Data Protection HubIndividual TopicsData Protection Officer

Designation of the Data Protection Officer

When a data protection officer must be designated: the obligation under Article 37(1) GDPR and under § 38 of the German Federal Data Protection Act (BDSG), voluntary designation, qualifications, formalities, the licensing requirement for external data protection officers under the German Legal Services Act (RDG), termination, plus drafting guidance and a checklist for the contract.

The GDPR does not impose a general obligation to designate a data protection officer. Whether a designation is required is governed by Article 37(1) GDPR and, additionally for Germany, by § 38 of the German Federal Data Protection Act (BDSG). Beyond that, every controller and processor is free to designate a data protection officer voluntarily.

Key takeaways

  • An obligation to designate exists only where the statutory criteria of Article 37(1) GDPR or of § 38 BDSG are met; both apply alongside each other.
  • For non-public (private) bodies, the obligation arises above all under § 38(1) BDSG: from as a rule 20 persons who are constantly engaged in the automated processing of data, as well as for processing operations subject to a data protection impact assessment or for processing carried out on a commercial basis for the purpose of transfer or for market or opinion research.
  • The data protection officer is designated on the basis of expert knowledge, ability and reliability (Article 37(5) GDPR); there is no rigid profile of requirements.
  • The designation may be internal (an employee) or external (on the basis of a service contract); the contact details must be published and communicated to the supervisory authority, but the name need not be.
  • In the case of an external data protection officer, the statutory designation and the underlying service contract must be kept apart (principle of separation); the activity may require a license under the German Legal Services Act (RDG).

1. Overview

1.1 Three routes to designation

The GDPR distinguishes three situations in which a data protection officer is designated:

  • designation that is mandatory throughout the Union in the cases covered by Article 37(1)(a) to (c) GDPR,
  • designation that is mandatory under Member State law by virtue of the opening clause in Article 37(4), first sentence, second half-sentence, GDPR, which in Germany is given effect by § 38 BDSG,
  • voluntary designation under Article 37(4), first sentence, first half-sentence, GDPR.

For the position and tasks of the data protection officer, it makes no difference which of these routes leads to the designation. All that matters is that a designation has been made: from that point on, the rules of Articles 38 and 39 GDPR apply uniformly. Speaking of "three forms" of data protection officer is therefore misleading.

Where the statutory criteria for a mandatory designation are met and no data protection officer is designated, this is subject to an administrative fine (see Section 9). The examination proceeds in two steps: first, it must be clarified whether an obligation exists throughout the Union under Article 37(1) GDPR; if that obligation does not apply, the national threshold in § 38 BDSG must be examined. Only if both are answered in the negative does the mere option of a voluntary designation remain.

2. Obligation under Union law (Article 37(1) GDPR)

An obligation to designate under Union law exists only subject to the narrow conditions of Article 37(1) GDPR. The provision sets out three categories of cases.

2.1 Public authorities and public bodies (point (a))

Public authorities and public bodies must always designate a data protection officer, except for courts acting in their judicial capacity. The GDPR does not define the concept of a public authority or public body; it is determined by national law and covers, in addition to State bodies, other entities governed by public law (Article 29 Working Party Guidelines on Data Protection Officers, WP 243 rev.01).

For the private sector, on which this hub is focused, this category is generally of no relevance; there, points (b) and (c) as well as § 38 BDSG are decisive. An exception applies to private bodies that carry out public tasks or exercise public authority, for example in local public transport, water and energy supply, public service broadcasting or social housing. Although they are not subject to an obligation under point (a), designating a data protection officer is recommended as good practice, because the individuals concerned find themselves in a situation comparable to the one they are in when dealing with public bodies (WP 243 rev.01).

2.2 Large-scale monitoring as a core activity (point (b))

Under Article 37(1)(b) GDPR, a data protection officer must be designated where the core activities consist of processing operations which require regular and systematic monitoring of data subjects on a large scale.

