77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Data protection officer in small businesses: When the obligation to order applies
Data Protection & Privacy

Data protection officer in small businesses: When the obligation to order applies

20 August 202612 min readBy Lena Vogt
CIVAC

The obligation to appoint a data protection officer can also apply to fewer than 20 people. Which thresholds, activities and types of processing make the difference and how small companies document the order clearly.

Since November 26, 2019, the threshold for the national obligation to appoint a data protection officer in accordance with Section 38 (1) BDSG has been 20 people who are constantly involved in the automated processing of personal data. In practice, this boundary, which is clear at first glance, regularly leads to misjudgments because it applies independently of Art. 37 GDPR and regardless of additional obligations in risk processing. Small and medium-sized companies below this threshold often assume that they do not have to appoint a data protection officer and in doing so overlook the parallel facts under Union law as well as the German special rule for processing with particular risk and for the commercial transfer of personal data.

This article explains which number of employees is actually counted, when a data protection impact assessment triggers the obligation to appoint, how an appointment document is formulated in a small company, what content the supervisory report contains, what special protection rules apply to the internal representative and what consequences a violation of Art. 83 GDPR entails. CIVAC is a compliance platform and officer-as-a-service that maps these audits, ordering and ongoing documentation into an audit-proof workspace with EU data residency, including the 490 audit templates, reporting line to management and verifiable versioning of every change across the entire ordering lifecycle.

Key Takeaways

  • The 20-person threshold according to Section 38 Paragraph 1 BDSG applies in addition to the triggers under Union law from Article 37 Paragraph 1 GDPR, not as an alternative.
  • Processing that is subject to a data protection impact assessment in accordance with Art. 35 GDPR triggers the order obligation regardless of the number of employees.
  • The order must be made in writing, documented and communicated to the supervisory authority in accordance with Article 37 (7) GDPR.

The threshold of Section 38 BDSG: 20 people, permanently employed

Section 38 Paragraph 1 BDSG obliges those responsible and processors in Germany to appoint a data protection officer if they usually employ at least 20 people on a permanent basis with the automated processing of personal data. What is important is not the total number of employees, but the number of people who regularly deal with data processing. Full-time, part-time, mini-job, trainees, working students and freelancers count equally as long as they process personal data automatically. The count is carried out regardless of employment law status and, in the event of a dispute, can be verified by the personnel file and the list of activities.

Anyone who maintains an email inbox, uses a CRM, writes invoices, reviews applications, runs an ordering system or operates a cash register system with customer cards processes personal data in accordance with the standard. In a typical craft business with an office, accounting and field service, the threshold is reached more quickly than the number of employees on the payroll suggests. Even part-time employees with occasional access to CRM are regularly involved and therefore count. Anyone who acts as an external data protection officer or appoints an internal DPO must clearly document the count and update it at regular intervals, at least annually.

The wording generally requires an average assessment over the financial year. Seasonal peaks, such as in retail or agriculture, do not change the threshold if staffing levels are significantly lower outside of the season. Conversely, deliberately splitting up activities among 19 people does not protect against the obligation if more people actually work with data. Constructive attempts at circumvention are regularly viewed by supervisory authorities as circumvention abuse and do not lead to an exemption from the ordering obligation, but rather to a tightening of the sanction. The appointment certificate, signed, filed, verifiable. The platform records the staffing level in an audit-proof manner and automatically alerts you when the threshold is exceeded.

Art. 37 GDPR: Obligation to order regardless of the number of employees

In addition to Section 38 BDSG, Art. 37 Para. 1 GDPR applies, which links the appointment of a data protection officer to three facts: processing by authorities or public bodies, core activity with extensive regular and systematic monitoring of individuals and core activity with extensive processing of special categories of personal data in accordance with Art. 9 GDPR or personal data about criminal convictions and offenses in accordance with Art. 10 GDPR. These facts apply regardless of the number of employees or company size and cannot be definitively modified by the BDSG threshold.

In concrete terms, this means: A private practice with five people that keeps patient files electronically falls under Article 37 (1) (c) GDPR. A security service provider with twelve employees who offers video surveillance as a core business falls under lit. b. Even a small tracking or profiling service provider, an online consulting service with health data, a detective agency, a recruiting provider with AI-supported pre-selection or an online medical service may be required to order despite having fewer than 20 employees. The interpretation of the terms core activity and extensive is based on the WP 243 guidelines of the European Data Protection Board, which are relevant for German supervisory practice and ensure coherent application in the internal market via Art. 70 GDPR.

