GDPR in practice: the 4 obligations every DPO has to master day to day
GDPR isn't something you apply once and file away. It's a set of operational habits you have to keep up over time, and that's exactly where most organizations slip: the register is up to date on audit day, then nobody touches it for six months. Here are the four obligations that shape a DPO's day-to-day work, and where the most common mistakes hide.
1. The processing register is not a one-off exercise
The register required under Article 30 has to document, for every processing activity: its purpose, the categories of data involved, the recipients, retention periods, and the security measures in place. Two mistakes show up over and over in audits: a generic register, copied from an online template and never adapted to the actual organization, and forgotten subcontracted processing — a SaaS tool a business team adopted without the DPO's sign-off, quietly processing personal data while appearing nowhere in the register. A credible register is built once, then maintained through a quarterly review, not rebuilt from scratch once a year.
2. Know when a DPIA is actually required
A Data Protection Impact Assessment (DPIA) isn't automatic: it's required for any processing likely to result in a high risk to individuals' rights and freedoms, per the criteria published by data protection authorities and the European Data Protection Board. The costliest mistake isn't running one unnecessarily — it's skipping one that was actually required, usually because the processing seemed minor when it was first set up. A solid DPIA documents the necessity and proportionality of the processing, the risks identified for the people concerned, and the measures chosen to reduce them.
3. Handle access requests within the deadline
Anyone can request access to their own data, with a one-month response deadline, extendable to three in genuinely complex cases. Three steps make up a compliant response: verify the requester's identity without overreaching, search exhaustively for the data held — including at subcontractors, often forgotten under time pressure — and document any legitimate exceptions to disclosure (trade secrets, third-party rights). A poorly handled access request is rarely due to bad faith — it's due to the absence of a written procedure prepared in advance.
4. Respond to a data breach without panicking
A personal data breach triggers two distinct obligations: notifying the supervisory authority within 72 hours when the breach poses a risk to individuals, and communicating directly with affected individuals when that risk is high. A third obligation, often overlooked, applies to every breach regardless of severity: keeping an internal register, including for incidents judged minor and never notified. That internal register is precisely what a regulator examines first — its absence is itself a red flag, independent of how serious the incidents it should have recorded actually were.
What separates an operational DPO from one who's just keeping up
These four obligations aren't independent boxes to tick: an up-to-date processing register makes a DPIA faster to document, and a well-run DPIA anticipates some of the questions an access request or a breach will raise later. The difference between a DPO who's driving GDPR and one who's just reacting to it rarely comes down to knowledge of the text — it comes down to how consistently these four habits are kept up.
Our GDPR in practice course puts these four obligations into practice on real scenarios. AuditForge also includes a dedicated GDPR module, linking your processing register directly to your compliance audits — get in touch to talk it through.