Core activity. Only the main activity is covered, not a mere auxiliary or ancillary activity (Recital 97 GDPR). What matters is whether the data processing forms an inextricable part of the actual business purpose or whether it constitutes a support function entirely subordinate to that purpose, such as general IT administration or payroll accounting (Article 29 Working Party Guidelines on Data Protection Officers, WP 243 rev.01). Medical care, for instance, is not possible without the processing of patient data, which is why this processing forms part of the core activity of a hospital; likewise, surveillance is the core activity of a security company. Core activity and scale interact here: an activity that is in itself merely supportive, such as the analysis of customer data, may become a core activity by virtue of its sheer scale. Textbook examples are credit reference agencies, detective agencies, security companies, recruitment and dating agencies, and online advertising providers operating on the basis of profiling.

Processing of HR data. The processing of employee data does not become a core activity merely because every undertaking processes HR data; otherwise almost every employer would be subject to the obligation. As a rule, it is a mere support process. Only a considerable scale, for example a dedicated HR department in which numerous employees spend a substantial part of their working time on the processing of HR data, can cross the threshold to a core activity. Mere payroll accounting and personnel administration for around 80 employees is not sufficient for this purpose (German Regional Labor Court of Hamm (LAG Hamm), judgment of 6 October 2022, 18 Sa 271/22).

Large scale, regular, systematic. None of the three criteria is determined by a fixed number. Whether processing is on a large scale is assessed by reference to the number of data subjects concerned, the volume and range of the data, the duration of the processing and its geographical extent (Recital 91 GDPR). Regular means observation that is continuous or recurs at particular intervals. Observation is systematic where it takes place according to a system, a data collection plan or a strategy; the monitoring is not confined to the internet, even though tracking and profiling online are typical use cases (Article 29 Working Party Guidelines on Data Protection Officers, WP 243 rev.01).

Typical instances of regular and systematic monitoring on a large scale are:

  • profiling and scoring,
  • large-area video surveillance, for example in shopping centers,
  • permanent monitoring of employees by video or by electronic performance monitoring,
  • fleet management with GPS tracking,
  • processing of location and movement data via apps,
  • individualized, behavior-based marketing and loyalty programs,
  • connected devices and wearables that continuously collect usage data.

2.3 Large-scale processing of sensitive data (point (c))

Under Article 37(1)(c) GDPR, the obligation arises where the core activities consist of processing on a large scale of special categories of personal data under Article 9 GDPR or of personal data relating to criminal convictions and offenses under Article 10 GDPR. It is sufficient that either Article 9 or Article 10 is concerned.

Here, too, core activity and scale are decisive. For physicians, the core activity lies in the processing of data concerning health, because medical care is not possible without it; what is decisive is therefore the scale. Under Recital 91 GDPR, processing by an individual physician does not qualify as large scale, with the result that single-physician practices are not subject to the obligation on the basis of point (c) alone; the same applies to an individual lawyer processing personal data relating to criminal convictions and offenses (Article 29 Working Party Guidelines on Data Protection Officers, WP 243 rev.01). By contrast, larger medical practices and medical laboratories, hospitals, health insurers and counseling centers dealing with sensitive matters must designate a data protection officer.

Mere personnel administration that occasionally records religious affiliation or incapacity for work for accounting purposes is not large-scale processing of sensitive data and does not trigger the obligation under point (c).

2.4 Processors

The categories in points (b) and (c) apply equally to controllers and processors. A processor, however, is subject to the obligation only where it carries out the core activity described itself, and not already where it merely provides technical framework conditions such as cloud services. A processor may also be subject to an obligation of its own where the controller is not, for example in the case of a service provider that carries out large-scale tracking for many small businesses. Conversely, an individual physician is not required to designate an officer merely because a service provider it has engaged processes data concerning health.

3. Obligation under national law (§ 38 BDSG)

The German legislature has made use of the opening clause in Article 37(4), first sentence, second half-sentence, GDPR and has created two further grounds for a mandatory designation in § 38 BDSG. They apply irrespective of whether Article 37(1) GDPR is already applicable.

