# Data Protection Officer vs CISO, Which Role Do You Need?

> DPO vs CISO, when do you need a Data Protection Officer, when a Chief Information Security Officer? Personal union, external appointment, 2026 guide.

- Source: https://www.sidd.swiss/en/insights/dpo-vs-ciso/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-06-18
- Author: Dr. Dominic Staiger
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## What is this about?

Data Protection Officers (DPO) and Chief Information Security Officers (CISO) are often lumped together in the DACH market, sometimes even held in personal union, which can be legally delicate. Both roles safeguard compliance, both frequently report directly to executive management, and both are increasingly procured externally. But they sit under different laws, pursue different protective objectives, and their formal separation is, in some constellations, legally required.

## Direct comparison at a glance

| Dimension | Data Protection Officer (DPO) | Chief Information Security Officer (CISO) |
| --- | --- | --- |
| Protective objective | Protection of personal data of natural persons | Protection of confidentiality, integrity and availability of all information (the CIA triad) |
| Legal basis | Art. 37–39 GDPR; Art. 10 Swiss DSG (Federal Act on Data Protection / FADP) for Switzerland | Industry standards (ISO 27001), NIS2 (for critical entities), FINMA circulars for regulated institutions |
| Mandatory? | Mandatory under the GDPR for large-scale regular monitoring or special categories of data; in Switzerland optional | No general statutory obligation; de facto required under ISO 27001, NIS2 and for FINMA-regulated entities |
| Reporting line | Direct to the highest management level (Art. 38(3) GDPR) | Usually to executive management or the CTO; direct reporting line for critical institutions |
| Independence | Legally required (Art. 38(3) GDPR); no conflict of interest | Functional independence recommended; conflicts of interest with IT operations to be avoided where possible |
| Typical profile | Legal education plus data protection certification (CIPP/E, CIPM) | Technical education plus information security certifications (CISSP, ISO 27001 Lead Auditor) |
| Personal union possible? | Delicate, holding both functions simultaneously can give rise to a conflict of interest under Art. 38(6) GDPR, particularly where the CISO personally takes processing decisions. In smaller structures it can be solved pragmatically; in large-scale processing the roles should be separated. |  |
| Supervision | FDPIC (Federal Data Protection and Information Commissioner) in CH, national DPA in EU Member States | No direct data protection supervision; FINMA for financial institutions, BAKOM for telecoms, BSI in DE for critical infrastructure |
| External appointment possible? | Yes, expressly foreseen in Art. 37(6) GDPR and Art. 10(3) DSG | Yes, as "external CISO", "vCISO" or "ISB", see the next section on nomenclature |

## What is what, exactly? CISO vs ISB vs ISO

The nomenclature is confusing in the DACH region and varies by jurisdiction:

- **CISO (Chief Information Security Officer)** is the internationally established designation. Standard in SaaS, pharma, banking and internationally active corporate groups.
- **Information Security Officer (German equivalent: ISB, Informationssicherheitsbeauftragter)** is the German public-sector and BSI tradition (BSI Grundschutz). Frequently used in public administration and in German mid-market companies.
- **ISO (Information Security Officer per eCH-0199, Swiss public-sector role; Informationssicherheitsoffizier)** is the Swiss administrative terminology for the role at federal, cantonal and municipal level. Note, not to be confused with ISO as a standards organisation or ISO 27001 as a standard.

Functionally the role is identical; the label follows the industry and the regulatory home. For the supervisory authority, what matters is not the title but the demonstrable performance of the function.

## When do you need a DPO?

Under Art. 37 GDPR, designation is **mandatory** in three cases: (1) public bodies; (2) core activity involves large-scale, regular and systematic monitoring of persons; (3) core activity involves large-scale processing of special categories of data or of criminal-conviction data. In Switzerland, designation under Art. 10 DSG is not mandatory for private controllers but is recommended, it opens up the consultation privilege for data protection impact assessments under Art. 23(4) DSG.

Even outside the mandatory cases, a DPO mandate is useful if you serve international clients, regularly receive data subject requests, or need a clear point of contact for supervisory authorities.

## When do you need a CISO / ISB?

A CISO role is de facto required as soon as you meet one of the following conditions: pursuing or holding an ISO/IEC 27001 certification; falling within scope of NIS2 as an essential or important entity; being FINMA-regulated and required to comply with FINMA-Rundschreiben 2023/01 on Operational Risks; being subject to DORA (financial entities from 17 January 2025); taking on large-scale processing as a Processor in pharma or healthcare; or having customers who require designated security ownership in their vendor audit.