If you are a small business and want to check whether one of these thresholds applies, you should use the list of processing activities according to Art. 30 GDPR as a starting point. Each activity is checked for sensitivity, group of people, scope, frequency, duration and geographical scope. Others run compliance like a filing cabinet. We run it like software. The CIVAC workspace connects the directory with the order requirement check and automatically sounds an alarm if new processing meets a GDPR requirement. The audit is stored in a structured questionnaire, which is countersigned by the management and, in the event of an audit, makes the decision-making process completely understandable, supplemented by the reasons and effective date.

Data protection impact assessment as an additional trigger

§ 38 Para. 1 Sentence 2 BDSG adds a risk component to the 20-person threshold: If a company carries out processing that is subject to a data protection impact assessment in accordance with Art. 35 GDPR, or processes personal data for commercial purposes for the purpose of transmission, anonymized transmission or for the purpose of market and opinion research, the obligation to order applies regardless of the number of employees. This rule is often overlooked in practice and is a common stumbling block, especially in young, data-intensive business models, which regularly comes to light in supervisory procedures.

The list of processing operations that require a DPIA results from Art. 35 Para. 3 GDPR and the so-called black lists of the German supervisory authorities. These include, among other things: systematic profiling with legal effect, processing of special categories on a large scale, systematic monitoring of publicly accessible areas, credit ratings, large patient record systems, biometric identification and certain AI-supported evaluations of employee data. A small business with time recording using fingerprints, an AI-supported application pre-selection, a recommendation system based on customer profiles or location tracking of delivery fleets can be immediately affected here.

The DPIA itself is an independent mandatory process that does not replace the order, but rather requires it, because according to Art. 35 Para. 2 GDPR it is mandatory to consult the DPO when drawing up the DPIA. Anyone who does not recognise the obligation to order usually does not have a clean DPIA, which can be punished twice in the event of a supervisory inspection. In the CIVAC workspace, the DPIA template is part of the 490 audit templates, and the order obligation check runs automatically with each new processing entry, which technically secures and documents the DSB's obligation to consult. The result is a continuous track from risk identification through consultation to residual risk acceptance by management, including version status and effective date.

Who can be appointed: internal or external data protection officer

Art. 37 Paragraph 5 GDPR requires the data protection officer to have professional qualifications, specialist knowledge in the field of data protection law and data protection practice and the ability to fulfil the tasks listed in Article 39 GDPR. Section 38 (2) BDSG refers to Section 6 BDSG, which regulates the position of the public DPO and thus in fact also sets standards for the private sector. The law does not require formal certification, but it is often required in supervisory practice, particularly for processing operations with particular risks or for larger companies with a multi-level organisation. Industry-specific knowledge, for example in the health, finance or telecommunications sector, must also be proven.

Small companies are faced with a business decision: Internal appointment means qualifying a person from the portfolio, releasing them, continuously training them and observing special dismissal protection rules according to Section 6 Paragraph 4 BDSG, which provide for extended dismissal protection up to one year after the end of the appointment. External DPO means appointing a technically qualified person from a compliance platform and officer-as-a-service who acts independently, without instructions and without a conflict of interest, with a written representation regulation and with clearly defined response times. Licence the workspace for your internal representatives or have our representatives appoint them.

Conflicts of interest must be expressly avoided in accordance with Art. 38 Para. 6 GDPR. Managing directors, IT managers, human resources managers, marketing managers and sales managers are generally not allowed to be data protection officers at the same time, as they have a say in the purposes and means of processing. In very small companies, this conflict almost inevitably leads to an external solution because otherwise the functions cannot be separated. The order is documented with an appointment certificate, provided with a written reporting line to management and supplemented by a resource commitment for training, time budget and tools, which prove in the event of an audit that the function can actually be carried out.

Appointment certificate, reporting line and report to the supervisory authority

The appointment of the data protection officer is made in writing. The contents of the appointment certificate are: Name and contact details of the appointed person, date of the order, scope of tasks in accordance with Art. 39 GDPR, reporting line to the top management level in accordance with Art. 38 Paragraph 3 GDPR, commitment of resources in accordance with Art. 38 Paragraph 2 GDPR, agreement on confidentiality in accordance with Art. 4 BDSG for internal representatives. Without these points, the order is formally vulnerable and is often viewed as an ineffective order in the fine proceedings.

According to Art. 37 Para. 7 GDPR, the name and contact details of the DPO must be communicated to the responsible supervisory authority and kept publicly available, usually in the legal notice or on a data protection page. In most federal states, the report is made via an online form from the state data protection authority with a confirmation email and transmission protocol. An order without notification does not formally fulfil the obligation and is viewed in the fine procedure as an independent violation, which is cumulated with the violation of the ordering obligation.

