
GDPR, India’s DPDP Framework and Practical Privacy Scenarios
Data Protection Officer interviews are no longer limited to definitions and legal terminology. Employers increasingly expect candidates to understand how privacy requirements translate into data inventories, Records of Processing Activities (RoPA), Data Protection Impact Assessments (DPIAs), data-subject requests, vendor governance, breach response, retention and executive reporting.
The strongest candidates can explain both the law and the operational steps required to apply it.
This guide covers 25 frequently asked DPO interview questions, from foundational concepts to practical scenarios. It includes the EU General Data Protection Regulation (GDPR), India’s Digital Personal Data Protection Act, 2023 (DPDP Act), the Digital Personal Data Protection Rules, 2025 and day-to-day privacy governance.
Important 2026 context: India notified the DPDP Rules, 2025 in November 2025, but their commencement is phased. Rules concerning the framework and functioning of the Data Protection Board came into force first; the Consent Manager rule is scheduled to commence one year after Gazette publication, while most operational rules are scheduled to commence 18 months after publication. Candidates should therefore distinguish between the notified framework, provisions currently in force and obligations that are still within the implementation period.
1. What is the role of a Data Protection Officer?
A Data Protection Officer, or DPO, supports an organisation in understanding, implementing and monitoring its data-protection obligations.
Under the GDPR, the DPO’s core tasks include:
- informing and advising the organisation and its employees about data-protection obligations;
- monitoring compliance with the GDPR and internal privacy policies;
- supporting awareness, training and privacy audits;
- advising on Data Protection Impact Assessments and monitoring their performance;
- cooperating with the supervisory authority; and
- acting as a contact point for the regulator and data subjects.
The DPO should be involved early in projects involving personal data. However, the DPO does not replace management’s accountability. The controller or processor remains responsible for compliance and for deciding how the organisation processes personal data.
Strong interview point: A DPO is an independent adviser and monitor—not the sole owner of every privacy risk or operational control.
2. When is appointing a DPO mandatory under the GDPR?
Under Article 37 of the GDPR, a controller or processor must appoint a DPO when:
- the processing is carried out by a public authority or public body, except courts acting in their judicial capacity;
- its core activities involve regular and systematic monitoring of individuals on a large scale; or
- its core activities involve large-scale processing of special-category data or personal data relating to criminal convictions and offences.
Examples may include hospitals processing patient data, banks or insurers processing customer information at scale, telecommunications providers, large behavioural-advertising platforms and organisations conducting extensive location or behavioural monitoring.
An organisation may voluntarily appoint a DPO, but if it formally uses the GDPR DPO title, it should respect the GDPR requirements concerning the DPO’s position, independence and tasks.
3. When is a DPO required under India’s DPDP Act?
Under Section 10 of the DPDP Act, the Central Government may notify a Data Fiduciary—or a class of Data Fiduciaries—as a Significant Data Fiduciary (SDF) after considering factors such as:
- the volume and sensitivity of personal data processed;
- risk to the rights of Data Principals;
- potential impact on India’s sovereignty and integrity;
- risk to electoral democracy;
- security of the State; and
- public order.
An SDF must appoint a DPO who:
- is an individual;
- is based in India;
- represents the SDF under the Act;
- is responsible to the board of directors or a similar governing body; and
- acts as the point of contact for the grievance-redressal mechanism.
Every Data Fiduciary must also publish the business contact information of its DPO, where applicable, or another person capable of answering questions about personal-data processing.
Important distinction: The statutory DPO requirement under the DPDP Act applies to notified SDFs. This is different from assuming that every organisation processing personal data in India must appoint a statutory DPO.
4. What is the current implementation status of India’s DPDP framework in 2026?
India enacted the DPDP Act in August 2023 and notified the final DPDP Rules in November 2025. The notified Rules use a phased implementation model:
- Rules 1, 2 and 17–21 commenced on Gazette publication;
- Rule 4, concerning Consent Managers, is scheduled to commence one year after publication; and
- Rules 3, 5–16, 22 and 23 are scheduled to commence 18 months after publication.
Therefore, as of 13 August 2026, organisations are in an important preparation period for many operational obligations involving notices, security safeguards, breach reporting, rights handling, children’s data and additional SDF duties.
A strong DPO candidate should verify the latest commencement notifications instead of relying only on the date the Act or Rules were issued.
5. What is the difference between a controller, processor, Data Fiduciary and Data Processor?
Under the GDPR:
- A controller determines the purposes and means of processing personal data.
