# German Regional Labor Court of Hamm (LAG Hamm), judgment of 6 October 2022, 18 Sa 271/22

Payroll accounting and personnel administration for around 80 employees do not constitute a core activity within the meaning of Article 37(1)(b) GDPR; a voluntarily designated data protection officer does not enjoy the special protection against dismissal under § 6(4) of the German Federal Data Protection Act (BDSG).

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/rechtsprechung/1.4.48-lag-hamm-18-sa-271-22
> Sprache: en



## 1. Overview [#1-overview]

Within a group of undertakings, a company carried out payroll accounting and personnel administration for around 80 employees and had designated a data protection officer. After that officer had been removed from office and his employment had been terminated, it had to be clarified whether the company was subject to any obligation to designate an officer at all and whether the officer benefited from the special protection against dismissal.

Reference: [LAG Hamm, judgment of 6 October 2022, 18 Sa 271/22](https://www.justiz.nrw.de/nrwe/arbgs/hamm/lag_hamm/j2022/18_Sa_271_22_Urteil_20221006.html)

## 2. Personnel administration is not a core activity [#2-personnel-administration-is-not-a-core-activity]

Under Recital 97 GDPR, the processing of employee data is as a rule not a main purpose but merely a support process. The mere fact that HR data are processed does not in itself give rise to an obligation to designate an officer. Nor are the sensitive data arising in the course of payroll accounting, such as data on religious affiliation or on periods of incapacity for work, processed on a scale that reaches the threshold of Article 37(1)(b) or (c) GDPR. Payroll accounting and personnel administration for around 80 employees therefore do not constitute a core activity that requires designation.

## 3. No special protection against dismissal in the case of a voluntary designation [#3-no-special-protection-against-dismissal-in-the-case-of-a-voluntary-designation]

As the company was not obliged to designate a data protection officer, the designation rested on a voluntary decision. A voluntarily designated data protection officer does not enjoy the special protection against dismissal under § 38(2) in conjunction with § 6(4) BDSG, which allows termination only for good cause. That stricter protection applies only where a statutory obligation to designate an officer exists.

## 4. Significance for practice [#4-significance-for-practice]

The decision gives concrete shape to the concept of a [core activity in the context of the designation](/docs/dsgvo-hub/einzelthemen/datenschutzbeauftragter/1.3.8.1-benennung) and at the same time shows the consequence for protection against dismissal: anyone designating an officer voluntarily, without being obliged to do so, should be aware that the German special protection against dismissal, which goes beyond EU law, does not then apply (for more detail, see the [prohibition on penalization and dismissal](/docs/dsgvo-hub/einzelthemen/datenschutzbeauftragter/1.3.8.2-stellung)).


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.