Data Protection HubCase Law

CJEU, judgment of 9 February 2023, C-453/21, X-FAB

A conflict of interests under Article 38(6) GDPR arises where the data protection officer at the same time performs tasks by which he or she determines the purposes and means of the processing; the assessment is made in the individual case.

1. Overview

An employee was at the same time chair of the works council and data protection officer of the same company and of affiliated companies. The company removed him from office as data protection officer, relying on a conflict of interests between the two positions. The Court had to clarify when a conflict of interests within the meaning of Article 38(6) GDPR exists and whether national law may lay down stricter rules on removal from office.

Reference: CJEU, judgment of 9 February 2023, C-453/21, X-FAB

2. Concept of a conflict of interests

A conflict of interests within the meaning of Article 38(6), second sentence, GDPR may arise where the data protection officer is entrusted with other tasks or duties that lead him or her to determine the purposes and means of the processing of personal data at the controller or the processor. The data protection officer may not hold a position within the organization whose very task is to determine the purposes and means of the processing, because he or she would otherwise have to monitor the results of his or her own activity.

3. Assessment in the individual case

Whether such a conflict exists must be assessed in the individual case on the basis of all relevant circumstances, in particular the organizational structure of the controller and the applicable rules, including any internal policies. The simultaneous function as chair of the works council does not in itself necessarily give rise to a conflict of interests; the national courts must examine this specifically.

4. Stricter national rules on removal from office are permissible

The GDPR does not preclude national rules that make the removal of the data protection officer from office subject to stricter conditions than Article 38(3), second sentence, GDPR, provided that the objectives of the GDPR are not thereby undermined. There is good cause for removal from office in particular where the data protection officer no longer has the professional qualities required under Article 37(5) GDPR or does not perform his or her tasks in accordance with the GDPR.

5. Significance in practice

The decision gives concrete shape to the prohibition of conflicts of interest where further tasks are assigned to the data protection officer. It must be observed above all where the function is combined with management responsibilities in IT, human resources or marketing, and where members of the management are designated.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn