Aishani Partners
One Role, Different Rules: Comparing Data Protection Officers Across Jurisdictions

As privacy regulation expanded across jurisdictions, many privacy laws introduced the concept of a data protection officer (“DPO”) or a function responsible for supporting an organization’s data compliance and providing a point of contact for individuals and regulators. Having said that, the nature of this role differs considerably under different laws.
This article compares the statutory requirements, roles, duties, independence, and related aspects of Data Protection Officers (“DPOs”) in India under the Digital Personal Data Protection Act, 2023 (“DPDPA”) and similar regulations under other key jurisdictions, such as the European Union’s GDPR[i], Singapore’s PDPA[ii], Brazil’s LGPD[iii] and South Africa’s POPIA[iv], and also look at the California state’s privacy laws as a contrasting regime that does not provide for a DPO and how it manages such requirements. The focus is on triggers for appointment, status in the governance structure, core statutory functions, independence, qualification/competence expectations, and enforcement risk.
India – DPDPA
1. Statutory Basis and Trigger for Appointment.
The DPDPA distinguishes between “Data Fiduciaries” and “Significant Data Fiduciaries” (“SDFs”), with Data Fiduciaries being entities that, that alone or jointly determines the purpose and means of processing personal data[v] and SDFs being data fiduciaries who may be identified through notification by the Government of India, based on certain factors[vi].
Section 10 of the DPDPA specifies that an SDF “shall appoint a Data Protection Officer”. The roles and obligations with respect to SDFs and DPOs are notified for future commencement on the 13th of May 2027.
DPOs appointed by SDFs must:
- Be an individual based in India;
- Represent the SDF under the DPDPA and function as the primary point of contact for the Data Protection Board and data principals with respect to data protection issues and grievances;
- Be responsible to the Board of Directors or equivalent governing body of such SDF.
2. Roles and duties of the DPOs:
While the DPDPA text sets out outline obligations, a DPO is expected to be obligated to:
- Act as the key contact for data principal’s queries and grievances and coordinating the grievance redressal mechanism required under the Act.
- Acting as the primary liaison with the Data Protection Board, including in relation to data breach notifications, investigations, and remedial directions.
- Driving implementation of DPDPA compliance, including oversight of notices, consent mechanisms, and data subject rights workflows.
- Leading or coordinating data independent protection impact assessments (DPIAs) and data audits mandated for SDFs under the Act and DPDP Rules.
- Advising the Board and C‑suite on privacy risk and embedding privacy into corporate governance and risk management practices.
3. Independence and Qualification
Unlike the GDPR, the DPDPA does not yet contain detailed statutory provisions on DPO independence or prohibition of conflicts of interest. Nor does it prescribe professional qualifications for DPOs. The requirement that the DPO be responsible to the board provides organisational seniority, but not the more elaborate independence framework found under the GDPR.
4. Violation of DPO related obligations:
Non‑compliance with SDF’s additional obligations under Section 10, which includes failure to appoint a DPO, can attract significant monetary penalties, up to ₹150 crore under the DPDPA.
European Union – GDPR
1. Statutory Basis and Trigger for Appointment:
Under Article 37, a DPO must be appointed by a controller[vii] or processor in cases where:
- it is a public authority or body (except courts in their judicial capacity); or
- the core activities consist of processing operations which inherently require regular and systematic monitoring of data subjects on a large scale; or
- the core activities consist of large‑scale processing of special categories of personal data under Article 9 or data relating to criminal convictions and offences under Article 10.
2. Roles and Duties:
Article 38 requires that the DPO:
- is involved, properly and in a timely manner, in all issues relating to personal data protection.
- is supported with necessary resources and access to personal data and processing operations, and continued knowledge development on the subject.
- does not receive instructions regarding the exercise of tasks, and is not dismissed or penalised for performing those tasks.
- reports directly to the highest management level of the controller or processor.
The DPO may perform other tasks, but the controller/ processor is required to ensure that such tasks do not result in a conflict of interest.
Article 39 of the GDPR sets out the mandatory responsibilities of a DPO, as:
- Informing and advising the controller, processor and their respective employees about obligations under the GDPR and applicable state-specific data protection regulations;.
- Monitoring compliance with GDPR, state-specific regulations and internal policies, including assigning responsibilities, raising awareness, training, and conducting related audits;
- Providing advice on, and monitoring, data protection impact assessments under Article 35;
- Cooperating with the supervisory authority;
- Acting as contact point for the supervisory authority on issues relating to processing, including prior consultation with the supervisory authority on high stakes processing.
3. Independence and Qualifications:
The GDPR does not mandate a specific formal qualification or license for DPOs. However, DPOs are to be designated on the basis of professional qualities and specifically expert knowledge of data protection law and practices. The DPO should also have the ability to perform the responsibilities mentioned in Article 39 of the GDPR[viii].
4. Violation of DPO related obligations:
Violation of the DPO‑related requirements (Articles 37-39) is subject to the GDPR administrative fines which may extend up to EUR 10 Million or 2% of total worldwide annual turnover in the preceding financial year, whichever is higher.[ix]
Singapore – PDPA
1. Statutory Basis and Trigger for Appointment/ Designation:
Singapore’s Personal Data Protection Act 2012 (PDPA), as amended in 2020, requires every organisation subject to the PDPA to designate at least one individual as a Data Protection Officer. This obligation applies regardless of size, sector, or volume of data, and covers both active and dormant companies handling personal data, including holding companies and entities in liquidation.
2. Roles and Duties:
The DPO is responsible for ensuring compliance with the PDPA when developing and implementing policies and processes for handling personal data, promoting data protection and security practices, communicating policies to staff, and handling consent and deletion requests, queries, and complaints from individuals. The DPO also alerts senior management to risks around personal data and establishes and reviews data protection policies and monitoring measures.
The PDPA requires that the DPO’s business contact information, such as email or phone number, be made publicly available so that individuals and the Personal Data Protection Commission (PDPC), can directly contact the organisation’s relevant point of contact on data protection matters.
3. Independence and Qualifications:
Like the DPDPA and GDPR, the PDPA, does not mandate any specific statutory educational, legal, or professional qualifications for a Data Protection Officer. However, an individual or organisation designated as a DPO is expected to have the appropriate skills, knowledge and authority to effectively oversee the organisation’s compliance.
The PDPA does not prescribe that the DPO be full‑time or independent; the function can be added to an existing role (for example, a partner or owner) or outsourced to an external service provider, although ultimate responsibility remains with the organisation. The DPO is not required to be based in Singapore.
4. Violation of DPO related obligations:
Failure to comply with DPO-related obligations under the PDPA may result in directions issued by the PDPC, including orders to cease non-compliant processing activities, to destroy unlawfully collected personal data, or to comply with any remedial directions issued by the PDPC.
Brazil – LGPD
1. Statutory Basis and Trigger for Appointment/ Designation:
Under Brazil’s Lei Geral de Proteção de Dados (LGPD) or General Personal Data Protection Law, data controller must appoint an Encarregado (or a Data Protection Officer), whereas processors that strictly process data for the controller are not mandatory obligated to appoint a DPO[x]. The DPO is a person appointed by the controller and operator to act as a communication channel between controller, data subjects, and the Autoridade Nacional de Proteção de Dados (ANPD) (or National Data Protection Authority).
Micro-enterprises, small businesses, startups and non-profit organisations (small processing enterprises) are exempt from appointing a DPO, if they satisfy ANPD’s high-risk criteria and do not exceed annual gross revenue thresholds[xi].
2. Roles and Duties:
Article 41(2) lists the core responsibilities of a DPO under the LGPD:
- Accepting complaints and communications from data subjects, providing explanations, and taking measures.
- Receiving and acting upon communications from the ANPD.
- Guiding employees and contractors regarding practices to be adopted for the protection of personal data.