3.1 The threshold of 20 persons

Under § 38(1), first sentence, BDSG, a data protection officer must be designated where, as a rule, at least 20 persons are constantly engaged in the automated processing of personal data (until 20 November 2019 the threshold was ten persons). Covered is every person who regularly deals with automated processing, irrespective of the form of employment and the extent of the activity.

3.2 Risk-based grounds

Irrespective of the number of persons, a designation is required under § 38(1), second sentence, BDSG where the controller or processor

  • carries out processing operations that are subject to a data protection impact assessment under Article 35 GDPR, or
  • processes personal data on a commercial basis for the purpose of transfer, of anonymized transfer or for purposes of market or opinion research.

Even though § 38 BDSG is national law, the terms it uses must be interpreted uniformly in line with the GDPR. A "parallel interpretation" of the same terms departing from Union law would run counter to the objective of a uniform data protection law and to legal certainty.

4. Voluntary designation

Controllers and processors may at any time voluntarily designate a data protection officer under Article 37(4), first sentence, first half-sentence, GDPR. The same rules of Articles 38 and 39 GDPR apply to a voluntarily designated data protection officer as to one designated under a legal obligation. The special protection against termination under § 6(4) BDSG, however, need not be configured to the same extent as in the case of a mandatory designation.

The designation brings no direct legal advantages; in particular, it does not remove any obligation, since all obligations of the controller and of the processor exist irrespective of the designation. A voluntary designation may, however, be taken into account as a mitigating factor when setting an administrative fine (Article 83(2)(k) GDPR).

Distinction from the chief data officer. Anyone entrusting employees or external third parties with data protection tasks must make clear whether they are being deployed as a data protection officer or in another function. For the data protection officer, position, duties and tasks are laid down as mandatory law by Articles 38 and 39 GDPR and cannot be shaped freely. A chief data officer can take on operational implementation tasks that would be precisely incompatible with the role of the data protection officer.

5. Qualifications, reliability and the person designated

5.1 Profile of requirements

Under Article 37(5) GDPR, the data protection officer is designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfill the tasks referred to in Article 39 GDPR. There is no abstractly defined profile of requirements: the greater the scale of the data processing and the higher the risk and the need for protection, the higher the requirements to be placed on the expert knowledge.

The expert knowledge must relate to data protection law and to data protection practices. Knowledge of the GDPR and of the BDSG is always required; depending on the activity, further areas of law are added. It is also advisable to have a technical understanding in order to identify risks arising from IT systems, as well as basic business and organizational knowledge. In addition to the qualifications, reliability is an unwritten requirement, yet one inherent in Article 37(5) GDPR.

The data protection officer need not possess specialist knowledge of his or her own in every sub-area; he or she may draw on knowledgeable staff and on external advice. What cannot be outsourced, however, is a basic competence enabling him or her to assess the overall picture personally. This includes a basic knowledge of all legal systems relevant to his or her area of responsibility and of the languages spoken there, in so far as the designating body operates in several States.

5.2 Point in time of the qualification

The obligation to designate applies immediately. The data protection officer does not necessarily have to possess the full qualification already at the time of the designation; it may be sufficient that he or she is willing and able to acquire the necessary expert knowledge at short notice. The yardstick is the risk-based approach of Article 39(2) GDPR. The expert knowledge must be maintained on an ongoing basis; for that purpose, the controller must enable the internal data protection officer to undergo training and continuing education at the controller's own expense (Article 38(2) GDPR).

The GDPR does not expressly regulate whether a legal person may also be designated as data protection officer. Since the Regulation neither requires nor excludes this, it must be assumed to be permissible; the required profile can often even be met better where the tasks are performed on a division-of-labor basis within an undertaking. The European Data Protection Board likewise considers the designation of a legal person to be possible. In practice there is hardly any difference in any event, because the underlying service contract can in any case be concluded with a legal person.

