Internal or external data protection officer
Art. 37(6) GDPR permits both: the data protection officer may be a staff member of the controller or fulfil the tasks on the basis of a service contract. The decision is therefore not a legal question but an organisational one — with legal consequences that differ markedly. Appointing internally creates a protected standing inside your own company and requires care over conflicts of interest. Engaging externally buys in expertise and cover, and you remain responsible either way. This page sets out the differences that matter in practice.
The differences in detail
| Criterion | Internal data protection officer | External data protection officer |
|---|---|---|
| Legal basis | A staff member of the controller, designated under the first alternative of Art. 37(6) GDPR. The designation sits alongside the employment contract and creates an office of its own. | Engaged on the basis of a service contract, second alternative of Art. 37(6) GDPR. An organisation may be engaged provided a contact person is named. |
| Conflict of interest | The critical point. Art. 38(6) GDPR allows further tasks only where no conflict of interest results. Anyone who helps determine the purposes and means of processing is ruled out — typically management and the heads of IT, HR and sales; case law has found a conflict for chairing the works council, among others. | Structurally low, because there is no operational role in the company. What remains to be checked is whether the same person also holds tasks with decision-making power, for instance as IT provider to the same client. |
| Protection against removal and dismissal | Strong. Sec. 38(2) BDSG makes sec. 6(4) BDSG applicable: removal from office only by analogous application of sec. 626 BGB, dismissal of the employment relationship generally impermissible, and protection continuing for a year after the designation ends. Case law applies this special protection where the appointment is legally mandatory. | No special dismissal protection. The service contract governs, with its agreed term and notice periods; independently of that, no removal may occur because of the performance of the tasks (Art. 38(3) GDPR). |
| Expertise | Has to be built and maintained. Art. 37(5) GDPR measures the required expert knowledge against the complexity of the processing; Art. 38(2) GDPR obliges the controller to provide the resources and to enable expert knowledge to be maintained. | Bought in and held by the provider. Training, literature and tracking case law and supervisory practice are part of the fee. |
| Cover during absence | Has to be organised. Leave, illness or departure create a gap that, without a named deputy, falls back on management. | Usually part of the contract: the provider supplies cover, and a change of personnel there does not change your organisation. |
| Knowledge of internal processes | High. Someone inside the company knows the systems, the owners and the edge cases and hears about projects early — which supports the timely involvement required by Art. 38(1) GDPR. | Has to be built and depends on a functioning reporting route. In exchange, an outside view brings comparative knowledge from other companies. |
| Cost structure | A share of staff cost, release from other duties, training, literature, tooling and cover. The effort is real but rarely appears as a line item. | A contractually agreed fee, usually a flat rate with a defined scope. Additional work such as audits, training or projects is often billed separately. |
| Confidentiality | Art. 38(5) GDPR imposes secrecy. Via sec. 38(2) BDSG, confidentiality about the identity of data subjects and a right to refuse testimony are added. | The same duties under Art. 38(5) GDPR and sec. 38(2) BDSG, plus contractual confidentiality towards the client. |
| Notification to the authority | Identical: publish the contact details and communicate them to the competent supervisory authority (Art. 37(7) GDPR). | Identical: publish the contact details and communicate them to the competent supervisory authority (Art. 37(7) GDPR). |
About these statements: This page is for orientation and is not legal advice. It reflects the state of the GDPR and the BDSG, and of the guidelines and case law referred to, at the time of writing (August 2026); legislation, supervisory practice and case law can change. Whether an appointment duty applies and which model suits your organisation depends on your processing, your structure and your people — take qualified advice if in doubt.
The conflict of interest decides more often than the budget
Art. 38(6) GDPR allows further tasks to be assigned to the data protection officer — but only for as long as no conflict of interest arises. The test is simple: anyone who helps decide the purposes and means of processing cannot supervise themselves. The Article 29 Working Party guidelines on data protection officers, endorsed by the European Data Protection Board, name the positions typically ruled out: management, and the heads of operations, finance, marketing, HR and IT. Case law has found a conflict for chairing the works council, among others.
For smaller companies that is often the real reason to go external. If the only people close enough to the IT are precisely the ones running the systems, nobody internal is left. Conversely: good intentions do not cure a bad appointment. If someone is designated who could not lawfully be designated under Art. 38(6) GDPR, the designation is open to challenge and the supervisory authority can require their removal.
The internal officer's protection binds in both directions
The internal data protection officer is protected by statute, and substantially so. Sec. 38(2) BDSG makes sec. 6(4) BDSG applicable to non-public bodies too: removal from office is possible only by analogous application of sec. 626 BGB, that is for good cause; dismissal of the employment relationship is generally impermissible, and the protection continues for a year after the designation ends. Case law applies this special protection where the appointment is legally mandatory — for a purely voluntary designation it is not guaranteed.