- Performing other duties determined by the controller or established in complementary internal policies.
3. Independence and Qualifications:
LGPD does not require that a DPO be an employee or a natural person. The DPO function can be fulfilled by a legal entity, internal committee, working group, or an external service provider independently. No specific DPO certification is required; however, the appointee should have sufficient knowledge to the organisation’s data processing activities and risks. The DPO’s identity and contact details are to be publicly disclosed.
The ANPD issues rules on the definition and duties of the DPO, including modification of the triggers to appoint a DPO. An ANPD Resolution[xii] in 2024 enhanced the role substantially, and brought in technical autonomy, management access and addresses conflicts of interest situations.
4. Violation of DPO related obligations:
Failure to comply with DPO-related requirements under the LGPD may result in directions and warnings issued by the ANPD, fines, or mandatory publicising of the violation.[xiii]
South Africa – POPIA
1. Statutory Basis and Trigger for Appointment/ Designation:
South Africa’s Protection of Personal Information Act (POPIA), together with the Promotion of Access to Information Act (PAIA)[xiv], creates the role of an Information Officer (IO) rather than a DPO.
Each public and private body has a default IO, who by statute would be the head of the respective organisation, and organisations must register their IO and Deputy IO if any, with the Information Regulator.
2. Roles and Duties
The POPIA requires[xv] the IO to ensure that the organisation complies with the lawful processing conditions for personal information, respond to data subject requests, and cooperate with the Information Regulator.
IO responsibilities include encouraging compliance through training and awareness, handling information access requests under PAIA, overseeing POPIA and PAIA compliance programmes, and managing information governance. The IO is the primary privacy and access‑to‑information governance officer.
The role is therefore broader than merely serving as a contact point and combines privacy and access-to-information governance. POPIA does not prescribe a particular professional qualification. Its model instead places responsibility at a senior level within the organisation’s domestic governance structure.
3. Violation Proceedings under POPIA:
If an organisation violates its IO-related obligations or fails to act on the instructions of the Information Regulator, the POPIA may issue Enforcement Notices, or impose penalties or fines, as per the general sanctions prescribed under the law.
California, USA – CCPA and CPRA
Unlike the other jurisdictions mentioned above, the California Consumer Privacy Act[xvi] (CCPA) amended by the California Privacy Rights Act[xvii] (CPRA) does not require businesses to appoint a data protection officer or an equivalent designated privacy officer. Compliance obligations are instead imposed directly on the business.
The CCPA instead places compliance obligations directly on businesses, requiring them to implement appropriate measures to ensure compliance with consumer rights, data governance, and statutory obligations. Consequently, organisations retain flexibility in determining their internal privacy governance structures and may designate existing personnel, such as privacy counsel, compliance officers, or other employees, to oversee CCPA compliance.
Pertinent to mention, while appointing a dedicated privacy officer may constitute a governance best practice, it is not a statutory requirement under the CCPA/CPRA.
Comparative Analysis
Across jurisdictions that explicitly recognise DPOs (or equivalent positions), there are several common core responsibilities. These generally include acting as a point of contact between the organisation and data subjects, as well as between the organisation and the relevant supervisory authority or regulator, as seen under frameworks such as India’s DPDPA, European GDPR, Brazil’s LGPD, Singapore’s PDPA and South Africa’s POPIA.
Further, DPOs are expected to inform and advise management and employees regarding obligations under applicable data protection laws and internal privacy policies. In some jurisdictions, the role also extends to monitoring compliance through audits, training initiatives and awareness programmes, in addition to overseeing or advising on privacy impact and risk assessments.
Despite these broad similarities, the level of statutory detail and protection afforded to the DPO role varies significantly across jurisdictions. The points of differentiation are as follows:
- Under the GDPR, the functions and independence afforded to DPOs are codified under Articles 38 and 39, which includes explicit safeguards against dismissal or penalisation for performing DPO functions.
