After more than 30 years working in policing and now supporting organisations as a Data Protection Officer, one thing has become very clear to me that most organisations who don’t have a dedicated Data Protection Officer (DPO), just don’t understand what is really needed and say to me…
“We know we need to improve our data protection, but we don’t have the expertise, time or resources to do it properly.”
And honestly, that’s a position many organisations find themselves in.
Data protection isn’t just about having a privacy notice on your website, and even some of those are too generic! or asking staff to complete annual training. It’s about understanding how personal data flows through your organisation, identifying the risks and putting the right governance in place to protect both your people and your business.
The reality is that many organisations don’t need a full-time Data Protection Officer. What they do need is someone who can provide practical advice, guide them through the compliance journey and be there when difficult decisions need to be made.
That’s where an outsourced or fractional DPO can make all the difference and really supports your business and lets you focus on the operational side of your company, which is what you do best!
One of the things I enjoy most about my role is working alongside organisations and becoming part of their team. I help them understand where they are today, where the gaps are and, more importantly, where to start.
Because let’s be honest compliance can feel overwhelming. There are policies to review, Records of Processing Activities to complete, DPIAs to carry out, contracts to assess, staff to educate, cyber risks to consider and, of course, legislation to keep up with. Trying to tackle everything at once often means nothing gets done as it can feel so overwhelming if data protection is not your main role.
Instead, I work with organisations to create a practical roadmap. We prioritise the areas that present the greatest risk, build governance step by step and make compliance something that supports the organisation rather than becoming another burden.
My role can include carrying out compliance reviews, developing governance documentation, completing DPIAs and Legitimate Interest Assessments, advising leadership teams, supporting data breach management and acting as an independent outsourced DPO. Every organisation is different, so the support is tailored to what they actually need.
One thing I always say is that data protection doesn’t exist on its own.
It sits alongside cyber security, AI governance, information management and organisational culture. When those areas work together, compliance becomes much more than a regulatory requirement – it becomes part of how an organisation builds trust.
At the end of the day, my job isn’t to create paperwork. It’s to help organisations feel confident that they’re making informed decisions, managing risk appropriately and demonstrating accountability when it matters most.
If your organisation is struggling to find the time or expertise to manage data protection effectively, you don’t necessarily need another full-time employee.
Sometimes you just need the right person alongside you for the journey.
By Irene Coyle, DPO, OSP Cyber Academy


