The European Data Protection Board published the final report of the coordinated enforcement action on DPOs. The picture is not encouraging: many DPOs operate with insufficient resources, lack access to top management, and in some cases find themselves in potential conflict of interest situations.
The 7 main issues identified
- Insufficient resources allocated to DPOs (both time and budget)
- DPO expert knowledge not adequate for the business context
- Risk of conflicts of interest (DPOs with other operational roles)
- DPO tasks not always properly assigned
- Lack of systematic involvement of DPOs in decision-making processes
- External DPOs 'spread too thin' across too many clients
- Internal DPOs used 'part-time' or diverted to other tasks
Key quote from the report
External DPOs 'may end up spreading themselves too thinly' across clients, while some companies use internal officers only 'on a part-time basis' or 'divert some of their DPO's time to other tasks'.
The Italian situation
In Italy the phenomenon is particularly felt in the local Public Administration sector, where many municipalities appoint an external DPO with fees of a few hundred euros per year, making it structurally impossible for the professional to dedicate adequate time. The ScoreGDPR dataset found that 53.7% of Italian municipalities do not make DPO contacts accessible on their institutional website.
What can an external DPO do
- Limit the number of clients to those actually manageable (suggestion: max 15-20)
- Have tools that allow you to dedicate the right time to each (deadline management, automatic alerts)
- Document the time dedicated to each client to justify the rate
- Have standardized processes instead of redoing everything from scratch for each client
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free