exactly where under-resourcing shows: an overstretched or inexperienced DPO tends either to over-notify, drawing avoidable regulatory attention, or to under-notify and miss the 72-hour deadline on the incident that actually mattered.
Case study 31 illustrates the role of the DPO in data breach management and preventative measures. In this case a national regulatory authority reported a data breach after official identity documents sent by standard post were never received and were ultimately deemed irretrievably lost. The investigation identified an incomplete handwritten address as a contributing factor. The DPO was part of the mitigation and preventatve actions, with the DPC noting that the DPO has “actively partnered with the individual business units and has updated training programmes within the organisation”.
Would your DPO function survive an examination?
Questions worth answering internally, before the DPC asks them:
How many hours a week does your DPO spend on the role — and is that recorded anywhere?
Does the DPO role have a job specification?
Does your DPO have a budget line of their own, or do they have to ask another function for money?
Who does your DPO report to, and does that person own any of the processing the DPO is meant to monitor?
The last time your DPO advised against something, what happened?
If the DPC emailed your DPO this morning, what could they answer without waiting on other teams?
Does the DPO and the data protection team have visible leadership support?
Key takeaways
DPO appointment is one critical decision; adequately resourcing the DPO is vital.
DPO appointment is not just for data controllers; it also applies to processors.
The DPC is actively examining whether DPOs are appropriately resourced.
The DPO serves as the primary point of contact with the DPC.
Where appointment is mandatory, failure to appoint a DPO risks a fine of up to €10 million or 2% of worldwide turnover — €1 million for Irish public bodies.
The test the DPC is applying is no longer whether an organisation has a DPO, but whether that DPO function would withstand scrutiny: enough time, enough budget, enough independence, and enough standing to be taken seriously when they advise against something. Organisations that cannot answer those questions internally may find themselves answering them to a regulator.
Further reading
The Data Protection Commission Annual Report 2025: https://www.dataprotection.ie/sites/default/files/uploads/2026-06/DPC-Annual-Report-2025-Digital-AW.pdf
The Data Protection Commission Annual Report 2025 (Case study 31) https://www.dataprotection.ie/sites/default/files/uploads/2026-07/DPC-CaseStudies2025-Digital-AW.pdf
At Rock Consultancy, we provide DPO services, including full outsourced DPO services, interim DPO services, and DPO support services (phone-a-friend DPO services).
On how Rock Consultancy can support your DPO obligations and requirements, please contact us at info@rockconsultancy.ie