This safeguards the independence of the office, but it also binds the company. Appointing internally is not merely allocating a responsibility; it is a personnel decision with heightened job security attached. That is not an argument against the internal model — it is an argument for taking the selection seriously, putting the tasks in writing, and actually providing the resources Art. 38(2) GDPR requires.
What stays the same in both models
Whichever you choose, responsibility remains with the controller. The data protection officer monitors and advises (Art. 39(1) GDPR) but is not liable for compliance; accountability under Art. 5(2) GDPR falls on the company. Equally unchanged are the timely involvement required by Art. 38(1) GDPR, the notification of contact details to the supervisory authority under Art. 37(7) GDPR, and the duty to provide the office with resources and access.
The work itself is the same too: maintaining the record of processing, checking processors, answering data subject requests on time, monitoring the notification deadline under Art. 33 GDPR, rolling out and chasing training, supporting impact assessments and documenting all of it well enough to survive an inspection. That is exactly what CIVAC is built for — and it works for both models: your internal officer works in the same workspace as an external officer you grant access to. If the model changes, the history stays.
When each model fits
Appoint internally when …
- there is a suitable person without a conflict of interest under Art. 38(6) GDPR.
- processing is so tightly woven into the core business that proximity to operations is decisive.
- enough time can be freed up for the task and training funded on a lasting basis.
- a deputy is named for leave, illness and departure.
- the heightened job security attaching to the person is knowingly accepted.
Engage externally when …
- every eligible internal candidate is subject to a conflict of interest.
- the required expertise does not exist internally and building it would be disproportionate.
- continuous availability and cover should be guaranteed by contract.
- an outside view and comparative knowledge from other companies are wanted.
- the effort should sit as a predictable line item rather than as hidden internal cost.
Frequently asked
- Is an external data protection officer permitted at all?
- Yes, expressly. Art. 37(6) GDPR puts both routes on the same footing: the data protection officer may be a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract. An organisation may be engaged; a contact person should then be named and communicated to the supervisory authority under Art. 37(7) GDPR. Supervisory authorities accept both models. What matters is not the form of engagement but that expertise, independence, resources and timely involvement are genuinely ensured.
- Who may not become the internal data protection officer?
- Under Art. 38(6) GDPR, anyone whose further tasks would create a conflict of interest. That typically rules out people who help decide the purposes and means of processing: management and the heads of IT, HR, sales, marketing or finance. The Article 29 Working Party guidelines on data protection officers, endorsed by the European Data Protection Board, name those positions expressly; case law has found a conflict for chairing the works council, among others. What counts is actual decision-making power, not the job title.
- Does the internal data protection officer have dismissal protection?
- Yes, via sec. 38(2) BDSG, which extends sec. 6(4) BDSG to non-public bodies. Removal from office is possible only by analogous application of sec. 626 BGB, that is for good cause. Dismissal of the employment relationship is generally impermissible while the designation stands, and the protection continues for a year after it ends; extraordinary dismissal for good cause remains possible. Case law applies this special protection where the appointment is legally mandatory; for a purely voluntary designation it is not guaranteed.
- What does an internal data protection officer actually cost?
- More than the working hours. On top of the share of staff cost come release from other duties, initial qualification and ongoing training, literature and access to case law, tooling for the record, deadlines and evidence, and a cover arrangement for leave and illness. Art. 38(2) GDPR expressly obliges the controller to provide those resources and to enable expert knowledge to be maintained. An honest comparison puts that total against the fee for an external engagement, not just against an hourly rate.
- Can you switch from the external to the internal model?
- Yes, at any time. You need a new designation, updated published contact details, a fresh notification to the supervisory authority under Art. 37(7) GDPR and an orderly handover. The handover is the critical part: the record of processing, open data subject requests, running impact assessments, audit findings, training status and the documentation of past years must transfer in full, because accountability under Art. 5(2) GDPR rests with the company. Have the format and scope of the handover guaranteed in the service contract.
- Does the internal officer need dedicated software?
- No particular software is mandatory, but the tasks in Art. 39 GDPR generate work that disappears into spreadsheets and inboxes without a tool: the record, deadlines, training evidence, audit findings, notifications under Art. 33 GDPR. Art. 38(2) GDPR obliges the controller to provide the resources needed to perform the tasks — tooling is part of that. CIVAC is built for exactly this and works in both models: the internal officer works in the same workspace as an external officer you grant access to.