In an age where data is the new oil, the role of a Data Protection Officer (DPO) has become indispensable for any organisation processing personal data. The recent enforcement action against Toyota Bank Polska S.A., as data controller, by the Polish Data Protection Authority serves as a cautionary tale for global organisations, including those in India preparing for compliance under the Digital Personal Data Protection Act, 2023 (DPDPA). Toyota Bank was fined over PLN 576,000 (approx. ₹1.15 crore) for two key lapses: 1.Improper structuring of the DPO role, particularly, the lack of independence and direct reporting lines, and 2.Failure to document and assess profiling practices in their processing activities and impact assessments. These findings highlight critical considerations while appointing a DPO.