Corporate · Privacy and data

Chief Privacy Officer and Data Protection Officer search

A US CPO is an officer the company designs. A GDPR DPO is a statutory role with independence the company does not get to redesign.

Brief a search How we run a search
01 Direct answer

A CPO search hires the officer who owns privacy. A DPO search designates the person GDPR Articles 37 to 39 require. They are not the same seat.

Chief Privacy Officer is a company-designed officer, most often in the United States, who owns the privacy programme, the regulator relationship, and increasingly the AI overlay. A Data Protection Officer is a statutory designation under GDPR Articles 37 (when you must designate), 38 (position, including independence) and 39 (tasks). You may put both titles on one person. You may not collapse Article 38 independence because the US title is more familiar to the board.

Privacy and AI-governance searches run on a 19-day shortlist and a 9-week median to accepted offer. Officer-level CPO and DPO seats also sit inside the 41 compliance and regulatory leadership placements when they are officers. Specialist privacy counsel sits inside the 96 senior in-house counsel placements. Parent desks: compliance recruitment and in-house counsel recruiting.

Seats
US CPO (officer the company designs) and GDPR DPO (statutory, Articles 37-39).
Clock
Privacy/AI-governance: 19 days to shortlist, 9 weeks median to accepted offer.
Pay context
IAPP 2025-26: half of AI-governance-only respondents sit below $151,800 base. Officer cash follows the company's officer band.
Reporting
CEO or board committee when independence is the test; GC when privacy sits inside legal.
AI overlay
Model-risk and EU AI Act where the company ships or procures AI. Separate Head of AI Governance when that is the standing seat.
Language
EU DPO searches are often bilingual. Brussels insurer: bilingual shortlist, 8 weeks to offer.
02 GDPR versus US officer

Articles 37 to 39 are statute. A CPO job description is not.

CPO versus DPO, as we brief it. Statute on the DPO side; company design on the CPO side.
QuestionGDPR DPOUS CPO
Legal basisGDPR Arts. 37-39Company officer; CCPA/CPRA and sector overlay
Must you designate?Art. 37: public body, large-scale regular monitoring, or special-category processing as coreNo statutory 'must' at federal level; state and sector rules still bite
IndependenceArt. 38(3): no instructions on Art. 39 tasks; cannot be dismissed for performing themCompany-designed; independence is a governance choice, not a statutory shield
TasksArt. 39: inform, monitor, advise DPIAs, cooperate with the authority, be the contact pointProgramme ownership, regulator, product, increasingly AI
Reporting line we lockCannot be instructed on Art. 39 tasks; often a board or CEO line plus a working line to the GCOften GC; CEO or committee when the board wants officer-grade independence
DegreeExpert knowledge of data-protection law; not a JD requirementJD common, not required

One person may hold both titles. The Article 38 independence test does not lapse because the US title is on the door.

Source: Regulation (EU) 2016/679, Arts. 37-39; Sartori briefing practice, 2026.

Sector landscape: cybersecurity and data privacy.

03 Reporting line

GC versus CEO is a design choice on a CPO. It is a statutory constraint on a DPO.

GC

Report to the GC

Privacy sits inside legal. The CPO is an officer of the legal department. Common in US groups where the GC already owns the regulator map. Risk: the DPO tasks in Article 39 cannot be instructed away if the same person is the DPO.

CEO

Report to the CEO or a committee

Independence is the test. Common where the audit committee or a privacy committee wants a line that does not run through the GC. ACC 2026: 40 percent of CLOs have majority oversight of privacy — which is not the same as owning the DPO.

04 AI overlay

Privacy counsel who has never touched a model is not an AI-governance hire. Head of AI Governance is not a CPO with extra adjectives.

Companies now ask for a CPO "who understands AI". That can mean three different seats. One: a CPO whose programme now covers training data, vendor models and an EU AI Act overlay — still a privacy officer, assessed on the privacy/AI clock (19 days / 9 weeks). Two: a privacy counsel intercept at a day-rate of $1,600-$2,800 while the officer search runs. Three: a standing Head of AI Governance, which is a different mandate on AI governance counsel.

The Brussels insurer brief was the first of those three: GDPR plus model-risk, bilingual shortlist, 8 weeks to accepted offer. We did not flatten it into legal operations, and we did not staff it as a CCO. Buyer guide: when to hire privacy and AI-governance counsel.

05 Pay and clock

IAPP for the job-family context. Sartori for the officer clock.

