Governance & Compliance · Human role
Data Protection Officer
Human roleGovernance & ComplianceSafety, Security & Governancearc:DataProtectionOfficer
A privacy-accountable human role that reviews lawful-basis choices, legitimate-interests assessments and DPIAs, handles escalated data-subject requests and advises on data-protection implications before new processing is adopted.
Responsibility. Holds accountability for day-to-day GDPR compliance decisions.
Also known as: DPO, Privacy team, Privacy officer
Relationships
receives escalation from dynamic
sends data to dynamic
approves control
audits assurance
evaluates assurance
Design guidance
- SHOULD run privacy review alongside security and legal review as a standard pre-deployment step for new features.
- SHOULD assess GDPR implications of new AI capabilities, cloud services or analytics tools before adoption.
- MAY consult data protection authorities when choosing a lawful basis for sensitive processing such as clinical research.
Classification
- Patterns
- Privacy by design
- Quality attributes
- Transparency and accountability (NIST AI RMF: accountable and transparent)
- Risks mitigated
- Compliance problems discovered after substantial implementation investment
- Frameworks & regulations
- GDPR
Sources
- Ch9.7: T. Nguyen, "GDPR and Data Protection Regulations," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.7. ISBN: 9798244538229.
- Ref9.05: "Privacy and Data Protection for AI Systems," unpublished reference note (references/Chapter 9 - Safety, Ethics, and Compliance/05-Privacy-Data-Protection.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note