I. Introductory Thoughts

Since the Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: GDPR or Regulation) and Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144, and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (hereinafter: AI Act) came into force, it became obvious to all data controllers and data subjects that significant overlaps have emerged between these two areas. Specifically mentionable the question of the overlap between the role of the Data Protection Officer (hereinafter: Data Protection Officer or DPO) and that of the AI Officer (hereinafter: AI Officer). It has become increasingly common for Data Protection Officers to simultaneously assume the role of AI Officer. At first sight, this may appear both justified and efficient, since the requirements imposed by the GDPR (professional competence and expert knowledge of data protection law and practice) could also be considered relevant to an AI Officer, given the close relationship between the two areas of law.

I. 1. What Is the Problem?

There is, however, an important question. While the GDPR establishes and regulates the position of the DPO, but neither the AI Act nor any other legislation specifically establishes the position or legal status of an AI Officer. The AI Officer can therefore be seen mainly as an organisational role created for practical reasons, for example to help an organisation comply with Article 4 of the AI Act on AI literacy. Article 4 states that providers and deployers of AI systems must take measures to ensure, to their best extent, that their staff have a sufficient level of AI literacy. In practice, one possible solution for providers and deployers is therefore to create the position of an AI Officer. It is important to emphasise that the position of an AI Officer is not a legal requirement. It is an organisational and practical solution.

Article 38 (6) of the GDPR states that “the data protection officer may fulfil other tasks and duties. The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests.” However, the GDPR does not give a detailed definition of when such a conflict of interest exists.

The purpose of this article is therefore to answer two questions: Is there a legal conflict of interest between the positions of DPO and AI Officer? And can a DPO also perform the duties of an AI Officer?

II. The Logic of Conflict of Interest Rules

To answer these questions, it is important to understand the purpose and function of conflict of interest rules. Tamás Török points out that it is difficult to give one general legal definition of a conflict of interest because different areas of law approach this concept from different perspectives. In our opinion, however, the main purpose is the same in all areas of law: conflict of interest rules are intended to protect independence.

Article 38 (3) of the GDPR states that „the controller and the processor must ensure that the DPO does not receive instructions regarding the exercise of those tasks”. In other words, the DPO must be independent when performing its duties. Because of this, conflict of interest is an important part of the legal position of the DPO and acts as a safeguard for this independence. „He or she shall not be dismissed or penalised by the controller or the processor for performing his tasks.” – also says the GDPR. The idea behind this rule is that the DPO should not have to fear negative consequences because of a professional opinion. The DPO’s opinions should be based on professional considerations.

But why must the DPO be independent? Recital 97 of the GDPR states that „DPOs should be able to perform their duties and tasks independently, regardless of whether they are employees of the controller.” Article 39 of the GDPR lists the tasks of the DPO. One of the most important tasks is to provide professional advice and information. These tasks can only work properly if the DPO is able to give advice independently and without being influenced by the organisation. So the DPOs must only depend ont he law.  For example, if a DPO gives data protection advice in a biased way, the purpose of the GDPR could be weakened. Important principles such as credibility, informed decision-making and transparency could also be affected. Independent professional advice is therefore an important part of the DPO’s role.

Finally, it is worth mentioning the 2016 WP 243 rev.01 Guidelines of the Article 29 Working Party. The Working Party identified situations where a conflict of interest exists for the DPO: „this entails in particular that the DPO cannot hold a position within the organisation that leads him or her to determine the purposes and the means of the processing of personal data.” A typical example would be a senior manager, such as a managing director, director or head of department.

III. The Tasks of the AI Officer

As we mentioned above, no specific law defines the legal status of the AI Officer. Because of that, there is no official list of tasks and responsibilities that must be performed by an AI Officer. In practice, however, there are many activities that may be given to such a professional. The following list – without the intention of fullness – is shows some of these.

  • First, AI literacy under Article 4 of the AI Act should be mentioned. AI literacy includes the skills, knowledge and understanding that allow providers, deployers and other affected persons to use AI systems with appropriate information and to understand the opportunities, risks and possible harm connected with AI systems. In our opinion, professional training in this area can be one of the main tasks of an AI Officer.
  • A closely related task is increasing awareness of AI use within the organisation.
  • AI literacy can also mean that organisations should have internal rules and policies concerning the use of AI. Preparing such internal policies can therefore also be considered an AI Officer’s task.
  • Article 13 of the AI Act requires providers and deployers to ensure transparency. The AI Officer can also play an important role in helping the organisation achieve effective transparency.
  • Ethical questions are also important. An AI Officer can help inform employees, deployers and providers about ethical behaviour and responsible use of AI.
  • Article 14 of the AI Act is particularly important because it deals with human oversight. It states that high-risk AI systems must be designed and developed so that natural persons can effectively supervise them while they are being used.
  • Particular attention should be paid to Article 14 of the AI Act, which governs human oversight: High-risk AI systems shall be designed and developed in such a way, including with appropriate human-machine interface tools, that they can be effectively overseen by natural persons during the period in which they are in use” Paragraph 4 of the same Article then sets out the criteria that the natural person assigned to carry out the oversight must be able to fulfil. These include, for example:
  • understand the capabilities and limitations of the high-risk AI system and monitor how it works;
  • be aware of “automation bias”, meaning that decisions and outputs produced by an AI system should be treated critically;
  • correctly understand the output of the high-risk AI system, taking into account the available tools and methods;
  • decide whether the AI system should not be used, whether its output should be overridden or whether it should be ignored;
  • intervene in the operation of the AI system and safely stop it, for example by pressing a “stop” button.