- A processor processes personal data on behalf of a controller and under its documented instructions.
Under India’s DPDP Act:
- A Data Fiduciary determines the purpose and means of processing personal data, either alone or together with others.
- A Data Processor processes personal data on behalf of a Data Fiduciary.
- A Data Principal is the individual to whom the personal data relates.
The business role is determined by the actual processing activity, not merely by the wording used in a contract. The same organisation may act as a controller or Data Fiduciary for one activity and as a processor for another.
6. What skills should an effective DPO possess?
An effective DPO needs a combination of legal, operational, technical and communication skills.
Key capabilities include:
- knowledge of applicable privacy laws and regulatory guidance;
- an understanding of data flows, applications, cloud services and cybersecurity controls;
- experience with RoPA, DPIAs, privacy notices and data-subject rights;
- vendor and contract-risk assessment;
- incident and breach-response coordination;
- audit, risk-management and evidence-management skills;
- the ability to communicate with legal, security, IT, HR, marketing, procurement and senior management; and
- independence, professional judgement and the confidence to escalate risk.
A DPO does not need to be the organisation’s best lawyer or security engineer, but must be able to connect privacy requirements with business processes and technical controls.
7. What does DPO independence mean, and what creates a conflict of interest?
Under the GDPR, the DPO must be able to perform DPO tasks independently. The organisation should not instruct the DPO about what conclusion to reach, penalise the DPO for performing the role or prevent direct reporting to the highest management level.
A conflict may arise when the DPO also holds a role that determines the purposes and means of personal-data processing. Examples can include senior positions such as chief executive, chief operating officer, chief financial officer, head of HR, head of marketing or head of IT, depending on their actual decision-making authority.
Other duties are not automatically prohibited. The organisation should assess and document whether those duties create a real conflict, implement safeguards and review the position periodically.
Example answer: “A Head of IT who decides which monitoring systems will be deployed and how employee data will be used may struggle to independently review those same decisions as DPO.”
8. Can an organisation appoint an external DPO?
Yes. The GDPR allows a DPO to be a staff member or to perform the role under a service contract. An external DPO can provide specialist expertise, scalability and independence, particularly for smaller organisations.
However, outsourcing the function does not outsource the organisation’s accountability. The engagement should define:
- scope and responsibilities;
- access to processing activities, records and personnel;
- confidentiality requirements;
- escalation and reporting lines;
- response availability;
- conflict-of-interest safeguards; and
- adequate resources and continuity arrangements.
For India, an SDF’s DPO must meet the DPDP Act’s specific requirements, including being an individual based in India and being responsible to the board or similar governing body. The appointment structure must be checked against those statutory requirements.
9. What are the core principles of data protection?
Under the GDPR, the core principles include:
- lawfulness, fairness and transparency;
- purpose limitation;
- data minimisation;
- accuracy;
- storage limitation;
- integrity and confidentiality; and
- accountability.
India’s DPDP framework similarly emphasises lawful and purpose-specific processing, consent and transparency, data minimisation, accuracy, storage limitation, security safeguards and accountability.
A DPO should convert these principles into testable questions. For example:
- Are we collecting more data than the stated purpose requires?
- Can the individual understand the notice?
- Is there a defined deletion trigger?
- Can we prove that security safeguards are working?
- Can we demonstrate why the processing is lawful?
10. What is personal data, and how does special-category data differ?
Under the GDPR, personal data is any information relating to an identified or identifiable natural person. It can include names, identification numbers, location data, online identifiers and factors relating to a person’s identity.
Article 9 identifies special categories that receive additional protection, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data used for unique identification, health data and data concerning a person’s sex life or sexual orientation.
The DPDP Act defines personal data broadly as data about an individual who is identifiable by or in relation to that data. It does not reproduce the GDPR’s separate Article 9 category structure. However, the sensitivity and volume of data are relevant when the Government considers whether an organisation should be notified as an SDF.
The candidate should avoid automatically importing GDPR terminology into the DPDP Act.
11. What lawful bases can an organisation use for processing personal data?
Under Article 6 of the GDPR, the six lawful bases are:
- consent;
- performance of a contract;
- compliance with a legal obligation;
- protection of vital interests;
- performance of a task in the public interest or exercise of official authority; and
- legitimate interests, subject to the required balancing and applicable limitations.
Special-category data also requires a valid Article 9 condition.