The $151,800 AI-governance-only figure is a self-reported base median. It is not a CPO bid.

Privacy and AI-governance search clock versus IAPP job-family pay context, 2025-26.
MeasureFigureBaseSource
Privacy / AI-governance shortlist19 daysSartori closed searchesSartori, 2017-2026
Privacy / AI-governance median offer9 weeksSartori closed searchesSartori, 2017-2026
Brussels insurer (GDPR + model-risk)8 weeks to accepted offerOne specialist mandateSartori vignette, of 96 specialist counsel
AI-governance-only median base$151,800 (half sit below)IAPP job family, self-reported baseIAPP Salary and Jobs Report 2025-26
Privacy / AI intercept (day-rate)$1,600-$2,800Sartori fractional/interim bandingSartori, 2026

Officer CPO cash follows the company's officer band, not the IAPP AI-governance-only base median. Do not blend.

Source: IAPP Salary and Jobs Report 2025-26; Sartori & Partners FACTS ledger, 10 September 2026.

19 days
Privacy and AI-governance time to shortlist.
Sartori & Partners
9 wk
Median brief to accepted offer.
Sartori & Partners
41
Compliance-leadership placements (officer CPO/DPO sit here when they are officers).Specialist privacy counsel sits in the 96.
Sartori & Partners
06 Brussels

Privacy and AI-governance counsel, EU insurer. GDPR plus model-risk. Bilingual. Eight weeks.

Insurance · Euronext-listed · Brussels

Privacy and AI-governance counsel

Situation
GDPR programme plus model-risk on the same desk. The company needed a bilingual shortlist who could sit with the supervisor and with the model-risk committee.
Approach
Mapped sitting privacy counsel and DPOs in EU insurance who had already owned a model-risk overlay. Not a US CPO brief translated into French.
Outcome
Bilingual shortlist. Accepted offer in 8 weeks. Specialist counsel clock, inside the 96.

Timeline: 8 weeks to accepted offer.

Client references

What the buyer said

First legal hire. They stopped us copying a listed-company GC job description. The counsel we hired still does commercial and privacy.

CHRO family-owned manufacturing group · Milan / New York

Chief Privacy Officer and DPO search — questions

What is the difference between a CPO and a DPO?

A US CPO is an officer the company designs; a GDPR DPO is a statutory role with independence under Articles 37 to 39. Article 37 sets when a DPO must be designated; 38 the position, including independence; 39 the tasks. You can hire one person into both, but the independence test does not go away because the US title is on the door.

Does a DPO have to be a lawyer?

No. GDPR requires professional qualifications and expert knowledge of data-protection law, not a law degree. We place lawyer and non-lawyer DPOs. The test is whether they can deal with the supervisory authority and with data subjects, which is Article 39, not a JD.

Should the CPO report to the GC or the CEO?

Report to the CEO or a board committee when independence is the test; report to the GC when privacy sits inside legal. A US CPO often reports to the GC. A GDPR DPO cannot be instructed on the tasks in Article 39. We lock the line in week 1 so the shortlist is not a mix of both designs.

How does AI-governance change the seat?

Where the company ships or procures AI systems, the CPO brief now includes model-risk, training data and EU AI Act overlay. That overlay is a different product when it is a standing Head of AI Governance. See AI governance counsel and when to hire privacy and AI-governance counsel.

How long does a privacy or DPO search take?

Privacy and AI-governance searches shortlist in 19 days, with a median accepted offer in 9 weeks. A privacy and AI-governance counsel search for an EU insurer in Brussels: GDPR plus model-risk, bilingual shortlist, 8 weeks to accepted offer. That is the specialist clock, not the GC clock.

What does the IAPP say about AI-governance pay?

IAPP's Salary and Jobs Report 2025-26 puts half of AI-governance-only respondents below $151,800 base, which we use as market context, not a bid. Officer CPO cash follows the company's officer bands, not that job-family median. We do not blend the two.

Do you also hire the surrounding privacy counsel?

Yes. Specialist privacy and AI-governance counsel sit inside the 96 senior in-house counsel placements, on the specialist clock. CPO and DPO officer seats sit inside the 41 compliance and regulatory leadership placements when they are officers, or on the specialist clock when they are counsel. Sector: cybersecurity and data privacy.

Sources

Clean external sources cited on this page.

Privacy officer

Brief CPO or DPO as the seat it actually is.

Articles 37-39 independence, or a US officer line. AI overlay named, not implied. No obligation.