DACH data protection officer: One order, three legal areas, one proof
A data protection officer for the entire DACH region sounds efficient. In practice, three supervisory authorities, three laws and three reporting obligations come together. This guide shows the legal basis, the operational setup and the documentation.
The revised Data Protection Act (revDSG) has been in force in Switzerland since September 1, 2023, which brings the requirements for those responsible closer to the GDPR without making them the same. In Austria, the GDPR applies in parallel with the Data Protection Act (DSG as amended), and in Germany with the BDSG. Anyone who appoints a data protection officer for the DACH region is effectively working in three legal areas with three supervisory authorities: BfDI and state supervisory authorities in Germany, DSB in Vienna and EDÖB in Bern. The operational question is rarely whether, but rather how, the order is structured cleanly, without a single gap making the entire group solution formally vulnerable.
This article addresses group structures with subsidiaries in several DACH countries and explains when a central order is viable, when local representatives are mandatory and which documentation is sufficient for the auditor. CIVAC is a compliance platform and officer-as-a-service that maps these structures in practice, from proof of order to the reporting line to the reporting chain. The article works with specific paragraphs, deadlines and interfaces so that the reading becomes a reliable decision. At the end you will receive a clear checklist of which documents, deadlines and languages you have to expect operationally.
Key Takeaways
- A central DPO order via DACH is permitted as soon as accessibility for data subjects and for every supervisory authority is demonstrably guaranteed.
- Under revDSG, Swiss subsidiaries also require a data protection advisor in accordance with Art. 10 revDSG if processing under private law is high-risk.
- According to Art. 33 GDPR, data breaches must be reported within 72 hours and according to Art. 24 revDSG as soon as possible, with different thresholds and different official forms.
Three legal areas, one representative: What is legally permissible
Art. 37 Para. 2 GDPR expressly allows a group of companies to appoint a common data protection officer, provided that he or she can be easily reached from each branch. This regulation applies directly in Germany and Austria. As a third country, Switzerland applies its own law: Art. 10 revDSG recognises the data protection advisor as a voluntary but factually expected function in private law processing with a high risk. In principle, a group order via DACH is possible, but it must fulfil three layers, which are rarely clearly separated in practice.
First layer: accessibility. The DPO function must be documented in the national language, with local telephone number and address, for each data subject. Second layer: supervisory communication. Inquiries from Vienna, Berlin or Bern end up with different authorities with different deadlines and different procedural rules. Third layer: verification. The appointment certificate, signed, filed, verifiable, in a language that the respective supervisory authority accepts. Accessibility does not necessarily have to be physical in the respective country, a reachable telephone number and a staffed email inbox are sufficient if they provide answers within 48 hours.
CIVAC maps these three layers in the workspace in a structured manner, with appointment certificates for each company and a consolidated reporting line to the external data protection officer. If you don't separate the layers, you risk that a single, incomplete subsidiary will make the entire group order formally vulnerable. Licence the workspace for your internal representatives, or have our representatives order it. The decision rarely depends on costs, but rather on the question of whether the professional profile already exists internally or needs to be developed first. A hybrid variant, in which the function is filled internally but secured by external audit templates and an external deputy, has proven to be a reliable compromise in medium-sized companies with between 250 and 1,500 employees.
GDPR, DSG and revDSG: Where the differences become operationally harsh
On paper, the three regimes appear similar, but in day-to-day business there are five differences that drive the effort. Firstly, the reporting obligation: Art. 33 GDPR requires a report to the supervisory authority within 72 hours of becoming aware of it, Art. 24 revDSG requires a report to the FDPIC as quickly as possible in the event of a high risk, without a rigid deadline. The clock starts on awareness. Secondly, the sanctions: fines of up to 20 million euros according to the GDPR, fines of up to 250,000 CHF according to revDSG, but personally against the responsible natural person, not against the legal entity of the company.
Thirdly, the list of processing activities: Art. 30 GDPR and Art. 12 revDSG are similar in content, but Switzerland allows exceptions for SMEs with fewer than 250 employees without high risk. Fourth, data transfer: Swiss data to other EU countries is considered cross-border disclosure according to Art. 16 revDSG, with its own list of safe states, maintained by the Federal Council. Fifth, order processing: Art. 28 GDPR and Art. 9 revDSG differ in the level of detail of the mandatory clauses. For Swiss processors, additional declarations of commitment are typically designed as an appendix to the existing GDPR-AVV.
