Data Protection Officer (DPO)

The data protection officer (DPO) monitors compliance with data protection law inside an organisation, advises the controller, and acts as the contact point for the supervisory authority and for data subjects. In Germany, § 38 BDSG requires a designation where, as a rule, at least 20 persons are permanently engaged in the automated processing of personal data.

GRCLast reviewed:

The GDPR sets one threshold for appointing a data protection officer. Germany sets a second, lower one, and it is the German threshold that catches international groups out, usually about a year after the German entity has grown past twenty people.

The role itself is a monitoring and advisory function, not a decision-making one. Responsibility for the lawfulness of processing stays with the company as controller, represented by its management. The data protection officer's job is to ensure that this responsibility is exercised on an informed basis, and to record it when the advice is not followed.

When an appointment is mandatory

Regulation (EU) 2016/679 governs the role across three articles: designation in Article 37, position in Article 38, tasks in Article 39. Under Article 37(1), a duty exists for public authorities and bodies (point (a)), where the core activities require regular and systematic monitoring of data subjects on a large scale (point (b)), and for large-scale processing of special categories under Article 9 or of data on criminal convictions under Article 10 (point (c)). A group of undertakings may appoint a single data protection officer under Article 37(2), provided that officer is easily accessible from each establishment.

Germany has extended that frame through § 38(1) BDSG. The wording carries three qualifiers, and all three carry weight: an officer must be designated where, as a rule, at least 20 persons are permanently engaged in the automated processing of personal data. The count is of persons rather than full-time equivalents; part-time staff, temporary staff and regularly deployed externals are included as soon as processing forms part of their permanent duties. A headcount alone, without the qualifiers "as a rule", "permanently" and "automated", does not meet the test.

Independently of the headcount, § 38(1) sentence 2 BDSG applies in two further cases: processing that requires a data protection impact assessment under Article 35 GDPR, and commercial processing for the purpose of transfer, of anonymised transfer, or for market or opinion research. The second case is missed almost everywhere.

In a group, the count is taken at the German entity. Twenty people working with a CRM system, a payroll system and a ticketing system are twenty people permanently engaged in automated processing; the threshold is reached earlier than most organisations expect, because it does not ask whether data protection is anybody's job.

Voluntary designation is not a free option

Below the threshold a voluntary designation is possible. It then attracts the same requirements as to position and independence, so it is not a non-binding gesture.

One thing does differ. The special protection against removal and dismissal in § 6(4) BDSG applies, under § 38(2) BDSG, only where the designation is mandatory. A voluntary designation does not attract it.

Tasks

TaskContent
Information and adviceAdvising the controller and employees on their obligations under the Regulation
MonitoringReviewing compliance with the Regulation and with internal policies, including the assignment of responsibilities and awareness-raising
Advice on the DPIAAdvising on request on the data protection impact assessment and monitoring its performance
CooperationContact point for the supervisory authority, cooperation and consultation
Point of contactContact for data subjects on questions concerning their rights

The data protection officer does not maintain the records of processing activities; that is a document of the controller. The upkeep is often parked with the officer anyway, which weakens the monitoring function, because they then review their own work.

Position in the organisation

Three features shape the role legally and are regularly underestimated:

  • Freedom from instructions under Article 38(3) sentence 1: no instructions regarding the exercise of the tasks. A data protection officer cannot be instructed to arrive at a particular conclusion.
  • A reporting line to the highest management level under Article 38(3) sentence 3, with no intermediate stop.
  • A prohibition on dismissal and on detriment under Article 38(3) sentence 2, supplemented in Germany by special protection against removal and dismissal for internal officers. That special protection applies, under § 38(2) BDSG, only in cases of mandatory designation; it does not apply to a voluntary one.

Added to this are confidentiality under Article 38(5), and the controller's duty under Article 38(2) to provide resources and access to processing operations, including the resources needed to maintain the officer's expert knowledge.

Conflicts of interest

Under Article 38(6), the officer may take on further tasks, provided no conflict of interest arises. That rules out positions deciding on the purposes and means of processing: management, and the leadership of IT, HR, marketing or sales. Supervisory authorities check this point routinely, because it can be established without much effort.

A group arrangement deserves exactly the same test. A group data protection officer who also owns the group's data platform, or whose reporting line runs through the IT organisation, has the conflict whether or not the German entity has noticed it.

Internal or external

Article 37(6) expressly permits both routes: the officer may be a staff member or fulfil the tasks on the basis of a service contract. An internal officer knows the processes and the people, but consumes working time and may, where designation is mandatory, enjoy the special protection against dismissal. An external officer brings routine from several mandates, can be engaged without conflict of interest, and can be released through the service contract; they do need an internal counterpart and organised access. Either way, the standard for selection is Article 37(5): professional qualities, expert knowledge of data protection law and practice, and the ability to perform the Article 39 tasks. The Regulation does not require a particular certificate.

For a foreign group with a small German entity the external route is usually the answer, for a practical reason as much as a legal one. Under Article 37(7), the contact details have to be published and communicated to the competent supervisory authority, and both are the first things reconciled in an inspection. A published contact that resolves to a named, reachable person in Germany avoids a conversation that starts badly.

Where the overview for the monitoring duty comes from

A data protection officer's monitoring duty presupposes an overview they rarely maintain themselves: which processing activities exist, which systems and providers are involved, and which data categories reach where. In many organisations they obtain it by asking around.

In Rizzqo it follows from the model. A processing activity is a primary asset carrying the categories of personal data it holds; the systems, applications and providers beneath it inherit that property along the chain, including across several steps. For the role itself there is a read-everything access that does not become an editing role, which suits the independence required: the officer sees the state without owning the implementation, which stays with the business units.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyHosted in your countryMulti-framework