Data Protection Officer vs CISO, Which Role Do You Need?

6 min readLast updated By Dr. Dominic Staiger

What is this about?

Data Protection Officers (DPO) and Chief Information Security Officers (CISO) are often lumped together in the DACH market, sometimes even held in personal union, which can be legally delicate. Both roles safeguard compliance, both frequently report directly to executive management, and both are increasingly procured externally. But they sit under different laws, pursue different protective objectives, and their formal separation is, in some constellations, legally required.

Direct comparison at a glance

DimensionData Protection Officer (DPO)Chief Information Security Officer (CISO)
Protective objectiveProtection of personal data of natural personsProtection of confidentiality, integrity and availability of all information (the CIA triad)
Legal basisArt. 37–39 GDPR; Art. 10 Swiss DSG (Federal Act on Data Protection / FADP) for SwitzerlandIndustry standards (ISO 27001), NIS2 (for critical entities), FINMA circulars for regulated institutions
Mandatory?Mandatory under the GDPR for large-scale regular monitoring or special categories of data; in Switzerland optionalNo general statutory obligation; de facto required under ISO 27001, NIS2 and for FINMA-regulated entities
Reporting lineDirect to the highest management level (Art. 38(3) GDPR)Usually to executive management or the CTO; direct reporting line for critical institutions
IndependenceLegally required (Art. 38(3) GDPR); no conflict of interestFunctional independence recommended; conflicts of interest with IT operations to be avoided where possible
Typical profileLegal education plus data protection certification (CIPP/E, CIPM)Technical education plus information security certifications (CISSP, ISO 27001 Lead Auditor)
Personal union possible?Delicate, holding both functions simultaneously can give rise to a conflict of interest under Art. 38(6) GDPR, particularly where the CISO personally takes processing decisions. In smaller structures it can be solved pragmatically; in large-scale processing the roles should be separated.
SupervisionFDPIC (Federal Data Protection and Information Commissioner) in CH, national DPA in EU Member StatesNo direct data protection supervision; FINMA for financial institutions, BAKOM for telecoms, BSI in DE for critical infrastructure
External appointment possible?Yes, expressly foreseen in Art. 37(6) GDPR and Art. 10(3) DSGYes, as "external CISO", "vCISO" or "ISB", see the next section on nomenclature

What is what, exactly? CISO vs ISB vs ISO

The nomenclature is confusing in the DACH region and varies by jurisdiction:

  • CISO (Chief Information Security Officer) is the internationally established designation. Standard in SaaS, pharma, banking and internationally active corporate groups.
  • Information Security Officer (German equivalent: ISB, Informationssicherheitsbeauftragter) is the German public-sector and BSI tradition (BSI Grundschutz). Frequently used in public administration and in German mid-market companies.
  • ISO (Information Security Officer per eCH-0199, Swiss public-sector role; Informationssicherheitsoffizier) is the Swiss administrative terminology for the role at federal, cantonal and municipal level. Note, not to be confused with ISO as a standards organisation or ISO 27001 as a standard.

Functionally the role is identical; the label follows the industry and the regulatory home. For the supervisory authority, what matters is not the title but the demonstrable performance of the function.

When do you need a DPO?

Under Art. 37 GDPR, designation is mandatory in three cases: (1) public bodies; (2) core activity involves large-scale, regular and systematic monitoring of persons; (3) core activity involves large-scale processing of special categories of data or of criminal-conviction data. In Switzerland, designation under Art. 10 DSG is not mandatory for private controllers but is recommended, it opens up the consultation privilege for data protection impact assessments under Art. 23(4) DSG.

Even outside the mandatory cases, a DPO mandate is useful if you serve international clients, regularly receive data subject requests, or need a clear point of contact for supervisory authorities.

When do you need a CISO / ISB?

A CISO role is de facto required as soon as you meet one of the following conditions: pursuing or holding an ISO/IEC 27001 certification; falling within scope of NIS2 as an essential or important entity; being FINMA-regulated and required to comply with FINMA-Rundschreiben 2023/01 on Operational Risks; being subject to DORA (financial entities from 17 January 2025); taking on large-scale processing as a Processor in pharma or healthcare; or having customers who require designated security ownership in their vendor audit.