In practice, many companies sit below the CISO threshold but would still benefit from a fractional external CISO, particularly as a bridge between IT operations and executive management.

## Can we hold DPO and CISO in personal union?

Legally problematic. Art. 38(6) GDPR prohibits conflicts of interest for the DPO. A CISO who personally takes processing decisions (for example, selecting security tools that process personal data) cannot at the same time supervise those decisions as the DPO.

In small structures with manageable processing, the dual role can be resolved pragmatically with documented control mechanisms. In structures with large-scale processing, typically from 100 employees upwards or where special categories of data are involved, organisational separation is the gold standard. An elegant variant is the external award of both roles to independent providers who are separate from one another.

## External vs internal appointment

External appointment is widespread for both roles and is provided for in Art. 37(6) GDPR (DPO) as well as customary in the industry for CISO roles. Advantages: no recruitment risk, immediate availability, clear escalation paths, avoidance of conflicts of interest with operational IT, and a more neutral posture vis-à-vis the supervisory authority.

Disadvantages: less informal internal knowledge, dependence on the availability of the external person, and higher hourly rates than an internal FTE (but still less expensive for part-time needs).

SIDD offers both roles externally, as DPO under Art. 10 DSG or Art. 37 GDPR respectively and as external CISO/ISB/ISO. In some mandates we hold both roles, but through personally separate mandate holders so as to exclude the conflict of interest.

## Frequently asked questions

**Must our group designate a DPO for every EU establishment?** No, the group DPO under Art. 37(2) GDPR can cover several establishments, provided that they are easily accessible to the data subjects concerned and to the supervisory authorities. "Easily accessible" is interpreted strictly; linguistic and time-zone accessibility must be ensured.

**Does a Swiss SME (small and medium-sized enterprise) need a CISO?** If you are pursuing ISO 27001, supplying to FINMA- or BAKOM-regulated customers, or falling under the Swiss ICT minimum standard, yes. Otherwise the role is recommended but not strictly required. A fractional external CISO with a few days per month can be a sensible starting point.

**What about the Swiss "Datenschutzberater", is that a DPO?** The "Datenschutzberater" is the Swiss designation for the role under Art. 10 DSG, functionally comparable to the EU DPO. The label was changed with the 2023 DSG revision (previously: "Datenschutzverantwortlicher"). SIDD uses both terms, Datenschutzberater (CH) and Data Protection Officer (EU), depending on the applicable law.

**Can our external data protection adviser also be our lawyer?** Yes, and that even reinforces the duty of confidentiality. SIDD's advisers are bound by professional confidentiality (Art. 321 Swiss Criminal Code), which provides additional protection vis-à-vis authorities. Note, however, that professional confidentiality does not protect against evidentiary use in respect of one's own breaches of duty.

**What does an external CISO role cost?** Depending on the model: advisory (1–2 days per month) from CHF 4,000 per month; interim (2–3 days per week) at a day rate of CHF 1,800–2,400; vCISO under a fixed mandate as an individual offer based on scope. SIDD offers all three models.

## How SIDD supports you

SIDD takes on both roles, the [external Swiss data protection adviser under Art. 10 DSG](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland), the [external Data Protection Officer EU under Art. 37 GDPR](https://www.sidd.swiss/en/services/data-protection-officer-eu) and the [external CISO / ISB / ISO](https://www.sidd.swiss/en/services/vciso). For mandates that require both roles, we ensure personal separation between DPO and CISO so as to exclude the conflict of interest under Art. 38(6) GDPR. For the legal background, read our [Article 27 GDPR Compliance Guide](https://www.sidd.swiss/en/insights/article-27-gdpr/) and speak with us about the right setup.

## Cited legislation and sources

- Art. 10 DSG
- Art. 23(4) DSG
- Art. 37 GDPR
- Art. 37(2) GDPR
- Art. 37(6) GDPR
- Art. 38(3) GDPR
- Art. 38(6) GDPR
- Art. 39 GDPR
- Art. 321 Swiss Criminal Code
- ISO/IEC 27001:2022
- NIS2 Directive
- DORA Regulation 2022/2554
- FINMA-Rundschreiben 2023/01
- eCH-0199

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
