HireACISO

DPO vs CISO: can one person be both?

A DPO is a statutory privacy role with a legal independence requirement. A CISO is an accountable security executive. In the EU the same person usually cannot be both. In Canada they routinely are, and here is why the answer differs.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Under the GDPR, your CISO should not also be your data protection officer. Article 38 requires that a DPO receives no instructions about how to perform the role, cannot be dismissed or penalised for performing it, reports directly to the highest management level, and holds no other duties that create a conflict of interest. A CISO decides how personal data is processed and protected, which is the activity a DPO is meant to independently review. Several European supervisory authorities have fined organizations for appointing a head of IT or head of security as DPO on that reasoning.

Under Canadian law the position is different. PIPEDA requires an individual accountable for the organization's privacy compliance but imposes no independence test, so the same executive can hold both. Quebec's Law 25 requires a person in charge of the protection of personal information, a role that defaults to the person with the highest authority unless it is delegated in writing. Neither statute forbids a CISO from holding it.

What is actually different between the two roles

DPO and CISO compared on mandate, independence and scope
DimensionData protection officerCISO
Source of the role Statute. GDPR Articles 37 to 39 Business need. No statute creates the title
Protects The data subject The company
Scope of data Personal data only, including on paper All information assets, most of which are not personal data
Independence Required. No instructions, no conflicting duties, protected from dismissal Not required. Takes direction from the CEO or the board
Reports to Highest management level, by law Wherever the company puts them, which matters a great deal
Contactable by the public Yes, and published to the supervisory authority No
Can be outsourced Yes, explicitly contemplated by the GDPR Yes, as a vCISO

When is a DPO actually mandatory?

Article 37(1) makes designation compulsory in three cases, and only three. Everything else is voluntary. A voluntarily appointed DPO is held to the same independence requirements, so do not use the title casually.

  1. The processing is carried out by a public authority or body, other than a court acting judicially.
  2. The core activities require regular and systematic monitoring of data subjects on a large scale. Advertising technology, behavioural analytics and fleet or workforce tracking usually land here.
  3. The core activities involve large-scale processing of special categories of data, which includes health data, biometrics and data about criminal convictions.

Note the phrase "core activities". A Canadian SaaS company that holds European customer data as a byproduct of selling software is generally not caught. A Canadian company whose product is the monitoring is.

The common Canadian mistake

Companies selling into Europe put "DPO" in their trust centre because a customer questionnaire asked for one, without checking whether they are in scope and without giving the named person any independence. That is worse than saying you have no DPO because you are not required to have one. If you are not caught by Article 37, write that sentence in your questionnaire response and move on.

Who owns privacy in a Canadian company?

PIPEDA's accountability principle requires that an organization designate an individual accountable for compliance, and that the identity of that person be made available on request. That is a lighter obligation than the GDPR's. The role is routinely held by a general counsel, a COO or the security lead.

The teeth in PIPEDA sit in the breach regime rather than in the role. An organization must report a breach that poses a real risk of significant harm, notify affected individuals, and keep a record of every breach for 24 months after determining it occurred, whether or not it was reportable. Knowingly failing to report or to keep those records is an offence carrying up to $10,000 CAD on summary conviction and up to $100,000 CAD on indictment. The 24 month record is the duty companies forget. It sits next to the incident log a vCISO is already keeping. How that fits into an incident process is on the incident response plan.

Quebec is the outlier. Law 25 requires a person in charge of the protection of personal information whose title and contact details are published, privacy impact assessments for information system projects and for transfers outside Quebec, and it carries administrative and penal penalties well past anything PIPEDA offers. A Quebec-based company that treats Law 25 as PIPEDA with a French translation will be wrong about the assessment requirement.

So who should hold which role?

Canadian company, no EU establishment, no EU monitoring
One accountable individual for privacy. Your vCISO can hold it, and often should: the breach duties and the security duties are the same file.
Canadian company selling into the EU, not caught by Article 37
Name a privacy contact, do not call them a DPO, and say plainly in questionnaires that a DPO is not required. Consider an EU representative under Article 27 instead, which is a different and more likely obligation.
Caught by Article 37
Appoint a DPO who is not the CISO, not the CTO, and not the head of marketing. An outsourced DPO on a small retainer is the usual answer at this size and is explicitly permitted.
Quebec establishment
Publish the person in charge. If nobody is designated in writing, it is your most senior executive by default, which is rarely what they intended.

Common questions

Can our CISO be our DPO?

Not if the GDPR applies and the DPO role is mandatory. The CISO decides how personal data is secured, and the DPO is required to independently monitor those decisions, which is the textbook conflict Article 38 prohibits. Under PIPEDA there is no such restriction and the arrangement is common and accepted.

Can a vCISO also act as an outsourced DPO?

For the same client, no, for the same conflict reason. Some firms offer both services and staff them with different people, which is fine as long as the DPO is genuinely able to disagree with the CISO in writing. Ask how that disagreement would be recorded before you buy both from one provider.

Does PIPEDA require a privacy officer by name?

It requires an individual accountable for compliance and that their identity be available on request. It does not prescribe a title, a reporting line or independence. Most Canadian companies publish a privacy contact address and name the accountable person internally, which satisfies it.

What does a customer questionnaire really mean when it asks for our DPO?

Usually it is a European template being sent to everyone. Answer with the name and contact of your accountable privacy individual, state whether a statutory DPO is required of you and why, and attach your breach process. Nobody has ever failed a vendor review for explaining accurately that Article 37 does not apply to them.

Need someone to own privacy and security together

Tell us which jurisdictions your customers sit in. We will tell you which roles you have to fill and which ones a questionnaire only implied.

Get matched