Data Protection HubIndividual TopicsData Protection Officer

Tasks of the Data Protection Officer

Tasks of the data protection officer under Article 39 GDPR: informing and advising, monitoring compliance, advice on the data protection impact assessment, cooperation with the supervisory authority, and the risk-based approach; no responsibility of his or her own for data protection.

Article 39 GDPR sets out the tasks incumbent on the data protection officer by operation of law. The list is a minimum content: further tasks may be assigned as long as they do not give rise to a conflict of interests. Where a data protection officer is designated without any more detailed description of tasks, he or she has exclusively the tasks under Article 39 GDPR.

Key takeaways

  • The data protection officer informs and advises the controller, the processor, and the employees (Article 39(1)(a) GDPR).
  • He or she monitors compliance with data protection law (point (b)) but does not ensure compliance himself or herself: responsibility lies with the controller.
  • He or she advises on the data protection impact assessment and monitors its performance (point (c)) but does not lead it.
  • He or she is the contact point for the supervisory authority and cooperates with it (points (d) and (e)); there is no obligation to report infringements on his or her own initiative.
  • He or she gears his or her activity to the risk associated with the processing (paragraph 2).
  • He or she has no power to issue instructions or to enforce and is not a guarantor of compliance with data protection law.

1. Overview

1.1 Tasks and responsibility

Article 39 GDPR assigns tasks to the data protection officer but does not confer on him or her any power to issue instructions or to enforce. In enforcing the GDPR, he or she is confined to advising and reporting; his or her influence is exercised through the direct reporting line under Article 38(3), third sentence, GDPR. The tasks of the data protection officer and those of the controller are not identical: responsibility for compliance with the Regulation remains with the controller.

The mandate is designed to be proactive: the data protection officer may not retreat into a reactive role but must call for his or her involvement on his or her own initiative and perform his or her tasks even where not asked to do so. When assessing processing activities, he or she must take into account the co-determination rights of the works council and existing collective agreements (§ 87 of the German Works Constitution Act (BetrVG), Article 88 GDPR), for example in the case of processing relating to working time, remuneration, or the monitoring of conduct and performance.

pointTaskCore
aInforming and advisingInformation on obligations, proactively and on request
bMonitoring complianceReview and notification, no responsibility of his or her own
cAdvice on the data protection impact assessmentProviding advice and monitoring its performance, not leading it
dCooperation with the supervisory authorityreactive cooperation
eContact point for the supervisory authoritycentral point of contact, including for the prior consultation

1.2 Further tasks in the same capacity

Article 39(1), first sentence, GDPR permits further tasks to be assigned to the data protection officer in his or her capacity as data protection officer. Those tasks are then likewise subject to the rules of Articles 37 to 39 GDPR. This must be distinguished from the assignment of other tasks lying outside that function under Article 38(6) GDPR (on the conflict of interests).

2. Informing and advising (Article 39(1)(a) GDPR)

The data protection officer informs and advises the controller, the processor, and the employees who carry out processing of their obligations under the GDPR and under other data protection provisions.

Informing means the general provision of information on the rights and obligations under data protection law; with employees this is the main focus, because only an informed employee can observe the limits of processing. Advising means presenting and assessing decision alternatives; the decision itself is taken by the controller who receives the advice, not by the data protection officer. Advising covers both proactive advice and advice given upon request. It relates to the operations of which the data protection officer becomes aware through his or her involvement (Article 38(1) GDPR), through being contacted by a data subject (Article 38(4) GDPR), or in some other way. Under Recital 77 GDPR, it may also take the form of guidance on appropriate measures and on the assessment of risk. Article 39 GDPR does not provide for any obligation to document the performance of these tasks.

The data protection officer may take on the operational delivery of awareness-raising and training measures. A limit arises, however, where he or she is at the same time responsible for the design of those measures and would have to monitor them under point (b): to that extent there is a risk of a conflict of interests through self-monitoring (on the conflict of interests).

3. Monitoring compliance (Article 39(1)(b) GDPR)

3.1 Content of the task

The data protection officer is responsible for monitoring compliance with the GDPR, with other data protection provisions, and with the policies of the controller in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and training of staff, and the related audits. To that end, he or she may in particular collect information to identify processing activities, analyze and check their lawfulness, and inform, advise, and issue recommendations to the controller and the processor (WP29 Guidelines on Data Protection Officers, WP 243 rev.01).

Monitoring means identifying and assessing deviations between the observed actual state and the prescribed target state. In practice this takes place in two stages: first, the data protection officer examines whether the controller's data protection policies (guidelines, works agreements, process specifications) are compatible with the law; second, he or she compares the actual processing activities against those specifications and against the law. Because the processing landscape changes continuously, this review is an ongoing task; where there is a specific reason, it may also be carried out without prior notice. The Standard Data Protection Model developed by the supervisory authorities can serve as a methodological benchmark.

