Business A.M
No Result
View All Result
Monday, August 24, 2026
  • Login
  • Technology
  • Finance
  • Comments
  • Companies
  • Commodities
  • ONLINE & DIGITAL CONTENT PACKAGE
Subscribe
Business A.M
  • Technology
  • Finance
  • Comments
  • Companies
  • Commodities
  • ONLINE & DIGITAL CONTENT PACKAGE
No Result
View All Result
Business A.M
No Result
View All Result
Home ANALYSTS INSIGHTS

You have been appointed DPO. Now what?

by Michael Irene
August 24, 2026
in ANALYSTS INSIGHTS
appointed

There is something deceptively ceremonial about being appointed a Data Protection Officer. The title arrives with authority, independence and the reassuring weight of legislation behind it, and for a brief moment you may imagine that the difficult part was acquiring enough knowledge to deserve the appointment. Then you enter the organisation and discover that the law was merely your passport. Somewhere there is a ROPA nobody entirely trusts, a retention schedule inherited from another age, a processor whose contract promises deletion while nobody has thought to test it, and a product team already halfway through building something that privacy has only just heard about. This is usually when the education of the DPO truly begins.

 

I have learnt from experience that the greatest temptation for a newly appointed DPO is to demonstrate expertise by finding everything that is wrong. It is remarkably easy to do. Give a competent privacy professional access to an organisation for several weeks and they will return carrying gaps like fishermen returning from sea: missing DPIAs, inconsistent lawful bases, questionable retention periods, incomplete records, weak processor oversight and policies approaching archaeological status. The difficulty is not finding twenty problems. The difficulty is sitting before senior leadership and explaining, with conviction, why three of them deserve attention before the other seventeen.

 

That is the moment privacy becomes governance. Boards rarely need another recital of the GDPR because legislation is not how they experience organisational failure. They experience it through regulatory exposure, operational disruption, customer harm, reputational damage, wasted capital and decisions made without adequate information. An incomplete ROPA therefore matters not because Article 30 says one should exist, but because an organisation that cannot reliably describe its processing activities may also struggle to understand the blast radius of an incident, challenge a supplier, execute deletion, respond to a regulator or know what it has exposed when a system fails.

 

The DPO who understands this begins to speak differently. Privacy vocabulary remains important, but it becomes the foundation rather than the ceiling of the conversation. When I discuss retention with executives, for example, the question is not merely whether information has exceeded a prescribed period; it is why the organisation continues carrying a liability whose business value may already have expired. When discussing DPIAs, I am less interested in celebrating the number completed than understanding whether material privacy risks are influencing decisions before money is spent, contracts are signed and technology becomes difficult to unwind. Governance has little value when it arrives after inevitability.

 

This also requires abandoning one of the profession’s more comfortable illusions: that independence means distance. A DPO cannot understand risk by observing the organisation from a privacy citadel. You need to understand how the business makes money, where growth is expected to come from, which technology the organisation is betting on, where third parties have become operationally indispensable and what senior management worries about when privacy professionals are not in the room. Only then can independence become useful, because challenging a decision without understanding what produced it is compliance; challenging it while understanding the commercial consequences is judgement.

 

Aspiring DPOs should therefore study beyond privacy with some seriousness. Read the annual report and strategy alongside regulatory guidance. Understand risk appetite, product governance, procurement, outsourcing, technology architecture and, crucially, the economics of the organisation you advise. A £10 million transformation programme does not become a “privacy project” because personal data appears somewhere inside it, yet the privacy implications may determine whether that investment produces value or creates an expensive remediation programme three years later. The DPO who can make that connection will eventually find that conversations at board level become less about explaining privacy and more about shaping decisions.

 

There will, of course, be uncomfortable moments. Senior executives occasionally want certainty where the law offers judgement, and businesses naturally prefer answers that allow momentum to continue. The mature DPO learns that the most useful question is not always, “Can we do this?” Sometimes it is whether we should do it, what assumptions make the decision defensible, who owns the residual risk and whether we would remain comfortable explaining the same decision to customers, regulators and the board after something has gone wrong. Those questions move privacy from legal interpretation into organisational character.

 

Perhaps that is what surprised me most about becoming a DPO. The further I progressed into privacy leadership, the less the job seemed to be about privacy alone. A ROPA became a map of organisational memory; a DPIA became evidence of institutional judgement; breach management became a test of whether governance survives contact with panic; retention became a conversation about whether an organisation possesses the discipline to let go of information simply because it can no longer justify keeping it. The artefacts remained the same, but their meaning changed once viewed from the boardroom.

 

So when the appointment finally comes, resist the urge to spend your first months proving how much privacy law you know. The organisation probably already assumes that competence, which is why it gave you the title. Spend that time understanding where decisions are made, where accountability becomes blurred, where commercial ambition is moving faster than governance and where the organisation may be carrying risks it has normalised simply because nothing has happened yet. A good DPO can explain the law with precision; a board-level DPO understands the business well enough to recognise the moment when tomorrow’s privacy problem is being created today, while everyone else in the room still believes they are discussing growth.

 

  • business a.m. commits to publishing a diversity of views, opinions and comments. It, therefore, welcomes your reaction to this and any of our articles via email: comment@businessamlive.com 

 

Michael Irene
Michael Irene

Michael Irene, CIPM, CIPP(E) certification, is a data and information governance practitioner based in London, United Kingdom. He is also a Fellow of Higher Education Academy, UK, and can be reached via moshoke@yahoo.com; twitter: @moshoke

Previous Post

Nigeria SMEs: AI for revenue increase while reducing cost

Next Post

Designing a “Stay Proposition” for Africa’s aviation workforce

Next Post
aviation

Designing a “Stay Proposition” for Africa’s aviation workforce

  • Trending
  • Comments
  • Latest

CBN to issue N1.5bn loan for youth led agric expansion in Plateau

July 29, 2025

How UNESCO got it wrong in Africa

May 30, 2017

Glo, Dangote, Airtel, 7 others prequalified to bid for 9Mobile acquisition

November 20, 2017
NGX taps tech advancements to drive N4.63tr capital growth in H1

Insurance-fuelled rally pushes NGX to record high

August 8, 2025

6 MLB teams that could use upgrades at the trade deadline

Top NFL Draft picks react to their Madden NFL 16 ratings

Paul Pierce said there was ‘no way’ he could play for Lakers

Arian Foster agrees to buy books for a fan after he asked on Twitter

N25bn aviation dispute puts airline revenues, passenger confidence at risk 

N25bn aviation dispute puts airline revenues, passenger confidence at risk 

August 24, 2026
RCS business messages to hit 485bn globally by 2030

RCS business messages to hit 485bn globally by 2030

August 24, 2026
Tinubu

President Tinubu’s tall order reviving moribound refineries

August 24, 2026
solution

The right idea, the wrong solution

August 24, 2026

Popular News

  • CBN to issue N1.5bn loan for youth led agric expansion in Plateau

    0 shares
    Share 0 Tweet 0
  • How UNESCO got it wrong in Africa

    0 shares
    Share 0 Tweet 0
  • Glo, Dangote, Airtel, 7 others prequalified to bid for 9Mobile acquisition

    0 shares
    Share 0 Tweet 0
  • Insurance-fuelled rally pushes NGX to record high

    0 shares
    Share 0 Tweet 0
  • Major tech companies conquering Africa with sports

    0 shares
    Share 0 Tweet 0
Currently Playing

CNN on Nigeria Aviation

CNN on Nigeria Aviation

Business AM TV

Edeme Kelikume Interview With Business AM TV

Business AM TV

Business A M 2021 Mutual Funds Outlook And Award Promo Video

Business AM TV

Recent News

N25bn aviation dispute puts airline revenues, passenger confidence at risk 

N25bn aviation dispute puts airline revenues, passenger confidence at risk 

August 24, 2026
RCS business messages to hit 485bn globally by 2030

RCS business messages to hit 485bn globally by 2030

August 24, 2026

Categories

  • Frontpage
  • Analyst Insight
  • Business AM TV
  • Comments
  • Commodities
  • Finance
  • Markets
  • Technology
  • The Business Traveller & Hospitality
  • World Business & Economy

Site Navigation

  • Home
  • About Us
  • Contact Us
  • Privacy & Policy
Business A.M

BusinessAMLive (businessamlive.com) is a leading online business news and information platform focused on providing timely, insightful and comprehensive coverage of economic, financial, and business developments in Nigeria, Africa and around the world.

© 2026 Business A.M

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Technology
  • Finance
  • Comments
  • Companies
  • Commodities
  • ONLINE & DIGITAL CONTENT PACKAGE

© 2026 Business A.M