CNIL (France) · August 13, 2026

CNIL Guidance: Identifying and Managing DPO Conflicts of Interest

CNIL has issued guidance addressing how organizations can identify and remedy conflicts of interest when their Data Protection Officer holds additional roles, as permitted under the GDPR.

What CNIL Addresses

CNIL's guidance notes that the GDPR permits organizations to assign additional tasks and duties to their Data Protection Officer (DPO) beyond core DPO responsibilities. However, the guidance emphasizes that these additional missions must not impede the DPO's ability to perform their statutory functions, nor place the DPO in a situation of conflict of interest. The publication is framed around two practical questions: how to recognize a conflict of interest, and how to remedy one once identified.

Why This Matters

The excerpt underscores a tension inherent in many organizational structures: DPOs are frequently given other operational or managerial responsibilities alongside their data protection duties. CNIL's guidance signals continued regulatory attention to whether such dual-hatting arrangements are compatible with the independence and objectivity the GDPR expects of the DPO role. By raising the question of "how to recognize" a conflict, the guidance implies that conflicts are not always obvious and require active organizational assessment rather than passive assumption of compliance.

What This Means

Organizations that have assigned additional responsibilities to their DPO should use this guidance as a prompt to review those arrangements. In practice, this means examining whether any of the DPO's other duties could compromise their independence or create a situation where they are effectively overseeing decisions they themselves made in another capacity. Where a conflict is identified, organizations should be prepared to take remedial steps, as contemplated by CNIL, to restore the DPO's ability to act independently. Privacy counsel and compliance teams should treat this as an occasion to document how DPO role definitions are structured and to reassess governance arrangements that combine DPO duties with other operational functions.

We use cookies to run this site. Necessary cookies are always on; functional, analytics, and marketing cookies are off unless you choose to enable them. See our Privacy Statement for details.