# CJEU, judgment of 22 June 2022, C-534/20, Leistritz

The stricter German special protection against dismissal for data protection officers (§ 6(4) BDSG) is compatible with the prohibition on removal from office under Article 38(3), second sentence, GDPR, provided that the objectives of the GDPR are not undermined.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/rechtsprechung/1.4.45-eugh-leistritz
> Sprache: en



## 1. Overview [#1-overview]

A stock corporation was not required under Article 37(1) GDPR, but was required under § 38(1) of the German Federal Data Protection Act (BDSG), to designate a data protection officer. It terminated the data protection officer's employment by ordinary notice. The Court had to clarify whether German law, which permits termination of the employment relationship only for good cause, is compatible with the prohibition on removal from office laid down in Article 38(3), second sentence, GDPR.

Reference: [CJEU, judgment of 22 June 2022, C-534/20, Leistritz](https://curia.europa.eu/juris/liste.jsf?num=C-534/20\&language=de)

## 2. Stricter national protection is permissible [#2-stricter-national-protection-is-permissible]

Article 38(3), second sentence, GDPR prohibits the data protection officer from being dismissed or penalized for performing his or her tasks. That provision does not prevent the national legislature from providing more extensive protection that excludes ordinary termination of the employment relationship and allows termination only for good cause. The Union lacks comprehensive legislative competence in the field of protection against dismissal, so that the Member States may adopt supplementary rules in that respect.

## 3. Limit: no undermining of the objectives of the GDPR [#3-limit-no-undermining-of-the-objectives-of-the-gdpr]

The stricter protection is permissible only in so far as it does not undermine the attainment of the objectives of the GDPR. Where national law prohibits any termination, this must not have the effect that a data protection officer who no longer has the professional qualities required for his or her tasks, or who does not perform those tasks in accordance with the GDPR, nevertheless remains in office.

## 4. Significance for the position of the data protection officer [#4-significance-for-the-position-of-the-data-protection-officer]

The decision secures the special protection against dismissal going beyond Union law that § 38(2) in conjunction with § 6(4) BDSG affords to the internal data protection officer designated as required by law (in more detail on the [prohibition on penalizing and on removal from office](/docs/dsgvo-hub/einzelthemen/datenschutzbeauftragter/1.3.8.2-stellung)). That protection does not apply to the external data protection officer; his or her relationship is governed solely by the service contract.


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.