# Data Protection Officer (Articles 37-39 GDPR)

Overview of the data protection officer under Articles 37-39 GDPR and § 38 of the German Federal Data Protection Act (BDSG): designation, position and tasks, as well as the contract with an external data protection officer.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/einzelthemen/datenschutzbeauftragter
> Sprache: en



The data protection officer is an instrument of self-monitoring in data protection law. Within the organization, the officer monitors compliance with the data protection rules and advises the controller, without bearing responsibility for data protection himself or herself. Articles 37 to 39 GDPR govern the designation, the position and the tasks of the officer; § 38 of the German Federal Data Protection Act (BDSG) supplements the obligation to designate for non-public (private) bodies.

<Callout type="info">
  **Key takeaways**

  * There is **no general obligation** to designate an officer; the obligation exists only under Article 37(1) GDPR or § 38 BDSG, and alongside it a voluntary designation is possible.
  * The data protection officer is **free from instructions**, reports directly to the highest management level and is protected against being penalized or dismissed.
  * He or she **monitors and advises**, but has no power to issue instructions or to enforce compliance and bears no responsibility of his or her own for compliance.
  * The designation may be made **internally or externally**; in the case of an external data protection officer, a service contract forms the underlying basis.
  * He or she is **not a controller** and is not liable under Article 82 GDPR; liability comes into consideration only for a breach of his or her own tasks.
</Callout>

## 1. Function and classification [#1-function-and-classification]

The GDPR conceives of the data protection officer as an effective instrument of data protection within the entity responsible for the processing. His or her position (Article 38 GDPR) and tasks (Article 39 GDPR) apply irrespective of whether the designation was mandatory or voluntary. What is decisive for position and tasks is solely the fact that a designation has been made, not the reason for it.

## 2. Topics at a glance [#2-topics-at-a-glance]

Designation, position and tasks form the three regulatory areas of Articles 37 to 39 GDPR. The question of liability follows on from them; it arises not from those provisions but from the general law.

<Cards>
  <Card title="Designation" href="/docs/dsgvo-hub/einzelthemen/datenschutzbeauftragter/1.3.8.1-benennung" description="Obligation under Article 37(1) GDPR and § 38 BDSG, voluntary designation, qualifications, formalities, and the contract with an external data protection officer." />

  <Card title="Position" href="/docs/dsgvo-hub/einzelthemen/datenschutzbeauftragter/1.3.8.2-stellung" description="Involvement, support with resources, freedom from instructions, prohibition on penalization and dismissal, reporting line, the right of data subjects to contact the officer, and conflicts of interest under Article 38 GDPR." />

  <Card title="Tasks" href="/docs/dsgvo-hub/einzelthemen/datenschutzbeauftragter/1.3.8.3-aufgaben" description="Informing and advising, monitoring compliance, advice on the data protection impact assessment, cooperation with the supervisory authority, and the risk-based approach under Article 39 GDPR." />

  <Card title="Liability" href="/docs/dsgvo-hub/einzelthemen/datenschutzbeauftragter/1.3.8.4-haftung" description="No compensation under Article 82 GDPR, tort liability towards data subjects, internal liability of the internal and the external data protection officer, as well as criminal and administrative fine responsibility." />
</Cards>

## 3. Primary sources [#3-primary-sources]

<Cards>
  <Card title="Article 37 GDPR" href="https://dsgvo-gesetz.de/art-37-dsgvo/" description="Designation of the data protection officer." />

  <Card title="Article 38 GDPR" href="https://dsgvo-gesetz.de/art-38-dsgvo/" description="Position of the data protection officer." />

  <Card title="Article 39 GDPR" href="https://dsgvo-gesetz.de/art-39-dsgvo/" description="Tasks of the data protection officer." />

  <Card title="WP 243 rev.01" href="https://ec.europa.eu/newsroom/article29/items/612048" description="Guidelines of the Article 29 Data Protection Working Party on data protection officers (endorsed by the European Data Protection Board)." />
</Cards>


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.