6. Formalities of the designation

6.1 Form, timing and content of the designation

The designation must be made immediately; Article 37 GDPR does not provide for any transitional period. If the data processing changes, it must be examined again whether an obligation to designate arises. There is no formal requirement; for reasons of evidence and documentation, however, the designation should be recorded in writing. The assessment of whether an obligation to designate exists should likewise be documented for the purposes of accountability.

The designation transfers to the designated person all tasks and rights associated with the function under Articles 37 to 39 GDPR; transferring only individual tasks is not sufficient. It must be made by the controller or by an authorized body. Merely booking a data protection training course or sending an internal circular email about a change in responsibilities does not yet amount to a designation. To be kept separate from it are the underlying relationship (an employment or service contract) and the communication of the contact details to the supervisory authority; neither is relevant to the validity of the designation. The designation may be made for a fixed term or for an indefinite period.

6.2 Internal or external data protection officer

Under Article 37(6) GDPR, either a staff member (internal data protection officer) or a person from outside the undertaking acting on the basis of a service contract (external data protection officer) may be designated. The controller is free to choose.

CriterionInternal data protection officerExternal data protection officer
Legal relationshipemployment relationship, additional functionindependent service contract
Protection against terminationspecial protection against termination under § 6(4) BDSG (in the case of a mandatory designation)no special protection against termination; termination governed by the service contract
Conflict of interestrisk in the case of dual roles (e.g. head of IT or of HR)risk where the officer acts for competing entities or for entities linked by other mandates
Effortbuilding up and maintaining the expert knowledge in houseexpert knowledge is bought in, often across several mandates

Within a group of undertakings, a single data protection officer (group data protection officer) may be designated, provided that he or she is easily accessible from each establishment (Article 37(2) GDPR). Easy accessibility has a geographical, a linguistic and a temporal component: personal contact must be possible with reasonable effort, the data protection officer must be able to communicate with employees, data subjects and supervisory authorities, and he or she must in fact be reachable at short notice. Several public authorities and public bodies may likewise designate a single data protection officer, taking account of their organizational structure and size (Article 37(3) GDPR). A single act of designation is sufficient for the entire group; it does not, however, replace the separate communication of the contact details to the competent supervisory authority, which each company subject to that duty must make for itself.

In order to secure effective accessibility, the data protection officer should be located in the European Union, irrespective of whether the controller or processor is itself established in the Union. Only where the controller or processor is not established in the Union may a data protection officer located outside the Union exceptionally be able to carry out his or her tasks more effectively (Article 29 Working Party Guidelines on Data Protection Officers, WP 243 rev.01).

6.3 Publication and communication of the contact details

The controller and the processor must publish the contact details of the data protection officer and communicate them to the supervisory authority (Article 37(7) GDPR). The publication must have external effect, for example in an easily findable place on a freely accessible website, typically in the legal notice and in the privacy policy; details accessible only internally are not sufficient. So that contact can be made even in urgent cases, at least an email address or a contact form should be provided.

The name of the data protection officer is not among the contact details to be published under Article 37(7) GDPR; publishing it is nevertheless advisable as a confidence-building measure. As regards the supervisory authority, by contrast, communication of the name is necessary, because the data protection officer is its point of contact (Article 39(1)(e) GDPR); the name must be stated expressly in the notification of a personal data breach (Article 33(3)(b) GDPR), as well as in the records of processing activities (Article 30 GDPR) and in a prior consultation (Article 36 GDPR). Internally, the name and contact details of the data protection officer should be made known to all employees, for example on the intranet or in the telephone directory (Article 29 Working Party Guidelines on Data Protection Officers, WP 243 rev.01).

The confidentiality of communications with the data protection officer must be secured. No shared contact form and no shared email address may therefore be used for the data protection officer and the general data protection team; mail addressed to the data protection officer must not be opened in the mailroom.