As a rule, the data protection officer may rely on the accuracy of the information available to him or her and may base his or her assessment on the statements of the competent units; he or she should document them and have them confirmed. An examination at the process, application, and infrastructure level is not mandatory, but is usually advisable. Where there are justified doubts, or where high-risk processing is involved, he or she must follow up on the statements and carry out at least random checks. His or her monitoring also extends to the processing of personal data by the works council, for which the employer is the controller; in doing so, the data protection officer maintains confidentiality vis-à-vis the employer (§ 79a BetrVG).

3.2 Monitoring is not ensuring

The wording "monitoring compliance" suggests that the data protection officer has to guarantee compliance. That is not the case. The central figure for compliance is the controller: under Article 5(2) GDPR, the controller is responsible for compliance with the principles and must be able to demonstrate it (accountability); Articles 24 and 35 GDPR confirm this role. The data protection officer merely monitors whether the controller complies with its obligations; he or she neither brings about compliance nor ensures it.

It follows that the data protection officer bears no responsibility of his or her own for compliance with data protection law. His or her task is limited to reporting identified deviations through the reporting line. Nor does he or she have to set up processes in order to obtain knowledge of all processing operations; the GDPR assumes that the controller involves him or her at an early stage.

No position of guarantor. The data protection officer is not a guarantor with a duty to supervise within the meaning of civil, employment, or criminal law and is not liable for the controller's compliance with data protection law. For a breach of his or her own tasks under Article 39 GDPR, however, he or she is liable like any other employee or service provider (in more detail on liability).

3.3 Awareness-raising and training

Under Article 39(1)(b) GDPR, the monitoring task also includes raising the awareness of, and training, the staff involved in processing operations.

4. Advice on the data protection impact assessment (Article 39(1)(c) GDPR)

Article 39(1)(c) GDPR is the counterpart to the controller's obligation under Article 35(2) GDPR to seek the advice of the data protection officer. Beyond merely providing advice, the data protection officer must monitor the performance of the data protection impact assessment. He or she does not, however, take the lead in conducting the impact assessment, because that would conflict with his or her advisory and monitoring function.

It makes sense to seek the data protection officer's advice on whether an impact assessment is required at all, what methodology should be used to carry it out, whether it is conducted in-house or with external support, and whether it has been carried out properly. Where the controller departs from the data protection officer's advice, it should record the reasons in writing in order to satisfy its accountability obligation under Article 24 GDPR.

5. Cooperation with and contact point for the supervisory authority (Article 39(1)(d) and (e) GDPR)

In light of the obligation of secrecy under Article 38(5) GDPR, cooperation with the supervisory authority under point (d) is to be understood as reactive cooperation in so far as specific operations are concerned. The data protection officer does not have to approach the supervisory authority on his or her own initiative; in particular, he or she is not obliged to report data protection infringements himself or herself, not even in the case of serious infringements.

Under point (e), the data protection officer is the contact point for the supervisory authority on all issues relating to processing, including the prior consultation referred to in Article 36 GDPR. The obligation to communicate his or her contact details under Article 37(7) GDPR underlines this function as the central point of contact.

In doing so, the data protection officer acts as an intermediary, not as an extended arm of the supervisory authority: he or she remains a body of self-monitoring within the controller's organization. Because he or she has no decision-making power and because of his or her obligation of secrecy (Article 38(5) GDPR), it is not for him or her to decide on the release of documents and information; even his or her own documentation of activities may be passed on to the supervisory authority only with the controller's approval. The notification of personal data breaches is assigned exhaustively to the controller by Article 33 GDPR; there is no second notification channel via the data protection officer. Conversely, the data protection officer may make use of the supervisory authority's advice free of charge (Article 39(1)(e), Article 57(3) GDPR) without this setting aside his or her duty of confidentiality.

6. Risk-based approach (Article 39(2) GDPR)

In the performance of his or her tasks, the data protection officer has due regard to the risk associated with processing operations, taking into account the nature, scope, context, and purposes of processing. This expresses the GDPR's risk-based approach for his or her activity as well: he or she may and must direct his or her attention according to the level of risk to the rights and freedoms of data subjects and weight the performance of his or her tasks accordingly.

This is a rule of prioritization, not an exemption: the data protection officer concentrates primarily on the higher-risk processing operations but may not neglect the monitoring of those involving less risk. At the same time, the approach helps him or her decide which methodology to recommend for a data protection impact assessment, which areas to examine, which training to initiate, and which processing operations to devote more time and resources to (WP29 Guidelines on Data Protection Officers, WP 243 rev.01).

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn