The DPO in 2027: from legal watchdog to GDPR & AI orchestrator
On paper, the GDPR limits the DPO to an advisory and oversight role. In practice, many remain stuck between being a "whistleblower" and an overworked professional single-handedly filling the gaps in governance. With the AI Act, this passive approach has reached its limit: by 2027, the DPO must become the driver of data governance for the executive board, leveraging a network of business liaisons, stronger collaboration with the CISO, and AI-driven automation of documentation to focus on risk assessment.

On paper, the GDPR is clear: the DPO advises and alerts, but does not implement compliance. In practice, both in the private and public sectors, the reality is more complex. Many professionals remain stuck between the "whistleblower" posture (covering themselves legally from a remote office) and the overworked DPO trying to manually compensate for a lack of governance.
With the arrival of the AI Act, this passive approach has reached its limit. By 2027, the DPO must establish themselves as the leader of data governance for the executive committee or senior management.
Legal framework and operational reality: what does it mean to be a DPO today?
Registered with the supervisory authority, the Data Protection Officer ensures compliance with data protection laws (Art. 37 to 39 of the GDPR).
Reminder of responsibility: The DPO is not legally responsible for compliance; this duty lies exclusively with the data controller (general management, mayor, president, or director). The DPO informs the decision, while the executive branch manages the risk.
To reduce administrative burden and improve the reliability of mapping, using GDPR compliance software helps automate registers and track actions.
Moving beyond passive alerts: the DPO's ideal operational stance
A DPO who points out faults without proposing a path forward will eventually be bypassed. The challenge is to calibrate requirements: neither too high (to avoid blocking service or business) nor too low (to avoid sanctions).
- Small and medium-sized organizations: hiring an external DPO or using an e-DPO service (or shared public resources) provides access to expertise without increasing payroll costs.
- Large organizations: building a network of privacy liaisons within business departments (HR, IT, marketing, user services) to spread a culture of compliance on the ground.
Legal, cyber, or IT: the evolution of DPO profiles
While legal expertise in GDPR remains essential, the rise in cyberattacks and the complexity of IT infrastructures are bringing professionals from cybersecurity and IT backgrounds to the forefront.
Trained in Privacy by Design, these professionals bring a pragmatic approach. The goal is to create synergies: collaboration between the DPO and the CISO is becoming the essential foundation for data security.
Will AI replace the DPO?
AI can verify a text or detect a missing clause, but it lacks the critical thinking required to weigh human risk.
In accordance with the European AI Act framework (EUR-Lex), the DPO is the natural point of contact to help their organization manage its AI Act project.
Horizon 2027: The DPO takes a seat at the table
By 2027, compliance is no longer a cost center, but a driver of trust—a competitive advantage that sustains essential relationships. To fulfill this strategic role, the DPO must demand the necessary resources: a dedicated budget, departmental liaisons, and automated SaaS tools.
FAQ - The DPO's role in the age of GDPR and the AI Act
Is a legal background mandatory to be a DPO?
No. The GDPR requires expertise in data protection law (Art. 37.5) without mandating a specific degree. Engineers, CISOs, or risk managers with relevant training are perfectly qualified for the role.
What is the difference between an internal and an external DPO?
An internal DPO is an employee or public official within the organization. An external DPO is a service provider or shared entity registered with the supervisory authority. This is a common arrangement for SMEs and local government bodies.
Does the AI Act require an "AI DPO"?
No. The AI Act does not create such a role. However, since most AI systems process personal data, compliance oversight naturally falls to the DPO, in collaboration with IT and CISO teams.