Legal advice forms a defining part of the range of tasks of the data protection officer (Article 39(1) GDPR). For external data protection officers, this raises the question whether they require a license under the German Legal Services Act.

An internal data protection officer is unproblematic: he or she acts in the affairs of his or her own organization and not in the affairs of another, with the result that the very concept of a legal service is not made out (§ 2(1) RDG).

In the case of the external data protection officer, the licensing requirement is disputed. A German bar court of appeal has held that the legal advisory tasks assigned to the data protection officer by Article 39 GDPR are covered by that provision as an authorization within the meaning of § 1(3) RDG and therefore do not require separate registration (Bar Court of Appeal for North Rhine-Westphalia (AGH NRW), judgment of 12 March 2021, 1 AGH 9/19). According to the opposing view, the activity of the external data protection officer crosses the threshold of an ancillary service exempt from licensing (§ 5(1) RDG) as soon as complex legal questions, including questions outside data protection law, have to be answered in an individual case; a license under § 3 RDG would then be required. A ruling by the highest court is still outstanding.

In practice. Lawyers and registered persons are on the safe side. Pure data protection service providers should keep the risk of a licensing requirement in view and align the scope of their activities as well as their contract accordingly.

Two special cases must be noted. A group data protection officer employed by one of the companies in the group generally does not require a license, because the handling of legal matters within affiliated undertakings is excluded from the concept of a legal service (§ 2(3)(6) RDG in conjunction with § 15 of the German Stock Corporation Act (AktG)). Where an employee of a service provider is designated as an external data protection officer, the contractual arrangements must avoid an unlawful hiring-out of employees (§ 1 of the German Temporary Agency Work Act (AÜG)).

8. Termination of the designation

The office of data protection officer may come to an end in several ways:

  • Resignation by the data protection officer. He or she may resign from the office; terminating the underlying relationship generally includes such a resignation. He or she should allow the controller sufficient time to designate a successor, unless good cause justifies immediate termination.
  • Expiry of a fixed term. Where the designation is permissibly made for a fixed term, the office ends when that term expires. If the obligation to designate continues, a successor must be designated in good time, since otherwise the criteria for an administrative fine are met.
  • Termination by mutual agreement. The controller and the data protection officer may revoke the designation by mutual agreement at any time.
  • Lapse of the obligation to designate. If the statutory obligation ceases to apply, for example because sensitive data are no longer processed on a large scale, the office does not end automatically; the data protection officer then remains designated on a voluntary basis, with unchanged rights and duties. At most, the lapse of the obligation may constitute an objective reason for a dismissal from office.
  • Corporate changes. If the designating body ceases to exist, for example through a merger, the office lapses automatically. Where the acquiring legal entity is itself subject to an obligation to designate, it must make its own designation, but it is not obliged to take over the previous data protection officer.

Dismissal by the controller. Dismissal is permissible only to a limited extent: the data protection officer may not be dismissed for performing his or her tasks, and where the designation is for a fixed term, early dismissal is possible only for good cause (for more detail, see the prohibition on penalization and dismissal).

Request for dismissal by the supervisory authority. The supervisory authority may require a non-public (private) body to dismiss the data protection officer where the officer lacks the necessary expertise or where a serious conflict of interest exists (§ 40(6), second sentence, BDSG). Such a request constitutes good cause for dismissal.

9. Sanction for failure to designate

An infringement of the obligations laid down in Articles 37 to 39 GDPR may, under Article 83(4)(a) GDPR, be subject to an administrative fine of up to EUR 10 million or, in the case of an undertaking, of up to 2 % of the total worldwide annual turnover of the preceding financial year. The entire range of obligations governed by Article 37 GDPR is covered, including a failure to publish or to communicate the contact details.

Supervisory authorities do in fact penalize a failure to designate. The competent supervisory authority imposed an administrative fine of EUR 10,000 on a micro-enterprise in the telecommunications sector because it had not designated a data protection officer despite repeated requests; its classification as a micro-enterprise had a mitigating effect on the amount of the fine (BfDI (German Federal Commissioner for Data Protection and Freedom of Information), press release of 9 December 2019).

