Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

AI Is Expanding the DPO’s Role Faster Than Organizations Are Preparing for It

AI Is Expanding the DPO’s Role Faster Than Organizations Are Preparing for It

By
Key Takeaways
  • AI Is Already Widespread: 70% of responding organizations use or plan to use AI, with generative AI used by 81% of that group.
  • Governance Remains Underdeveloped: Fewer than one-quarter of organizations have a formal AI strategy or policy, while only 31% have begun preparing for the AI Act.
  • DPOs Are Taking on AI Act Responsibilities: 55% of DPOs say the AI Act already falls within their responsibilities, and 71% want their role extended to cover compliance with it.
  • Training Has Not Kept Pace: Only 27% of DPOs report a good level of knowledge of the AI Act, while 85% have received no specific AI training.
  • The DPO Role Is Becoming More Technical: DPOs expect AI to require new skills and increase the complexity of their work, even as many continue to perform the role part-time.
Deep Dive

A study released by France’s data protection authority, the CNIL, alongside the French Ministry of Labour and Solidarity and the French Association of Data Protection Officers (AFCDP), found that 55% of DPOs already consider the EU AI Act part of their responsibilities. Seventy-one percent would like their role formally extended to include compliance with the regulation.

There is no such role for them written into the AI Act itself. That omission has left organizations to work out the division of labor for themselves, just as AI systems are becoming more common and the regulatory questions surrounding them more immediate. For DPOs, the boundary is particularly difficult to draw. Whenever an AI system processes personal data, the familiar obligations of the GDPR remain. The AI Act adds another body of requirements without neatly replacing the first.

The findings come from the fifth edition of the DPO Observatory, an initiative through which the General Delegation for Employment and Vocational Training (DGEFP) and the CNIL, in partnership with the AFCDP, have studied the changing employment and skills demands surrounding data protection officers since 2018. The latest study, carried out by the French national association for adult professional training, Afpa, turned its attention to AI and the AI Act.

What it found was a profession being drawn further into AI governance while the governance itself is still being built. Seventy percent of responding organizations use AI or plan to do so. Among those organizations, generative AI is by far the most common application, used by 81%. Roughly two-thirds buy their AI solutions from external providers, compared with 22% that develop them internally. Larger organizations are more likely to use the technology.

The machinery has arrived faster than much of the structure around it. Fewer than one-quarter of organizations have a formal AI strategy or policy, according to the survey. Fewer than one-third have introduced employee awareness campaigns or adopted an AI code of practice. Only 31% have begun preparing for the AI Act’s entry into force.

For the DPO, these are not distant governance questions. Respondents said AI systems are predominantly being used to process personal data, placing the GDPR squarely inside many AI projects. More than half of the DPOs surveyed said they are often or systematically involved in such work.

The practical result is that two regulatory regimes meet inside the same systems, while responsibility for one of them remains much clearer than responsibility for the other.

A Role Growing Faster Than Its Training

The GDPR gives the DPO an established place in data protection governance. The AI Act does not do the same. It makes no mention of the position, leaving the DPO’s place within AI governance undefined even as many of the people holding that position are already assuming responsibility for the work.

The survey’s 55% figure is revealing for precisely that reason. DPOs are not merely anticipating that AI Act compliance may eventually reach them. A majority already say it has. But responsibility and preparation are not advancing at the same pace.

Only 27% of DPOs surveyed said they have a good level of knowledge of the AI Act. Eighty-five percent have received no specific training on AI. CNIL said that while DPOs are generally well equipped to assess the GDPR dimensions of AI, they often lack the tools and methods needed to address the requirements arising from the AI Act.

That gap becomes more consequential when set against the profession itself. Seventy-nine percent of DPOs surveyed work internally, and 54% came to the role from areas other than law and IT. Among internal and shared DPOs, 85% perform the job part-time. At the same time, the profession is not an inexperienced one. Forty-five percent of respondents have worked in data protection for more than six years. The survey also found a balanced representation of men and women in the role.

There has never been a single DPO profile. Experience, professional background, available resources, organizational size and the amount of time devoted to the job vary considerably. AI now asks this already varied profession to absorb another layer of technical and regulatory knowledge.

The DPOs surveyed appear to understand what that means. Respondents said the development of AI will require them to acquire new skills and will make their work more complex and technical. They also see the change as a possible avenue for career progression.

There is something important in that combination. DPOs are not simply being handed another regulation. They are being pulled toward a broader form of governance in which privacy law, AI regulation and the actual behavior of increasingly complicated systems cannot always be separated into clean organizational boxes.

For employers, that creates a question larger than who reads the AI Act. If DPOs are going to carry responsibilities beyond the role envisioned for them under the GDPR, then training, resources and authority have to keep pace with the work. The survey suggests that the work is already moving.

CNIL said it will continue developing practical tools and resources to help professionals apply GDPR requirements to AI systems and understand and implement the AI Act.

The larger change may be harder to package into guidance. A profession built around the protection of personal data is finding itself close to the center of AI governance, not because a regulation placed it there, but because the systems themselves did. Organizations are now left to decide what should follow from that fact.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong