The data protection officer monitors compliance with data protection rules within an organisation and is the point of contact for the supervisory authority and data subjects.
When is a data protection officer mandatory?
In Germany, designation is mandatory once 20 or more persons regularly process personal data by automated means. The role can be filled internally or assigned to an external data protection officer, who is formally appointed and is personally liable.
Irrespective of headcount, the obligation applies, among other cases, where the core activities consist of large-scale processing of special categories of personal data or large-scale regular monitoring, or where processing is subject to a data protection impact assessment.
Tasks and position
The data protection officer advises management and staff, monitors compliance with data protection law, provides training, advises on data protection impact assessments and cooperates with the supervisory authority.
The DPO does not receive any instructions regarding the performance of their tasks and must not be penalised for performing them. Their contact details must be published and communicated to the supervisory authority.
Legal provisions
- Art. 37 GDPR
- Obligation to designate, qualifications and publication of contact details.
- Arts. 38 and 39 GDPR
- Position and tasks of the data protection officer.
- Section 38 BDSG
- Obligation to designate a DPO, as a rule from 20 persons, and special protection against dismissal.