10. Contract with an external data protection officer

Where an external data protection officer is designated, the designation is based on a service contract. This section provides drafting guidance and a checklist; it is no substitute for individual contract drafting.

10.1 Principle of separation

Two levels must be distinguished in legal terms: the underlying contractual relationship (the service contract) and the designation required by law. The service contract governs the relationship between the client and the service provider; the designation is the act by which the person assumes the statutory function under Articles 37 to 39 GDPR. It is customary and practical to attach the letter of designation to the contract as an annex, because it must be evidenced towards third parties and the supervisory authority. Likewise, the evidence of expert knowledge under Article 37(5) GDPR should be included as an annex, since the proper selection has to be demonstrated in the event of a dispute.

10.2 Areas to be regulated

A workable contract gives concrete form to the statutory requirements without undermining the mandatory requirements of Articles 38 and 39 GDPR. The following areas should be regulated:

  • Subject matter of the contract: assumption of the tasks of a data protection officer within the meaning of Articles 37 to 39 GDPR and of § 38 BDSG, with the letter of designation and the evidence of qualifications as annexes.
  • Position and involvement: clarification of the freedom from instructions (Article 38(3) GDPR), designation of fixed contact persons at the client, the duty to involve the officer at an early stage, access to documents, premises and IT systems, as well as publication and communication of the contact details.
  • Organization of the services: determination of place and time by the data protection officer at his or her own discretion, appropriate response times and availability in urgent cases, provisions on the use of the officer's own staff and of subcontractors.
  • Scope of services: concrete specification of the tasks under Article 39 GDPR, for example taking stock of the processing operations, advice on the selection of IT applications, involvement in the records of processing activities under Article 30 GDPR, advice on the data protection impact assessment, training, review of processing on behalf of the controller under Article 28 GDPR, as well as an annual activity report to management.
  • Remuneration: determination as a flat fee or on a time basis at hourly rates, provisions on the reimbursement of expenses and on value added tax.
  • Liability: provisions on liability in the internal relationship; where liability is capped at a fixed sum, the maximum amount must cover the damage typically foreseeable under this type of contract, failing which the limitation is invalid.
  • Secrecy and confidentiality: an obligation of secrecy, where appropriate with continuing effect after the end of the contract; the special duty of secrecy for the benefit of data subjects remains unaffected.
  • Term and termination: minimum term and renewal, extraordinary termination for good cause (such as a gross breach of duty or a request by the supervisory authority for dismissal), linkage of the end of the contract to removal from office.
  • Final provisions: written form, severability clause and choice of law.

Keep liability separate. The contract governs only liability in the internal relationship towards the client. To be distinguished from this is the liability of the data protection officer in the external relationship towards data subjects, which is governed by the general rules and cannot be limited by contract to the detriment of third parties.

10.3 Checklist of contractual points

  • Subject matter of the contract: tasks under Articles 37 to 39 GDPR and § 38 BDSG specified
  • Letter of designation and evidence of qualifications attached as annexes
  • Freedom from instructions and fixed contact persons regulated
  • Duty of early involvement and access to documents and systems
  • Publication of the contact details and communication to the supervisory authority
  • Scope of services specified concretely (stocktaking, records, training, audits, activity report)
  • Use of the officer's own staff and of subcontractors regulated
  • Remuneration (flat fee or hourly rate), reimbursement of expenses and value added tax
  • Liability with a valid maximum amount; internal and external relationship kept separate
  • Secrecy with continuing effect; duty of secrecy for the benefit of data subjects preserved
  • Term, extraordinary termination and linkage to removal from office
  • Written form and choice of law

The designation is followed by the duties concerning the position and the tasks of the data protection officer, which apply irrespective of whether the designation was mandatory or voluntary.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn