Skip to main content

CISO vs DPO vs RSSI: who does what, really.

The practical boundaries between three roles that organisations confuse. What each one is accountable for, where they overlap, and which certifications signal which role.

By Christophe Mazzola, Practicing CISO · Founder of Cyber AcademyCertifications & credentialsAll pillars

The Cyber Academy take

The CISO (Chief Information Security Officer) owns the information-security strategy and programme. The DPO (Data Protection Officer) owns the GDPR-mandated independent oversight of personal-data processing. The RSSI (Responsable de la Sécurité des Systèmes d'Information) is the French equivalent of CISO. The three roles overlap at the data-security perimeter but answer to different mandates: CISO and RSSI to the executive, DPO to the regulator.

TL;DR

  • 1CISO and RSSI are the same role with different vocabulary. RSSI is the French title; CISO is the international title. Same scope.
  • 2DPO is independent by GDPR design, reports to the highest management level, cannot be dismissed for performing the role, and is the contact point for the supervisory authority.
  • 3CISO/RSSI accountability: information security strategy, risk register, incident response, board reporting. Mandate from the executive.
  • 4DPO accountability: GDPR compliance oversight, DPIA review, data-subject rights, supervisory dialogue. Mandate from the regulation.
  • 5They overlap on data security (Article 32 of GDPR) and incident response. A single person should not hold both roles in significant organisations, the DPO must remain independent of the data-processing decisions the CISO operates.

Two accountabilities, one perimeter

The confusion between these roles is not about job titles. It is about which authority each person answers to. The CISO and the RSSI run a programme on behalf of the executive: they are judged on whether the organisation is secure enough to keep operating and whether the board understands the residual risk it is carrying. The DPO answers to a different master entirely. The role exists because GDPR put an independent compliance function inside the organisation, and that function reports to the highest level of management while staying out of the operational decisions it has to assess. One side optimises for the business. The other side has to be able to tell the business it is wrong.

In operational terms, the CISO and RSSI build and defend; the DPO reviews and challenges. When a marketing team wants to enrich a customer database with third-party data, the CISO asks whether it can be done securely and the DPO asks whether it should be done at all under the lawfulness, minimisation and purpose-limitation tests. Both questions are legitimate. They are not the same question, and the moment you collapse them into one person you lose the second one.

The comparison that actually matters

Most published comparisons stop at definitions. The distinction that decides org-chart fights is the reporting line and the source of the mandate, because that is what determines who can overrule whom and who carries the liability when something goes wrong.

CISO vs DPO vs RSSI: mandate, reporting line, and signalling certifications
DimensionCISODPORSSI
Primary mandateInformation security strategy and programmeIndependent oversight of personal-data processingSame as CISO (French title)
Source of authorityDelegated by the executiveRequired and protected by GDPRDelegated by the executive
Reports toCEO, board, or risk committeeHighest management level, with independenceDirection générale or DSI
Accountable forRisk register, controls, incident response, board reportingDPIA review, data-subject rights, records of processing, supervisory dialogueSame scope as CISO, French regulatory context
Can be dismissed for doing the job?Yes, like any executiveNo, protected against dismissal for performing the roleYes, like any executive
Signalling certificationsCISM, PECB CCISO, Lead Cybersecurity Manager, CRISCGDPR DPO, CDPSE, ISO 27701 Lead ImplementerSame as CISO, often plus French-market ISO 27001

The certification column is the practical signal a hiring manager reads. A security leader profile is built on CISM for the management-level credential, the PECB Certified CISO for the executive framing, and Lead Cybersecurity Manager for the programme build. A data-protection profile signals through the Certified Data Protection Officer credential and a privacy-engineering layer like CDPSE. The two stacks are not interchangeable, and a CV that mixes them without a clear primary role usually signals someone who has done neither at depth.

Where they genuinely overlap: Article 32 and incidents

The overlap is real, and pretending otherwise is how organisations end up with gaps. Article 32 of GDPR requires appropriate technical and organisational measures to secure personal data: encryption, resilience, the ability to restore availability, and regular testing of those measures. That is security work. The CISO owns the controls that deliver it. But the DPO has to be able to assess whether those measures are appropriate to the risk to data subjects, which is a different lens from appropriate to the business.