On the other hand, jurisdictions such as Singapore and Brazil adopt a flexible approach, permitting DPO responsibilities to be combined with existing organisational roles or outsourced, while continuing to hold the organisation accountable for compliance outcomes.
India’s DPDPA is still in its nascent stage and detailed expectations are likely to emerge through rules, regulations and evolving practice.
- With respect to independence, the GDPR imposes stringent statutory independence requirements, mandating that DPOs operate free from instructions concerning the discharge of their duties, report directly to the highest level of management, and remain protected against dismissal or adverse consequences arising from the bona fide performance their functions.
While the DPDPA requires DPOs of SDFs to be responsible to the board of directors or equivalent governing body, it does not presently prescribe detailed statutory protections relating to conflicts of interest, removal or operational autonomy.
Singapore and South Africa places emphasis on ensuring the existence of an accountable and accessible compliance function. Brazil, following ANPD Resolution of 2024, requires technical autonomy and addresses conflicts of interest.
- DPDPA specifically requires the DPO of an SDF to be based in India.
By contrast, the GDPR does not impose residency requirements on DPOs, although entities processing personal data without an establishment in the European Union are separately required to appoint a local representative. Singapore similarly does not mandate physical presence within the country, provided the DPO remains contactable from Singapore and relevant business contact details are publicly available.
Brazil’s LGPD expressly permits DPO functions to be discharged by external service providers or legal entities, without imposing any explicit residency requirement. South Africa’s framework, however, inherently ties IOs to the domestic organisational structure established under PAIA and POPIA.
Unlike the other jurisdictions, the CCPA/CPRA represents an evolving governance model that dispenses with the requirement of appointing a statutory privacy officer altogether. Instead, it places primary accountability directly upon the business, allowing organisations the flexibility to determine their own internal privacy governance structures.
Concluding Remarks
From the above analysis;
- It is evident that the DPO is not a uniform legal concept and differs across different foreign geographies. Its appointment trigger, obligations and functions, institutional hierarchy, and independence depend upon the law under which it has been created.
- Across all models, the effectiveness of the privacy function ultimately depends not only upon appointment, but also upon the authority, resources, information and access to management provided by the organisation.
- Multinational organisations should therefore not assume that a group-level DPDPA or GDPR compliant DPO would satisfy global requirements. Each jurisdiction’s needs are specific, and their governance models may need to accommodate different individuals and/or functions under different privacy laws.
Contributed by: Aditi Verma Thakur and Akash Sajan
[i] General Data Protection Regulations, 2016, The European Parliament and the Council of the European Union.
[ii] Personal Data Protection Act, 2012, Singapore.
[iii] Lei Geral de Proteção de Dados, 2018, Brazil.
[iv] Protection of Personal Information Act, 2013, South Africa.
[v] § 2(i), DPDPA, 2023, India.
[vi] Supra note v, § 2(z). The factors considered in determining whether a Data Fiduciary qualifies as a Significant Data Fiduciary include: (i) the volume and sensitivity of the personal data processed; (ii) the risk to the rights of Data Principals; (iii) the potential impact on the sovereignty and integrity of India; (iv) the risk to electoral democracy; (v) the security of the State; and (vi) public order.
[vii] Supra Note i, Article 4(7) . A Controller under GDPR, similar to a Data Fiduciary under the DPDPA, is any entity that determines the purposes and means of the processing of personal data.
[viii] Supra note i, Article 37(5).
[ix] Supra note i, Article 83.
[x] Resolution CD/ANPD No. 18/2024, Autoridade Nacional de Proteção de Dados.
[xi] ibid, Resolution CD/ANPD N0.2/2022.
[xii] Supra Note x.
[xiii] Supra Note iii, Article 52.
[xiv] Promotion of Access to Information Act, 2000, South Africa.
[xv] Supra Note iv, §Section 55. of the POPIA
[xvi] California Consumer Privacy Act, 2019, State of California, USA.
[xvii] California Privacy Rights Act, 2020, State of California, USA.