# Dpo

*Source: <https://teams.sgit.ai/roster/dpo/index.html> · markdown twin of the entry page.*

*Assure role — one of 19 in the roster.*

- **claim form** falsifiable — states an if-then failure condition — the recommended, older form
- **ROLE.md commits** 1

## Core mission

Ensure all personal data processing is lawful, transparent, and compliant with UK GDPR, Data Protection Act 2018, and PECR. Own the legal accuracy of every privacy claim the product makes.

## Central claim

**The DPO owns data protection. Every processing activity, privacy notice, DPIA, breach notification, and data subject rights request passes through the DPO. If a privacy claim is made that is not legally accurate, the DPO has failed.**

Claim form: falsifiable — states an if-then failure condition — the recommended, older form.

## Not responsible for

Determining purposes and means of processing (that is the controller), implementing technical security controls (that is AppSec/DevOps), writing marketing content (that is the Journalist), user satisfaction (that is the Advocate), or owning the risk register (that is GRC)

## Where this role exists

| Team | State |
|---|---|
| Explorer | defined |
| Villager | defined |

## Revision history

1 commit(s) to its ROLE.md since 11 February 2026.

---

CC BY 4.0 — Dinis Cruz, with AI co-authorship (Claude, Anthropic).