The auditor calls, the evidence is ready. In the CIVAC workspace there is a standardised template for the order that contains all of the mandatory content mentioned and is automatically integrated into the management's digital compliance cockpit via the reporting line. The notification to the supervisory authority is archived with the transmission protocol, confirmation of receipt and version status. Changes, dismissals and successors are also documented in a versioned manner, which can be a relief in later fine proceedings and ensures that there are no gaps in the event of a handover between the internal and external DPO. Deadline begins as soon as we become aware of it. The workspace sets the deadlines for reporting and publishing automatically.

What does the breach of duty cost: fine limits and supervisory practice

A breach of the ordering obligation is punishable by a fine of up to 10 million euros or 2 percent of the global annual turnover of the previous financial year in Art. 83 Para. 4 lit. a GDPR, whichever is higher. Section 41 BDSG also refers to the law on administrative offenses and enables the application of Section 30 OWiG to legal entities. In the supervisory practice of the German data protection authorities, the obligation to order is a frequently examined aspect, often as an accompanying finding when investigating other incidents such as a data breach according to Art. 33 GDPR or a complaint according to Art. 77 GDPR.

The amount of the specific fines imposed varies considerably. Small companies that make up for the order at short notice, cooperate and have no further violations are often charged four-digit to low five-figure amounts. In the case of systematic failures, combined with violations of Articles 5, 6, 13, 30 or 32 GDPR, the amounts quickly rise into the six-figure range. The list of published fine decisions by the supervisory authorities shows this range and is publicly comprehensible via the activity reports of the state authorities.

There are also reputational risks because fine decisions are often made public. Contractual partners, especially large customers with their own order processing contracts, are increasingly demanding proof of the order. Anyone who has to tick in the purchasing questionnaire that no DPO has been named, even though this is mandatory, is often eliminated from the award process. Audit-proof, documented, § 38 BDSG-proof. This exact evidence can be pulled from the workspace in minutes, including the appointment certificate, supervisory report and reporting line. The costs of a clean order are clearly disproportionate to the risk of fines and reputational risk.

The mandatory process in action: step by step

The operational implementation of the ordering obligation in small businesses can be clearly structured in seven steps. First: Recording of all persons who are constantly involved in the automated processing of personal data in an updated list with function, scope of employment, data categories and access rights. Second: Comparison against the 20-person threshold with an average analysis over twelve months, documented in a comprehensible calculation with quarterly reference dates. Third: Examination of the GDPR facts according to Art. 37 Para. 1 based on the list of processing activities and the WP 243 guidelines of the European Data Protection Board.

Fourth: Examination of whether a data protection impact assessment according to Art. 35 GDPR is required and thus the ordering obligation is triggered via Section 38 Para. 1 Sentence 2 BDSG. Fifth: decision internally or externally, documented with justification, resource calculation and consideration of possible conflicts of interest. Sixth: Appointment with an appointment certificate, task description, reporting line, representation regulations, resource commitment and confidentiality agreement. Seventh: Report to the supervisory authority and publish the contact details in the legal notice or on a data protection page, each with a transmission protocol and confirmation of receipt stored in the workspace.

Each of these steps must be able to be reconstructed in a later test procedure. The platform provides a template, a deadline, a responsibility and an escalation rule for each step. Anyone who orders an external DPO receives the complete mandatory process as a managed service with an SLA of two business days instead of the classic two to six weeks. Anyone who licences the workspace themselves manages the process with their own staff, but with the same template base, with identical versioning and with an audit-proof trace that completely reflects the decision-making process in the event of an audit. The result is the same quality of evidence in both models, with the difference that in the service model the operational responsibility lies externally.

Common mistakes in practice

Three types of errors dominate supervisory proceedings against small businesses. Firstly, the headcount, which does not count part-time, mini-jobs and freelancers. If you have an office worker, two field staff, a working student, an external accountant with system access and several part-time employees in a sales office, formally there can be more than 20 people, although the perceived workforce seems smaller. The count must be objectively documented and based on a reference date in conjunction with an average calculation, ideally updated annually.

Secondly, the assumption that the managing director or IT manager can also be the DPO. Art. 38 Para. 6 GDPR prohibits conflicts of interest. Anyone who decides on ends and means cannot simultaneously control themselves. Supervisory authorities have punished this conflict several times, sometimes with explicit reference to the self-audit bans and with the additional accusation of ineffective appointments. In very small structures, external appointment is often the only legally secure option because the functions cannot be separated otherwise and the dual role would not be formally permissible.

