Cyber Security Awareness Blog | The Security Company

First 90 Days as a DPO | Free eBook | TSC

Written by The Security Company | Jul 22, 2026 3:33:13 PM

Navigate your first 90 days as a new DPO with practical guidance on GDPR compliance, data protection culture, DPIAs, SARs, and data breach response.

How to make an impact in your first 90 days as a new DPO: Essential guidance for new Data Protection Officers

As a new Data Protection Officer (DPO), the foundations you build in your first 90 days will shape your organisation's data protection compliance, privacy risk management, and security culture for years to come. With 95% of cyber security incidents linked to human error and more than 120 nations adopting data protection rules, DPOs play a critical role in protecting personal data, supporting GDPR compliance, and reducing the risk of costly data breaches.

This guide explains the core responsibilities of a DPO, from Data Protection Impact Assessments (DPIAs) and Subject Access Requests (SARs) to data breach response, data mapping, regulatory liaison, stakeholder engagement, and employee data protection training. It also explores how DPOs can build a stronger data protection culture through awareness campaigns, gamified learning, continual training, and clear communication with IT, legal, HR, marketing, senior leaders, and employees.

In this free eBook, you'll discover:

The typical strategic and day-to-day activities of a Data Protection Officer
How to conduct Data Protection Impact Assessments (DPIAs) effectively
Managing Subject Access Requests (SARs): timelines, process and common pitfalls
How to prepare for, detect and report a data breach within GDPR obligations
Building relationships with key stakeholders to embed data protection across teams
Staying current with GDPR, UK data protection law and new regulations
Designing effective data protection awareness and training programmes for employees
How to liaise with the ICO and other regulators during audits and investigations

Start strong as a new DPO

Build confidence in your first 90 days with practical guidance on GDPR, DPIAs, SARs, data breaches, and data protection culture.

View the eBook Book an eLearning demo

First 90 days as a new DPO FAQ

What should a new DPO focus on in the first 90 days?

A new Data Protection Officer should focus on understanding the organisation's data processing activities, reviewing data protection policies, mapping personal data, monitoring GDPR compliance, and building relationships with key teams such as IT, legal, HR, marketing, and senior management.

Why are DPIAs important for data protection compliance?

Data Protection Impact Assessments (DPIAs) help organisations identify, assess, and reduce privacy risks before launching new projects or changing data processing activities. They are essential for demonstrating accountability, protecting personal data, and reducing the risk of data breaches or regulatory non-compliance.

How should a DPO manage Subject Access Requests?

A DPO should create a clear Subject Access Request (SAR) process, verify requester identity, collect relevant personal data, protect third-party information, respond within required timeframes, use secure communication channels, and keep records for audit and compliance purposes.

Related pages

Human Risk Platform
Products & Services