A controller appoints a Data Protection Officer but also makes that person Head of Marketing with conversion-rate KPIs that conflict with privacy advice. What requirement is most clearly breached?
Select an answer to reveal the explanation.
Short Explanation
Picture a referee who also owns one of the teams—nobody trusts the whistle. A DPO with marketing conversion KPIs is pulled both ways, so independence and no-conflict rules get broken even if the title looks fine on paper.
Full Explanation
GDPR requires that the DPO perform their tasks independently and without a conflict of interest. Combining DPO duties with a role that pushes aggressive personal-data use for revenue creates exactly that conflict. Formal appointment alone is not enough if organisational pressure undermines independent advice. Salary disclosure and academic credentials are not the core independence rule being tested here.