Thirdly, the incomplete appointment certificate, which contains a name but no task description, no promise of resources, no reporting line and no confidentiality agreement. In the event of a dispute, such a document is not a valid order within the meaning of the GDPR and leads to double liability: violation of the order obligation and violation of the documentation obligation according to Art. 5 Para. 2 GDPR. Anyone who uses templates from the Internet should check their legal status and ensure at least a reference to Articles 38 and 39 GDPR. In the CIVAC workspace, the template is part of the 490 audit templates and is automatically updated in a versioned manner with every legal change, with a change log, effective date and reference to affected existing orders.

Turn reading into an assignment

The obligation to appoint a data protection officer in small companies is neither a marginal question nor a pure mathematics of the number of employees. It is the interface between Section 38 BDSG, Art. 37 GDPR and Art. 35 GDPR, and in the event of an audit it decides whether the remaining data protection obligations could even be reliably documented. A fine limit of up to 10 million euros or 2 percent of group sales is in proportion to the manageable costs of a clean order and continuously maintained documentation. Anyone who works in a structured manner not only reduces the risk of sanctions, but also the effort involved in order processing contracts with major customers, who increasingly require proof in their purchasing questionnaires. The order is not only mandatory, but also a requirement for market access in B2B business with demanding procurement processes.

CIVAC is a compliance platform and officer-as-a-service. Licence the workspace for your internal representatives and carry out the order obligation check, appointment certificate, reporting line, supervisory report and directory in accordance with Art. 30 GDPR in an audit-proof system with EU data residency. Or have our officers appointed and hand over the complete mandatory process as a managed service with an SLA of two business days. In both cases, the 490 audit templates, the directory according to Art. 30 GDPR and the reporting channels are stored in a central workspace, and the reporting line to management is technically mapped, with escalation rules and versioning.

If you want to check whether your own organisation is subject to the order requirement, write to info@civac.de or use the contact form on civac.de/faq. We check the number of employees, directory and DPIA requirements and provide a written assessment with an order recommendation, an effort estimate and a roadmap for the first 30 days, including specific responsibilities and milestones. Turn reading into an assignment.

FAQ

How many people does a small business have to appoint a data protection officer?

The national threshold according to Section 38 Paragraph 1 BDSG is generally 20 people who are constantly involved in the automated processing of personal data. Regardless of this, Art. 37 Para. 1 GDPR applies to core activities with extensive monitoring or with special categories of personal data, even for fewer than 20 people.

Do mini-jobbers and freelancers count towards the 20-person threshold?

Yes. What is important is not the employment status, but rather the constant concern with the automated processing of personal data. Full-time, part-time, mini-jobs, trainees, working students and freelancers are counted equally, provided they regularly process personal data. The counting is carried out independently of the employment contract; the actual activity on the system is decisive. External accountants with permanent access to the system are also included in the calculation.

Can the managing director of a small company himself be a data protection officer?

No. Art. 38 Para. 6 GDPR prohibits conflicts of interest. Anyone who has a say in the purposes and means of processing cannot also control themselves. This typically applies to managing directors, IT, human resources, sales and marketing management. In very small structures, external ordering is usually the legally secure solution because the functions cannot be separated in any other way. Supervisory authorities regularly punish this conflict as an ineffective order.

What content must an appointment certificate contain at least?

Name and contact details of the appointed person, date of appointment, task description according to Art. 39 GDPR, reporting line to the top management level according to Art. 38 Para. 3 GDPR, resource commitment according to Art. 38 Para. 2 GDPR, confidentiality agreement and a representation regulation. For internal representatives, the special protection against dismissal in accordance with Section 6 Paragraph 4 BDSG is added. Without these points, the order is formally vulnerable.

How much does a violation of the ordering obligation cost?

Article 83 (4) (a) GDPR provides for fines of up to 10 million euros or 2 percent of global annual turnover, whichever is higher. Small companies are often penalized in the low four to five figure range. Systematic violations in conjunction with further breaches of duty can result in six-figure amounts, as well as reputational consequences for major customers.

How quickly can an external data protection officer be appointed?

Through CIVAC's compliance platform and officer-as-a-service, the order is placed within a two-business-day SLA, including appointment certificate, reporting line, supervisory notification and inclusion in the EU data residency workspace. Classic market processes often take two to six weeks, without improving the quality of documentation. In the service model, CIVAC also bears operational responsibility for the function.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles