The role of the Data Protection Officer (DPO) in the age of artificial intelligence: survey results released
22 September 2026
The integration of AI into professional practices and the implementation of the AI regulation are creating new challenges for DPOs and their organisations. To better understand their expectations and concerns, the French Ministry of Labour and Solidarity, the AFCDP, and the CNIL are publishing the results of a study launched in 2025.
Since 2018, the General Delegation for Employment and Vocational Training (DGEFP) and the CNIL in partnership with the French Association of Data Protection Officer (AFCDP), study the employment and skills challenges related to the GDPR by monitoring the evolution of the role of the data protection officer (DPO).
For its fifth edition, the DPO Observatory focused on the prospects for the evolution of the data protection officer’s role driven by artificial intelligence and the AI Act.
Carried out by the French national association for adult professional training (Afpa), the study sheds new light on the changes currently taking place, as seen through the eyes of data protection officers. It provides a better understanding of how AI is used within organisations and how its governance is structured. It also highlights the main compliance challenges identified by DPOs under the GDPR and the AI Regulation. Finally, it examines the future evolution of the role and the practical support needs of DPOs.
The profile of DPOs in 2025
The survey confirms some of the key trends identified in the previous study:
- 79 % of DPOs work as internal DPOs;
- 54 % of DPOs come from fields of expertise other than law and IT;
- 85 % of internal and shared DPOs work part-time;
- 45 % have more than six years ofexperience in the field of data protection;
- there is a balanced representation of men and women in the role.
The DPO profiles remain highly diverse, whether in terms of experience, background, resources, the time devoted to the role, or the size of the organisation they work for.
AI applications are developing, but governance is still under construction
The results show that 70% of responding organisations use or plan to use AI. Among them:
- The use of generative AI systems is by far the most common, affecting 81% of organizations using them;
- 2/3 purchase their solutions from external providers, compared to 22% who develop them internally.
This practice is strongly correlated with the size of organisations, with larger organisations making use of it more frequently.
To support this rapid growth in the use of AI, a framework for AI governance is gradually being put in place. However, the survey shows that, in most cases, this governance remains largely unstructured:
- less than a quarter of organisations have a formal strategy or policy on the subject;
- less than a third have implemented employee awareness campaigns or adopted an AI code of practice;
- 31% have started preparing for the entry into force of the AI regulation.
According to DPOs, AI systems are predominantly used to process personal data, making GDPR compliance a key issue.
More than half of the DPOs surveyed stated that they are often or systematically involved in AI projects.
AI Act, a new field of action for the DPO?
While there is no doubt that the DPO must be involved whenever AI processes personal data, the question of extending the DPO's skills to compliance with the AI Act remains fully open.
Since the AI Act makes no mention of the DPO, the DPO’s role is not clearly defined within internal governance structures.
In this regard, the study’s results are particularly significant and illustrate, in practice, that DPOs are highly likely to adopt the AI Act:
- 55 % of DPOs state that the AI Act already falls under their responsibility.
- 71 % would like the scope of their role to be extended to include compliance with the AI Act.
However, DPO still have a limited grasp of the AI Act:
- Only 27% of DPOs report having a good level of knowledge of the text.
- 85% of DPOs have not yet received specific training on AI.
While DPOs are generally well-equipped to assess the GDPR aspects of AI, they still often lack the tools and methods to address AI Act aspects.
Respondents are aware that the development of AI requires them to acquire new skills and makes their role more complex and technical, although it may also present an opportunity for career progression.
Faced with the many challenges raised by artificial intelligence and AI Act, the CNIL will continue to support DPOs by developing practical tools and resources to facilitate GDPR compliance for AI systems and to help professionals understand and apply this new legislation.