Anyone who uses a DACH-DPO needs documented instructions for action for each of these five fields. The auditor calls, the evidence is ready. CIVAC's 490 audit templates cover each of the five fields with two to three different templates, depending on group size and risk profile. The templates are available in the respective national language and in the English corporate version, with audit-proof versioning. This means that the effort per country remains manageable without losing the group view.
Order in Austria: DSB notification to the Vienna Data Protection Authority
The Austrian Data Protection Authority (DSB) is based in Vienna and keeps the register of registered data protection officers. Section 5 DSG refers to the GDPR, but supplemented by national procedural rules. A DSB order must be displayed to the authority online via the company service portal (USP), with name, contact details and accessibility. For group solutions, the central DSB function is entered, but each Austrian subsidiary is also provided with its own notification. This double structure is often overlooked and is one of the most common formal findings in supervisory audits.
In practical terms, this means: A DPO function based in Munich that is responsible for the Austrian subsidiary must be registered in Vienna, with a German address and accessibility regulations in German. The DSB Vienna accepts this, but regularly asks if you can only be reached via a foreign hotline. A local response channel, such as an Austrian PO box or a summonsable address via a Viennese representative in accordance with Art. 27 GDPR, closes the gap. For corporations with more than three Austrian subsidiaries, it is recommended to have a central postal address in Vienna to which all supervisory correspondence is addressed.
CIVAC structures this double display as a standard process in the workspace, including a template for USP entry and the obligation to report on incidents. Licence the workspace for your internal representatives or have our representatives order it. The notification to the DSB Vienna is stored in the system with a confirmation number and date so that the proof can be found in seconds during a supervisory check. The appointment certificate, signed, filed, verifiable. This documentation chain is the crucial difference between a formally clean and a vulnerable corporate order. In the past two years, the DSB Vienna has emphasised several times that formally incomplete reports can be viewed as a violation of the obligation to cooperate, with the potential for a fine of their own.
Switzerland under revDSG: data protection advisor instead of DPO, different logic
The revised data protection law distinguishes between the GDPR logic of a data protection officer and the Swiss concept of the data protection advisor according to Art. 10 revDSG. Those responsible under private law are not obliged to appoint one, but gain the relief that a data protection impact assessment does not necessarily have to be submitted to the FDPIC in the event of a high risk, provided a data protection advisor has been consulted. Federal bodies are subject to stricter rules according to Art. 25 VDSG. This dividing line is often drawn incorrectly in corporate structures, with the result that an actually facilitating function is not used.
Operationally, this means: A DACH DPO function can take on the role of data protection advisor in Switzerland, provided that it can demonstrate sufficient expertise and independence and the FDPIC can reach the contact. The FDPIC in Bern does not require prior notification of the person, but does require proof of consultation in DPIA-relevant processes. Swiss subsidiaries must also check whether they need a representative in Switzerland in accordance with Art. 14 revDSG if processing operations are offered from abroad. The representative is not identical to the data protection advisor, but both functions can be held by the same natural or legal person.
CIVAC maps both roles in the workspace, with a separate reporting line for Swiss matters and an audit template for the DPIA consultation. The reporting line runs directly to management, not through local IT managers. The DPIA consultation is filed as a signed document between the data protection advisor and the person responsible, with the version status and proof of the statement made. Others run compliance like a filing cabinet. We run it like software. The platform reminds you of follow-up consultations, documents risk decisions made and makes them available for an FDPIC request in under 60 seconds.
Managing reporting obligations in parallel: 72 hours, as soon as possible, and the differences in between
In the worst case, a data breach in a DACH group affects all three supervisory authorities at the same time. Art. 33 GDPR sets 72 hours from knowledge for Germany and Austria, with different reporting portals: federal state authorities in Germany, DSB Vienna for Austria. Art. 24 revDSG requires a report to the FDPIC as soon as possible if there is likely to be a high risk to the personality of the person concerned. The threshold is therefore higher than under the GDPR, but the deadline is indefinite. Three parallel reports are not an exception, but rather the rule for cross-border incidents.
CIVAC's DSB workspace maps a uniform incident path with three branches. The date of receipt, risk analysis and those affected are recorded once and the three reporting forms are filled out automatically. The clock starts on awareness. A follow-up message in accordance with Art. 33 Para. 4 GDPR in the event of incomplete information will be noted in the workspace. For Switzerland, the system generates an accompanying note explaining why the report was made or intentionally not made, with reference to the risk assessment. This note is the decisive audit evidence for the FDPIC.