The clean way to run this: the CISO is accountable for implementing and operating the Article 32 measures, and the DPO is accountable for forming an independent opinion on their adequacy. The CISO builds the encryption-at-rest standard; the DPO records in the DPIA that it is sufficient for the processing in scope, or flags that it is not. Neither approves their own homework.

ISO 27701 sits exactly on this seam. It extends an ISO 27001 ISMS into a privacy information management system, which gives the CISO and DPO a shared control framework instead of two disconnected vocabularies. The ISO 27701 Lead Implementer course is the single most useful qualification for the person who has to make the security programme and the privacy programme speak to each other.

Incident response is the second overlap and the one that breaks under pressure. The CISO runs the technical response: contain, eradicate, recover. The DPO runs the regulatory clock: GDPR gives 72 hours to notify the supervisory authority of a personal-data breach, and that assessment (is it a breach, is it notifiable, are data subjects at risk) is the DPO call, not the CISO call. If these two people are not in the same room within the first hour of a serious incident, you will either over-notify and burn credibility with the regulator or under-notify and breach the deadline.

Why one person should not hold CISO and DPO

The reason is structural, not workload. GDPR requires the DPO to be free of any conflict of interest: the DPO cannot hold a position that involves determining the purposes and means of processing personal data. A CISO does exactly that. The CISO decides which logging is retained, how long backups live, what monitoring inspects employee traffic, which vendors process data. Those are processing decisions. A single person who both makes them and is supposed to independently audit them cannot do the second job, because the supervisory authority will not accept self-review as independent oversight.

This is not a Cyber Academy opinion. European supervisory authorities have already fined organisations for appointing a DPO who also held an operational role over the processing they were meant to supervise. In a small organisation you may genuinely have one capable person who could do both. The answer there is not to combine the roles; it is to make that person the CISO and appoint the DPO externally, or vice versa. An external DPO is a recognised and often cleaner solution precisely because independence is built in.

The audit-room reality

When an ISO 27001 auditor or a supervisory authority looks at this, they are testing for one thing: can you show that security decisions and privacy decisions were made by people with the right authority and the right independence. The evidence they want is mundane and specific.

  1. A RACI or equivalent that names who is accountable for the risk register versus the records of processing, with no person holding both the operate and the oversee role for the same control.
  2. Incident records showing the DPO was engaged on notifiability and the CISO on containment, with timestamps that fit inside the 72-hour window.
  3. DPIAs that carry an independent DPO opinion on the security measures, not a security sign-off relabelled as a privacy review.

The audit and assurance skills that make this provable belong to a distinct profile again. CISA builds the audit and evidence discipline, and CRISC builds the risk-quantification language that lets the CISO present residual risk to the board in terms it can actually decide on. These are the credentials that turn a defensible structure into a demonstrable one.

Common mistakes to avoid

  • Treating CISO and RSSI as two roles to be filled separately. They are the same role; the title follows the language and the regulatory context, not the scope.
  • Letting the DPO report into the CISO or the IT function. That destroys the independence GDPR requires and is an easy finding for any regulator.
  • Assuming the highest-ranking certification wins. A CISM holder is not therefore qualified as a DPO, and a strong DPO credential does not make someone a security leader. Match the credential to the mandate.
  • Writing a board report that blends security risk and privacy risk into one number. The board needs to see both, because the consequences and the authorities involved are different.

The organisations that get this right do not have more headcount than the ones that get it wrong. They have a clear answer to a single question: for any decision about personal data, who builds it and who independently judges it. Keep those two answers in two different people, give each the credential that matches their mandate, and the org chart stops being a source of audit findings.

Frequently asked questions

01Can the same person be CISO and DPO?

Technically yes in small organisations, but the EDPB strongly discourages it. The DPO must remain independent of the processing decisions; the CISO operates those decisions. In a small org where the same person makes the call, the independence is fictional.

In any organisation of meaningful size (50+ FTE handling meaningful personal data), separate the roles. The DPO can sit in the legal team, the risk team, or report directly to the CEO. The CISO sits in the technology or security organisation.

