Bar Court of Appeal for North Rhine-Westphalia (AGH NRW), judgment of 12 March 2021, 1 AGH 9/19
The legal advisory tasks of the data protection officer under Article 39 GDPR constitute a legal service permitted by statute; a person working as an external data protection officer may be admitted to the bar as in-house counsel.
1. Overview
A fully qualified lawyer worked as an internal and external data protection officer and applied for admission to the bar as in-house counsel (Syndikusrechtsanwältin). At issue was whether the activity of a data protection officer involves legal advice of the kind characteristic of the legal profession and whether the legal advisory tasks may be performed at all without infringing the German Legal Services Act (RDG).
Reference: AGH NRW, judgment of 12 March 2021, 1 AGH 9/19
2. Data protection advice as a permitted legal service
The Bar Court of Appeal proceeded on the basis that the tasks assigned to the data protection officer by Article 39(1) GDPR involve, to a defining extent, the legal examination of the individual case and therefore legal services within the meaning of § 2(1) RDG. In the court's view, however, those services are permitted by another statute within the meaning of § 1(3) RDG: Article 39 GDPR assigns to the data protection officer a sufficiently specific field of tasks and thereby at the same time permits him or her to provide legal advice within that field. No separate registration under the RDG is required for those statutory tasks.
3. Significance in practice
The decision concerns the licensing requirement for external data protection officers under the RDG. It supports the view that the statutory tasks of the data protection officer may be performed without a separate license under the RDG. The reach of that entitlement has not, however, been conclusively settled: on the opposing view, the activity of an external data protection officer may exceed the threshold of an ancillary service not requiring a license (§ 5(1) RDG) as soon as complex legal questions outside data protection law also have to be answered in the individual case. A ruling by the highest courts is still awaited.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
CJEU, judgment of 9 February 2023, C-453/21, X-FAB
A conflict of interests under Article 38(6) GDPR arises where the data protection officer at the same time performs tasks by which he or she determines the purposes and means of the processing; the assessment is made in the individual case.
German Regional Labor Court of Hamm (LAG Hamm), judgment of 6 October 2022, 18 Sa 271/22
Payroll accounting and personnel administration for around 80 employees do not constitute a core activity within the meaning of Article 37(1)(b) GDPR; a voluntarily designated data protection officer does not enjoy the special protection against dismissal under § 6(4) of the German Federal Data Protection Act (BDSG).