Without this note, the decision against a report remains open to argument. A later supervisory audit can then no longer understand the risk assessment, and the failure is viewed as a supervisory violation. Linking to the NIS-2 reporting path is possible if the incident also triggers a cybersecurity report, such as ransomware with data exfiltration. The auditor calls, the evidence is ready. The parallel provision of the three reporting paths is the central added value of a consolidated DACH DPO list. Experience has shown that manual processing of parallel reports takes four to six hours without a platform, and under an hour with a platform.
Reporting line and independence: Whoever is not authorised to give instructions to the DPO
Art. 38 Para. 3 GDPR requires that the data protection officer does not receive any instructions and reports directly to the highest management level. § 6 DSG Austria and Art. 10 revDSG Switzerland formulate similar, although not identical, requirements. In a DACH group, this practically means: The DSB reports to the group board, not to the management of an individual subsidiary, and certainly not to the IT manager. This reporting line is often linguistically abbreviated in appointment certificates, which becomes a question of interpretation in the event of an audit.
A clean list documents three points. Firstly, the direct reporting line to the highest management level, by name and by proxy. Secondly, the prohibition of instructions on technical data protection issues, including the obligation to record dissenting opinions. Thirdly, protection against dismissal in accordance with Article 38 Paragraph 3 Sentence 2 GDPR, which is additionally protected in Germany by Section 6 Paragraph 4 BDSG. In Austria and Switzerland, this special legal anchoring is missing, which is why contractual regulations are even more important. The appointment certificate should provide for a separate clause on protection against dismissal for each DSB area, with reference to the national legal situation.
CIVAC provides an appointment certificate template for each country that covers all three points and can be accessed in the respective country version via the FAQ overview. The templates were coordinated with German, Austrian and Swiss data protection lawyers and are updated centrally if the law changes. The reporting line is stored in the workspace as an organisational chart; every change creates a versioned file. Others run compliance like a filing cabinet. We run it like software. This is not just a question of style, but the basis for a robust audit in each of the three jurisdictions.
Language questions and representation: If the supervisor answers in the local language
An often underestimated hurdle is the procedural language. The DSB Vienna conducts procedures in German, the EDÖB in German, French or Italian for each cantonal jurisdiction, and the German state supervisory authorities exclusively in German. A DACH DPO must therefore be able to respond in writing in the relevant languages, or appoint a local representative to take on this task. Art. 27 GDPR regulates the representative for those responsible who are not established in the EU, Art. 14 revDSG regulates the representative in Switzerland for the opposite constellations.
The clean variant: A DACH DPO with a German native language, supplemented by a Swiss data protection advisor for Romansh-speaking areas and an Austrian representative with a summonsable address. This three-way structure costs less than three separate DPO functions and satisfies all three oversight requirements. Anyone who relies on a pure DACH DSB without local representatives risks procedural delays, which can be seen as aggravating circumstances in the fine proceedings. The FDPIC in particular has explicitly criticized the lack of local accessibility in recent decisions.
CIVAC has a template available for every constellation, from a simple display to a three-tier representative structure. The audit templates are available in the respective procedural language and are updated centrally if the law changes. In practice, this saves the days that would otherwise be lost due to translations between the incident and the report. Corporations that work with French-speaking cantons such as Geneva or Vaud should also check whether their DPIA templates are available in two languages. For larger data flows into Romansh-speaking areas, continuous French file management is recommended, with a German corporate version as an accompanying document. The FDPIC entries can be made in both languages; a translation is only mandatory in proceedings before the Federal Administrative Court.
Calculate costs and effort realistically: What really binds a DACH order
Classic consulting offers for a DACH DSB appointment bill three separate mandates: Germany, Austria, Switzerland. Hourly rates of 180 to 250 euros per jurisdiction are standard market rates, with minimum quotas of 8 to 16 hours per month per country. Extrapolated, the annual costs are between 60,000 and 110,000 euros, without incident processing and without training. The majority of the effort does not arise from consulting, but rather from repeating the same issues in three files and manually consolidating the reports for the corporate board.
A consolidated officer-as-a-service approach reduces this repetition. CIVAC SLA: 2 working days instead of 2 to 6 weeks classic, with 490 ready-to-use audit templates that are pre-designed for GDPR, DSG and revDSG. The reporting line runs to the top of the group, the appointment certificates are generated for each country, and the reporting chain is consolidated. Overall, the administrative effort is reduced by the factor that repetition would otherwise cause. Training for local employees takes place via a central learning system, with country-specific mandatory modules on GDPR, DSG and revDSG.
