Data Protection HubIndividual TopicsData Protection Officer

Position of the Data Protection Officer

The position of the data protection officer under Article 38 GDPR: involvement at an early stage, support with resources, freedom from instructions, prohibition on penalization and dismissal, direct reporting line, the right of data subjects to contact the officer, secrecy and the prohibition of conflicts of interest.

Article 38 GDPR governs the position of the data protection officer. The provision applies irrespective of whether the designation was mandatory or voluntary and of whether the officer is an internal or an external data protection officer. Its purpose is to safeguard the performance of the tasks under Article 39 GDPR and to ensure the independence of the data protection officer.

Key takeaways

  • The data protection officer must be involved at an early stage in all issues relating to the protection of personal data (Article 38(1) GDPR).
  • He or she must be provided with the resources necessary to carry out those tasks, with access to personal data and to processing operations, and with the means to maintain his or her expert knowledge (paragraph 2).
  • He or she is free from instructions in the exercise of those tasks, may not be penalized or dismissed for performing them, and reports directly to the highest management level (paragraph 3).
  • Data subjects may contact him or her (paragraph 4); he or she is bound by secrecy and confidentiality (paragraph 5).
  • Further tasks are permissible, but they must not give rise to a conflict of interest (paragraph 6).
  • The data protection officer has no power to give instructions or to enforce compliance; he or she acts through advice and reporting.

1. Overview

1.1 Function of the provision

The rules in Article 38 GDPR safeguard the performance of the tasks under Article 39 GDPR. This is achieved through the duty to involve the officer in processing decisions (paragraph 1), through the provision of the necessary means (paragraph 2), through the personal protection that preserves independence (paragraph 3) and through the possibility for data subjects to turn to the data protection officer (paragraph 4). The duty of secrecy (paragraph 5) makes it easier to address processing questions openly, and paragraph 6 permits further tasks within the limits set by the prohibition of conflicts of interest.

1.2 No powers of its own

Article 38 GDPR confers no powers on the data protection officer, in particular no right to give instructions to, or to enforce compliance by, the workforce or the management. His or her position is that of an independent adviser and monitoring body, not that of a decision-making entity.

2. Involvement (Article 38(1) GDPR)

The controller and the processor must ensure that the data protection officer is involved, properly and in a timely manner, in all issues which relate to the protection of personal data. What the GDPR requires is involvement at an early stage, not merely involvement that is still in good time; this makes it necessary to examine at the very outset of a planned processing operation whether data protection is affected. Only in that way can the data protection officer still influence the design of the processing through guidance and advice. Involvement must be secured by organizational measures; the data protection officer need not, however, be involved in every single preliminary consideration of the management.

The duty of involvement extends beyond the introduction and modification of individual processing activities and covers all questions of principle, of concept and of infrastructure that are relevant to data protection, such as the choice of business models involving customer data or the design of the technical infrastructure. In practice, this means recognizing the data protection officer as an interlocutor, inviting him or her to management meetings, calling him or her in for decisions relevant to data protection and involving him or her without delay in the event of a personal data breach or any other incident (Article 29 Working Party Guidelines on Data Protection Officers, WP 243 rev.01). A defined and binding process determining when and how the data protection officer is to be involved is recommended. It may be useful to link that process to the documentation in the records of processing activities under Article 30 GDPR: a modified or new processing operation is brought to the data protection officer's attention before it is implemented and is put into effect only after an appropriate review period has expired.

A particular expression of this duty is contained in Article 35(2) GDPR: when carrying out a data protection impact assessment, the advice of the data protection officer must be sought.

Risk of an administrative fine. Failure to involve the data protection officer properly or at an early stage is subject to an administrative fine under Article 83(4)(a) GDPR (up to EUR 10 million or 2 % of total worldwide annual turnover). Where the management departs from recommendations made by the data protection officer, the reasons should be documented for the purposes of accountability.

3. Support and resources (Article 38(2) GDPR)

The controller and the processor must support the data protection officer in the performance of his or her tasks. This includes:

  • the resources necessary to carry out those tasks, including a sufficient time budget, especially where the function is not exercised on a full-time basis,
  • access to personal data and to processing operations, that is to say, corresponding rights of access to premises and rights of inspection,
  • the means to maintain expert knowledge, such as access to current specialist publications and to training at the controller's expense.

The extent of the resources to be provided follows the risk-based approach of Article 39(2) GDPR. Article 38(2) GDPR does not provide for any express reservation as to funding; the principle of proportionality must nevertheless be observed. Maintaining expert knowledge is an ongoing process and must not be ensured only once, at the time of designation; in this respect there is a connection with the qualification requirement of Article 37(5) GDPR.