Under India’s DPDP Act, personal data may be processed for a lawful purpose based on:
- consent; or
- certain legitimate uses specified in Section 7.
The DPDP Act’s “certain legitimate uses” are statutory situations and should not be treated as identical to the GDPR’s legitimate-interests basis.
A DPO should ensure that the chosen basis is determined before processing, documented and accurately reflected in the notice and operational workflow.
12. What is a Record of Processing Activities, or RoPA?
A RoPA is a structured record of an organisation’s personal-data processing activities. Under Article 30 of the GDPR, controllers and processors must maintain specified records, subject to the Regulation’s conditions and limited exemption.
A practical controller RoPA commonly captures:
- processing activity and business owner;
- purpose of processing;
- categories of data subjects and personal data;
- lawful basis;
- recipients and processors;
- international transfers and safeguards;
- retention periods;
- security measures;
- systems and storage locations; and
- links to DPIAs, notices and contracts.
A RoPA should be a living governance record, not a one-time spreadsheet prepared only for an audit.
13. What is the difference between a data inventory, data map and RoPA?
These terms are related but not identical:
- A data inventory identifies what data exists, where it is stored and who owns it.
- A data map shows how data moves between people, systems, departments, vendors and countries.
- A RoPA records processing activities and the compliance information required for those activities.
In practice, a reliable RoPA depends on accurate inventory and flow information. A DPO may begin with interviews, system inventories, application scans, vendor lists and questionnaires, then validate the result with business and technical owners.
14. What is a DPIA, and when should it be conducted?
A Data Protection Impact Assessment is a structured assessment used to identify and reduce privacy risks before or during high-risk processing.
Under the GDPR, a DPIA is required when processing is likely to result in a high risk to individuals’ rights and freedoms. Common indicators include systematic and extensive profiling with significant effects, large-scale processing of special-category data, systematic monitoring of publicly accessible areas, use of new technology or combinations of risk factors identified by regulators.
A practical DPIA should:
- describe the proposed processing and its purpose;
- assess necessity and proportionality;
- identify risks to individuals;
- evaluate likelihood and impact;
- define controls and owners;
- record residual risk and approvals; and
- establish review triggers.
Under India’s DPDP Act, SDFs must undertake periodic DPIAs. The notified DPDP Rules prescribe a 12-month cycle for an SDF’s DPIA and audit once the relevant operational rule commences.
15. What is privacy by design and by default?
Privacy by design means integrating privacy requirements into a product, service or process from the earliest planning stage rather than attempting to add them after launch.
Privacy by default means configuring the service so that only the personal data necessary for the specified purpose is processed unless the individual chooses otherwise.
Practical measures include:
- collecting fewer fields;
- limiting access by role;
- using privacy-protective default settings;
- separating mandatory and optional purposes;
- pseudonymising or anonymising data where appropriate;
- defining retention and automated deletion;
- testing consent and rights workflows; and
- completing privacy reviews before production release.
The DPO should advise and challenge, while product, engineering and business owners implement the controls.
16. How would you design a Data Subject Request or Data Principal Rights workflow?
A practical rights-request workflow should include:
- Intake: Provide accessible channels for submitting requests.
- Identity verification: Use proportionate verification and avoid collecting unnecessary identity data.
- Classification: Identify the right being exercised and the applicable law.
- Scope and search: Locate relevant information across systems, vendors, archives and unstructured sources.
- Legal review: Assess exemptions, third-party rights and retention obligations.
- Action: Access, correct, update, erase or otherwise fulfil the valid request.
- Response: Communicate clearly within the applicable deadline.
- Evidence: Maintain an auditable record of the request, decisions, actions and response.
Under the GDPR, organisations generally must respond without undue delay and within one month, subject to permitted extension. The notified DPDP Rules establish a period—up to 90 days—for Data Fiduciaries and Consent Managers to respond to grievances, once the relevant provisions commence. Candidates should distinguish a rights request from a grievance and confirm the exact applicable workflow and deadline.
17. How should a DPO respond to a personal-data breach?
The DPO should be part of a documented, cross-functional incident-response process involving security, legal, privacy, communications, business owners and senior management.
The response should include:
- containing and investigating the incident;
- establishing what happened and when the organisation became aware;
- identifying affected data, individuals, systems and jurisdictions;
- assessing likely risk or harm to individuals;
- preserving evidence and maintaining a breach log;
- deciding whether regulator and individual notification is required;
- documenting the reasoning, even when notification is not made;
- coordinating accurate communications; and
- tracking remediation and lessons learned.
Under the GDPR, a controller generally notifies the competent supervisory authority within 72 hours of becoming aware of a breach unless the breach is unlikely to result in a risk to people’s rights and freedoms. Affected individuals must be informed without undue delay where the breach is likely to result in a high risk, subject to the Regulation’s conditions.
Under India’s notified DPDP Rules, once the relevant provisions commence, the Data Fiduciary must inform affected Data Principals without delay, provide an initial intimation to the Board without delay and provide detailed information to the Board within 72 hours, unless the Board allows a longer period on written request.
18. How should a DPO manage third-party and processor risk?
Third parties should be assessed before onboarding, contractually governed and monitored throughout the relationship.
A practical privacy due-diligence review should examine:
- the service and processing purpose;
- categories and volume of personal data;
- the vendor’s role and instructions;
- security controls and incident history;
- sub-processors;
- hosting locations and international transfers;
- deletion and return of data;
- assistance with rights requests and DPIAs;
- breach-notification obligations;
- audit rights and evidence; and
- termination and exit arrangements.
The depth of review should be risk-based. A payroll processor, health-data platform or biometric provider needs more scrutiny than a supplier that never receives personal data.
19. How do you build a data-retention schedule?
A retention schedule should connect each record category with:
- its business and processing purpose;
- applicable legal or regulatory requirement;
- limitation, dispute or investigation needs;
- retention start event;
- retention period;
- system and owner;
- archive conditions; and
- secure deletion or anonymisation method.
“Keep everything forever” is not a valid privacy strategy. The organisation should be able to explain why data is still needed and prove that deletion occurs across production systems, backups, archives and vendors according to an approved lifecycle.
The DPO should challenge excessive retention and monitor the governance process, while system and business owners implement deletion.
20. How should international data transfers be assessed?
Under the GDPR, the first step is to identify whether personal data is transferred or made accessible outside the European Economic Area. The organisation must then identify an appropriate Chapter V mechanism, such as an adequacy decision, Standard Contractual Clauses or another permitted safeguard or derogation. Where required, it should assess the destination-country risks and implement supplementary measures.
Under India’s DPDP Act, the Central Government may restrict transfers to notified countries or territories. The notified Rules also allow specified categories of personal data handled by SDFs to be subject to restrictions based on Government requirements once the relevant rule commences. Sector-specific localisation or transfer rules may still apply independently.
A DPO should maintain a transfer inventory, understand remote access as well as hosting, and review vendors, sub-processors, contractual safeguards and technical measures.
21. What privacy controls are required when processing children’s data?
Children’s data needs heightened protection.
Under the GDPR, the lawful basis, transparency and risk controls must reflect the child’s age and understanding. For consent-based information-society services offered directly to a child, Article 8 sets the default age at 16 but permits Member States to lower it to no less than 13.
Under India’s DPDP Act, a child is an individual under 18. The framework requires verifiable parental consent before processing a child’s personal data and restricts processing likely to harm the child, tracking or behavioural monitoring of children and targeted advertising directed at children, subject to notified exemptions and conditions.
A strong answer should also cover age assurance, child-friendly notices, minimisation, safe defaults, restricted profiling, parental workflows and documented exemption analysis.
22. How should a DPO assess AI and automated decision-making?
A DPO should examine the complete AI data lifecycle rather than only the final model.
The assessment should cover:
- the source and lawful use of training, testing and input data;
- transparency to affected individuals;
- data minimisation and purpose limitation;
- accuracy, bias and discriminatory effects;
- sensitive-data inference;
- profiling and significant decisions;
- human review and contestability;
- security, prompt or output leakage and model access;
- retention of prompts, logs and outputs;
- vendor and cross-border risk; and
- the ability to honour rights requests.
Under the GDPR, Article 22 and related transparency, fairness and DPIA requirements may apply to solely automated decisions that produce legal or similarly significant effects. Under India’s notified DPDP Rules, an SDF must conduct due diligence regarding technical measures, including algorithmic software, that may pose a risk to Data Principals’ rights once the relevant rule commences.
23. Which privacy metrics should a DPO report to senior management?
Useful privacy metrics should show risk, control effectiveness and decision needs rather than only activity counts.
