All news
Regulation August 10, 2026 5 min

A DPO who decides cannot supervise themselves

The French DPA publishes guidance on conflicts of interest: which combined roles are incompatible, how to document a recusal, and why a deputy DPO cannot be a subordinate

On 10 August 2026 the CNIL published practical guidance on a problem nearly every organisation has and almost none has written down: the conflict of interest of the data protection officer.

The starting point is Art. 38(6) GDPR. The DPO may perform tasks beyond those in Art. 39, subject to two cumulative conditions: those tasks must not deprive them of the time needed to act as DPO, and must not place them in a conflict of interest.

The questions that reveal it

The CNIL recommends carrying out the analysis before designating a DPO, or before assigning new duties to a serving one. These are the questions it proposes:

  • Which other roles are combined with that of DPO?
  • Does the DPO hold management duties? Chief executive and head of HR are generally incompatible, but so may be lower-ranking roles if they lead the DPO to determine the purposes and means of processing
  • Do the DPO or their team hold decision-making power over purposes or means? If the DPO is also head of information security: do they set log retention periods, propose security measures, decide on access requests to staff data?
  • In their other duties, does the DPO take positions on projects involving personal data, for example as a member of an ethics committee?
  • Is the DPO a staff representative or trade union officer? A vote may require them to take a position on employee monitoring measures
  • If the DPO is external: have they already represented the organisation in data protection litigation? Do they belong to a body with opposing interests, such as a processor or a joint controller?

If there is a conflict, it must be removed

The designating organisation is under an obligation to end the conflict. There are three routes: replace the DPO, withdraw the third-party duties that generate the conflict, or adopt other remedial measures.

Recusal and the deputy DPO

The most common measure is recusal: the DPO steps back from the affected scope and a deputy DPO acts there instead. The CNIL is firm that this cannot be a formality. A mere countersignature, without genuine decision-making power for the deputy, is not enough.

The deputy must enjoy the same guarantees as Arts. 37 and 39: resources, training, involvement in matters within their scope. And they must have no relationship of subordination to the designated DPO. The CNIL's example is plain: if an insurer's DPO is also head of anti-fraud and must recuse themselves there, an anti-fraud analyst cannot serve as deputy, because they cannot independently supervise processing decided by their own line manager.

Both the risk justifying the recusal and the division of responsibilities between DPO and deputy must be documented, so that no processing is left uncovered. The deputy is not notified to the authority: the point of contact remains the designated DPO, who must however be able to inform the deputy when the authority writes about processing within the recused scope.

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Regulation
26the article nobody signs before broadcasting

Who answers for the live stream of the under-14 match? Sweden answers the question nobody asks

On 25 August the Swedish authority published guidance on streaming youth sport. Many clubs stream children's matches online, and the guidance sets out the factors that decide what is allowed. But the part worth reading is the other one: responsibility when the municipality owns the venue and the club wants to install cameras.

Aug 25, 2026New 5 min
Regulation
24months after which a past incident should not be used

The score they refuse your credit with can be requested, and it has to be explained

On 19 August the CNIL translated for the public its May 2026 recommendation on assessing creditworthiness. Inside are three numbers and one principle that concern anyone doing scoring: twenty-four months for past incidents, six months for the data of a refused application, and a right of access to the score that cannot be dismissed by invoking trade secrecy.

Aug 19, 2026New 6 min
Regulation
2EDPB criteria and the DPIA becomes mandatory

In schools, advertising trackers are prohibited — and consent has nothing to do with it

On 24 August the CNIL published its rules for the digital workspaces used in schools. The decisive point is not the protection of minors but a principle of administrative law: the neutrality of the public education service includes commercial neutrality, so trackers used for advertising or profiling are prohibited in principle. If the tool has them, the controller must switch them off.

Aug 24, 2026New 6 min