The material resources include an appropriate budget, the purchase of specialist literature and the customary means of communication, in each case at the level customary within the organization. Because of the duty of confidentiality (see section 8), the data protection officer must be able to keep confidential documents securely and to conduct confidential conversations and telephone calls undisturbed. A dedicated, permanently allocated individual office is not strictly required for this purpose; in open-plan office structures, however, lockable storage facilities and a screened room that can be used when needed must be provided.

Resources also include support in terms of staff. Where the volume of tasks exceeds the capacity of a single person, a team may be formed consisting of the data protection officer and employees supporting him or her; responsibilities must then be clearly defined. Only one person, however, is designated as the data protection officer for each controller. Where members of the team perform the functions of a data protection officer, they must meet the requirements applying to that officer and enjoy the corresponding protection; overall responsibility for the performance of the tasks remains with the person designated.

4. Freedom from instructions (Article 38(3), first sentence, GDPR)

The data protection officer must not receive any instructions regarding the exercise of his or her tasks. This freedom from instructions is an expression of his or her independence (Recital 97 GDPR).

The freedom from instructions is not unlimited, however. It concerns only the performance and the exercise of the tasks under Article 39 GDPR, that is to say, whether and how the data protection activity is carried out. In the case of organizational decisions without any connection to data protection law, the data protection officer remains subject to the employer's general right to give directions. This weakens the protection in day-to-day practice, particularly where the data protection officer also performs other activities within the undertaking. In accordance with its purpose, the provision must therefore be applied in such a way that it also protects against indirect measures which in their effect operate like an instruction.

It follows from the freedom from instructions that the controller can neither assign audit mandates to the data protection officer nor prescribe which systems and processes he or she is to advise on or review, and when; suggestions to that effect have the character of recommendations only. Nor may the outcome of his or her professional assessment be prescribed: he or she may not be instructed to reach a particular result, to deal with a complaint in a particular way, to consult or not to consult the supervisory authority, or to take a particular position on a question of data protection law (Article 29 Working Party Guidelines on Data Protection Officers, WP 243 rev.01). The data protection officer, by contrast, has no power to decide on the purposes and means of processing; such a power would jeopardize the independent exercise of his or her office and would give rise to a conflict of interest (see section 9). This is without prejudice to the controller's right to obtain information about the data protection officer's activity: the officer must comply with requests for information and for the production of documents in so far as this does not impede the independent performance of his or her tasks and does not breach his or her duty of confidentiality.

5. Prohibition on penalization and dismissal (Article 38(3), second sentence, GDPR)

The data protection officer must not be penalized or dismissed for performing his or her tasks. This prohibition flanks the freedom from instructions and secures independence.

Penalization is impermissible only in so far as it is linked precisely to the performance of the tasks of a data protection officer. If, for example, he or she recommends a data protection impact assessment which the controller considers unnecessary, he or she may not be dismissed on that account. Penalization may occur directly or indirectly, for example in the form of a promotion that is withheld or delayed, of a denial of professional development or of exclusion from benefits granted to other employees; even the threat of such a measure suffices where it is intended to put pressure on the data protection officer because of his or her activity (Article 29 Working Party Guidelines on Data Protection Officers, WP 243 rev.01). Dismissal remains possible, by contrast, for reasons unconnected with the performance of the tasks (on this, see termination of the designation).

For the company data protection officer designated as required by law, German law goes further: § 38(2) in conjunction with § 6(4) of the German Federal Data Protection Act (BDSG) grants special protection against termination, under which the employment relationship may be terminated only for good cause. That stricter protection is compatible with Union law as long as it does not undermine the objectives of the GDPR (CJEU, judgment of 22 June 2022, C-534/20, Leistritz). For a voluntarily designated data protection officer, the special protection against termination under § 6(4) BDSG does not apply; in the case of an external data protection officer, termination is governed exclusively by the service contract. For the further ways in which the office may come to an end, and for the supervisory authority's request for dismissal under § 40(6), second sentence, BDSG, see in more detail termination of the designation.

6. Direct reporting line (Article 38(3), third sentence, GDPR)

The data protection officer reports directly to the highest management level, that is to say, to the management of the undertaking or of the public body. Where the management consists of several persons, the reporting duty may be tied to the member responsible. The direct reporting line gives the data protection officer the necessary hearing and prevents his or her observations from being lost within the hierarchy without ever reaching the management level.

The German wording ("berichtet") is open to misunderstanding. What is meant is not primarily a duty to submit activity or status reports, but direct organizational subordination to the highest management level. The data protection officer must therefore be integrated into the organization in such a way that no intermediate function restricts his or her access to the management; in practical terms, a staff position directly below the executive board or the managing directors is appropriate, and in the case of an external data protection officer, a direct advisory relationship with that level.

7. Right of the data subject to contact the officer (Article 38(4) GDPR)

Data subjects may contact the data protection officer with regard to all issues related to the processing of their personal data and to the exercise of their rights. That right to contact the officer is limited to the interests of the individual data subject concerned.