An exact calculation depends on the number of subsidiaries and the volume of incidents. One indication: Groups with five to twelve DACH subsidiaries typically earn less than 50,000 euros annually in the consolidated model, with fully documented evidence. The savings are not in cheaper hourly rates, but in avoiding redundant file management. For very small subsidiaries with less than ten employees, the workspace licence for internal officers can be worthwhile; for medium-sized and larger subsidiaries, the external officer-as-a-service can be worthwhile. Both models use the same platform with identical audit templates and EU data residency. This data residency is particularly relevant for Swiss clients because it avoids additional disclosure in third countries and simplifies the assessment according to Art. 16 revDSG.
Turn reading into an assignment
A DACH DSB set-up does not succeed through three parallel mandates, but rather through a consolidated structure with locally visible accessibility. The legal basis is Art. 37 Para. 2 GDPR in conjunction with the national specifics in Section 5 DSG Austria and Art. 10 revDSG Switzerland. The operational basis is a platform that maintains appointment certificates, reporting paths and reporting lines in a single file structure. The commercial basis is to avoid redundant advice across three jurisdictions without compromising local accessibility.
CIVAC is a compliance platform and officer-as-a-service with 25 officer roles, 490 audit templates and EU data residency. Licence the workspace for your internal representatives, or have our representatives order it, in any DACH jurisdiction. The setup takes two working days instead of two to six weeks. We deliver a complete initial set with an appointment certificate, reporting line, reporting paths and an initial inventory of processing activities.
Turn reading into a mandate. Write to info@civac.de or use the contact form on civac.de. We respond to inquiries within four hours on weekdays with a concrete proposal for the list, including information on the appointment certificate, reporting line and reporting chain. In a preliminary discussion, we will clarify whether your internal team needs a workspace licence or our order. This is followed by a set-up appointment lasting around 90 minutes, during which the appointment certificates for each country are signed and the first reporting paths are tested. The appointment certificate, signed, filed, verifiable. The entire onboarding process is kept as a versioned file in the workspace so that a later supervisory audit can completely reconstruct when which order was placed. Anyone planning a DACH setup should also check whether other representative roles such as information security, money laundering or whistleblower protection can be managed in the same platform in order to consolidate the reporting lines to the corporate board and save audit effort across all representative roles.
FAQ
Can we appoint a single data protection officer for Germany, Austria and Switzerland?
Yes, Art. 37 Para. 2 GDPR allows a group order for Germany and Austria. For Switzerland, the person can be used as a data protection advisor in accordance with Art. 10 revDSG. The prerequisite is verifiable accessibility in every national language and jurisdiction as well as a separate notification to the respective supervisory authority, in particular to the DSB Vienna via the company service portal.
What is the deadline for data breaches in Switzerland compared to the GDPR?
Art. 33 GDPR requires 72 hours from knowledge. Art. 24 revDSG requires a report to the FDPIC as soon as possible, but only if the risk is likely to be high. The threshold in Switzerland is higher, but the deadline is more vague. In practice, a 72-hour line is also recommended in Switzerland, documented with a written risk assessment as to whether a report is necessary or not.
Does a DPO order have to be reported to the Austrian data protection authority in Vienna?
Yes, every Austrian subsidiary reports its data protection officer to the DSB Vienna via the company service portal. This also applies to a central DACH order; the function is then stored with a German address and accessibility in Austria is proven. The advertisement contains name, contact details and availability times in German and is updated with every personnel change in order to keep the supervisory inventory correct.
What distinguishes a data protection consultant according to revDSG from a data protection officer according to GDPR?
The data protection advisor according to Art. 10 revDSG is voluntary, but has the advantage that a DPIA does not necessarily have to be presented to the FDPIC if the risk is high. The GDPR obligation to order a DSB for extensive data processing does not apply accordingly in Switzerland. A DPO function from the EU can also act as a Swiss data protection advisor, provided that availability and expertise are documented.
What fines are threatened in the three DACH countries?
GDPR fines range up to 20 million euros or 4% of group sales, in Germany and Austria alike. The Swiss revDSG provides for fines of up to 250,000 CHF, but personally against the natural person responsible, not against the company. Experience has shown that this personal liability in Switzerland is a stronger driver of a clean position in corporations than the company-related EU fines.
How quickly can CIVAC set up a DACH DSB structure?
The standard setup takes two business days. CIVAC creates appointment certificates for each jurisdiction, establishes the reporting line to the top management and sets up a consolidated incident path. Either an internal representative with a workspace licence or an externally appointed CIVAC representative then takes over the ongoing function. Training for local managers is included in the standard package, as is an onboarding workshop for IT and human resources with country-specific mandatory content.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.