Examples include:
- number and status of rights requests and grievances;
- response times, overdue cases and request-quality issues;
- open high-risk DPIA actions and residual risks;
- processing activities without current notices or lawful-basis documentation;
- vendor assessments completed, overdue or rated high risk;
- retention and deletion exceptions;
- privacy incidents, breaches and notification decisions;
- repeat control failures;
- training completion and role-specific gaps;
- audit findings and remediation ageing; and
- percentage of high-risk projects reviewed before launch.
The DPO should add context, trends and recommended decisions. A dashboard without risk interpretation is rarely enough for the board.
24. What would your first 90 days as a new DPO look like?
Days 1–30: Understand and baseline
- Confirm applicable laws, entities, roles and jurisdictions.
- Establish access to senior management and key stakeholders.
- Review existing policies, notices, RoPA, DPIAs, contracts, incidents and audits.
- Identify important data flows, systems, vendors and high-risk processing.
- Record urgent gaps and define an escalation path.
Days 31–60: Prioritise and stabilise
- Build or validate the processing inventory and RoPA.
- Review rights-request, grievance and breach-response workflows.
- Prioritise high-risk DPIAs and vendor reviews.
- Assess retention, children’s data, transfers and privacy notices.
- Define owners, deadlines and evidence requirements.
Days 61–90: Operationalise and report
- Present a risk-based roadmap to senior management.
- Test a rights request and breach scenario.
- Establish privacy review gates for projects and procurement.
- Launch role-based awareness activities.
- Agree on metrics, governance forums and periodic reporting.
The aim is not to solve every issue within 90 days. It is to establish visibility, ownership, prioritisation and a defensible compliance programme.
25. Scenario: The business wants to launch a mobile app that collects location, identity and behavioural data. What would you do?
A strong DPO response should be structured and risk-based:
- Clarify the purpose: Why is each category of data required?
- Identify roles and scope: Which entity determines the processing, and which vendors are involved?
- Map the data: Document collection, use, sharing, storage, access and deletion.
- Minimise: Remove fields and tracking that are not necessary.
- Determine the lawful basis: Assess each purpose separately and design valid consent where required.
- Review transparency: Prepare a layered, clear and accessible privacy notice.
- Conduct a DPIA: Assess location tracking, profiling, children, new technology and other high-risk factors.
- Assess vendors and transfers: Review analytics, advertising, cloud and software-development providers.
- Define security controls: Apply encryption, strong access control, logging, testing and incident readiness.
- Design rights and consent withdrawal: Make the workflows functional, not merely described in a policy.
- Set retention: Define deletion triggers for account, location, analytics and support data.
- Validate before launch: Test settings, notices, permissions, deletion, rights and breach-response paths.
The DPO should document advice, unresolved risk and management decisions. If the residual risk is unacceptable, it should be escalated before launch.
How to Answer DPO Interview Questions Effectively
Strong DPO interview answers normally follow four steps:
- State the requirement or principle.
- Explain the operational process.
- Give a practical example.
- Describe the evidence or outcome.
For example, instead of saying, “I would conduct a DPIA,” explain how you would describe the processing, test necessity and proportionality, identify risks to individuals, assign controls, assess residual risk and record the final decision. Employers are looking for candidates who can convert privacy law into repeatable governance and business decisions.
Final Takeaway
A DPO is not only a policy writer or regulatory contact. The role connects law, technology, risk, security, business operations and individual rights.
To succeed in a DPO interview, demonstrate that you can:
- interpret requirements accurately;
- identify privacy risks in real processing activities;
- design practical and measurable controls;
- maintain independent judgement;
- communicate with both technical and non-technical stakeholders; and
- give management clear, evidence-based advice.
That combination of legal knowledge and operational ability is what makes a DPO effective
– Wiseman CyberSec
Build Practical DPO Expertise with Wiseman CyberSec
Wiseman CyberSec’s live DPO Training Program helps professionals build practical expertise in data privacy, GDPR and India’s DPDP framework.
The program includes hands-on exposure to:
- RoPA, DPIA and DSR frameworks;
- privacy governance and risk management;
- GDPR and DPDP compliance;
- data-lifecycle security;
- vendor, compliance and audit support; and
- practical exercises, templates and interview preparation.
Participants also receive session recordings, mentorship support and interview guidance.
Upcoming batch: 29 August 2026
Schedule: Weekend sessions, 7:00 PM–10:00 PM IST
Duration: 24 hours of live instructor-led training
Instructor: Senior privacy professional with 20+ years of industry experience
