Where should DPOs sit under Chile's data protection law?

Chile's new data protection framework requires organizations to balance DPO independence, reporting lines and potential conflicts of interest.

Contributors:
Oliver Ortiz
CIPP/E
Senior manager
Deloitte Legal
Catalina Salas
Consultant
Deloitte Legal
Editor's note
The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains.
One of the major new features introduced by Chile's Personal Data Protection Law (Law No. 21,719) is the introduction of the data protection officer. Although the role is, in principle, voluntary and only mandatory for those entities that adopt an infringement prevention model, as highlighted in a previous analysis, the question we must now ask is: within which area should the DPO be placed, and to whom should they report?
The question is relevant because Decree No. 662 of 13 June 2025, still pending review by the Republic's comptroller general, approves the regulation governing the requirements, modalities and procedures for the implementation, certification, registration, and supervision of LPDP infringement prevention models. Article 8 provides that the DPO must report directly to the authority that appointed them and that authority must be the data controller's highest governing or administrative authority. However, the decree does not provide guidance on where the DPO should be placed, leaving that decision to each organization's discretion.
At this point, the European experience suggests the most logical approach is to place the DPO within an already existing team. A 2025 study by the European Data Protection Supervisor indicates the role is often located in compliance or legal. However, the EU General Data Protection Regulation does not contain any specific determination on this matter either. This decision, which may seem minor, can create both conflicts of interest and operational issues, so it is worth examining carefully.
The golden rule: The DPO cannot act as judge and party
Behind this entire discussion lies a simple idea: the DPO exists to ensure the organization processes personal data properly and safeguards individuals' rights. For that reason, the DPO should not be placed in a position where they effectively end up monitoring their own decisions. In other words, when the same person is responsible for deciding how data is used and assessing whether that processing is being carried out correctly, oversight ceases to be credible.
The LPDP is clear on this point. Article 50 provides that the DPO "may perform other functions and duties, while seeking to maintain independence in the performance of the role." Likewise, Spain's data protection authority, the Agencia Española de Protección de Datos, has indicated the DPO's placement is up to each organization, with a single limit: preserving the DPO's independence and avoiding conflicts of interest
With that rule in mind, here are the four most common placements and the advantages and risks of each.
DPO in cybersecurity or IT
Pros. Usually acceptable only in exceptional circumstances, particularly in organizations that, due to their size and resources, cannot separate the roles, provided the reasons are documented and independence is reinforced.
Cons. DPAs such as the AEPD have stated that, as a general rule, there must be separation between the DPO and the information security officer.
Conflicts to watch. If the information security officer makes a mistake and is also the DPO, they would have incentives not to report it. And, for example, if the DPO reports to the cybersecurity area, the same could supervise them, affecting their independence.
DPO in compliance or risk
Pros. It leverages an existing position and reporting line to senior management. This is a good option when most data risks arise from business processes.
Cons. Compliance manages legal risk for the organization; the DPO manages risk to individuals' rights. They do not always point in the same direction.
Conflicts to watch. To avoid conflict, the DPO must be able to apply both approaches properly at the same time: the company's legal compliance and the protection of data subjects' rights.
DPO in the legal area
Pros. Legal is usually cross-functional and nonoperational, which reduces conflict of interest. It is close to senior management, facilitating alerts, resources and weight in decision-making. It also knows how to deal with regulators and interpret legal rules.
Cons. A conflict may arise if the legal department must defend the organization before courts on data-related matters. In such cases, the company's defense strategy could be confused with the DPO's independent judgment and role in helping to prevent potential damages to data holders.
Conflicts to watch. Legal is usually more removed from the areas that handle the means of processing, especially IT and systems functions, which may reduce the DPO's operational proximity.
Independent DPO function
Pros. It makes it possible to define the DPO's position from the outset and, in principle, does not create conflicts of interest.
Cons. It requires the organization to have the real capacity to allocate an exclusive area, with its own resources and competencies.
Conflicts to watch. It does not present major conflicts, but because it is a new and separate area, the DPO may become unintentionally isolated from operational processes.
Although there is no single answer as to where the DPO should be placed, the answer will depend on the size of the organization, where its main risks lie, available resources, and maintaining the DPO's independence while avoiding conflicts of interest.
How to choose without getting it wrong
Placing the DPO within cybersecurity or IT is the most delicate option and should be reserved for exceptional circumstances as it is the area that makes technical decisions about data, in particular, the means of processing personal data. Asking it to oversee itself is not advisable. If a small organization has no choice but to combine both roles, it should, at a minimum, put in writing why it is doing so and the measures adopted to protect the DPO's independence. Another high-risk placement is Human Resources, since in practice it often determines the purpose and means of processing employee data.
Consequently, although not the only correct formula, placing the DPO in compliance or legal is usually the most convenient option for most companies, because they are cross-functional, close to senior management, and do not directly operate the data. The difference lies in the focus. Housing the DPO in compliance works well when risks arise from business processes, while legal offers proximity to senior management and experience with regulators, provided care is taken not to confuse the defense of the company's interests with the independent perspective the DPO owes to individuals.
Finally, creating an independent area is clearly the cleanest solution in terms of conflicts, but it is only within reach of organizations with sufficient size and budget to sustain it.
Four questions to ask
As a practical exercise, and with an organization that is just beginning to build its model in mind, we propose reviewing four simple questions before determining where to place the DPO.
- Does the DPO report directly to the highest authority — the board of directors, managing partner or highest-level manager as indicated by the GDPR and also by the LPDP Regulation currently under review?
- Does the designated person refrain from deciding for which purposes, and through which means, data is used — that is, are they not both, the one who controls and the one who is controlled?
- Do they have real autonomy? Meaning they do not receive instructions on the outcome of their work and cannot be sanctioned for doing it properly, and is this reflected in their contract or appointment?
- And do they have resources, access to information and a cross-functional position that allows them to act throughout the organization?
If the answer to any of these questions is no, it may be worth reconsidering the decision.

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.
Submit for CPEsContributors:
Oliver Ortiz
CIPP/E
Senior manager
Deloitte Legal
Catalina Salas
Consultant
Deloitte Legal



