
The roles of Data Protection Officer (DPO) and Internal Information System Manager (RSII) are incompatible, according to the National Court.
Commentary on the Judgment of the National High Court (First Section, Contentious-Administrative Chamber) No. 139/2026 dated 18 March 2026.
The National High Court Judgment No. 139/2026, which is the subject of this commentary, stems from the contentious- No. 894/2023, brought by the Official Association of Architects of Granada against a penalty decision by the Spanish Data Protection Agency (AEPD), which imposed three penalties on it for breaches of data protection regulations.
Specifically, the AEPD imposed a penalty on the Association on the grounds that the person appointed as Data Protection Officer (DPO) was in a conflict of interest, as they held that position alongside that of Secretary of the Association and was involved in decision-making regarding the processing of personal data. Furthermore, the AEPD found a breach of the duty to provide information set out in Article 13 of the GDPR in the complaints and claims forms, as well as a breach of the regulations on cookies for installing third-party analytical cookies without adequately informing users or obtaining their consent. In response to these sanctions, the appellant Bar Association argued, amongst other grounds, that the appointment of the DPO did not give rise to any conflict of interest, that the omission of information on the forms had not been deliberate, that the sanctioning decision did not adequately identify the cookies installed, and that the sanctions imposed were disproportionate. In any event, the National High Court dismissed the appeal and upheld the AEPD’s penalty decision in its entirety, constituting a significant ruling on data protection that can be extrapolated to the field of internal investigations, as we shall see later.
The central focus of the decision lies in the interpretation of Article 38(6) of the GDPR and, in particular, in the independence requirements that must be met by the DPO. In the case under consideration, the secretary of the professional body was a member of its governing bodies and exercised powers relating to the admission of members, disciplinary matters, the organisation of services and other decisions having a direct impact on the processing of personal data. The National High Court considers these functions to be incompatible with the independent supervisory role of the DPO, as the person responsible for monitoring compliance with the regulations cannot, at the same time, be involved in the decisions whose appropriateness they are required to oversee. Consequently, the Chamber concludes that a conflict of interest arises when the DPO simultaneously performs functions that involve participating in determining the purposes and means of data processing.
The judgement also confirms the existence of two further data protection infringements. Firstly, it finds a breach of the duty to provide information laid down in Article 13 of the GDPR, as the necessary information was not provided to data subjects on the complaint and claims forms. Secondly, it upholds the penalty imposed for the use of third-party analytical cookies without providing the required information or obtaining users’ prior consent. Furthermore, the Court rejects the argument that the fines breach the principle of proportionality, considering that they were imposed at the minimum level and in a moderate amount. It also clarifies that the special regime applicable to certain public-law bodies does not preclude the imposition of fines on professional bodies where the infringements relate to data processing that goes beyond the exercise of public powers.
From a practical perspective, the ruling reinforces the importance of analysing potential conflicts of interest by taking into account the functions actually performed by the appointed person, rather than focusing solely on their post or title. The approach adopted by the Court emphasises the need to ensure genuine independence in supervisory and control functions, particularly in the case of those individuals who, by regulatory mandate, must act autonomously within the organisation. This approach is particularly relevant in the context of internal investigations, where the investigator’s impartiality is an essential guarantee of the validity of the procedure. The existence of functional or hierarchical links, or involvement in the events under investigation, may compromise the objectivity of the investigation and affect the credibility of its conclusions. Organisations should therefore assess in advance whether there are any conflicts of interest among those holding the position of Head of the Internal Reporting System (RSII) and should engage external investigators or utilise mechanisms that reinforce the independence of the process.
In short, the resolution in question reaffirms a principle of good governance that extends beyond the sphere of data protection, namely that the effectiveness of any internal control function depends, to a large extent, on the genuine independence of the body carrying it out. This same principle should guide the design and operation of internal investigations departments and internal reporting channels.
Cristina Molins Joly.
Internal Investigations Department.