In practice, many companies sit below the CISO threshold but would still benefit from a fractional external CISO, particularly as a bridge between IT operations and executive management.

Can we hold DPO and CISO in personal union?

Legally problematic. Art. 38(6) GDPR prohibits conflicts of interest for the DPO. A CISO who personally takes processing decisions (for example, selecting security tools that process personal data) cannot at the same time supervise those decisions as the DPO.

In small structures with manageable processing, the dual role can be resolved pragmatically with documented control mechanisms. In structures with large-scale processing, typically from 100 employees upwards or where special categories of data are involved, organisational separation is the gold standard. An elegant variant is the external award of both roles to independent providers who are separate from one another.

External vs internal appointment

External appointment is widespread for both roles and is provided for in Art. 37(6) GDPR (DPO) as well as customary in the industry for CISO roles. Advantages: no recruitment risk, immediate availability, clear escalation paths, avoidance of conflicts of interest with operational IT, and a more neutral posture vis-à-vis the supervisory authority.

Disadvantages: less informal internal knowledge, dependence on the availability of the external person, and higher hourly rates than an internal FTE (but still less expensive for part-time needs).

SIDD offers both roles externally, as DPO under Art. 10 DSG or Art. 37 GDPR respectively and as external CISO/ISB/ISO. In some mandates we hold both roles, but through personally separate mandate holders so as to exclude the conflict of interest.

Frequently asked questions

Must our group designate a DPO for every EU establishment? No, the group DPO under Art. 37(2) GDPR can cover several establishments, provided that they are easily accessible to the data subjects concerned and to the supervisory authorities. "Easily accessible" is interpreted strictly; linguistic and time-zone accessibility must be ensured.

Does a Swiss SME (small and medium-sized enterprise) need a CISO? If you are pursuing ISO 27001, supplying to FINMA- or BAKOM-regulated customers, or falling under the Swiss ICT minimum standard, yes. Otherwise the role is recommended but not strictly required. A fractional external CISO with a few days per month can be a sensible starting point.

What about the Swiss "Datenschutzberater", is that a DPO? The "Datenschutzberater" is the Swiss designation for the role under Art. 10 DSG, functionally comparable to the EU DPO. The label was changed with the 2023 DSG revision (previously: "Datenschutzverantwortlicher"). SIDD uses both terms, Datenschutzberater (CH) and Data Protection Officer (EU), depending on the applicable law.

Can our external data protection adviser also be our lawyer? Yes, and that even reinforces the duty of confidentiality. SIDD's advisers are bound by professional confidentiality (Art. 321 Swiss Criminal Code), which provides additional protection vis-à-vis authorities. Note, however, that professional confidentiality does not protect against evidentiary use in respect of one's own breaches of duty.

What does an external CISO role cost? Depending on the model: advisory (1–2 days per month) from CHF 4,000 per month; interim (2–3 days per week) at a day rate of CHF 1,800–2,400; vCISO under a fixed mandate as an individual offer based on scope. SIDD offers all three models.

How SIDD supports you

SIDD takes on both roles, the external Swiss data protection adviser under Art. 10 DSG, the external Data Protection Officer EU under Art. 37 GDPR and the external CISO / ISB / ISO. For mandates that require both roles, we ensure personal separation between DPO and CISO so as to exclude the conflict of interest under Art. 38(6) GDPR. For the legal background, read our Article 27 GDPR Compliance Guide and speak with us about the right setup.

Need help putting this into practice? SIDD operates the matching service.
See service →

Data Protection Officer vs CISO, Which Role Do You Need?

INSIGHT

Pillar · Datenschutz
18 June 2026
Dr. Dominic Staiger
DPO vs CISO, when do you need a Data Protection Officer, when a Chief Information Security Officer? Personal union, external appointment, 2026 guide.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.