It should be emphasised that the AI Officer does not perform human oversight simply because the AI Act gives this role to the AI Officer. Rather, in practice, a professional who works as an AI Officer may have the necessary competences to perform these tasks effectively.

IV. Similarities Between the DPO and the AI Officer

At this point, it may already be clear that there are several similarities between the two roles. One reason is that both areas of law are based on similar principles. These include, for example, the lawfulness and fairness of processing personal data, transparency, purpose limitation, accuracy and storage limitation (Recital 94 of the AI Act).[2] 

Both positions can also be described as governance roles. This means that they can be part of the internal system used by an organisation to decide how it approaches data protection and/or the use of AI. This system can be supported by internal policies and rules. It is therefore useful to have a professional who coordinates these issues and provides advice. This person may be the DPO and/or the AI Officer. 

Another important similarity is training and awareness-raising: both roles involve explaining the most important aspects of the relevant area and providing professional, independent and responsible information about good practices. Both positions also require professional knowledge and skills.

The requirement of AI literacy under Article 4 of the AI Act logically means that the person responsible for AI should have appropriate professional knowledge. After all, it would be difficult for someone to explain the use, risks and possibilities of AI systems to providers, deployers and affected persons if that person did not have sufficient knowledge themselves.

Finally, both roles include an important element of human supervision and control. The DPO has a supervisory role concerning the organisation’s data protection activities, while the AI Officer may have a supervisory role concerning the use and outputs of AI systems.

V. Conclusion – Is There a Conflict of Interest Between the Two Positions?

In legal terms, there is no absolute conflict of interest between the two positions: as a general rule, a DPO can also perform the tasks of an AI Officer. Article 38 (6) of the GDPR states that „the DPO may fulfil other tasks and duties”. This provides a legal basis for a DPO to also perform AI Officer tasks as a general rule. However, whether there is a conflict of interest must be examined based on the specific tasks and decision-making powers given to the AI Officer.

There can be exceptions to this general rule. As mentioned above, the Article 29 Working Party’s guidelines consider it a conflict of interest if the DPO performs functions that belong to the controller. The DPO cannot decide the purposes and means of processing personal data. At the same time, there are no similar specific legal restrictions on the AI Officer. In principle, therefore, an AI Officer could also be a senior manager who decides the purposes and means of processing personal data within an organisation. It follows that if taking on the role of AI Officer also means deciding the purposes and means of processing personal data and/or performing senior management functions, then, based on the reasoning of the Article 29 Working Party, there is a conflict of interest. In such a situation, the person cannot also hold the position of DPO.

In conclusion, the answer depends on what specific tasks and decision-making powers are given to the AI Officer.

We recommend that organisations carefully examine whether the circumstances described above exist in their particular case. Organisations may also contact us for professional advice.

Dr. Péter Miklós

Attila Saly

8 September 2026

This website is maintained by Dr. Miklós Péter Ákos, attorney at law registered in the Budapest Bar Association (registered office: 1117 Budapest, Völgycsillag utca 4., 6. emelet 02. a., tax number: 42982117-2-41, BAR ID number: 36079442) in accordance with the laws and internal regulations applicable to lawyers, which, together with information on client rights, is accessible at www.magyarugyvedikamara.hu. The blog posts and articles on the website do not constitute specific legal advice, an offer or a solicitation. It is intended to inform the website visitors about the areas of expertise of Dr. Miklós Péter Ákos attorney at law. The website has been prepared in accordance with the Hungarian Bar Association (MÜK) Presidium's Resolution No. 2/2001 (IX.3.) on the "Content of the website of the Hungarian Bar Association" and with the provisions of Chapter 10 of the MÜK's Rules of Procedure No. 6/2018 (26.III.). Legal notice​

Web: ZK DESIGN - Ügyvédhonlap

dr. Miklós Péter adatvédelmi jogász
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website.