CNIL (France) · August 13, 2026
CNIL Guidance: Identifying and Managing DPO Conflicts of Interest
CNIL has issued guidance addressing how organizations can identify and remedy conflicts of interest when their Data Protection Officer holds additional roles, as permitted under the GDPR.
What CNIL Addresses
CNIL's guidance notes that the GDPR permits organizations to assign additional tasks and duties to their Data Protection Officer (DPO) beyond core DPO responsibilities. However, the guidance emphasizes that these additional missions must not impede the DPO's ability to perform their statutory functions, nor place the DPO in a situation of conflict of interest. The publication is framed around two practical questions: how to recognize a conflict of interest, and how to remedy one once identified.
Why This Matters
The excerpt underscores a tension inherent in many organizational structures: DPOs are frequently given other operational or managerial responsibilities alongside their data protection duties. CNIL's guidance signals continued regulatory attention to whether such dual-hatting arrangements are compatible with the independence and objectivity the GDPR expects of the DPO role. By raising the question of "how to recognize" a conflict, the guidance implies that conflicts are not always obvious and require active organizational assessment rather than passive assumption of compliance.
What This Means
Organizations that have assigned additional responsibilities to their DPO should use this guidance as a prompt to review those arrangements. In practice, this means examining whether any of the DPO's other duties could compromise their independence or create a situation where they are effectively overseeing decisions they themselves made in another capacity. Where a conflict is identified, organizations should be prepared to take remedial steps, as contemplated by CNIL, to restore the DPO's ability to act independently. Privacy counsel and compliance teams should treat this as an occasion to document how DPO role definitions are structured and to reassess governance arrangements that combine DPO duties with other operational functions.