Portland, Ore., approved the creation of a Data and Privacy Office (DPO) during its Fiscal Year 2026-2027 budget process. Now, with the office set to begin operations imminently, city leaders are looking for an inaugural data and privacy officer to lead it.
The DPO exists at a historical moment where there has never been a greater intersection between the sheer volume of digital information captured and how that affects privacy measures. The advent and broad deployment of surveillance cameras, AI-enabled camera networks and automated license plate reader (ALPR) systems have yielded to data brokers who obtain and distribute that information to entities seeking workarounds to local safeguards.
As these technologies become more prominent and integrated, cities are obligated to match increased scrutiny with greater transparency. Portland officials have advertised the opening for the data and privacy officer, which is slated to close on Oct. 5. The City Council approved the classification and salary range for the role earlier this month. The officer will oversee DPO operations and serve as the top authority for data governance and privacy oversight.
Some of the role’s key responsibilities will include:
- Establishing and chairing the Data Governance Board to set the strategic direction for data practices.
- Developing and implementing citywide data governance and privacy policies.
- Conducting privacy impact assessments for high-risk technologies that use city data.
- Auditing high-risk technologies for bias, privacy risk and policy compliance.
- Developing reports that document sensitive data holdings, risk trends and policy gaps for city officials.
Filling the position is the latest move in the city’s efforts to increase its oversight of how data is used regarding privacy and security. The DPO was initially legislated through Ordinance 192143 and Resolution 37736, establishing the office to support privacy protections, manage data assets and mitigate risks from data brokers, uncontrolled sharing of personal information and secondary data use.
Portland’s decision follows in the wake of a wave of technological development and adoption, predominantly those that collect, consolidate and share information. Surveillance systems, smart-city sensors and AI-powered camera technologies are increasingly popularized in municipalities across the nation. Increased oversight and management is needed to prevent that data from being misappropriated and shared with federal agencies, corporations and other entities that profit or benefit from using personal information.
The DPO will operate as a centralized authority on data governance and privacy, while also focusing on addressing emerging threats and closing gaps in protections. The office will have a voting seat on the Portland AI Steering Committee and will oversee assessments of high-risk technologies such as AI and automated decision-making systems. Ultimately, the DPO will be pivotal in proactively creating secure, functional privacy and data governance policies for technology decisions and systems rather than addressing issues following implementation.
Photo by Tabitha Mort from Pexels
For more of the latest from the expansive government marketplace, check Government Market News daily for new stories, insights and profiles from public sector professionals. Check out our national contracting newsletter here.