The German wording "zu Rate ziehen" (to consult) suggests a duty to advise in its own right; the English version, however, speaks only of "may contact". The data protection officer is therefore a point of contact for the data subject, not a representative of his or her interests; the officer need not act on the substance of the request and will in practice often forward the enquiry to the department responsible or refer the person to customer service. Before forwarding a request in a form that permits identification of the person, however, the officer must be released from the duty of secrecy by the data subject. In mass-market business with end customers, the right to contact the officer may lead to a large number of enquiries; even then, its function remains this limited one. The right to contact the officer is safeguarded by the duty of secrecy under Article 38(5) GDPR.

8. Secrecy and confidentiality (Article 38(5) GDPR)

The data protection officer is bound by secrecy or confidentiality concerning the performance of his or her tasks. That duty operates in two directions:

  • in favor of the controller and the processor, whose interests are thereby protected in the context of involvement under Article 38(1) and Article 35(2) GDPR,
  • in favor of the data subject, so that the data protection officer will as a rule not disclose the identity of a person who has contacted him or her under Article 38(4) GDPR, unless that person releases the officer from that duty.

In order to make confidential treatment possible, the controller must also provide the data protection officer with the resources needed for that purpose.

German law gives concrete form to that duty: the data protection officer is bound to secrecy as regards the identity of data subjects and as regards circumstances allowing conclusions to be drawn about them, unless the data subject releases the officer from that duty (§ 6(5), second sentence, BDSG). Where the officer acts for a person bound by professional secrecy, the unauthorized disclosure of secrets is a criminal offense (§ 203(4) of the German Criminal Code (StGB); on this, see liability). Where the controller enjoys a right to refuse to give evidence or the benefit of a prohibition on seizure, that protection extends to the data protection officer designated for it (§ 6(6) BDSG). Where the data protection officer advises, informs or monitors the works council, he or she must at the same time maintain secrecy vis-a-vis the employer as regards the works council's decision-making process (§ 79a of the German Works Constitution Act (BetrVG)).

9. Further tasks and conflicts of interest (Article 38(6) GDPR)

9.1 Further tasks

Under Article 38(6), first sentence, GDPR, the data protection officer may fulfill other tasks and duties. The function therefore need not be structured as a full-time post. This takes account of the fact that not every undertaking carries out data processing that requires a full-time data protection officer, and it also makes it possible to designate external data protection officers who take on further tasks in other undertakings.

9.2 Prohibition of conflicts of interest

Under Article 38(6), second sentence, GDPR, the controller and the processor must ensure that any such further tasks do not result in a conflict of interest. Such a conflict exists where the data protection officer is entrusted with tasks in which he or she determines the purposes and means of processing and would thus have to monitor the results of his or her own activity. Whether a conflict exists must be assessed in each individual case in the light of the organizational structure and the applicable rules (CJEU, judgment of 9 February 2023, C-453/21, X-FAB). The duty of avoidance falls on the controller; an infringement is subject to an administrative fine and is indeed penalized, for example by a fine of EUR 525,000 imposed on a group company whose data protection officer was at the same time managing director of service providers whose processing he should have been monitoring (BlnBDI (Berlin Commissioner for Data Protection and Freedom of Information), press release of 20 September 2022).

Typical conflict scenarios. A conflict of interest is likely where the function is combined with the management of the IT, human resources or marketing department, and where members of the management are designated, because those positions determine the purposes and means of processing; also covered are positions lower down the hierarchy, in so far as their tasks entail the determination of purposes and means. Equally incompatible is the office of a voting member of the works council, because the works council has a say in the use of employee data. In the case of external data protection officers, a conflict may arise where they have previously been involved in designing the processing to be monitored or where they are to represent the controller in court in legal matters relevant to data protection.

A management position need not always give rise to a conflict. What is decisive is whether its scope for decision-making concerns the processing of personal data. In the case of management tasks in the finance area of a purely B2B business, in product development without any connection to individuals or in purely mass marketing that does not use personal data, a conflict may be ruled out. Conversely, taking on additional tasks is unobjectionable where it entails no determination of purposes and means and no self-monitoring. It is therefore permissible, for example, to assign the data protection officer the additional role of internal reporting office under the German Whistleblower Protection Act (HinSchG), since that office takes no decision on the purposes and means of processing.

A separate question is whether the data protection officer may take on tasks that are assigned to the controller itself. Maintaining the records of processing activities under Article 30 GDPR, or drafting model texts, checklists and guidelines, may be delegated to him or her, because this does not constitute a determination of the processing. Responsibility for the data protection strategies themselves, that is to say, for general policies, for the management of notifications of personal data breaches, for carrying out the data protection impact assessment and for consent and transparency concepts, must by contrast remain with the controller; if the data protection officer assumes them in substance, he or she comes into tension with the monitoring task under Article 39(1)(b) GDPR. The separation of tasks must be maintained at the organizational level.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn