On 10 August 2026 the CNIL published practical guidance on a problem nearly every organisation has and almost none has written down: the conflict of interest of the data protection officer.
The starting point is Art. 38(6) GDPR. The DPO may perform tasks beyond those in Art. 39, subject to two cumulative conditions: those tasks must not deprive them of the time needed to act as DPO, and must not place them in a conflict of interest.
The questions that reveal it
The CNIL recommends carrying out the analysis before designating a DPO, or before assigning new duties to a serving one. These are the questions it proposes:
- Which other roles are combined with that of DPO?
- Does the DPO hold management duties? Chief executive and head of HR are generally incompatible, but so may be lower-ranking roles if they lead the DPO to determine the purposes and means of processing
- Do the DPO or their team hold decision-making power over purposes or means? If the DPO is also head of information security: do they set log retention periods, propose security measures, decide on access requests to staff data?
- In their other duties, does the DPO take positions on projects involving personal data, for example as a member of an ethics committee?
- Is the DPO a staff representative or trade union officer? A vote may require them to take a position on employee monitoring measures
- If the DPO is external: have they already represented the organisation in data protection litigation? Do they belong to a body with opposing interests, such as a processor or a joint controller?
If there is a conflict, it must be removed
The designating organisation is under an obligation to end the conflict. There are three routes: replace the DPO, withdraw the third-party duties that generate the conflict, or adopt other remedial measures.
Recusal and the deputy DPO
The most common measure is recusal: the DPO steps back from the affected scope and a deputy DPO acts there instead. The CNIL is firm that this cannot be a formality. A mere countersignature, without genuine decision-making power for the deputy, is not enough.
The deputy must enjoy the same guarantees as Arts. 37 and 39: resources, training, involvement in matters within their scope. And they must have no relationship of subordination to the designated DPO. The CNIL's example is plain: if an insurer's DPO is also head of anti-fraud and must recuse themselves there, an anti-fraud analyst cannot serve as deputy, because they cannot independently supervise processing decided by their own line manager.
Both the risk justifying the recusal and the division of responsibilities between DPO and deputy must be documented, so that no processing is left uncovered. The deputy is not notified to the authority: the point of contact remains the designated DPO, who must however be able to inform the deputy when the authority writes about processing within the recused scope.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free