02Which certifications signal a CISO?

CISM (ISACA) is the most common credential on a CISO resume, about 60% of CISO postings in Europe ask for it. ISO 27001 Lead Implementer or Lead Auditor (PECB) is the next most common. CISSP is the traditional US-style alternative.

For French RSSI roles, ANSSI-recognised qualifications (EBIOS Risk Manager, qualifications via the SecNumCloud or PASSI programmes) carry weight in addition to or instead of international credentials.

03Which certifications signal a DPO?

The Certified Data Protection Officer (CDPO, PECB-issued, GDPR-aligned) is the European reference. The CIPP/E (IAPP) is the alternative international privacy credential, particularly recognised in firms with US presence.

For technical DPOs (privacy engineers operating inside or alongside the security team), CDPSE (ISACA) is the technical complement. ISO/IEC 27701 Lead Implementer (PECB) is the management-system credential for organisations running a privacy ISMS.

04How do their salaries compare in Europe?

Wide variance by country and sector. In France in 2026, an experienced CISO/RSSI in a CAC 40 company earns 130,000 to 220,000 euros base. An experienced DPO in the same company earns 90,000 to 150,000 euros base. In financial services, both roles trend 20% to 30% higher. In mid-market, both roles trend 30% to 40% lower.

The salary spread reflects the scope: CISO/RSSI owns budget, headcount, technology choices. DPO owns oversight, independence, regulatory contact.

Cohorts that turn the reading into a credential.

ISACA★ Featured

CISM: Certified Information Security Manager

Manager4 daysLiveSelf-pacedIn-house
Self-paced. Start any time

The ISACA reference credential for security management. Four domains, the cert asked for in roughly 60% of CISO postings. Four-day cohort with one re-sit included.

Live €2,900

Self-paced €790

Book
PECB★ Featured

Certified CISO by PECB

Expert5 daysSelf-pacedLiveIn-house
Self-paced. Start any time

Certified CISO by PECB. Review available formats, prerequisites, current inclusions and certification terms before booking.

Live €2,499

Self-paced €899

Book
PECB

Lead Cybersecurity Manager

Manager5 daysSelf-pacedLiveIn-house
Self-paced. Start any time

Lead Cybersecurity Manager. Review available formats, prerequisites, current inclusions and certification terms before booking.

Live €2,499

Self-paced €899

Book
PECB

GDPR - Certified Data Protection Officer

Expert5 daysSelf-pacedLiveIn-house
Self-paced. Start any time

GDPR - Certified Data Protection Officer. Review available formats, prerequisites, current inclusions and certification terms before booking.

Live €2,499

Self-paced €899

Book
ISACA

CDPSE: Certified Data Privacy Solutions Engineer

Practitioner3 daysLiveSelf-pacedIn-house
Self-paced. Start any time

The ISACA credential at the intersection of privacy and technology. Three domains spanning privacy governance, privacy architecture and data lifecycle. The cert for privacy engineers building GDPR-grade systems, not just policies.

Live €2,900

Self-paced €790

Book
PECB

ISO 27701 Lead Implementer

Lead Implementer5 daysSelf-pacedLiveIn-house
Self-paced. Start any time

ISO 27701 Lead Implementer. Review available formats, prerequisites, current inclusions and certification terms before booking.

Live €2,499

Self-paced €899

Book
ISACA★ Featured

CISA: Certified Information Systems Auditor

Practitioner4 daysLiveSelf-pacedIn-house
Self-paced. Start any time

The ISACA reference credential for IT audit. Five domains, four-hour exam, the audit credential Big Four engagements default to. Four-day cohort with one re-sit included.

Live €2,900

Self-paced €790

Book
ISACA★ Featured

CRISC: Certified in Risk and Information Systems Control

Risk Manager4 daysLiveSelf-pacedIn-house
Self-paced. Start any time

The ISACA reference credential for IT risk. Four domains bridging business risk to IS controls. The natural complement to CISA and to ISO 31000 / 27005 for the ISACA vocabulary.

Live €2,900

Self-paced €790

Book

Pillar read. What next?

Each pillar links to the cohort that turns it into a credential. Browse the catalogue, or talk to us for a tailored path.